Open Security Controls Assessment Language (SME) (TS/SCI)

Koniag Services, Inc.

Alexandria (VA)

Hybrid

USD 140,000 - 210,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Health insurance
Dental insurance
Vision insurance
401(k) with company matching
Paid holidays
3 weeks PTO

Job summary

Koniag IT Systems, a Koniag Government Services company, seeks an OSCAL SME with an active TS/SCI to design, implement, and optimize automated security compliance solutions for a federal program in Alexandria, VA. This hybrid role requires 1–4 days onsite weekly.

Responsibilities include developing OSCAL-based artifacts (SSPs, assessment plans, POA&Ms), mapping controls to OSCAL models, supporting ATO workflows, and delivering training and best practices to internal teams and customers.

Qualifications

  • Bachelor’s degree or equivalent work experience in a related field.
  • 15+ years of experience in cybersecurity compliance, security assessment, or risk management.
  • Hands-on expertise with OSCAL schema, XML/JSON/YAML, and validation tools.
  • Deep knowledge of NIST SP-800-53 Rev.5, SP-800-37 Rev.2 RMF, CSF 2.0 and federal standards (FedRAMP, FISMA, DoD RMF).
  • Experience with cybersecurity documentation automation and GRC platforms.
  • Excellent communication and technical writing skills.
  • Ability to work on-site 1-4 days a week.

Responsibilities

  • Serve as the technical expert for OSCAL adoption and integration in federal programs.
  • Develop, validate, and maintain OSCAL-based artifacts (SSPs, plans, POA&Ms).
  • Map security controls to OSCAL models and align with NIST standards.
  • Support automation of ATO/authorization workflows with GRC tools.
  • Collaborate with owners, assessors, and compliance teams to improve efficiency.
  • Deliver training and best practices on OSCAL adoption.
  • Stay current with OSCAL standards and federal policy changes.

Skills

OSCAL
NIST RMF
Cybersecurity compliance
Technical writing
Communication

Education

Bachelor's degree in Cybersecurity/Info Systems/Computer Science

Tools

OSCAL tooling
GRC platforms
CI/CD pipelines

Job description

Open Security Controls Assessment Language (SME) (TS/SCI)
Job Description

Posted Friday, July 24, 2026 at 4:00 AM

Koniag IT Systems, a Koniag Government Services company, is seeking an Open Security Controls Assessment Language SME with an active TS/SCI to support KITS and our government customer at the Mark Center, Alexandria, VA. This is a hybrid opportunity that requires 1-4 days of onsite work.

We offer competitive compensation and an extraordinary benefits package including health, dental, and vision insurance, 401K with company matching, flexible spending accounts, paid holidays, three weeks paid time off, and more.

We are seeking an experienced Open Security Controls Assessment Language (OSCAL) Subject Matter Expert (SME) to support the design, implementation, and optimization of automated security compliance and risk management solutions. The OSCAL SME will play a critical role in advancing our cybersecurity compliance initiatives by enabling machine-readable security documentation, enhancing interoperability, and streamlining authorization processes across multiple federal frameworks.

Essential Functions, Responsibilities & Duties may include, but are not limited to:

  • Serve as the technical expert for OSCAL adoption, implementation, and integration within federal compliance programs (e.g., FedRAMP, NIST RMF, DoD).
  • Develop, validate, and maintain OSCAL-based artifacts, including system security plans (SSPs), assessment plans, assessment results, and POA&M packages.
  • Provide guidance on mapping security controls to OSCAL models and ensuring alignment with NIST standards.
  • Support automation of ATO/authorization workflows by integrating OSCAL with governance, risk, and compliance (GRC) tools.
  • Collaborate with system owners, security assessors, and compliance teams to improve efficiency in security control assessment and reporting.
  • Deliver training, documentation, and best practices to internal teams and customers on OSCAL adoption.
  • Provide support and recommendations for the Department of Defense OSCAL standards development.
  • Stay current with OSCAL federal policy changes and industry adoption trends.

Qualifications

Required:

  • TS/SCI security Clearance required.
  • Bachelor's degree in Cybersecurity, Information Systems, Computer Science, or related field (or equivalent work experience).
  • 15+ years of experience in cybersecurity compliance, security assessment, or risk management.
  • Hands-on expertise with OSCAL schema, XML/JSON/YAML, and associated validation tools.
  • Deep knowledge of NIST frameworks (NIST SP-800-53 Rev. 5, NIST SP-800-37 Rev. 2 RMF, NIST Cybersecurity Framework [CSF 2.0]) and federal compliance standards (e.g., FedRAMP, FISMA, DoD RMF [DoDI 8510.01]).
  • Experience with cybersecurity documentation automation and Governance, Risk, and Compliance (GRC) platforms.
  • Excellent communication and technical writing skills.
  • Ability to work on-site 1-4 days a week.

Preferred:

  • Experience of contributing to or collaborating with the NIST OSCAL community.
  • Familiarity with DevSecOps pipelines, CI/CD automation, and security-as-code practices.
  • Understanding of cloud service provider (CSP) compliance processes (AWS, Azure, GCP, etc.).
  • Active security certification (e.g., CISSP, CISM, CAP, CCSP).

Our Equal Employment Opportunity Policy

The company is an equal opportunity employer. The company shall not discriminate against any employee or applicant because of race, color, religion, creed, ethnicity, sex, sexual orientation, gender or gender identity (except where gender is a bona fide occupational qualification), national origin or ancestry, age, disability, citizenship, military/veteran status, marital status, genetic information or any other characteristi c protected by applicable federal, state, or local law. We are committed to equal employment opportunity in all decisions related to employment, promotion, wages, benefits, and all other privileges, terms, and conditions of employment.

The company is dedicated to seeking all qualified applicants. If you require an accommodation to navigate or apply for a position on our website, please get in touch with Heaven Wood via e-mail at accommodations@koniag-gs.com or by calling 703-488-9377 to request accommodations.

Koniag Government Services (KGS) is an Alaska Native Owned corporation supporting the values and traditions of our native communities through an agile employee and corporate culture that delivers Enterprise Solutions, Professional Services and Operational Management to Federal Government Agencies. As a wholly owned subsidiary of Koniag, we apply our proven commercial solutions to a deep knowledge of Defense and Civilian missions to provide forward leaning technical, professional, and operational solutions. KGS enables successful mission outcomes for our customers through solution-oriented business partnerships and a commitment to exceptional service delivery. We ensure long-term success with a continuous improvement approach while balancing the collective interests of our customers, employees, and native communities. For more information, please visit www.koniag-gs.com.

Equal Opportunity Employer/Veterans/Disabled.Shareholder Preference in accordance with Public Law 88-352

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Control Accessor
Security Control Accessor

Koniag Government Services • Washington

Hybrid
USD 120,000 - 180,000
Health, dental, and vision insurance
401K with company matching
Flexible spending accounts
+2
Compliance & Audit Support - Jr.
Compliance & Audit Support - Jr.

Koniag Services, Inc. • Washington, Northern (KY)

Hybrid
USD 55,000 - 75,000
Health, dental, and vision insurance
401K with company matching
Flexible spending accounts
ISSO/Control Evaluator - High/Senior
ISSO/Control Evaluator - High/Senior

Koniag Services, Inc. • Washington, Northern (KY)

Hybrid
USD 120,000 - 180,000
Health, dental, vision insurance
401K with company match
Paid holidays
+1
Compliance & Audit Support - Jr.
Compliance & Audit Support - Jr.

Koniag Government Services • Washington

Hybrid
USD 65,000 - 85,000
Health, dental, and vision insurance
401K with company matching
Flexible spending accounts
+2
Security Engineer
Security Engineer

Koniag Services, Inc. • Washington, Northern (KY)

Hybrid
USD 110,000 - 140,000
Health insurance
401K with company matching
Paid holidays
+1
Jr DevSecOps Engineer
Jr DevSecOps Engineer

Koniag Services, Inc. • Washington, Northern (KY)

Hybrid
USD 65,000 - 90,000
Health, dental, and vision insurance
401K with company matching
Flexible spending accounts
+2
ISSO/Control Evaluator – Low
ISSO/Control Evaluator – Low

Koniag Services, Inc. • Washington

On-site
USD 70,000 - 110,000
Health insurance
Dental insurance
Vision insurance
+4
Cyber Defense Analysts – Senior
Cyber Defense Analysts – Senior

Koniag Government Services • Washington

On-site
USD 140,000 - 190,000
Medical, dental, vision insurance
401(k) retirement plan
Paid time off
Jr DevSecOps Engineer
Jr DevSecOps Engineer

Koniag Government Services • Washington

Hybrid
USD 65,000 - 90,000
Health insurance
401K with company match
Flexible spending accounts
+2
Deputy Program Manager
Deputy Program Manager

Koniag Government Services • Washington

Hybrid
USD 120,000 - 170,000
Medical
Dental
Vision
+8