SME – Information Security Analyst DoS CSS

OneZero Solutions

Washington (District of Columbia)

Remote

USD 150,000 - 190,000

Full time

6 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Health insurance
Dental insurance
Vision insurance
Life insurance
401(k) with company matching
Paid time off
Holidays
Employee referral program
Educational assistance

Job summary

OneZero Solutions LLC is seeking an experienced SME – Information Security Analyst to serve as ISSO of record for high-value assets and cloud/hybrid systems. You will lead RMF steps, develop and maintain authorization artifacts, and mentor junior analysts.

The role requires a final SECRET clearance, US citizenship, and strong writing and communication skills; remote within NCR and occasional travel.

Qualifications

  • Ten (10)+ years of information security experience, incl. six (6)+ years as an ISSO or A&A lead for federal information systems.
  • Expert working knowledge of NIST SP 800-37 Rev. 2, SP 800-53/53A Rev. 5, SP 800-60, SP 800-34, and FIPS 199/200; experience authoring complete authorization packages.

Responsibilities

  • Serve as ISSO of record for a portfolio of 3–4 HVA or complex systems.
  • Lead RMF Steps 1–3 with proper categorization and control overlays.
  • Develop and maintain full authorization artifacts (SSP, POA&M, etc.).
  • Lead security control review meetings with assessors and track findings.
  • Direct security operations contractors to obtain evidence and remediate.
  • Maintain POA&M in GRC with monthly updates and closures.
  • Review iPost scores and remediate high-risk findings.
  • Monitor vulnerability/KEV/STIG results and address critical items.

Skills

ISSO lead
RMF end-to-end
NIST SP 800-37/53
Security control assessment
POA&M management
Vulnerability management
Technical writing
GRC tooling
CISSP/CISM

Education

Bachelor's degree in CS/IT/Cybersecurity
Master's degree

Tools

ArchAngel
iPost
Tenable
WIZ

Job description

We are an employee-centric company that truly values our team members and the contributions they make to our customers and the missions they support. We pride ourselves on being forward-leaning thinkers and on building teams that are, and continue to be, technically proficient across a broad range of cyber mission areas. OneZero full-time employees receive a highly competitive benefits package, including health, dental, vision, and life insurance, a 401(k) with company matching, paid time off and holidays, an employee referral program, and educational assistance.

Additional details are available on our website: https://www.onezerollc.com/careers/.

Position Title:

SME – Information Security Analyst

Location:

Remote; must reside within the National Capital Region (NCR).

Work Schedule:

Full-time, 40 hours per week. Must be available during Department core hours of 9:00 a.m. – 3:00 p.m. ET, Monday – Friday, and flex working hours as needed to meet CST day-to-day and emergent requirements. No work is performed on Federal holidays or during Government closures.

Employment Type:

Full-Time, Exempt (W-2), contingent upon Call Order award

Position Summary

The SME – Information Security Analyst is the program's most senior ISSO practitioner. The SME serves as ISSO of record for DT/EA/CST's High Value Assets, High-baseline, cloud/hybrid, and most complex consular systems; leads categorization, control selection, and authorization packages for new and re-authorizing systems; and acts as technical mentor and peer reviewer for the Senior and Information Assurance analysts.

Key Responsibilities
  • Serve as ISSO of record and primary cybersecurity point of contact for an assigned portfolio of approximately 3–4 HVA, High-baseline, or otherwise complex systems.
  • Lead RMF Steps 1–3 for new and re-authorizing systems: FIPS 199 / NIST SP 800-60 categorization with documented CIA justifications; baseline selection and HVA, zero-trust, and cloud overlays; Control Tailoring Rationale; Inherited Controls Matrix; SSP development; Security Plan Approval Recommendation Letter; Evidence Index; and Implementation Readiness Review.
  • Develop and maintain the full authorization artifact set: SSP, Security Control Implementation Statements, PIA, DIRA, ISA/MOU, Security Assessment Plan, POA&M, SIA, system inventory, IRP, CP/ISCP, CP Test reports, and CMP.
  • Lead Security Control Review Meetings and control demonstrations with the independent Security Control Assessor; attend A&A Findings Meetings; support remediation validation; prepare the AODR Information Sheet for risk briefings (RMF Steps 4–5).
  • Direct system-specific security operations contractors to obtain technical evidence and implement remediation; validate closure evidence before POA&M closure.
  • Maintain authoritative POA&M(s) in the GRC tool with monthly updates and updates within 5 business days of status changes; ensure realistic milestones, accurate risk levels, and attached closure evidence (RMF Step 6).
  • Review iPost scores weekly, coordinate remediation of findings contributing to elevated risk, and track and report findings open more than 30 days.
  • Review vulnerability, KEV, CVE, and STIG scan results within 5 business days; ensure critical and high vulnerabilities are addressed within Department and BOD timelines.
  • Plan and conduct annual Contingency Plan tests and Annual Control Assessments for assigned systems; document objectives, scope, results, and lessons learned.
  • Perform Security Impact Analyses for CCB/ECM changes; prepare the Quarterly Configuration and Change Impact Summary.
  • Coordinate with the SOC, incident response teams, and system owners on incidents; support post-incident reviews and update RMF artifacts accordingly.
  • Serve as first line of defense during OIG, GAO, CISA, HVA, BOD, OMB, penetration test, and CDM audits and data calls; maintain the Audit and Data Call Response Package.
  • Develop system retirement memos and POA&M (risk) transfer memos; validate and close POA&M(s) at decommissioning.
  • Mentor Senior and Information Assurance analysts; peer-review artifacts for accuracy, completeness, and Department format compliance.
Required Qualifications
  • Ten (10)+ years of information security experience, including six (6)+ years as an ISSO or A&A lead for federal information systems.
  • Expert working knowledge of NIST SP 800-37 Rev. 2, SP 800-53/53A Rev. 5, SP 800-60, SP 800-34, and FIPS 199/200; demonstrated experience authoring complete authorization packages.
  • Experience as ISSO for High-baseline or HVA systems, or for cloud/hybrid authorization boundaries.
  • Current CISSP (or CISM, or CGRC/CAP with CISSP obtained within 12 months).
  • Active, final SECRET security clearance; U.S. citizenship.
  • Experience managing POA&M(s) and authorization packages in an enterprise GRC tool.
  • Excellent technical writing skills; able to produce Government-ready artifacts with minimal editing.
Preferred Qualifications
  • Master's degree in a related field.
  • Department of State (DT/CA/CST) experience; ArchAngel and iPost proficiency.
  • CISA, CRISC, or CCSP certification.
  • Experience with FedRAMP inheritance, DevSecOps pipeline controls, and Privacy (PIA) / Digital Identity (DIRA, NIST SP 800-63) assessments.
Technical Skills
  • NIST RMF end to end; SSP, SAR, POA&M, SIA, CP/ISCP, IRP, CMP, PIA, DIRA, ISA/MOU authoring.
  • GRC platforms (ArchAngel or equivalent), iPost or equivalent risk scoring, CDM data.
  • Interpretation of Tenable and Wiz vulnerability/compliance results, KEV reports, STIG scans, and penetration test findings.
  • Visio boundary and data-flow diagramming; advanced Word/Excel for artifact and metrics production.
Education

Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field, or an additional four (4) years of directly relevant ISSO experience in lieu of degree.

Remote/Hybrid/On-site and any other relevant work-environment requirement

Remote. Duties are performed remotely; the selected candidate must reside within the National Capital Region (NCR). The Government does not furnish equipment; OneZero provides the laptop and collaboration tools. Position requires an OpenNet account, DoS PIV badge, multifactor authentication, and adherence to DoS SBU/CUI handling requirements. Local travel within the National Capital Region; minimal other travel.

Position Status:

New Position, contingent upon Call Order award

OneZero Solutions LLC is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or protected veteran status.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Information Security Analyst DoS CSS
Senior Information Security Analyst DoS CSS

OneZero Solutions • Washington

Remote
USD 110,000 - 170,000
Health, dental, vision, life insurance
401(k) with company matching
Paid time off and holidays
+2
Senior Information Security Analyst DoS CSS
Senior Information Security Analyst DoS CSS

OneZero Solutions • Washington

Remote
USD 110,000 - 150,000
ISSO Lead DoS CSS
ISSO Lead DoS CSS

OneZero Solutions • Washington

Remote
USD 140,000 - 190,000
Health insurance
Dental insurance
Vision insurance
+5
Program Manager DoS CSS
Program Manager DoS CSS

OneZero Solutions • Washington

Remote
USD 150,000 - 210,000
Health, dental, vision, life insurance
401(k) with company matching
Paid time off and holidays
+2
Deputy Program Manager DoS CSS
Deputy Program Manager DoS CSS

OneZero Solutions • Washington

Remote
USD 120,000 - 160,000
Health insurance
Dental insurance
Vision insurance
+5
Information System Security Officer (SME), Level III
Information System Security Officer (SME), Level III

onezerollc • Baltimore (MD)

On-site
USD 120,000 - 180,000
Health insurance
Dental insurance
Vision insurance
+5
Information System Security Officer (SME), Level III
Information System Security Officer (SME), Level III

OneZero Solutions • Baltimore (MD)

On-site
USD 120,000 - 160,000
Health insurance
Dental insurance
Vision insurance
+5
Information Assurance Specialist III
Information Assurance Specialist III

onezerollc • Arlington (VA)

Hybrid
USD 120,000 - 150,000
Health insurance
Dental insurance
Vision insurance
+6
Information Assurance Specialist III
Information Assurance Specialist III

OneZero Solutions • Arlington (VA)

On-site
USD 110,000 - 150,000
Health insurance
Dental insurance
Vision insurance
+5
Cybersecurity SME Level III
Cybersecurity SME Level III

onezerollc • Alexandria (VA)

Hybrid
USD 120,000 - 180,000
Health insurance
Dental insurance
Vision insurance
+4