SME – Information Security Analyst DoS CSS

onezerollc

Washington (District of Columbia)

Remote

USD 120,000 - 160,000

Full time

6 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Health insurance
Dental insurance
Vision insurance
Life insurance
401(k) with company matching
Paid time off
Paid holidays
Employee referral program
Educational assistance

Job summary

OneZero LLC is actively seeking an experienced SME – Information Security Analyst to lead RMF compliance for high-value systems. This role, remote within the National Capital Region, requires deep ISSO expertise, federal standards proficiency, and a final SECRET clearance.

You will oversee categorization, control selection, and authorization packages, mentor junior analysts, and coordinate with SOC and audit teams to maintain secure operations in a cloud/hybrid environment.

Qualifications

  • Ten or more years in information security, incl. six+ years as ISSO or A&A lead for federal systems.
  • Expert knowledge of NIST SP 800-37 Rev. 2, SP 800-53/53A Rev. 5, SP 800-60, SP 800-34, FIPS 199/200; able to author complete authorization packages.
  • Experience as ISSO for High-baseline or HVA systems, or for cloud/hybrid boundaries.
  • Current CISSP (or CISM, or CGRC/CAP with CISSP within 12 months).
  • Active, final SECRET clearance; U.S. citizenship.
  • Experience managing POA&M and authorization packages in a GRC tool.
  • Excellent technical writing; able to produce government-ready artifacts with minimal editing.

Responsibilities

  • Serve as ISSO of record for ~3–4 complex systems.
  • Lead RMF Steps 1–3 with categorization and control selection.
  • Develop and maintain the full authorization artifact set.
  • Lead Security Control Review Meetings with the assessor.
  • Direct system security operations contractors to obtain evidence and remediate.
  • Maintain POA&M in the GRC tool with monthly updates.
  • Review iPost scores and remediate findings over 30 days.
  • Review vulnerability scans and address high-risk items within timelines.
  • Plan annual Contingency Plan tests and Control Assessments.
  • Coordinate with SOC and IR teams on incidents and update RMF artifacts.
  • Mentor analysts and review artifacts for accuracy.

Skills

ISSO leadership
NIST RMF
SECRET clearance
Technical writing
GRC tools
Vulnerability management
Security governance

Education

Bachelor's degree in CS/IT/Cybersecurity
Master's degree (preferred)
Experience in lieu of degree

Tools

Tenable
Wiz
Visio
MS Word
MS Excel

Job description

We are an employee-centric company that truly values our team members and the contributions they make to our customers and the missions they support. We pride ourselves on being forward-leaning thinkers and on building teams that are, and continue to be, technically proficient across a broad range of cyber mission areas. OneZero full-time employees receive a highly competitive benefits package, including health, dental, vision, and life insurance, a 401(k) with company matching, paid time off and holidays, an employee referral program, and educational assistance. Additional details are available on our website: https://www.onezerollc.com/careers/

Position Title: SME – Information Security Analyst

Location: Remote; must reside within the National Capital Region (NCR).

Work Schedule: Full-time, 40 hours per week. Must be available during Department core hours of 9:00 a.m. – 3:00 p.m. ET, Monday – Friday, and flex working hours as needed to meet CST day-to-day and emergent requirements. No work is performed on Federal holidays or during Government closures.

Employment Type: Full-Time, Exempt (W-2), contingent upon Call Order award

Position Summary

The SME – Information Security Analyst is the program’s most senior ISSO practitioner. The SME serves as ISSO of record for DT/EA/CST’s High Value Assets, High-baseline, cloud/hybrid, and most complex consular systems; leads categorization, control selection, and authorization packages for new and re-authorizing systems; and acts as technical mentor and peer reviewer for the Senior and Information Assurance analysts.

Key Responsibilities
  • Serve as ISSO of record and primary cybersecurity point of contact for an assigned portfolio of approximately 3–4 HVA, High-baseline, or otherwise complex systems.
  • Lead RMF Steps 1–3 for new and re-authorizing systems: FIPS 199 / NIST SP 800-60 categorization with documented CIA justifications; baseline selection and HVA, zero-trust, and cloud overlays; Control Tailoring Rationale; Inherited Controls Matrix; SSP development; Security Plan Approval Recommendation Letter; Evidence Index; and Implementation Readiness Review.
  • Develop and maintain the full authorization artifact set: SSP, Security Control Implementation Statements, PIA, DIRA, ISA/MOU, Security Assessment Plan, POA&M, SIA, system inventory, IRP, CP/ISCP, CP Test reports, and CMP.
  • Lead Security Control Review Meetings and control demonstrations with the independent Security Control Assessor; attend A&A Findings Meetings; support remediation validation; prepare the AODR Information Sheet for risk briefings (RMF Steps 4–5).
  • Direct system-specific security operations contractors to obtain technical evidence and implement remediation; validate closure evidence before POA&M closure.
  • Maintain authoritative POA&M in the GRC tool with monthly updates and updates within 5 business days of status changes; ensure realistic milestones, accurate risk levels, and attached closure evidence (RMF Step 6).
  • Review iPost scores weekly, coordinate remediation of findings contributing to elevated risk, and track and report findings open more than 30 days.
  • Review vulnerability, KEV, CVE, and STIG scan results within 5 business days; ensure critical and high vulnerabilities are addressed within Department and BOD timelines.
  • Plan and conduct annual Contingency Plan tests and Annual Control Assessments for assigned systems; document objectives, scope, results, and lessons learned.
  • Perform Security Impact Analyses for CCB/ECM changes; prepare the Quarterly Configuration and Change Impact Summary.
  • Coordinate with the SOC, incident response teams, and system owners on incidents; support post-incident reviews and update RMF artifacts accordingly.
  • Serve as first line of defense during OIG, GAO, CISA, HVA, BOD, OMB, penetration test, and CDM audits and data calls; maintain the Audit and Data Call Response Package.
  • Develop system retirement memos and POA&M (risk) transfer memos; validate and close POA&M at decommissioning.
  • Mentor Senior and Information Assurance analysts; peer-review artifacts for accuracy, completeness, and Department format compliance.
Required Qualifications
  • Ten (10)+ years of information security experience, including six (6)+ years as an ISSO or A&A lead for federal information systems.
  • Expert working knowledge of NIST SP 800-37 Rev. 2, SP 800-53/53A Rev. 5, SP 800-60, SP 800-34, and FIPS 199/200; demonstrated experience authoring complete authorization packages.
  • Experience as ISSO for High-baseline or HVA systems, or for cloud/hybrid authorization boundaries.
  • Current CISSP (or CISM, or CGRC/CAP with CISSP obtained within 12 months).
  • Active, final SECRET security clearance; U.S. citizenship.
  • Experience managing POA&M and authorization packages in an enterprise GRC tool.
  • Excellent technical writing skills; able to produce Government-ready artifacts with minimal editing.
Preferred Qualifications
  • Master's degree in a related field.
  • Department of State (DT/CA/CST) experience; ArchAngel and iPost proficiency.
  • CISA, CRISC, or CCSP certification.
  • Experience with FedRAMP inheritance, DevSecOps pipeline controls, and Privacy (PIA) / Digital Identity (DIRA, NIST SP 800-63) assessments.
Technical Skills
  • NIST RMF end to end; SSP, SAR, POA&M, SIA, CP/ISCP, IRP, CMP, PIA, DIRA, ISA/MOU authoring.
  • GRC platforms (ArchAngel or equivalent), iPost or equivalent risk scoring, CDM data.
  • Interpretation of Tenable and Wiz vulnerability/compliance results, KEV reports, STIG scans, and penetration test findings.
  • Visio boundary and data-flow diagramming; advanced Word/Excel for artifact and metrics production.
Education

Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field, or an additional four (4) years of directly relevant ISSO experience in lieu of degree.

Remote/Hybrid/On-site and any other relevant work-environment requirement

Remote. Duties are performed remotely; the selected candidate must reside within the National Capital Region (NCR). The Government does not furnish equipment; OneZero provides the laptop and collaboration tools. Position requires an OpenNet account, DoS PIV badge, multifactor authentication, and adherence to DoS SBU/CUI handling requirements. Local travel within the National Capital Region; minimal other travel.

Position Status

New Position, contingent upon Call Order award

OneZero Solutions LLC is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or protected veteran status.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

SME – Information Security Analyst DoS CSS
SME – Information Security Analyst DoS CSS

OneZero Solutions • Washington

Remote
USD 150,000 - 190,000
Health insurance
Dental insurance
Vision insurance
+6
Information Assurance Analyst DoS CSS
Information Assurance Analyst DoS CSS

OneZero Solutions • Washington

Remote
USD 85,000 - 110,000
Health insurance
Dental insurance
Vision insurance
+6
Senior Information Security Analyst DoS CSS
Senior Information Security Analyst DoS CSS

OneZero Solutions • Washington

Remote
USD 110,000 - 170,000
Health, dental, vision, life insurance
401(k) with company matching
Paid time off and holidays
+2
Senior Information Security Analyst DoS CSS
Senior Information Security Analyst DoS CSS

OneZero Solutions • Washington

Remote
USD 110,000 - 150,000
Information Assurance Analyst DoS CSS
Information Assurance Analyst DoS CSS

OneZero Solutions • Washington

Remote
USD 120,000 - 160,000
Health insurance
Dental insurance
Vision insurance
+6
ISSO Lead DoS CSS
ISSO Lead DoS CSS

onezerollc • Washington

Remote
USD 120,000 - 180,000
ISSO Lead DoS CSS
ISSO Lead DoS CSS

OneZero Solutions • Washington

Remote
USD 140,000 - 190,000
Health insurance
Dental insurance
Vision insurance
+5
Program Manager DoS CSS
Program Manager DoS CSS

OneZero Solutions • Washington

Remote
USD 150,000 - 210,000
Health, dental, vision, life insurance
401(k) with company matching
Paid time off and holidays
+2
Deputy Program Manager DoS CSS
Deputy Program Manager DoS CSS

OneZero Solutions • Washington

Remote
USD 120,000 - 160,000
Health insurance
Dental insurance
Vision insurance
+5
Technical Writer DoS CSS
Technical Writer DoS CSS

onezerollc • Washington

Remote
USD 95,000 - 130,000
Health insurance
Dental insurance
Vision insurance
+6