CybersecurityJobs.io
← Back to all jobs

Job Description

Support an INSCOM cybersecurity mission from Ft. Meade with SMX as a Cybersecurity SME Senior. This onsite role focuses on keeping DoD/IC systems operating through disciplined ISSO execution, continuous monitoring, and assessment and accreditation support, including active management of eMASS and POA&M records to help maintain ATO.

Compensation for this position is USD 140,000 - 175,000 per year. You will join a team operating under established DoD frameworks and standards, working closely with government stakeholders while leading security control validation, reporting, and security documentation.

Responsibilities

  • Perform the duties of an Information System Security Officer (ISSO) in accordance with AR 25-2, DA 25-2-14, and NIST SP 800-53 security controls when ISSO personnel are organizationally-defined.
  • Actively manage the organization’s eMASS records, including validating security controls and associated artifacts.
  • Assess security scan results and STIGs as required.
  • Perform POA&M updates, tracking, and resolution activities.
  • Lead continuous monitoring efforts for the organization’s security controls.
  • Manage day-to-day activities and the professional development of Cybersecurity Analysts.
  • Collaborate with the O-ISSM on assessment and authorization activities to support ATO on applicable DoD/IC networks.
  • Maintain up-to-date status on assigned systems and communicate status to government leads, including complete records of communications and written status reporting as required.
  • Conduct peer-review and attend weekly meetings.
  • Coordinate with government system administrators and the customer to communicate unacceptable risks and drive corrective actions for deficient POA&M items to meet DoD and IC standards.
  • Coordinate with the Security Control Assessor (SCA) to analyze the system’s overall risk level to enterprise networks and mission data.
  • Create and maintain cybersecurity policies and standards, ensuring plans, controls, processes, standards, policies, and procedures remain aligned with cybersecurity standards.
  • Ensure security scans and STIG checklists are updated per DA G2 policy.
  • Produce actionable, risk-based reports from security assessment results and assist with vulnerability remediation when necessary.
  • Develop and maintain security plans and security testing plans, and periodically update risk models, metrics, reports, processes, and activities to stay compliant with evolving DoD and IC standards.
  • Ensure the user community understands and follows procedures needed to maintain the security posture of information systems.
  • Provide guidance on creation and maintenance of SOPs, Tactics, Techniques, and Procedures (TTPs), and related documentation.

Requirements

  • PhD in a STEM field with cybersecurity professional experience, or Master’s in a STEM field with cybersecurity professional experience, or Bachelor’s in a STEM field with cybersecurity professional experience.
  • Active TS security clearance and eligible for SCI and NATO read-on prior to starting work.
  • Meet DoD requirements for a privileged user on a TS/SCI information system prior to starting work.
  • Meet DoD 8570 level III certification compliance, including one of: CASP+ CE, CCNP Security, CISA, CISSP (or Associate), GCED, GCIH, CCSP.
  • Experience with assessment and accreditation activities of national security systems (NSSs).
  • Experience validating system security controls.
  • Experience with vulnerability management.
  • Experience with DISA STIGs, DISA SRG, and vendor-specific security guides.
  • Experience with RMF and eMASS.
  • Experience with POA&M tracking and resolution.
  • Experience performing continuous monitoring of system security controls.

Desired Skills & Experience

  • 10 years experience as an ISSO on Army Intel programs.
  • 2 years experience with AC2SP tenant assessment and accreditation activities.

Tech Stack

  • AR 25-2, DA 25-2-14, NIST SP 800-53
  • eMASS, POA&M, STIGs, DA G2 policy
  • DoD/IC, RMF
  • DISA Security Technical Implementation Guides (STIGs), DISA Security Requirements Guide (SRG)
  • CASP+ CE, CCNP Security, CISA, CISSP (or Associate), GCED, GCIH, CCSP
  • SOPs, Tactics, Techniques, and Procedures (TTPs)
  • AC2SP tenant

Application deadline: November 30, 2026

Similar Jobs