Cybersecurity SME Senior
Job Description
Support an INSCOM cybersecurity mission from Ft. Meade with SMX as a Cybersecurity SME Senior. This onsite role focuses on keeping DoD/IC systems operating through disciplined ISSO execution, continuous monitoring, and assessment and accreditation support, including active management of eMASS and POA&M records to help maintain ATO.
Compensation for this position is USD 140,000 - 175,000 per year. You will join a team operating under established DoD frameworks and standards, working closely with government stakeholders while leading security control validation, reporting, and security documentation.
Responsibilities
- Perform the duties of an Information System Security Officer (ISSO) in accordance with AR 25-2, DA 25-2-14, and NIST SP 800-53 security controls when ISSO personnel are organizationally-defined.
- Actively manage the organization’s eMASS records, including validating security controls and associated artifacts.
- Assess security scan results and STIGs as required.
- Perform POA&M updates, tracking, and resolution activities.
- Lead continuous monitoring efforts for the organization’s security controls.
- Manage day-to-day activities and the professional development of Cybersecurity Analysts.
- Collaborate with the O-ISSM on assessment and authorization activities to support ATO on applicable DoD/IC networks.
- Maintain up-to-date status on assigned systems and communicate status to government leads, including complete records of communications and written status reporting as required.
- Conduct peer-review and attend weekly meetings.
- Coordinate with government system administrators and the customer to communicate unacceptable risks and drive corrective actions for deficient POA&M items to meet DoD and IC standards.
- Coordinate with the Security Control Assessor (SCA) to analyze the system’s overall risk level to enterprise networks and mission data.
- Create and maintain cybersecurity policies and standards, ensuring plans, controls, processes, standards, policies, and procedures remain aligned with cybersecurity standards.
- Ensure security scans and STIG checklists are updated per DA G2 policy.
- Produce actionable, risk-based reports from security assessment results and assist with vulnerability remediation when necessary.
- Develop and maintain security plans and security testing plans, and periodically update risk models, metrics, reports, processes, and activities to stay compliant with evolving DoD and IC standards.
- Ensure the user community understands and follows procedures needed to maintain the security posture of information systems.
- Provide guidance on creation and maintenance of SOPs, Tactics, Techniques, and Procedures (TTPs), and related documentation.
Requirements
- PhD in a STEM field with cybersecurity professional experience, or Master’s in a STEM field with cybersecurity professional experience, or Bachelor’s in a STEM field with cybersecurity professional experience.
- Active TS security clearance and eligible for SCI and NATO read-on prior to starting work.
- Meet DoD requirements for a privileged user on a TS/SCI information system prior to starting work.
- Meet DoD 8570 level III certification compliance, including one of: CASP+ CE, CCNP Security, CISA, CISSP (or Associate), GCED, GCIH, CCSP.
- Experience with assessment and accreditation activities of national security systems (NSSs).
- Experience validating system security controls.
- Experience with vulnerability management.
- Experience with DISA STIGs, DISA SRG, and vendor-specific security guides.
- Experience with RMF and eMASS.
- Experience with POA&M tracking and resolution.
- Experience performing continuous monitoring of system security controls.
Desired Skills & Experience
- 10 years experience as an ISSO on Army Intel programs.
- 2 years experience with AC2SP tenant assessment and accreditation activities.
Tech Stack
- AR 25-2, DA 25-2-14, NIST SP 800-53
- eMASS, POA&M, STIGs, DA G2 policy
- DoD/IC, RMF
- DISA Security Technical Implementation Guides (STIGs), DISA Security Requirements Guide (SRG)
- CASP+ CE, CCNP Security, CISA, CISSP (or Associate), GCED, GCIH, CCSP
- SOPs, Tactics, Techniques, and Procedures (TTPs)
- AC2SP tenant
Application deadline: November 30, 2026