Cybersecurity Subject Matter Expert; SME) Secret or -Secret
Listed on 2026-09-01
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Job Title: Cybersecurity Subject Matter Expert (SME)
Location: Washington, DC
Clearance Required: Active Secret or Top-Secret (TS) Clearance
Salary: $140k-$170K Based on Years of Experience
Final date to receive applications: September 30, 2026
DescriptionIBSS is seeking a Cyber Security Subject Matter Expert (SME) to support a Federal customer. This position serves as the principal information assurance and cybersecurity expert on the contract, leading IA engineering, risk and vulnerability assessments, and security evaluation activities that protect NTIA's classified and unclassified systems, data, and networks and that maintain compliance with NIST, FISMA, and Department of Commerce (DOC) security policy.
The Cyber Security SME works closely with the security engineer, ISSOs/Security Assessors, and customer leadership to sustain a strong security posture and Authority to Operate (ATO) portfolio.
- Provide enhancement capabilities and standard operating procedures (SOPs) to assessment operations for execution and implementation.
- Maintain accountability for the integrity and confidentiality of the security assessment process; provide in-depth analysis of vulnerabilities across customer systems.
- Review and make recommendations on program-level documentation, including requirements specifications, system architecture, design documents, test plans, and security plans.
- Develop and document security evaluation test plans and procedures; conduct hands-on security testing, analyze results, document risk, and recommend countermeasures.
- Assess and calculate risk based on threats, vulnerabilities, and shortfalls uncovered in testing, and identify mitigating countermeasures.
- Provide oversight of the design, development, and implementation of security-related support systems.
- Research, evaluate, and develop Information Security policies and guidance.
- Develop, review, and update Information Assurance (IA) policies, procedures, and guidelines to keep NTIA systems aligned with evolving federal security requirements and enterprise governance expectations.
- Perform comprehensive risk and vulnerability assessments; document findings and recommend mitigation and remediation strategies to reduce organizational exposure to cyber threats.
- Ensure compliance with federal cybersecurity regulations, including NIST and FISMA, by reviewing security controls, identifying gaps, and supporting continuous monitoring activities.
- Develop and maintain system- and enterprise-level IA documentation, including System Security Plans (SSPs), risk assessments, control implementation statements, POA&Ms, and audit-ready ATO artifacts.
- Support system security engineering activities, ensuring security requirements are incorporated into system design, architecture, and configuration baselines throughout each system's lifecycle.
- Coordinate with system owners, ISSOs, architecture teams, and cybersecurity leadership to validate system requirements, address IA concerns, and resolve compliance or security issues.
- Monitor IA-related compliance activities, ensuring artifacts, assessments, and system configurations remain aligned with NIST SP 800-53 controls, agency policy, and Department directives.
- Actively participate in or lead technical exchange meetings, document action items and results, and brief customer leadership on the status of activities and risk findings.
- Bachelor's degree in Information Technology, Computer Science, Business Management, or a related field.
- Minimum of eight (8) years of professional cybersecurity experience.
- CISSP or similar (CISM, CASP+, GSLC, etc.) recognized cybersecurity certification.
- Working knowledge of NIST SP 800-53, FISMA, and federal Risk Management Framework / ATO processes.
- Demonstrated experience conducting risk and vulnerability assessments and developing security evaluation test plans and procedures.
- Strong written and verbal communication skills, with experience briefing technical findings to leadership and government stakeholders.
- Active Secret Clearance required.
- Experience supporting the Department of Commerce or another…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).