SME – Information Security Analyst DoS CSS
Listed on 2026-10-02
-
IT/Tech
Cybersecurity, Information Security & Data Protection
We are an employee-centric company that truly values our team members and the contributions they make to our customers and the missions they support. We pride ourselves on being forward-leaning thinkers and on building teams that are, and continue to be, technically proficient across a broad range of cyber mission areas. One Zero full-time employees receive a highly competitive benefits package, including health, dental, vision, and life insurance, a 401(k) with company matching, paid time off and holidays, an employee referral program, and educational assistance.
Additional details are available on our website:
Position Title: SME – Information Security Analyst
Location: Remote; must reside within the National Capital Region (NCR).
Work Schedule: Full-time, 40 hours per week. Must be available during Department core hours of 9:00 a.m. – 3:00 p.m. ET, Monday – Friday, and flex working hours as needed to meet CST day-to-day and emergent requirements. No work is performed on Federal holidays or during Government closures.
Employment Type: Full-Time, Exempt (W-2), contingent upon Call Order award
Position SummaryThe SME – Information Security Analyst is the program’s most senior ISSO practitioner. The SME serves as ISSO of record for DT/EA/CST’s High Value Assets, High-baseline, cloud/hybrid, and most complex consular systems; leads categorization, control selection, and authorization packages for new and re-authorizing systems; and acts as technical mentor and peer reviewer for the Senior and Information Assurance analysts.
Key Responsibilities- Serve as ISSO of record and primary cybersecurity point of contact for an assigned portfolio of approximately 3–4 HVA, High-baseline, or otherwise complex systems.
- Lead RMF Steps 1–3 for new and re-authorizing systems: FIPS 199 / NIST SP 800-60 categorization with documented CIA justifications; baseline selection and HVA, zero-trust, and cloud overlays;
Control Tailoring Rationale;
Inherited Controls Matrix; SSP development;
Security Plan Approval Recommendation Letter;
Evidence Index; and Implementation Readiness Review. - Develop and maintain the full authorization artifact set: SSP, Security Control Implementation Statements, PIA, DIRA, ISA/MOU, Security Assessment Plan, POA&M, SIA, system inventory, IRP, CP/ISCP, CP Test reports, and CMP.
- Lead Security Control Review Meetings and control demonstrations with the independent Security Control Assessor; attend A&A Findings Meetings; support remediation validation; prepare the AODR Information Sheet for risk briefings (RMF Steps 4–5).
- Direct system-specific security operations contractors to obtain technical evidence and implement remediation; validate closure evidence before POA&M closure.
- Maintain authoritative POA&M in the GRC tool with monthly updates and updates within 5 business days of status changes; ensure realistic milestones, accurate risk levels, and attached closure evidence (RMF Step
6). - Review iPost scores weekly, coordinate remediation of findings contributing to elevated risk, and track and report findings open more than 30 days.
- Review vulnerability, KEV, CVE, and STIG scan results within 5 business days; ensure critical and high vulnerabilities are addressed within Department and BOD timelines.
- Plan and conduct annual Contingency Plan tests and Annual Control Assessments for assigned systems; document objectives, scope, results, and lessons learned.
- Perform Security Impact Analyses for CCB/ECM changes; prepare the Quarterly Configuration and Change Impact Summary.
- Coordinate with the SOC, incident response teams, and system owners on incidents; support post-incident reviews and update RMF artifacts accordingly.
- Serve as first line of defense during OIG, GAO, CISA, HVA, BOD, OMB, penetration…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).