Unknown Company

Cybersecurity SME Senior

fort meade, md • Posted Today
Onsite Full Time IT Management & IT Project Management

Support an INSCOM cybersecurity mission from Ft. Meade with SMX as a Cybersecurity SME Senior. This onsite role focuses on keeping DoD/IC systems operating through disciplined ISSO execution, continuous monitoring, and assessment and accreditation support, including active management of eMASS and POA&M records to help maintain ATO .

Compensation for this position is USD 140,000 - 175,000 per year . You will join a team operating under established DoD frameworks and standards, working closely with government stakeholders while leading security control validation, reporting, and security documentation.

Responsibilities

  • Perform the duties of an Information System Security Officer (ISSO) in accordance with AR 25-2 , DA 25-2-14 , and NIST SP 800-53 security controls when ISSO personnel are organizationally-defined.
  • Actively manage the organization’s eMASS records, including validating security controls and associated artifacts.
  • Assess security scan results and STIGs as required.
  • Perform POA&M updates, tracking, and resolution activities.
  • Lead continuous monitoring efforts for the organization’s security controls.
  • Manage day-to-day activities and the professional development of Cybersecurity Analysts .
  • Collaborate with the O-ISSM on assessment and authorization activities to support ATO on applicable DoD/IC networks .
  • Maintain up-to-date status on assigned systems and communicate status to government leads, including complete records of communications and written status reporting as required.
  • Conduct peer-review and attend weekly meetings.
  • Coordinate with government system administrators and the customer to communicate unacceptable risks and drive corrective actions for deficient POA&M items to meet DoD and IC standards.
  • Coordinate with the Security Control Assessor (SCA) to analyze the system’s overall risk level to enterprise networks and mission data.
  • Create and maintain cybersecurity policies and standards , ensuring plans, controls, processes, standards, policies, and procedures remain aligned with cybersecurity standards.
  • Ensure security scans and STIG checklists are updated per DA G2 policy .
  • Produce actionable, risk-based reports from security assessment results and assist with vulnerability remediation when necessary.
  • Develop and maintain security plans and security testing plans, and periodically update risk models, metrics, reports, processes, and activities to stay compliant with evolving DoD and IC standards.
  • Ensure the user community understands and follows procedures needed to maintain the security posture of information systems.
  • Provide guidance on creation and maintenance of SOPs , Tactics, Techniques, and Procedures (TTPs) , and related documentation.

Requirements

  • PhD in a STEM field with cybersecurity professional experience, or Master’s in a STEM field with cybersecurity professional experience, or Bachelor’s in a STEM field with cybersecurity professional experience.
  • Active TS security clearance and eligible for SCI and NATO read-on prior to starting work.
  • Meet DoD requirements for a privileged user on a TS/SCI information system prior to starting work.
  • Meet DoD 8570 level III certification compliance, including one of: CASP+ CE , CCNP Security , CISA , CISSP (or Associate) , GCED , GCIH , CCSP .
  • Experience with assessment and accreditation activities of national security systems (NSSs).
  • Experience validating system security controls.
  • Experience with vulnerability management.
  • Experience with DISA STIGs , DISA SRG , and vendor-specific security guides.
  • Experience with RMF and eMASS .
  • Experience with POA&M tracking and resolution.
  • Experience performing continuous monitoring of system security controls.

Desired Skills & Experience

  • 10 years experience as an ISSO on Army Intel programs .
  • 2 years experience with AC2SP tenant assessment and accreditation activities.

Tech Stack

  • AR 25-2, DA 25-2-14, NIST SP 800-53
  • eMASS, POA&M, STIGs, DA G2 policy
  • DoD/IC, RMF
  • DISA Security Technical Implementation Guides (STIGs), DISA Security Requirements Guide (SRG)
  • CASP+ CE, CCNP Security, CISA, CISSP (or Associate), GCED, GCIH, CCSP
  • SOPs, Tactics, Techniques, and Procedures (TTPs)
  • AC2SP tenant

Application deadline: November 30, 2026

#J-18808-Ljbffr

Cybersecurity SME Senior in fort meade at Unknown Company

This position is listed as full time and onsite.

Back to Job Search