Cybersecurity Plan Reviewer at RSSi / OneZero Solutions in Washington, DC, USA
- Company: RSSi / OneZero Solutions
- Location: Washington, DC, USA
- Posted: Sep 18, 2026
- Type: Full-time
- Experience: 4+ years
Overview
Cybersecurity Plan Reviewers perform the cursory and detailed technical review of cybersecurity plans, cybersecurity assessments, waiver requests, and equivalency requests submitted by U.S.-flagged vessels, facilities, and Outer Continental Shelf facilities under 33 CFR Part 101 Subpart F. Reviewers…
Job description
- Cybersecurity Plan Reviewers perform the cursory and detailed technical review of cybersecurity plans, cybersecurity assessments, waiver requests, and equivalency requests submitted by U.S.-flagged vessels, facilities, and Outer Continental Shelf facilities under 33 CFR Part 101 Subpart F. Reviewers apply Government-furnished checklists and process guides and recommend findings for Government decision. Maritime knowledge may be met through company-provided training, so candidates from federal RMF and assessment and authorization, regulatory compliance, or audit backgrounds are encouraged to apply.
Responsibilities
- Conduct Stage One cursory review of assigned submittals to determine whether the submission is complete and includes all required documents, information, and elements.
- Identify incomplete submittals and prepare draft signature-ready correspondence clearly identifying each deficiency, omission, or discrepancy, the associated regulatory basis, and brief instructions for resubmission.
- Conduct Stage Two detailed technical review to evaluate whether submissions satisfy the applicable requirements of 33 CFR Subpart F and associated Government guidance.
- Recommend a finding of Satisfactory, Unsatisfactory, or Not Applicable for each regulatory checklist element, using Government-furnished checklists, process guides, and decision matrices.
- Ensure findings are clearly stated, technically supportable, internally consistent, and traceable to the applicable regulatory requirement, checklist element, or Government guidance.
- Prepare review packages and draft signature-ready correspondence for Government review and signature.
- Record and maintain review status in MISLE, USCG SharePoint, and USCG ServiceNow before the close of the following business day.
- Respond to status inquiries using only information available in Government databases or published Government regulations and guidance, and refer all policy-related inquiries to the designated USCG representative.
- Complete company-provided maritime operations and OT cybersecurity training as assigned.
- Report to the Sub-Project Manager any submitter that may present an organizational conflict of interest.
Requirements
- No security clearance is required. This work is performed at the Controlled Unclassified Information (CUI) level.
- US. citizenship is required. All personnel must undergo and successfully pass, at minimum, a Tier 1 background investigation (or equivalent) and be favorably adjudicated.
- A working knowledge of 33 CFR Subchapter H, specifically 33 CFR Part 101 Subpart F.
- A foundational understanding of maritime operations. This may be met through prior experience or through company-provided training.
- A foundational understanding of general cybersecurity principles and frameworks.
- Strong technical writing skills and demonstrated attention to detail in document review.
- Ability to meet recurring turnaround requirements in a high-volume review environment.
- Must disclose, for organizational conflict of interest screening, any current or prior engagement performed for MTSA-regulated vessel, facility, or Outer Continental Shelf facility owners or operators involving cybersecurity plan development, cybersecurity assessment, or related advisory services.
- One of the following certifications required: Security +, CASP, PenTest +, GSEC, SecurityX
- Checklist-based technical review and evidence evaluation.
- NIST Cybersecurity Framework fundamentals.
- Technical writing for a regulatory audience.
- USCG MISLE, SharePoint, and ServiceNow, or comparable case management systems.
- CUI and SSI handling in accordance with 49 CFR Part 1520 and DHS MD 11042.1.
- No security clearance is required. This work is performed at the Controlled Unclassified Information (CUI) level.
- S. citizenship is required. All personnel must undergo and successfully pass, at minimum, a Tier 1 background investigation (or equivalent) and be favorably adjudicated.
- Associate's or Bachelor's degree in cybersecurity, information technology, maritime studies, or a related field preferred. Equivalent experience and certification considered.
- Prior maritime industry, port, terminal, or vessel operations experience.
- Experience performing RMF control assessments, ATO package review, or similar regulatory compliance document review.
- Familiarity with NIST CSF and NIST SP 800-series guidance.
- Exposure to OT and ICS environments.
- Prior U.S. Coast Guard or DHS support experience.
Skills
Preferred
- Exposure to OT and ICS environments.
About RSSi / OneZero Solutions
We are an employee-centric company that truly values our team members and the contributions they make to our customers and the missions they support. We pride ourselves on being forward-leaning thinkers and on building teams that are, and continue to be, technically proficient across a broad range of cyber mission areas. OneZero full-time employees receive a highly competitive benefits package, including health, dental, vision, and life insurance, a 401(k) with company matching, paid time off and holidays, an employee referral program, and educational assistance. Additional details are available on our website: https://www.onezerollc.com/careers/