SME – Information Security Analyst DoS CSS at RSSi / OneZero Solutions in Washington, DC, USA
- Company: RSSi / OneZero Solutions
- Location: Washington, DC, USA
- Posted: Sep 24, 2026
- Type: Full-time
- Experience: 10+ years
Overview
The SME – Information Security Analyst is the program's most senior ISSO practitioner. The SME serves as ISSO of record for DT/EA/CST's High Value Assets, High-baseline, cloud/hybrid, and most complex consular systems; leads categorization, control selection, and authorization packages for new and r…
Job description
- The SME – Information Security Analyst is the program's most senior ISSO practitioner. The SME serves as ISSO of record for DT/EA/CST's High Value Assets, High-baseline, cloud/hybrid, and most complex consular systems; leads categorization, control selection, and authorization packages for new and re-authorizing systems; and acts as technical mentor and peer reviewer for the Senior and Information Assurance analysts.
Responsibilities
- Serve as ISSO of record and primary cybersecurity point of contact for an assigned portfolio of approximately 3–4 HVA, High-baseline, or otherwise complex systems.
- Lead RMF Steps 1–3 for new and re-authorizing systems: FIPS 199 / NIST SP 800-60 categorization with documented CIA justifications; baseline selection and HVA, zero-trust, and cloud overlays; Control Tailoring Rationale; Inherited Controls Matrix; SSP development; Security Plan Approval Recommendation Letter; Evidence Index; and Implementation Readiness Review.
- Develop and maintain the full authorization artifact set: SSP, Security Control Implementation Statements, PIA, DIRA, ISA/MOU, Security Assessment Plan, POA&M, SIA, system inventory, IRP, CP/ISCP, CP Test reports, and CMP.
- Lead Security Control Review Meetings and control demonstrations with the independent Security Control Assessor; attend A&A Findings Meetings; support remediation validation; prepare the AODR Information Sheet for risk briefings(RMF Steps 4–5).
- Direct system-specific security operations contractors to obtain technical evidence and implement remediation; validate closure evidence before POA&M closure.
- Maintain authoritative POA&Ms in the GRC tool with monthly updates and updates within 5 business days of status changes; ensure realistic milestones, accurate risk levels, and attached closure evidence(RMF Step 6).
- Review iPost scores weekly, coordinate remediation of findings contributing to elevated risk, and track and report findings open more than 30 days.
- Review vulnerability, KEV, CVE, and STIG scan results within 5 business days; ensure critical and high vulnerabilities are addressed within Department and BOD timelines.
- Plan and conduct annual Contingency Plan tests and Annual Control Assessments for assigned systems; document objectives, scope, results, and lessons learned.
- Perform Security Impact Analyses for CCB/ECM changes; prepare the Quarterly Configuration and Change Impact Summary.
- Coordinate with the SOC, incident response teams, and system owners on incidents; support post-incident reviews and update RMF artifacts accordingly.
- Serve as first line of defense during OIG, GAO, CISA, HVA, BOD, OMB, penetration test, and CDM audits and data calls; maintain the Audit and Data Call Response Package.
- Develop system retirement memos and POA&M (risk) transfer memos; validate and close POA&Ms at decommissioning.
- Mentor Senior and Information Assurance analysts; peer-review artifacts for accuracy, completeness, and Department format compliance.
Requirements
- Ten (10)+ years of information security experience, including six (6)+ years as an ISSO or A&A lead for federal information systems.
- Expert working knowledge of NIST SP 800-37 Rev. 2, SP 800-53/53A Rev. 5, SP 800-60, SP 800-34, and FIPS 199/200; demonstrated experience authoring complete authorization packages.
- Experience as ISSO for High-baseline or HVA systems, or for cloud/hybrid authorization boundaries.
- Current CISSP (or CISM, or CGRC/CAP with CISSP obtained within 12 months).
- Active, final SECRET security clearance; U.S. citizenship.
- Experience managing POA&Ms and authorization packages in an enterprise GRC tool.
- Excellent technical writing skills; able to produce Government-ready artifacts with minimal editing.
- NIST RMF end to end; SSP, SAR, POA&M, SIA, CP/ISCP, IRP, CMP, PIA, DIRA, ISA/MOU authoring.
- GRC platforms (ArchAngel or equivalent), iPost or equivalent risk scoring, CDM data.
- Interpretation of Tenable and Wiz vulnerability/compliance results, KEV reports, STIG scans, and penetration test findings.
- Visio boundary and data-flow diagramming; advanced Word/Excel for artifact and metrics production.
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field, or an additional four (4) years of directly relevant ISSO experience in lieu of degree.
- Master's degree in a related field.
- Department of State (DT/CA/CST) experience; ArchAngel and iPost proficiency.
- CISA, CRISC, or CCSP certification.
- Experience with FedRAMP inheritance, DevSecOps pipeline controls, and Privacy (PIA) / Digital Identity (DIRA, NIST SP 800-63) assessments.
Skills
Required
- Excellent technical writing skills
Preferred
- CISA, CRISC, or CCSP certification
About RSSi / OneZero Solutions
We are an employee-centric company that truly values our team members and the contributions they make to our customers and the missions they support. We pride ourselves on being forward-leaning thinkers and on building teams that are, and continue to be, technically proficient across a broad range of cyber mission areas. OneZero full-time employees receive a highly competitive benefits package, including health, dental, vision, and life insurance, a 401(k) with company matching, paid time off and holidays, an employee referral program, and educational assistance. Additional details are available on our website: https://www.onezerollc.com/careers/