> Markdown version of [/jobs/ext/229498-cybersecurity-sme](https://www.wearedevelopers.com/jobs/ext/229498-cybersecurity-sme). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity SME - **Company:** Wintrio LLC - **Location:** United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Xacta, Agile Methodology, Amazon Web Services, Microsoft Azure, Cloud Computing Security, Configuration Management, Cyber Security, Executive Information Systems, Information Security Management, Fortify (Software), Zero Trust Network Access, RSA (Cryptosystem), Security Content Automation Protocol, Security Information and Event Management, SonarQube, Systems Integration, Software Vulnerability Management, Webinspect, Enterprise Software Applications, Cloud Platform System, Software Security, Information Technology, Nessus, CIS Benchmarks, Cloudwatch, Splunk, Devsecops, Qualys, Servicenow, Static Application Security Testing, Dynamic Application Security Testing - **Published:** May 21, 2026 - **Apply:** https://www.wintrio.com/careers/cybersecurity-sme-rmf-ato-continuous-monitoring/ ## About the Role * 10+ years of cybersecurity experience, with strong federal RMF, ATO, or continuous monitoring experience. * Hands-on experience with NIST RMF, NIST 800-53, FISMA, POA&M management, and security authorization processes. * Experience developing or reviewing ATO documentation and security control evidence. * Experience working with federal security stakeholders including ISSOs, System Owners, Security Control Assessors, and Authorizing Officials. * Strong understanding of vulnerability management, audit readiness, continuous monitoring, and risk-based remediation. * Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related field., * Frameworks: NIST RMF, NIST 800-37, NIST 800-53, NIST 800-30, NIST 800-137, FISMA, FedRAMP, Zero Trust Architecture * GRC / ATO Tools: eMASS, Xacta, CSAM, RSA Archer, ServiceNow GRC, RegScale * Vulnerability Tools: ACAS, Nessus, Tenable.io, Tenable.sc, Qualys, Rapid7 * Application Security: Fortify, WebInspect, SonarQube, SAST, DAST, SCA tools * SIEM / Monitoring: Splunk, ELK, Azure Monitor, AWS CloudWatch, Sentinel * Cloud Security: AWS GovCloud, Azure Government, FedRAMP baselines, cloud control inheritance * Documentation: SSP, SAR, RAR, POA&M, PTA, PIA, BIA, Contingency Plans, Incident Response Plans * Standards: STIG, SCAP, CIS Benchmarks, DISA guidance, agency-specific cyber policy Preferred Certifications, Not Required * CISSP * CISM * CAP / Certified Authorization Professional * Security+ * CASP+ * CCSP * Certified Ethical Hacker (CEH) * AWS Security Specialty or Azure Security Engineer Associate * GIAC certifications such as GSEC, GSLC, or GCIH, * Experience supporting DHS, USDA, DoD, IRS, CBP, or other federal civilian agencies. * Experience with ongoing authorization or continuous authorization environments. * Experience supporting classified, sensitive, high-value asset, or mission-critical systems. * Experience integrating cyber compliance with Agile, DevSecOps, and cloud delivery workflows. ## Description WINTrio LLC is seeking a Cybersecurity Subject Matter Expert (SME) with deep experience supporting Risk Management Framework (RMF), Authority to Operate (ATO), continuous monitoring, and federal cyber compliance programs. This role supports the full system security lifecycle, including control implementation, assessment readiness, authorization packages, Plan of Action and Milestones (POA&M) management, vulnerability remediation tracking, and audit support., * Lead RMF lifecycle activities including system categorization, control selection, implementation, assessment, authorization, and continuous monitoring. * Develop, review, and maintain ATO artifacts including System Security Plans (SSP), Security Assessment Reports (SAR), Risk Assessment Reports (RAR), Contingency Plans, Configuration Management Plans, Privacy Threshold Analysis (PTA), Privacy Impact Assessment (PIA), and POA&M documentation. * Support security control implementation and validation against NIST Special Publication 800-53, FISMA, FedRAMP, agency policy, and system-specific requirements. * Coordinate with Information System Security Officers (ISSOs), System Owners, Authorizing Officials, Security Control Assessors, cloud teams, and application teams. * Monitor continuous authorization activities, recurring assessments, vulnerability remediation, and security posture reporting. * Analyze security findings from tools such as ACAS, Nessus, Tenable, WebInspect, Fortify, Splunk, Xacta, eMASS, CSAM, Archer, ServiceNow, or similar platforms. * Manage POA&M development, remediation evidence, milestone tracking, risk acceptance packages, and closure validation. * Support audit readiness, control inheritance analysis, cloud security documentation, and FedRAMP package reviews. * Provide senior-level guidance on Zero Trust, DevSecOps, cloud security, and security architecture alignment. * Prepare executive dashboards, compliance reports, risk briefings, and security status updates for federal stakeholders. ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)