> Markdown version of [/jobs/ext/2713514-information-system-security-officer-sme-level-iii](https://www.wearedevelopers.com/jobs/ext/2713514-information-system-security-officer-sme-level-iii). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information System Security Officer (SME), Level III - **Company:** OneZero Solutions - **Location:** Baltimore, MD, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Systems Engineering, Audit Trail, Cyber Security, Information Systems, Disaster Recovery, Federal Information Processing Standards (FIPS), Identity and Access Management, Information Security Management, Information Technology Audit, Intrusion Detection and Prevention, Information Systems Security Architecture Professional, Network Connections, Security Content Automation Protocol, Information Technology, Process Control Systems, Nessus, Operational Systems, Plan of Action and Milestones, Vulnerability Analysis - **Published:** September 4, 2026 - **Apply:** https://www.dice.com/job-detail/db9a0241-4a47-4804-aea0-4b69ec63ca37 ## About the Role * Ten (10) or more years of cybersecurity experience, including at least five (5) years serving as an ISSO or equivalent with direct ownership of federal A&A packages. * Demonstrated record of carrying systems to an ATO decision and sustaining authorization through continuous monitoring. * Experience managing POA&Ms from identification through closure, including waiver and risk acceptance packages. * Experience conducting Security Impact Assessments and participating in formal change control processes. * Experience developing interconnection documentation (ISAs, MOUs, SLAs) and contingency/disaster recovery documentation and testing. Certification * Must hold and maintain at least one active certification approved for Information Assurance Management (IAM) Level II or Level III. Any one of the following satisfies the requirement: + CISSP - Certified Information Systems Security Professional (or CISSP Associate) + CISM - Certified Information Security Manager + CGRC - Governance, Risk and Compliance Certification (formerly CAP) + CASP+ - CompTIA Advanced Security Practitioner + GSLC - GIAC Security Leadership Certification + CCISO - EC-Council Certified Chief Information Security Officer (Level III only) * Certification requirements are subject to confirmation against COMDTINST M2620.2 (series) Appendix D, the controlling USCG certification matrix. Verify the accepted certification list with the Program Manager before extending an offer. * Evidence of active certification in good standing is required prior to onboarding. Waivers and exceptions to certification requirements will not be granted. * Certifications must remain current, active, and in good standing throughout performance. Loss, lapse, or revocation of a required certification is grounds for removal from the contract. Continuing education required to maintain certification is at the employee's and company's expense. * Ability to serve as the Government's primary ISSO point of contact for an assigned system portfolio. * Strong written communication: the role produces bi-weekly written reporting and briefs the ISSM monthly. * Ability to read, write, speak, and understand English fluently., * Prior USCG, DHS, or DoD ISSO experience, particularly with Surface Domain OT or Platform IT systems. * Familiarity with COMDTINST M2620.2 (series) and COMDTINST 5500.13 (series). * Experience with OT/ICS or PIT systems where conventional endpoint agents cannot be deployed and compensating controls are required. * CGRC (formerly CAP) or CISM in addition to the required baseline certification. * Experience supporting DHS SELC-aligned acquisitions. * Master's degree in cybersecurity, information systems, or a related field., * Bachelor's degree in cybersecurity, computer science, information systems, engineering, or a related field. ## Description * No security clearance required. This position does not involve access to classified information or classified IT systems. * S. citizenship is required in accordance with HSAR 3052.204-71 Alternate I., The senior Information System Security Officer serves as the designated ISSO for assigned USCG SFLC Operational Technology and Platform IT systems and leads the Risk Management Framework process for that portfolio. The role owns the authorization packages end to end: preparation, submission, continuous monitoring, POA&M management, and sustainment of the Authorization to Operate. As the SME-level ISSO on the task order, this position also sets the technical standard for the Level 2 ISSOs, handles the most complex or highest-visibility systems, and is the primary ISSO interface to the OT Security Manager (ISSM) on policy, risk posture, and authorization strategy., * Serve as the designated OT Security Officer (ISSO) for assigned SFLC Operational Technology and lead the RMF process for those systems. * Support the OT Security Manager (ISSM) and staff in maintaining the programs, procedures, and policies that protect Government Sensitive But Unclassified (SBU) information. * Review existing policies, procedures, and guidelines for compliance with DHS, USCG, and DoD cybersecurity policy; draft or revise SFLC policy documentation for ISSM review and approval. * Prepare and maintain RMF security authorization documentation for assigned OT, ensuring Assessment and Authorization (A&A) packages are completed and submitted to the Authorizing Official in sufficient time to prevent expiration of the Authorization to Operate (ATO). * Maintain Host Based Security System (HBSS/ESS) compliance for assigned OT and review applicable system reports. * Create and validate SFLC RMF and security authorization accounts within Government-designated systems and tools. * Update and maintain RMF and authorization status and associated cybersecurity documentation within Government-designated tracking tools, keeping documentation current and accessible to authorized individuals. * Manage and track POA&Ms for assigned OT from creation through closure: validate content with stakeholders, track remediation, maintain supporting artifacts, and identify items requiring waivers or risk acceptance. * Maintain the continuous monitoring process for assigned OT and support compliance with DoD and USCG cybersecurity requirements and DISA STIGs. * Perform vulnerability and security compliance assessments for assigned OT using Government-approved methods and tools, including DISA STIGs and Security Requirements Guides. * Conduct, review, and analyze vulnerability and compliance scans of assigned OT, networks, devices, and associated components. * Coordinate with system administrators and stakeholders to remediate vulnerabilities and compliance findings, and initiate protective or corrective measures per Government policy. * Review system logs, audit records, and intrusion detection data for assigned OT to identify incidents, threats, and vulnerabilities; request system audit triggers and correlate audit records at least weekly; report incidents and log integrity gaps to the Government and coordinate incident response. * Support the Request for Modification (RFM) and change management processes; participate in change management boards and conduct Security Impact Assessments (SIAs) on proposed changes. * Develop and maintain connection approval documentation for assigned OT requiring USCG network connectivity, including Interconnection Security Agreements (ISAs), Memoranda of Understanding (MOUs), and Service Level Agreements (SLAs). * Develop and coordinate Contingency Plan (CP) training and testing; coordinate annual Disaster Recovery failover testing for systems with a DR capability and document results for Government review. * Support and coordinate external inspections, evaluations, audits, and assessments applicable to assigned OT. * Review security exception and exclusion requests for assigned OT and provide recommendations to the Government. * Monitor for and coordinate remediation of rogue devices and analyze potential threat vectors across related systems. * Provide cybersecurity and A&A support throughout applicable phases of the DHS Systems Engineering Life Cycle (SELC). * Perform Security Readiness Reviews (SRRs) for operating systems and applications associated with assigned OT. * Review and interpret system designs and diagrams to identify interconnections, interfaces, protocols, and data types, and support selection and implementation of appropriate controls. * Lead authorization strategy for the most complex or highest-risk systems in the assigned portfolio., * NIST SP 800-37 (RMF), 800-53 / 53A / 53B, 800-137 (ISCM), FIPS 199 and FIPS 200 * DHS 4300A Sensitive Systems Handbook and the DHS Systems Engineering Life Cycle (SELC) * Government-designated A&A repositories and tracking tools (e.g., eMASS or successor) * DISA Security Technical Implementation Guides (STIGs) and Security Requirements Guides (SRGs) * Government-approved vulnerability scanning and compliance tooling (e.g., ACAS/Nessus, SCAP-validated scanners) * POA&M development, tracking, and closure, including waiver and risk acceptance packages * Operational Technology (OT), Platform IT (PIT), and industrial control system environments, including constraints on agent-based tooling * Security Impact Assessments and change management board participation * Interconnection documentation: ISAs, MOUs, SLAs * Contingency planning, contingency plan testing, and disaster recovery failover exercises * Audit log review, audit trigger configuration, and incident reporting workflows * Security Readiness Reviews for operating systems and applications ## Related Videos - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Resilient by Design: Building Robust Architectures in High-Stakes Financial Systems](https://www.wearedevelopers.com/videos/2106-resilient-by-design-building-robust-architectures-in-high-stakes-financial-systems) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)