> Markdown version of [/jobs/ext/3097506-sme-information-security-analyst](https://www.wearedevelopers.com/jobs/ext/3097506-sme-information-security-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # SME - Information Security Analyst - **Company:** OneZero Solutions - **Location:** Washington, DC, United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Word, Microsoft Excel, Software System Penetration Testing, Collaborative Software, Cyber Security, Information Systems, Multi-Factor Authentication, Federal Information Processing Standards (FIPS), Data Flow Control, Microsoft Visio, Zero Trust Network Access, Test Scripts, Information Technology, RSA Archer Platform, Devsecops, Plan of Action and Milestones - **Published:** September 26, 2026 - **Apply:** https://www.dice.com/job-detail/ab39b9d1-f707-47d3-89a2-0f8b95b66b40 ## About the Role * Ten (10)+ years of information security experience, including six (6)+ years as an ISSO or A&A lead for federal information systems. * Expert working knowledge of NIST SP 800-37 Rev. 2, SP 800-53/53A Rev. 5, SP 800-60, SP 800-34, and FIPS 199/200; demonstrated experience authoring complete authorization packages. * Experience as ISSO for High-baseline or HVA systems, or for cloud/hybrid authorization boundaries. * Current CISSP (or CISM, or CGRC/CAP with CISSP obtained within 12 months). * Active, final SECRET security clearance; U.S. citizenship. * Experience managing POA&Ms and authorization packages in an enterprise GRC tool. * Excellent technical writing skills; able to produce Government-ready artifacts with minimal editing., * Master's degree in a related field. * Department of State (DT/CA/CST) experience; ArchAngel and iPost proficiency. * CISA, CRISC, or CCSP certification. * Experience with FedRAMP inheritance, DevSecOps pipeline controls, and Privacy (PIA) / Digital Identity (DIRA, NIST SP 800-63) assessments. Technical Skills * NIST RMF end to end; SSP, SAR, POA&M, SIA, CP/ISCP, IRP, CMP, PIA, DIRA, ISA/MOU authoring. * GRC platforms (ArchAngel or equivalent), iPost or equivalent risk scoring, CDM data. * Interpretation of Tenable and Wiz vulnerability/compliance results, KEV reports, STIG scans, and penetration test findings. * Visio boundary and data-flow diagramming; advanced Word/Excel for artifact and metrics production. Education Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field, or an additional four (4) years of directly relevant ISSO experience in lieu of degree. Remote/Hybrid/On-site and any other relevant work-environment requirement Remote. Duties are performed remotely; the selected candidate must reside within the National Capital Region (NCR). The Government does not furnish equipment; OneZero provides the laptop and collaboration tools. Position requires an OpenNet account, DoS PIV badge, multifactor authentication, and adherence to DoS SBU/CUI handling requirements. Local travel within the National Capital Region; minimal other travel. ## Description The SME - Information Security Analyst is the program's most senior ISSO practitioner. The SME serves as ISSO of record for DT/EA/CST's High Value Assets, High-baseline, cloud/hybrid, and most complex consular systems; leads categorization, control selection, and authorization packages for new and re-authorizing systems; and acts as technical mentor and peer reviewer for the Senior and Information Assurance analysts., * Serve as ISSO of record and primary cybersecurity point of contact for an assigned portfolio of approximately 3-4 HVA, High-baseline, or otherwise complex systems. * Lead RMF Steps 1-3 for new and re-authorizing systems: FIPS 199 / NIST SP 800-60 categorization with documented CIA justifications; baseline selection and HVA, zero-trust, and cloud overlays; Control Tailoring Rationale; Inherited Controls Matrix; SSP development; Security Plan Approval Recommendation Letter; Evidence Index; and Implementation Readiness Review. * Develop and maintain the full authorization artifact set: SSP, Security Control Implementation Statements, PIA, DIRA, ISA/MOU, Security Assessment Plan, POA&M, SIA, system inventory, IRP, CP/ISCP, CP Test reports, and CMP. * Lead Security Control Review Meetings and control demonstrations with the independent Security Control Assessor; attend A&A Findings Meetings; support remediation validation; prepare the AODR Information Sheet for risk briefings(RMF Steps 4-5). * Direct system-specific security operations contractors to obtain technical evidence and implement remediation; validate closure evidence before POA&M closure. * Maintain authoritative POA&Ms in the GRC tool with monthly updates and updates within 5 business days of status changes; ensure realistic milestones, accurate risk levels, and attached closure evidence(RMF Step 6). * Review iPost scores weekly, coordinate remediation of findings contributing to elevated risk, and track and report findings open more than 30 days. * Review vulnerability, KEV, CVE, and STIG scan results within 5 business days; ensure critical and high vulnerabilities are addressed within Department and BOD timelines. * Plan and conduct annual Contingency Plan tests and Annual Control Assessments for assigned systems; document objectives, scope, results, and lessons learned. * Perform Security Impact Analyses for CCB/ECM changes; prepare the Quarterly Configuration and Change Impact Summary. * Coordinate with the SOC, incident response teams, and system owners on incidents; support post-incident reviews and update RMF artifacts accordingly. * Serve as first line of defense during OIG, GAO, CISA, HVA, BOD, OMB, penetration test, and CDM audits and data calls; maintain the Audit and Data Call Response Package. * Develop system retirement memos and POA&M (risk) transfer memos; validate and close POA&Ms at decommissioning. * Mentor Senior and Information Assurance analysts; peer-review artifacts for accuracy, completeness, and Department format compliance. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Developing the Rich Text Editor for DeepL.com](https://www.wearedevelopers.com/videos/1172-developing-the-rich-text-editor-for-deepl-com) - [Are Classical Automation Frameworks Dead? How AI Agents Are Transforming QA](https://www.wearedevelopers.com/videos/100243-are-classical-automation-frameworks-dead-how-ai-agents-are-transforming-qa) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)