Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Information System Security Officer (SME), Level III

OneZero Solutions

Job Description

Job Description

We are an employee-centric company that truly values our team members and the contributions they make to our customers and the missions they support. We pride ourselves on being forward-leaning thinkers and on building teams that are, and continue to be, technically proficient across a broad range of cyber mission areas. OneZero full-time employees receive a highly competitive benefits package, including health, dental, vision, and life insurance, a 401(k) with company matching, paid time off and holidays, an employee referral program, and educational assistance. Additional details are available on our website: Title: Information System Security Officer (SME), Level IIILocation: USCG Surface Forces Logistics Center, 2401 Hawkins Point Road, Baltimore, MD 21226. Work may also be performed at the SFLC satellite offices at 707 East Ordnance Road, approximately one mile from the primary site, and at other sites as determined necessary by the Contracting Officer's Representative (COR).Clearance:No security clearance required. This position does not involve access to classified information or classified IT systems.S. citizenship is required in accordance with HSAR 3052.204-71 Alternate I.Position SummaryThe senior Information System Security Officer serves as the designated ISSO for assigned USCG SFLC Operational Technology and Platform IT systems and leads the Risk Management Framework process for that portfolio. The role owns the authorization packages end to end: preparation, submission, continuous monitoring, POA&M management, and sustainment of the Authorization to Operate.As the SME-level ISSO on the task order, this position also sets the technical standard for the Level 2 ISSOs, handles the most complex or highest-visibility systems, and is the primary ISSO interface to the OT Security Manager (ISSM) on policy, risk posture, and authorization strategy.Key ResponsibilitiesServe as the designated OT Security Officer (ISSO) for assigned SFLC Operational Technology and lead the RMF process for those systems.Support the OT Security Manager (ISSM) and staff in maintaining the programs, procedures, and policies that protect Government Sensitive But Unclassified (SBU) information.Review existing policies, procedures, and guidelines for compliance with DHS, USCG, and DoD cybersecurity policy; draft or revise SFLC policy documentation for ISSM review and approval.Prepare and maintain RMF security authorization documentation for assigned OT, ensuring Assessment and Authorization (A&A) packages are completed and submitted to the Authorizing Official in sufficient time to prevent expiration of the Authorization to Operate (ATO).Maintain Host Based Security System (HBSS/ESS) compliance for assigned OT and review applicable system reports.Create and validate SFLC RMF and security authorization accounts within Government-designated systems and tools.Update and maintain RMF and authorization status and associated cybersecurity documentation within Government-designated tracking tools, keeping documentation current and accessible to authorized individuals.Manage and track POA&Ms for assigned OT from creation through closure: validate content with stakeholders, track remediation, maintain supporting artifacts, and identify items requiring waivers or risk acceptance.Maintain the continuous monitoring process for assigned OT and support compliance with DoD and USCG cybersecurity requirements and DISA STIGs.Perform vulnerability and security compliance assessments for assigned OT using Government-approved methods and tools, including DISA STIGs and Security Requirements Guides.Conduct, review, and analyze vulnerability and compliance scans of assigned OT, networks, devices, and associated components.Coordinate with system administrators and stakeholders to remediate vulnerabilities and compliance findings, and initiate protective or corrective measures per Government policy.Review system logs, audit records, and intrusion detection data for assigned OT to identify incidents, threats, and vulnerabilities; request system audit triggers and correlate audit records at least weekly; report incidents and log integrity gaps to the Government and coordinate incident response.Support the Request for Modification (RFM) and change management processes; participate in change management boards and conduct Security Impact Assessments (SIAs) on proposed changes.Develop and maintain connection approval documentation for assigned OT requiring USCG network connectivity, including Interconnection Security Agreements (ISAs), Memoranda of Understanding (MOUs), and Service Level Agreements (SLAs).Develop and coordinate Contingency Plan (CP) training and testing; coordinate annual Disaster Recovery failover testing for systems with a DR capability and document results for Government review.Support and coordinate external inspections, evaluations, audits, and assessments applicable to assigned OT.Review security exception and exclusion requests for assigned OT and provide recommendations to the Government.Monitor for and coordinate remediation of rogue devices and analyze potential threat vectors across related systems.Provide cybersecurity and A&A support throughout applicable phases of the DHS Systems Engineering Life Cycle (SELC).Perform Security Readiness Reviews (SRRs) for operating systems and applications associated with assigned OT.Review and interpret system designs and diagrams to identify interconnections, interfaces, protocols, and data types, and support selection and implementation of appropriate controls.Lead authorization strategy for the most complex or highest-risk systems in the assigned portfolio.Required QualificationsExperienceTen (10) or more years of cybersecurity experience, including at least five (5) years serving as an ISSO or equivalent with direct ownership of federal A&A packages.Demonstrated record of carrying systems to an ATO decision and sustaining authorization through continuous monitoring.Experience managing POA&Ms from identification through closure, including waiver and risk acceptance packages.Experience conducting Security Impact Assessments and participating in formal change control processes.Experience developing interconnection documentation (ISAs, MOUs, SLAs) and contingency/disaster recovery documentation and testing.CertificationMust hold and maintain at least one active certification approved for Information Assurance Management (IAM) Level II or Level III. Any one of the following satisfies the requirement:CISSP - Certified Information Systems Security Professional (or CISSP Associate)CISM - Certified Information Security ManagerCGRC - Governance, Risk and Compliance Certification (formerly CAP)CASP+ - CompTIA Advanced Security PractitionerGSLC - GIAC Security Leadership CertificationCCISO - EC-Council Certified Chief Information Security Officer (Level III only)Certification requirements are subject to confirmation against COMDTINST M2620.2 (series) Appendix D, the controlling USCG certification matrix. Verify the accepted certification list with the Program Manager before extending an offer.Evidence of active certification in good standing is required prior to onboarding. Waivers and exceptions to certification requirements will not be granted.Certifications must remain current, active, and in good standing throughout performance. Loss, lapse, or revocation of a required certification is grounds for removal from the contract. Continuing education required to maintain certification is at the employee's and company's expense.Ability to serve as the Government's primary ISSO point of contact for an assigned system portfolio.Strong written communication: the role produces bi-weekly written reporting and briefs the ISSM monthly.Ability to read, write, speak, and understand English fluently.Preferred QualificationsPrior USCG, DHS, or DoD ISSO experience, particularly with Surface Domain OT or Platform IT systems.Familiarity with COMDTINST M2620.2 (series) and COMDTINST 5500.13 (series).Experience with OT/ICS or PIT systems where conventional endpoint agents cannot be deployed and compensating controls are required.CGRC (formerly CAP) or CISM in addition to the required baseline certification.Experience supporting DHS SELC-aligned acquisitions.Master 's degree in cybersecurity, information systems, or a related field.Technical SkillsNIST SP 800-37 (RMF), 800-53 / 53A / 53B, 800-137 (ISCM), FIPS 199 and FIPS 200DHS 4300A Sensitive Systems Handbook and the DHS Systems Engineering Life Cycle (SELC)Government-designated A&A repositories and tracking tools (e.g., eMASS or successor)DISA Security Technical Implementation Guides (STIGs) and Security Requirements Guides (SRGs)Government-approved vulnerability scanning and compliance tooling (e.g., ACAS/Nessus, SCAP-validated scanners)POA&M development, tracking, and closure, including waiver and risk acceptance packagesOperational Technology (OT), Platform IT (PIT), and industrial control system environments, including constraints on agent-based toolingSecurity Impact Assessments and change management board participationInterconnection documentation: ISAs, MOUs, SLAsContingency planning, contingency plan testing, and disaster recovery failover exercisesAudit log review, audit trigger configuration, and incident reporting workflowsSecurity Readiness Reviews for operating systems and applicationsEducationBachelor 's degree in cybersecurity, computer science, information systems, engineering, or a related field.OneZero Solutions, LLC is an Equal Opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, pregnancy, genetic information, disability, status as a protected veteran, or any other protected category under applicable federal, state, and local laws.To request an accommodation, please contact us at View email address on us.fitly.work or call View phone number on us.fitly.work.

Job Posted by ApplicantPro

Vacancy posted 3 days ago
Similar jobs that could be interesting for youBased on the Information System Security Officer (SME), Level III in Curtis Bay, MD vacancy
  •  ...website: Position Title : Security Control Assessor (SME), Level IIILocation:  USCG...  ...at the SFLC satellite offices at 707 East Ordnance Road...  ...access to classified information or classified IT systems.S. citizenship is...  ...IAM) Level II or Level III. Any one of the following... 
    Suggested
    Full time
    Contract work
    For contractors
    Work at office
    Local area
    Remote work

    OneZero Solutions

    Curtis Bay, MD
    5 days ago
  • $10k

     ...technology lab. Learn more at The Information Systems Security Officer will be responsible for maintaining the...  ...Assurance Systems Technical (IAT), Level 1 or higher Knowledge of basic networking...  ...8570 certifications (IAT Level II or III, or IASAE) Experience with cloud... 
    Suggested

    ClearEdge

    Jessup, MD
    10 days ago
  •  ...can achieve. Together.SummaryThe Chief Information Security Officer (CISO), working in collaboration with...  ...’s Information Security Management System, security governance, risk management...  ...structures, governance routines, service levels, intake and prioritization processes,... 
    Suggested
    Full time
    Work at office
    Remote work
    Relocation
    Visa sponsorship
    Relocation package

    DLA Piper

    Baltimore, MD
    4 days ago
  •  ...Information Systems Security Officer Hanover, Maryland Steel Point Solutions is an amazing SBA Certified (8a), HUBZone, Small Disadvantaged Business...  ...world class, integrated business solutions for all levels of Government and commercial enterprises. We are represented... 
    Suggested

    Steel Point Solutions LLC

    Hanover, MD
    4 days ago
  •  ...Senior Information Systems Security Officer Base-2 Solutions is seeking a Senior Information Systems Security Officer responsible for safeguarding...  ...protection/classification requirements. Recommends system-level solutions to resolve security requirements. Supports... 
    Suggested

    Base2 Solutions

    Elkridge, MD
    3 days ago
  • $112k - $179k

     ...Responsibilities Peraton is seeking a Information Systems Security Officer in our Linthicum, MD office in support of our Department of Defense...  ...without loss of productivity. Certifications: Active IAT Level II certification (CompTIA Security+ preferred).... 
    Full time
    Contract work
    Work at office
    Monday to Friday
    Shift work

    Peraton

    Linthicum Heights, MD
    5 days ago
  • $134.5k - $265.1k

     ...Engineering and Product Engineer III on the Cyber...  ...delivery learnings to inform reusable product and platform...  ...SDKUnderstanding of AI system architectures and...  ...concepts (e.g., application security, cloud security,...  ...development From entry-level employees to senior leaders... 
    Local area
    Visa sponsorship

    Deloitte

    Baltimore, MD
    18 hours ago
  •  ...Vibrint transforms national security missions through advanced technology...  ...that enable faster, more informed mission decisions across some...  ...active TS/SCI with polygraph level clearance. US citizenship is...  ..., and enforcing information systems security policies, standards,... 
    Contract work
    Temporary work
    Local area
    Immediate start

    Vibrint

    Hanover, MD
    12 days ago
  • $217.5k

     ...education and experience Security Requirements: TS/SCI with CI...  ...discipline. Malware Analyst III (MA3) Salary: Up to $217,5...  .../penetration tests of information systems. Ensures software standards...  ...USCYBERCOM. Possesses senior-level experience as a Malware... 

    Beyond SOF

    Linthicum, MD
    3 days ago
  •  ...programs, dockets, records center, or other information services under the supervision of a...  ...maintenance; and use of automated information systems, such as the Federal Docket Management System (FDMS).Qualifications:- At Level III, the personnel must have at least three (... 
    Full time
    Flexible hours

    Contact Government Services LLC

    Baltimore, MD
    3 days ago
  •  ...expertise in all facets of Information Operations, making sure...  ...AND INFORMATION SECURITY CAREERS IN THE NAVY INTELLIGENCE OFFICER Analyze top-secret information...  ...decision-makers at all levels and achieve military...  ...your team of Information Systems Technicians to ensure the... 
    Full time
    Part time
    Worldwide

    U.S. Navy

    Baltimore, MD
    3 days ago
  •  ...Network SME The resource will need to visit the...  ...licenses, network device information, risks, gaps, etc....  ...Design and draw High-Level Designs (HLD) and Low-Level...  ...for future network and security architectural designs....  ...Computer Science, Information Systems, or other related field... 
    Local area
    Remote work

    RIT Solutions

    Catonsville, MD
    1 day ago
  •  ...Information System Security Engineer III Join ClearPoint and become part of a team focused on delivering secure environments that support mission-critical...  ...SP 800-53 and DoD RMF processes at an implementation level Capable of translating security findings into... 

    ClearEdge IT Solutions

    Jessup, MD
    1 day ago
  •  ...NOVACES is seeking a SME Management Analyst / Supply Systems Specialist for a U.S. Coast...  ...role requires advanced user-level proficiency with the...  ...administration, management, information systems, operations,...  ...helpful. Must be able to obtain a Tier 1 security clearance.... 
    Full time
    Temporary work
    Remote work

    NOVACES

    Baltimore, MD
    a month ago
  •  ...ASSYST's Information Assurance and Cybersecurity Practice is seeking an experienced Information Systems Security Officer (ISSO) to support a Federal customer. ASSYST delivers comprehensive cybersecurity solutions to Federal, State, and Local government agencies, helping... 
    Local area
    Flexible hours

    Assyst

    Baltimore, MD
    5 days ago
  •  ...Chief Information Security Officer (CISO) - Non Profit & Associations ~ Information Technology...  ...cultivate and leverage people, processes and systems to change and transform organizations...  ...industries. This is a senior-level, client-facing role responsible for advising... 
    Full time
    Temporary work

    Hartman Executive Advisors

    Baltimore, MD
    2 days ago
  •  ...Information Systems Security Officer (ISSO) Employment Type: Full-Time, Experienced Department: Information Technology CGS is seeking an Information Systems Security Officer (ISSO) with DIACAP and/or RMF experience who has deep expertise in security assessment... 
    Full time
    Local area
    Flexible hours

    Contact Government Services LLC

    Baltimore, MD
    3 days ago
  •  ...award. NOVACES is seeking a SME Project Management Specialist...  ...contact for the Contracting Officer and Contracting Officer's...  ...management, operations, engineering, information systems, public administration,...  ...Experience: 10+ years, senior-level project/program management... 
    Full time
    Contract work
    Temporary work
    For contractors
    Remote work

    NOVACES

    Baltimore, MD
    a month ago
  • $166.9k - $309.9k

     ...$309,900.00Experience Level: Experienced ProfessionalFT...  ...Martin, Rotary Mission Systems Cyber & Intelligence...  ...way of life. As a cyber security professional at...  ...Financial assets. Healthcare information. Critical infrastructure...  ...Cyber Operations Planner SME you will provide... 
    Full time
    Temporary work
    Work experience placement
    Casual work
    Flexible hours

    Lockheed Martin

    Hanover, MD
    1 day ago
  •  ...Job Description Job Description System Engineer Level 0, Clearance Required – TS/SCI w/Polygraph...  ...or nominated for a government security clearance. The Program: This...  ...System Engineering, Computer Science, Information Systems, Engineering Science, Engineering... 
    Bi-weekly pay
    Remote work

    SSATI

    Hanover, MD
    25 days ago
  • $135.8k - $203.6k

     ...to work on revolutionary systems that impact people's...  ...rapidly changing global security environments, Northrop Grumman brings informed insights and secure technological...  ...Analyst - IAM III.Candidates must have a current...  ...join us! CIDO Primary Level Salary Range: $135,800.0... 
    Full time
    Local area
    Remote work
    Relocation package
    Flexible hours
    Shift work

    Northrop Grumman

    Baltimore, MD
    4 days ago
  •  ...Stryke Infotech has an exciting opportunity for the security professionals to join our team as an Information Systems Security Engineer (ISSE) in the Annapolis...  ...CISA or CASP Certification is required for Senior level positions. Tenable Nessus/ACAS Scanning experience... 
    Full time
    Contract work
    Immediate start
    Remote work
    Worldwide
    Monday to Friday
    Flexible hours
    Shift work
    Day shift

    STRYKE INFOTECH LLC

    Elkridge, MD
    a month ago
  • $112.5k - $170k

     ...Global Solutions, Inc.’s (AGS) information security and data privacy initiatives...  ...(at an operating company level in concert with a shared services...  ...business operations and systems, protecting against security...  ...as local and global remote offices adhere to all applicable laws... 
    Permanent employment
    Contract work
    Temporary work
    For contractors
    Work at office
    Local area
    Remote work

    Allegis Group

    Hanover, MD
    4 days ago
  • $43.27 - $79.33 per hour

     ...architect technical solutions and write secure Infrastructure as Code (IaC) for...  ...government security clearance at the Secret Level or HigherMust have a degree in one of the...  ..., Electrical/Computer Engineering, Information Systems/Technology, Cybersecurity, Software Engineering... 
    Hourly pay
    Contract work
    For contractors
    Local area
    Relocation package

    Cipher Tech Solutions

    Linthicum Heights, MD
    5 days ago
  • $131.3k - $237.35k

     ...opening for a Cyber Security Fusion Analyst on the...  ...support to the Defense Information Systems Agency (DISA) in support...  ...equivalent DoD 8570 Level II certification) In...  ...Service (SES) and General Officer/Flag Officer (GO/FO)...  .... IAT Level III and IAM Level II+III Certifications... 

    Jobleads-US

    Odenton, MD
    4 days ago
  •  ...an experienced and highly motivated Information Systems Security Manager (ISSM) to lead the security management...  ...of Information System Security Officers (ISSO) and System Administrators (...  .... DoD 8140/DoD 8570 approved (IAM Level 2-3) certification required within 6... 
    Work at office
    Local area

    Kratos Defense & Rocket Support Services, Inc

    Glen Burnie, MD
    4 days ago
  •  ...Network Systems EngineerOur customer, the Defense Information Systems Agency (DISA), provides...  ...(DoD) and national security organizations. This...  ...at the Top-Secret level with SCI eligibilitySecurity+...  ...:Extensive SME level knowledge of...  ...concepts.IAT Level III Certification (i.e.... 
    Contract work

    United One Communications, LLC

    Odenton, MD
    48 minutes ago
  •  ...Additional details are available on our website: Title : Information Systems Security Engineer (ISSE), Level IILocation: USCG Surface Forces Logistics Center, 24...  ...6. Work may also be performed at the SFLC satellite offices at 707 East Ordnance Road, approximately one mile... 
    Full time
    Contract work
    For contractors
    Work at office
    Local area
    Remote work

    OneZero Solutions

    Curtis Bay, MD
    3 days ago
  • $144.9k - $265.8k

     ...As a Digital Identity & Authentication SME, you will help clients enhance user experience...  ..., Okta, Ping, Saviynt Design cloud security and IAM architectures for Azure, AWS,...  ...California, please click here for additional information. EY focuses on high‑ethical standards... 
    Work experience placement
    Summer holiday
    Flexible hours

    EY

    Baltimore, MD
    4 days ago
  •  ...Network Engineer III We are looking for a skilled Network Engineer III to join...  ...networks, including elements of the Defense Information Systems Network (DISN) and the Global...  ...the underlying architecture, protocols, security, network management, and physics. Technical... 

    ClearanceJobs

    Baltimore, MD
    3 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Information System Security Officer (SME), Level III. Be the first to apply!