Cybersecurity Assessment and Authorization SME (DAAS API GW)
About the role
Position Overview
Cybersecurity Assessment and Authorization Subject Matter Expert (SME) for a proposal future job opportunity. Fully remote.
Responsibilities
- Serves as cybersecurity SME for Assessment and Authorization (A&A) of information systems and associated cybersecurity policies and procedures.
- Performs DOW cybersecurity process while authorizing an information system or serving as SME for a system undergoing authorization.
- Understands application of NIST 800-53 security controls to assessing and authorizing large organization IT infrastructure such as DLA’s enclaves, AIS applications, and outsourced IT processes.
- Determines applicable severity value for identified vulnerabilities and possible ramifications on the system’s current or future authorization.
- Briefs senior management on progress or results of an information system undergoing the Risk Management Framework (RMF) process.
Minimum Experience
- Five (5) years of relevant Risk Management Framework (RMF), NIST, and A&A experience.
- Five (5) years of relevant DOW cybersecurity experience.
- Assessing security controls and conducting authorization reviews for large, complex organizations.
- Knowledge of general tenets supporting DOW implementation of its authorization process, including cybersecurity policy, procedures, and processes.
- Knowledgeable in cybersecurity of emerging technology areas such as Cloud and Industrial Control Systems (ICSs), warehouse execution systems, and Operational Technology (OT) infrastructures.
Required Skills
- Certification: CNDSP-Analyst or CSSP-Analyst certification.
- Investigative Requirement: Secret clearance.
- 8570/8140: DoW Approved 8570 Baseline Certification: Category IAM Level III.
- Computing Environment: AC & PHY SEC, CompTIA Security+, CE, CISSP, MCDST, MCITP EDST, MCITP EDA, MCITP SA, MCITP EA, MCM, MCA: MS Windows Server: Directory, Windows 10, MCSA, MCSE within 3 months after onboarding start date.
Remote Work Environment
This position is performed in a 100% remote, collaborative environment supporting government development activities. The employee will work closely with Task Order Project Manager, Requirements Analysts, Scrum Master, Developers, Testers, and Government stakeholders through virtual meetings and Agile ceremonies. Employees must maintain a secure remote workspace, use government-approved systems and security controls, and comply with all cybersecurity and data protection requirements, including Controlled Unclassified Information (CUI). Regular availability during standard business hours is required to support team collaboration, customer meetings, and project deliverables.