Cybersecurity Assessment and Authorization SME
About the role
Cybersecurity Assessment and Authorization SME
Overview
Electrosoft is seeking an experienced Cybersecurity Assessment & Authorization (A&A) Subject Matter Expert (SME) to support a complex Cybersecurity Program under Task Order in support of the Department of War portfolio. This position plays a critical role in protecting customer’s enterprise Information Technology (IT), Operational Technology (OT), Platform Information Technology (PIT), Cloud Hosted Services, Facility Related Control Systems (FRCS), and mission-critical information systems by supporting the implementation, assessment, authorization, and continuous monitoring of cybersecurity controls throughout the System Development Life Cycle (SDLC).
The Cybersecurity A&A SME serves as a trusted advisor to Information System Security Managers (ISSMs), Security Control Assessors (SCAs), Authorizing Officials (AOs), Program Managers, and Government stakeholders, providing expert guidance on the DoD Risk Management Framework (RMF), cybersecurity compliance, vulnerability management, and security authorization activities. The successful candidate will assess security controls, prepare authorization documentation, evaluate cybersecurity risk, and ensure compliance with DoD, customer, Federal, and NIST cybersecurity requirements while supporting enterprise cybersecurity initiatives across complex operational environments.
The ideal candidate is a highly motivated cybersecurity professional with extensive experience performing Assessment & Authorization activities, applying NIST SP 800-53 security controls, and supporting enterprise RMF implementations within large Department of Defense environments.
Duties/Responsibilities
- Serve as a Cybersecurity Assessment & Authorization (A&A) Subject Matter Expert supporting enterprise Risk Management Framework (RMF) activities across customer Information Systems, Cloud Hosted Services, Operational Technology (OT), Platform Information Technology (PIT), Facility Related Control Systems (FRCS), and hybrid computing environments.
- Lead and support all phases of the RMF lifecycle, including system categorization, security control selection, implementation, assessment, authorization, and continuous monitoring.
- Develop, review, update, and maintain RMF artifacts including System Security Plans (SSPs), Security Assessment Plans (SAPs), Security Assessment Reports (SARs), Plans of Action & Milestones (POA&Ms), Continuous Monitoring Strategies, Privacy Impact Assessments (PIAs), Risk Assessment Memorandums (RAMs), Authorizing Official Risk Acceptance (AORA) documentation, and authorization packages.
- Assess and validate security controls in accordance with DoDI 8510.01, NIST SP 800-53, DLA RMF