Cyber Security Assessment & Authorization SME

ESMVienna, VA
$110,000 - $160,000Remote

About The Position

Enterprise Solutions and Management (ESM) is a rapidly growing government contractor that provides strategic IT services that meet mission needs for Defense and Federal customers. We are hiring a Cyber Security Assessment & Authorization SME for an exciting remote opportunity. The successful candidate serves as a Cybersecurity Subject Matter Expert (SME) for the Assessment and Authorization (A&A) of information systems, ensuring compliance with Department of Defense (DoD) and Defense Logistics Agency (DLA) cybersecurity policies, procedures, and the Risk Management Framework (RMF). They execute cybersecurity authorization processes to obtain and maintain system authorizations while providing expert guidance to stakeholders throughout the authorization lifecycle. They apply a strong understanding of NIST SP 800-53 security controls to assess and authorize complex enterprise IT environments, including cloud-hosted services, operational technology, application information systems, and outsourced IT services across large and diverse infrastructures. The successful candidate evaluates security control deficiencies, determines residual risk and the potential impact of identified vulnerabilities on system authorization, and develops risk-based recommendations to support informed decision-making. They also communicate the status, progress, and outcomes of RMF activities by briefing senior leadership and collaborating with technical and program stakeholders to ensure secure, compliant, and mission-ready information systems.

Requirements

  • Expert knowledge of the Department of Defense (DoD) Risk Management Framework (RMF), Assessment and Authorization (A&A) processes, and applicable DoD, DLA, and NIST cybersecurity policies and guidance, including NIST SP 800-53 security controls.
  • Demonstrated ability to plan, execute, and maintain cybersecurity authorizations for complex information systems, ensuring compliance throughout the system lifecycle and supporting timely authorization decisions.
  • Skill in assessing security controls, identifying and evaluating control deficiencies, analyzing residual risk, and developing risk-based recommendations to support informed authorization and cybersecurity risk management decisions.
  • Knowledge of cybersecurity principles and best practices for enterprise IT environments, including cloud-hosted services, operational technology (OT), application information systems, and outsourced IT services across large, complex infrastructures.
  • Ability to serve as a cybersecurity subject matter expert (SME) by providing technical guidance, interpreting cybersecurity requirements, and collaborating with system owners, program managers, engineers, and other stakeholders to achieve compliance and mission objectives.
  • Skill in communicating complex cybersecurity concepts and RMF activities through clear written documentation, briefings, and presentations to senior leadership, technical teams, and other stakeholders regarding authorization status, risks, and recommended courses of action.
  • Five (5) years of relevant certification and accreditation experience; Risk Management Framework (RMF) and NIST C&A experience; DOD cybersecurity experience. Experience for large complex organizations.
  • 8570/8140 compliant certification.
  • Secret clearance.

Nice To Haves

  • Be a positive, self-motivated, and proactive person with the ability to adapt to change and tolerate stressful situations.
  • Candidate must communicate effectively with team members, team lead, management, and government customer.

Responsibilities

  • Serve as a Cybersecurity Subject Matter Expert (SME) for the Assessment and Authorization (A&A) of information systems.
  • Ensure compliance with Department of Defense (DoD) and Defense Logistics Agency (DLA) cybersecurity policies, procedures, and the Risk Management Framework (RMF).
  • Execute cybersecurity authorization processes to obtain and maintain system authorizations.
  • Provide expert guidance to stakeholders throughout the authorization lifecycle.
  • Apply a strong understanding of NIST SP 800-53 security controls to assess and authorize complex enterprise IT environments, including cloud-hosted services, operational technology, application information systems, and outsourced IT services across large and diverse infrastructures.
  • Evaluate security control deficiencies, determine residual risk and the potential impact of identified vulnerabilities on system authorization.
  • Develop risk-based recommendations to support informed decision-making.
  • Communicate the status, progress, and outcomes of RMF activities by briefing senior leadership.
  • Collaborate with technical and program stakeholders to ensure secure, compliant, and mission-ready information systems.
  • Other duties as assigned.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service