Cybersecurity Assessment & Authorization SME

ADEPT Force Group IncorporatedAlexandria, VA
$110,000 - $125,000Remote

About The Position

The Cybersecurity Assessment & Authorization (A&A) Subject Matter Expert (SME) executes DoD/DLA cybersecurity processes to authorize information systems, maintain authorization of information systems, and serves as a Subject Matter Expert for systems undergoing the Risk Management Framework (RMF) process. The Cybersecurity Assessment & Authorization SME possesses an understanding of how security controls identified in NIST SP 800-53 apply to the process of assessing and authorizing a large organization's IT infrastructure such as DLA, including large and small enclaves, Cloud Hosted Services, Operational Technology, AIS applications, and outsourced IT processes. The SME determines the residual risk of identified vulnerabilities and evaluates the potential impact on a system's current or future authorization while briefing senior management on the progress and results of systems undergoing the RMF process.

Requirements

  • Five (5) years of relevant C&A experience.
  • Risk Management Framework (RMF) and NIST C&A experience.
  • DoD cybersecurity experience.
  • Experience assessing security controls and conducting authorization reviews for large, complex organizations.
  • DoD Approved 8570/8140 Baseline Certification: Category IAM Level III.
  • Active Secret clearance with a Moderate Risk, Non-Critical Sensitive, Tier 3 (T3)/NACLC/ANACI investigation at the time of proposal submission.

Nice To Haves

  • Experience supporting Authorization to Operate (ATO) packages and RMF documentation.
  • Excellent analytical and technical writing skills.
  • Proficiency with Microsoft Office applications (Excel, Word, PowerPoint, MS Project, etc.).
  • Experience supporting DoD and/or DLA organizations.

Responsibilities

  • Execute DoD/DLA cybersecurity processes to authorize information systems.
  • Maintain authorization of information systems.
  • Serve as a Subject Matter Expert for systems undergoing the Risk Management Framework (RMF) process.
  • Determine the residual risk of identified vulnerabilities.
  • Evaluate the potential impact on a system's current or future authorization.
  • Brief senior management on the progress and results of systems undergoing the RMF process.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service