Sub-Project Manager, Cybersecurity Plan Review

OneZero SolutionsWashington, DC
Remote

About The Position

The Sub-Project Manager, Cybersecurity Plan Review leads the team responsible for reviewing cybersecurity plans and cybersecurity assessments submitted under 33 CFR Part 101 Subpart F. This position manages the Plan Reviewers and serves as the lead for resolving and providing the final recommendation on complex or novel submittals. This is a designated Key Personnel position; the Government must acknowledge any replacement in writing.

Requirements

  • One (1) year of experience in a team leadership or project management role.
  • A detailed understanding of 33 CFR Subchapter H, specifically 33 CFR Part 101 Subpart F, and knowledge of maritime operational environments for both vessels and facilities.
  • Proficiency in regulatory compliance with industry-standard cybersecurity frameworks such as NIST CSF.
  • Three (3) years of experience demonstrating proficiency in maritime security or operations, or three (3) years of experience in cybersecurity policy or compliance.
  • At least one cybersecurity certification satisfying the certification requirement for the DoD 8140 DCWF work role of Security Control Intermediate proficiency level (for example CISA, CGRC, or CISSP).
  • Must disclose, for organizational conflict of interest screening, any current or prior engagement performed for MTSA-regulated vessel, facility, or Outer Continental Shelf facility owners or operators involving cybersecurity plan development, cybersecurity assessment, or related advisory services.
  • U.S. citizenship is required.
  • All personnel must undergo and successfully pass, at minimum, a Tier 1 background investigation (or equivalent) and be favorably adjudicated.

Nice To Haves

  • Certification satisfying the Security Control Assessor (612) requirement at the Advanced proficiency level.
  • Prior U.S. Coast Guard, DHS, or MTSA regulatory experience.
  • Experience as a Facility Security Officer, Vessel Security Officer, or Company Security Officer.
  • Experience leading document review, assessment, or authorization package quality control teams.
  • Familiarity with OT and ICS environments.
  • Bachelor's degree in cybersecurity, information technology, maritime studies, or a related field preferred.
  • Equivalent experience considered.

Responsibilities

  • Manage the Plan Reviewer team, including assignment, prioritization, and workload balancing; process submittments in the order received unless reprioritized by the COR.
  • Serve as the lead for resolving and providing the final recommendation on complex or novel cybersecurity plans.
  • Ensure Stage One cursory reviews are completed within ten (10) business days of assignment and that incomplete submittals are identified with draft signature-ready correspondence stating each deficiency, its regulatory basis, and resubmission instructions.
  • Ensure Stage Two detailed technical reviews and quality control are completed within forty-five (45) calendar days of receipt of a complete submittal.
  • Ensure reviewers recommend a finding of Satisfactory, Unsatisfactory, or Not Applicable for each regulatory checklist element in each plan and assessment.
  • Perform quality control on review products before submission to the Government, confirming findings are clearly stated, technically supportable, internally consistent, and traceable to the applicable requirement.
  • Oversee recording and maintenance of Alternative Security Program certifications, maintain the updated list of regulated entities covered by an ASP, and ensure ASP acknowledgment letters are drafted for USCG review.
  • Ensure Stage Three packages are provided to the USCG representative with the plan and annotated checklist, and that signature-ready correspondence is prepared for USCG signature and processed within one business day of signature.
  • Ensure MISLE, SharePoint, and ServiceNow records are updated before the close of the following business day for every status change.
  • Provide workload and aging inputs to the weekly and monthly status reports.
  • Escalate OT and ICS technical questions to the Senior SME, Equivalency, and refer policy-related inquiries to the designated USCG representative.
  • Identify and report to the Project Manager any submitter that may present an organizational conflict of interest.

Benefits

  • health, dental, vision, and life insurance
  • a 401(k) with company matching
  • paid time off and holidays
  • an employee referral program
  • educational assistance
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service