Source Job

$105,000–$155,000/yr
US

  • Provide expert guidance on cybersecurity policies, Risk Management Framework (RMF) processes, and security control implementation.
  • Conduct vulnerability assessments, penetration testing, and Cybersecurity Compliance and Readiness Inspections (CCRI).
  • Prepare detailed technical reports and briefings for senior leadership on cybersecurity findings and progress.

Cybersecurity RMF NIST 800-53 Vulnerability Assessment Penetration Testing

18 jobs similar to Cyber Security Subject Matter Expert

Jobs ranked by similarity.

US

  • Serves as a cybersecurity SME for Assessment and Authorization (A&A) of information systems, applying NIST 800-53 security controls and the Risk Management Framework (RMF) process.
  • Possesses five years of relevant RMF, NIST, and A&A experience, including assessing security controls for large, complex organizations like DLA.
  • Briefs senior management on authorization progress and understands cybersecurity in emerging technology areas such as Cloud and Industrial Control Systems.

Horizon Industries Limited is a dynamic IT and Management Consulting firm based in the Washington, DC area, providing full-cycle IT consulting and management support to both private and public sectors. Founded in 1996, the company prides itself on a diverse, employee- and family-centric culture with a focus on professional growth.

US

  • Lead ISSO activities to ensure confidentiality, integrity, availability, and compliance of enterprise applications and information systems.
  • Manage RMF processes including ATO packages, continuous monitoring, risk assessments, and accreditation documentation within eMASS.
  • Implement and maintain compliance with DISA STIGs, NIST 800-53 controls, and federal cybersecurity requirements.

Jobgether is a platform that uses AI-powered matching to connect candidates with job opportunities. The company facilitates the hiring process by sharing top-fitting candidate shortlists with partner companies, focusing on efficiency and objectivity.

US 3w PTO

  • Lead quality assurance for RMF authorization packages to ensure completeness and readiness for government review.
  • Coordinate with RMF analysts, ISSOs, system owners, and technical stakeholders to validate security documentation and evidence.
  • Mentor team members on documentation standards and best practices while tracking assessment readiness metrics to reduce rework.

True Zero Technologies is a veteran-owned small business that enables people and technology to drive quality outcomes. The company has been named a Best Place to Work multiple times and made the Inc. 5000 list of fastest-growing companies, reflecting its people-first culture and commitment to excellence.

US Unlimited PTO

  • Lead RMF activities including control selection, POA&M management, and ATO support for the depot.
  • Design supply chain security controls such as SBOM generation, artifact signing, and vulnerability scanning.
  • Integrate security tooling into CI/CD pipelines and interface with government assessors and authorizing officials.

OpenTeams builds AI that empowers, focusing on energy-efficient, cost-effective models that give users full ownership of their data. As a small company, they value freedom, teamwork, accountability, and reinvest 3% of profits into the open-source community.

$117,500–$166,250/yr
US

  • Lead FedRAMP Moderate and CMMC readiness assessments, including system boundary validation and control gap analysis.
  • Design and implement cloud security architectures aligned to NIST 800-53 and NIST 800-171 requirements.
  • Develop and own System Security Plans (SSPs), control narratives, and compliance documentation.

Riveron helps organizations implement leading governance, risk and compliance practices with a hands-on approach. The company fosters an entrepreneurial culture with collaboration and diverse perspectives, offering flexible work and progressive benefits.

US

  • Lead RMF authorization activities, including SSP, SAP, SAR, and POA&M development.
  • Conduct vulnerability assessments and enforce secure configurations using CIS Benchmarks and DISA STIGs.
  • Support cloud security initiatives in AWS GovCloud and advise on AI-enabled system security.

This company provides cybersecurity solutions for federal government systems. They are a mid-sized organization with a collaborative culture focused on security and compliance.

US

  • Provide RMF security artifacts for ARTRANS programs to inherit NIST 800-53 controls.
  • Maintain STIG/SRG checklists and monthly status reports.
  • Evaluate risk assessments and develop plans for full inheritance from DevSecOps pipeline.

DecisionPoint Corporation provides IT and cloud services, specializing in DevSecOps platforms and security compliance. They are a mid-sized company with a focus on supporting government programs through robust security practices.

$110,000–$145,000/yr
US

  • Partner with application development teams to integrate security requirements into design, development, and deployment workflows.
  • Support ATO efforts including development of System Security Plans (SSPs), POA&Ms, and control documentation.
  • Conduct risk assessments, vulnerability scans, and threat modeling aligned with NIST SP 800-53 and VA security standards.

Oddball builds quality software for the federal space, focusing on improving the daily lives of millions of people. They are a small company that values learning, growth, and making a big impact.

US

  • Lead the design and governance of control frameworks and risk workflows within the GRC platform, ensuring alignment with compliance requirements like HIPAA, HITRUST, and NIST.
  • Oversee risk assessments, control testing, and vendor evaluations to identify and mitigate security risks.
  • Manage policy lifecycle, audit coordination, and reporting on control effectiveness and risk indicators.

USAP is a healthcare organization focused on providing anesthesia services and patient safety. It is a growing company with a culture of security, compliance, and collaboration.

US

  • Design and implement cybersecurity architectures, controls, and technologies for secure government systems.
  • Manage Authority to Operate (ATO) activities, including security documentation, compliance tracking, and continuous monitoring.
  • Apply NIST SP 800 security controls and support Risk Management Framework (RMF) implementation.

The partner organization provides advanced cybersecurity solutions for critical government technology environments. They operate in a mission-driven, collaborative culture with a focus on protecting federal systems.

$105,000–$130,000/yr
US

  • Consult onsite and remotely with customers to collect and analyze data related to policies, infrastructure, and compliance requirements.
  • Perform gap analyses of current environments and recommend remediation steps.
  • Assist with sales and marketing activities as a subject matter expert and prepare industry presentations.

CampusGuard provides information security and privacy consulting and compliance services for campus-based organizations. It is a full-service firm leveraging industry standards to deliver world-class security and compliance services.

US

  • Manage and maintain version control of all documentation related to compliance for each standard and track implementation status of security controls.
  • Oversee preparation and execution of external compliance audits, including facilitating security assessments.
  • Support mapping of compliance requirements to security control implementation using agile development processes.

Hypori is a high-growth cybersecurity SaaS company providing a virtual workspace platform for secure mobile access. Backed by $55M in funding, the company is expanding into commercial and regulated markets with a focus on innovation and security.

$175,000–$265,000/yr
US Unlimited PTO

  • Develop and execute cybersecurity strategy, roadmap, and governance to protect Voyager's information systems and mission-critical environments.
  • Lead security operations, incident response, vulnerability management, and compliance with government regulations like CMMC and NIST.
  • Oversee security architecture, risk management, and team leadership to enable secure innovation in aerospace and defense.

Voyager is an innovative space, defense, and national security technology company delivering transformative, mission-critical solutions. It fosters a culture where innovation thrives, curiosity is rewarded, and impact is real, with a team of doers, thinkers, and builders united by purpose.

US

  • Execute formal SCA/R duties and lead security assessment efforts.
  • Establish reusable security playbooks and assessment frameworks for rapid AI deployment.
  • Evaluate technical control effectiveness across AWS cloud, DevSecOps pipelines, and AI/LLM stacks.

Dark Wolf Solutions specializes in cybersecurity engineering, cloud architecture, and DevSecOps prototyping for high-priority projects, including AI/LLM technologies. The company is an EEO/AA employer and focuses on fast-paced, collaborative environments.

$135,000–$155,000/yr
US 3w PTO

  • Lead formal CMMC Level 2 assessments for defense industrial base organizations pursuing certification.
  • Manage and mentor assessment teams, evaluate evidence against NIST SP 800-171 practices, and produce defensible findings.
  • Serve as the primary client point of contact, plan scope, and make final certification outcome decisions.

Sentinel Blue is a cybersecurity company focused on bringing enterprise-class cybersecurity to small and medium businesses. They are a young, fast-paced company that operates fully remote, constantly learning and pushing the envelope.

US 24w maternity 24w paternity

  • Own FedRAMP and GovRAMP certifications and roadmaps, including package management and compliance timelines.
  • Manage 3PAO relationships and assessments, coordinating scoping, evidence, and results validation.
  • Lead continuous monitoring, POA&M processes, and drive compliance automation and efficiency.

Smartsheet empowers teams to manage work seamlessly and scale solutions smarter, now uniting human teams with AI agents. It is an equal opportunity employer committed to fostering an inclusive environment with the best employees.

US 3w PTO

  • Analyze enterprise vulnerability data to identify the highest priority cyber exposures across the NIH environment.
  • Correlate vulnerability findings with threat intelligence, exploit availability, and operational risk to improve remediation prioritization.
  • Collaborate with incident responders, penetration testers, and security engineers to refine enterprise risk prioritization.

True Zero Technologies is a veteran-owned small business founded on the principle that enabling people and technology drives quality outcomes. We are a people-first company recognized as a Best Place to Work and on the Inc. 5000 list of fastest-growing companies.

$120,000–$132,000/yr
US

  • Improve, manage, and provide direction for LSAC's Security Policies, Procedures, and Best Practices.
  • Perform IT security inspections, tests, audits, and vulnerability assessments to ensure compliance with SOC2, IT/Financial Audits, and PCI/DSS.
  • Consult, monitor, and report on security systems like intrusion prevention, VPNs, firewalls, and conduct penetration testing to close security gaps.

LSAC advances law and justice by promoting access, equity, and fairness in law school admission and supporting the learning journey from prelaw through practice. They are a mission-driven organization with a culture of continuous improvement and creativity, emphasizing accountability and technical leadership.