Summary
OneZero Solutions is an employee-centric company that builds technically proficient teams supporting customer missions across cyber mission areas. The Information Assurance Analyst supports Risk Management Framework and continuous monitoring activities for Department of State consular systems, maintaining authorization artifacts, monitoring findings, supporting assessments, and keeping systems audit-ready.
Responsibilities
- Develop and update RMF artifacts under the direction of the assigned ISSO: SSP sections and Security Control Implementation Statements, POA&M entries, system inventories, network and data-flow diagrams, SIAs, and CP/IRP/CMP updates
- Build and maintain the Evidence Index, Inherited Controls Matrix, and System Boundary & Data Flow Package for assigned systems; collect configuration baselines, SOPs, ACLs, screenshots, and log samples as control evidence(RMF Steps 1–3)
- Review iPost scores weekly for assigned systems, identify findings driving elevated risk, and track remediation status; maintain the list of findings open more than 30 days
- Update POA&M entries in the GRC tool at least monthly and within 5 business days of status changes; gather and attach closure evidence for ISSO validation
- Review vulnerability and compliance scan results within 5 business days of scan completion; track critical and high findings to BOD timelines; document remediation in POA&Ms
- Support annual Contingency Plan tests and Annual Control Assessments: draft test plans, coordinate participants, record results and lessons learned
- Prepare Security Control Review Meeting materials and collect artifacts requested by the Security Control Assessor; assist with control demonstrations(RMF Step 4)
- Capture and distribute meeting minutes for system meetings; maintain action-item logs
- Assemble Audit and Data Call Response Packages (SSP, POA&Ms, vulnerability reports, assessment results, CP test reports) and respond to HVA, BOD, OMB, OIG, and CDM data calls within DT/EA/CST timelines
- Register and maintain system records in the GRC tool; support asset inventory andiPostapplication grouping accuracy
- Collect data for quarterly FISMA metrics and weekly Issue Resolution, Remediation Status, and Risk Acceptance Recommendation reports
Skills
- Three (3)+ years of information assurance or cybersecurity compliance experience with hands-on exposure to NIST RMF / FISMA authorization activities
- Working knowledge of NIST SP 800-53 Rev. 5, SP 800-37 Rev. 2, and FIPS 199, and of SSP, POA&M, and contingency plan structure
- DoD 8140/8570 IAT Level II or IAM Level I baseline certification (e.g., Security+ CE, CySA+, SSCP, CGRC/CAP) or ability to obtain within 6 months
- Active, final SECRET security clearance; U.S. citizenship
- Strong written communication and attention to detail; able to produce Government-format documents
- Proficiency with Microsoft Word, Excel, PowerPoint, Visio, and SharePoint
- Department of State experience; ArchAngel and iPost familiarity
- Experience interpreting Tenable/Nessus, Wiz, or STIG scan output
- Familiarity with cloud (AWS/Azure) security concepts and FedRAMP
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field preferred; an additional four (4) years of directly relevant experience may substitute for the degree
- Remote; must reside within the National Capital Region (NCR)
- Full-time, 40 hours per week. Must be available during Department core hours of 9:00 a.m. – 3:00 p.m. ET, Monday – Friday, and flex working hours as needed to meet CST day-to-day and emergent requirements
- Position requires an OpenNet account, DoS PIV badge, multifactor authentication, and adherence to DoS SBU/CUI handling requirements
- Local travel within the National Capital Region; minimal other travel
- CISSP or Associate of ISC2, CGRC/CAP, or CISA
Qualifications
Must Haves
- Three (3)+ years of information assurance or cybersecurity compliance experience with hands-on exposure to NIST RMF / FISMA authorization activities
- Working knowledge of NIST SP 800-53 Rev. 5, SP 800-37 Rev. 2, and FIPS 199, and of SSP, POA&M, and contingency plan structure
- DoD 8140/8570 IAT Level II or IAM Level I baseline certification (e.g., Security+ CE, CySA+, SSCP, CGRC/CAP) or ability to obtain within 6 months
- Active, final SECRET security clearance; U.S. citizenship
- Strong written communication and attention to detail; able to produce Government-format documents
- Proficiency with Microsoft Word, Excel, PowerPoint, Visio, and SharePoint
- Department of State experience; ArchAngel and iPost familiarity
- Experience interpreting Tenable/Nessus, Wiz, or STIG scan output
- Familiarity with cloud (AWS/Azure) security concepts and FedRAMP
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field preferred; an additional four (4) years of directly relevant experience may substitute for the degree
- Remote; must reside within the National Capital Region (NCR)
- Full-time, 40 hours per week. Must be available during Department core hours of 9:00 a.m. – 3:00 p.m. ET, Monday – Friday, and flex working hours as needed to meet CST day-to-day and emergent requirements
- Position requires an OpenNet account, DoS PIV badge, multifactor authentication, and adherence to DoS SBU/CUI handling requirements
- Local travel within the National Capital Region; minimal other travel
Nice to Haves
- CISSP or Associate of ISC2, CGRC/CAP, or CISA
Benefits
- Health insurance
- Dental insurance
- Vision insurance
- Life insurance
- 401(k) with company matching
- Paid time off and holidays
- Employee referral program
- Educational assistance
- Remote work
- OneZero provides the laptop and collaboration tools