Koniag · 3 months ago
Cybersecurity Automation Subject Matter Expert (SME) (TS/SCI)
Koniag IT Systems, a Koniag Government Services company, is seeking a Cybersecurity Automation Subject Matter Expert (SME) with an active TS/SCI to support government customers. The role involves engineering and implementing automated solutions to modernize cybersecurity compliance and streamline the DoD Risk Management Framework processes.
Financial ServicesImpact InvestingWealth Management
Responsibilities
Provide subject matter expertise in the development and deployment of automated RMF security control assessment, informing authorization, and continuous monitoring processes
Develop, integrate, and maintain automated workflows for evidence collection, control validation, and reporting
Leverage scripting, orchestration, and DevSecOps pipelines to embed compliance and security checks
Collaborate with cybersecurity engineers, assessors, system owners, and other stakeholders to align automation solutions with mission needs
Integrate automated testing tools (e.g., vulnerability scanners, configuration management tools) into RMF packages
Provide subject matter expertise on leveraging OSCAL (Open Security Controls Assessment Language) and other machine-readable compliance frameworks
Deliver training, documentation, and guidance to program teams on automated RMF practices
Stay current and provide feedback and recommendations on DoD cybersecurity policies, NIST updates, and emerging compliance automation technologies
Qualification
Required
TS/SCI security clearance required
Bachelor's degree in Cybersecurity, Information Systems, Computer Science, or related field
15+ years of experience in DoD cybersecurity compliance, assessment, or risk management
Hands-on expertise with RMF processes, NIST SP 800-53 Rev. 5 controls, and DoD RMF [DoDI 8510.01]
Experience developing automation solutions using Python, PowerShell, Ansible, or similar scripting/orchestration tools
Familiarity with continuous monitoring and automated compliance reporting
DoD 8570.01-M certification (e.g., CISSP, CAP, Security+ CE)
Ability to work on-site 1-4 days a week
Preferred
Experience with Governance, Risk, and Compliance (GRC tools) (e.g., eMASS, Archer, Xacta) and their automation/integration
Knowledge of OSCAL and machine-readable RMF artifacts
Experience with DevSecOps pipelines, CI/CD, and Infrastructure as Code (IaC)
Background in vulnerability management, STIG compliance, or automated security testing
Benefits
Health, dental, and vision insurance
401K with company matching
Flexible spending accounts
Paid holidays
Three weeks paid time off
Company
Koniag
Koniag was incorporated on June 23, 1972, to manage the land and financial assets on behalf of the corporation.
Funding
Current Stage
Late StageRecent News
2025-06-09
2025-03-27
Company data provided by crunchbase