We are an employee-centric company that truly values our team members and the contributions they make to our customers and the missions they support. We pride ourselves on being forward-leaning thinkers and on building teams that are, and continue to be, technically proficient across a broad range of cyber mission areas. OneZero full-time employees receive a highly competitive benefits package, including health, dental, vision, and life insurance, a 401(k) with company matching, paid time off and holidays, an employee referral program, and educational assistance. Additional details are available on our website: https://www.onezerollc.com/careers/
Position Title: Sub-Project Manager, Cybersecurity Plan Review
Location: Remote (United States).
Security Clearance
- No security clearance is required. This work is performed at the Controlled Unclassified Information (CUI) level.
- S. citizenship is required. All personnel must undergo and successfully pass, at minimum, a Tier 1 background investigation (or equivalent) and be favorably adjudicated.
Position Summary
The Sub-Project Manager, Cybersecurity Plan Review leads the team responsible for reviewing cybersecurity plans and cybersecurity assessments submitted under 33 CFR Part 101 Subpart F. This position manages the Plan Reviewers and serves as the lead for resolving and providing the final recommendation on complex or novel submittals. This is a designated Key Personnel position; the Government must acknowledge any replacement in writing.
Key Responsibilities
- Manage the Plan Reviewer team, including assignment, prioritization, and workload balancing; process submittals in the order received unless reprioritized by the COR.
- Serve as the lead for resolving and providing the final recommendation on complex or novel cybersecurity plans.
- Ensure Stage One cursory reviews are completed within ten (10) business days of assignment and that incomplete submittals are identified with draft signature-ready correspondence stating each deficiency, its regulatory basis, and resubmission instructions.
- Ensure Stage Two detailed technical reviews and quality control are completed within forty-five (45) calendar days of receipt of a complete submittal.
- Ensure reviewers recommend a finding of Satisfactory, Unsatisfactory, or Not Applicable for each regulatory checklist element in each plan and assessment.
- Perform quality control on review products before submission to the Government, confirming findings are clearly stated, technically supportable, internally consistent, and traceable to the applicable requirement.
- Oversee recording and maintenance of Alternative Security Program certifications, maintain the updated list of regulated entities covered by an ASP, and ensure ASP acknowledgment letters are drafted for USCG review.
- Ensure Stage Three packages are provided to the USCG representative with the plan and annotated checklist, and that signature-ready correspondence is prepared for USCG signature and processed within one business day of signature.
- Ensure MISLE, SharePoint, and ServiceNow records are updated before the close of the following business day for every status change.
- Provide workload and aging inputs to the weekly and monthly status reports.
- Escalate OT and ICS technical questions to the Senior SME, Equivalency, and refer policy-related inquiries to the designated USCG representative.
- Identify and report to the Project Manager any submitter that may present an organizational conflict of interest.
Required Qualifications
- One (1) year of experience in a team leadership or project management role.
- A detailed understanding of 33 CFR Subchapter H, specifically 33 CFR Part 101 Subpart F, and knowledge of maritime operational environments for both vessels and facilities.
- Proficiency in regulatory compliance with industry-standard cybersecurity frameworks such as NIST CSF.
- Three (3) years of experience demonstrating proficiency in maritime security or operations, or three (3) years of experience in cybersecurity policy or compliance.
- At least one cybersecurity certification satisfying the certification requirement for the DoD 8140 DCWF work role of Security Control Intermediate proficiency level (for example CISA, CGRC, or CISSP)
- Must disclose, for organizational conflict of interest screening, any current or prior engagement performed for MTSA-regulated vessel, facility, or Outer Continental Shelf facility owners or operators involving cybersecurity plan development, cybersecurity assessment, or related advisory services.
Preferred Qualifications
- Certification satisfying the Security Control Assessor (612) requirement at the Advanced proficiency level.
- Prior U.S. Coast Guard, DHS, or MTSA regulatory experience.
- Experience as a Facility Security Officer, Vessel Security Officer, or Company Security Officer.
- Experience leading document review, assessment, or authorization package quality control teams.
- Familiarity with OT and ICS environments.
Technical Skills
- Regulatory checklist-based review and quality control methods.
- NIST Cybersecurity Framework and NIST SP 800-series guidance.
- USCG MISLE, SharePoint, and ServiceNow, or comparable case management systems.
- Workload tracking and aging reporting.
- CUI and SSI handling in accordance with 49 CFR Part 1520 and DHS MD 11042.1.
Education
Bachelor's degree in cybersecurity, information technology, maritime studies, or a related field preferred. Equivalent experience considered.
OneZero Solutions, LLC is an Equal Opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, pregnancy, genetic information, disability, status as a protected veteran, or any other protected category under applicable federal, state, and local laws.
To request an accommodation, please contact us at recruiting@onezerollc.com or call (202) 987-2580.