Cyber Security Subject Matter Expert
This position is contingent upon the successful award of a contract currently under bid.
About the role
Serves as a cybersecurity Subject Matter Expert (SME) with regards to Assessment and Authorization (A&A) of information systems and all associated cybersecurity policies and procedures. Executes DoW/DLA cybersecurity processes to authorize information systems, maintain authorization of information systems, or serves as a Subject Matter Expert (SME) for systems undergoing the authorization process. Possesses an understanding of how security controls identified in the NIST 800-53 apply to the process of assessing and authorizing a large organization’s IT infrastructure such as DLA, which includes a compilation of large and small enclaves, Cloud Hosted Services, Operational Technology, AIS applications, and outsourced IT processes. Determines the residual risk of an identified vulnerability (e.g., non-compliant security control) and assesses possible ramifications on the system’s current or future authorization. Briefs senior management on the progress or results of an information system undergoing the Risk Management Framework (RMF) process.
Responsibilities
- Conduct in-depth research and analysis to support the development of cybersecurity strategies and solutions.
- Recommend and assist in the selection of cybersecurity software tools, including the development of product-specific STIGs based on applicable DISA SRGs.
- Perform vulnerability assessments, penetration testing, and CCRI evaluations across networks, databases, applications, and IT frameworks.
- Apply advanced technical principles, theories, and methodologies to solve unusually complex problems.
- Develop and guide the implementation of new cybersecurity concepts and technologies.
- Work independently under consultative direction to achieve long-range objectives.
- Produce high-quality written reports and deliver oral briefings to stakeholders and leadership.
- Ensure compliance with DoD cybersecurity regulations and standards.
Requirements
- Five (5) years of relevant C&A experience; Risk Management Framework (RMF) and NIST C&A experience; DoD cybersecurity experience.
- Experience in assessing security controls and conducting authorization reviews for large, complex organizations.
- Must possess a Moderate Risk, Non-Critical Sensitive, Tier 3 (T3)/NACLC/ANACI at the time of proposal submission.
- Secret clearance.
- DoD Approved 8570 Baseline Certification: Category IAM Level III.
Qualifications
- Strong analytical and problem-solving skills for resolving security issues.
- Strong skills implementing and configuring networks and network components.
- Expert experience in cybersecurity and evaluations.
Preferred Qualifications
- Bachelor’s degree in a relevant field.
Pay
The annual salary range for this position is $105,000 to $155,000.
Benefits
- Medical, dental, and vision insurance.
- 401(k) plan with company matching.
- Tax-deferred savings options.
- Supplementary benefits.
- Paid time off.
- Professional development opportunities.