Jobs · Engineering · Colorado

Cybersecurity SME

KaiHonua · Denver, CO · 4 days ago
Engineering$135k/yrFull-time

Mano Lani LLC is seeking a well-qualified Cybersecurity Subject Matter Expert (SME) to provide comprehensive cybersecurity support for the DTMO Enterprise Infrastructure in accordance with the Risk Management Framework (RMF), NIST 800-37, and DoD cybersecurity requirements. This role serves as the primary SME for all cybersecurity matters, ensuring DTMO systems maintain their Authority to Operate (ATO) by managing the RMF process, conducting security assessments, and overseeing remediation of vulnerabilities.

About the Role

The Cybersecurity SME coordinates with DMDC, the DTMO Information System Security Manager (ISSM), Authorizing Official (AO), and Security Control Assessor (SCA) to maintain system security posture, manage Plans of Action and Milestones (POA&Ms), and ensure compliance with DoD cybersecurity mandates. Responsibilities include monitoring and reporting on security events, supporting incident response activities, and providing cybersecurity guidance to DTMO leadership and technical staff. The role also supports cloud security compliance and ensures adherence to DoD cloud computing requirements.

Responsibilities

  • Coordinate with DMDC to administer all aspects of RMF to ensure DTMO systems are accredited and maintain ATO.
  • Coordinate with the DTMO ISSM to maintain DTMO system security packages.
  • Support the Authorizing Official (AO) and Security Control Assessor (SCA) to ensure systems remain compliant.
  • Work with the ISSM to record, track, and close all applicable POA&Ms.
  • Participate in audit support during planned assessment events.
  • Coordinate with DMDC to report security status of DTMO systems via automated and manual tools.
  • Monitor and audit security event logging, generate reports, and analyze findings.
  • Analyze system vulnerability reports and recommend and implement remediation efforts.
  • Ensure system patches are applied to address security vulnerabilities.
  • Review security controls to ensure appropriate access control measures are in place.
  • Develop and submit Deviation Requests to authorize deviations from DoD STIG requirements.
  • Develop and maintain system security documentation including System Security Plans (SSPs), Security Assessment Reports (SARs), and Risk Assessment Reports (RARs).
  • Support incident response activities and coordinate with DMDC on security incidents.
  • Provide cybersecurity guidance and recommendations to DTMO leadership.
  • Support cloud security compliance and ensure adherence to DoD cloud computing requirements.
  • Stay current on emerging cybersecurity threats and recommend appropriate countermeasures.
  • Conduct security assessments and penetration testing coordination.
  • Support continuous monitoring activities and ensure compliance with DoD Information Assurance Vulnerability Management (IAVM) requirements.

Requirements

  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Engineering, or a related field or Certified Information Systems Security Professional (CISSP) certification.
  • 5+ years of experience in the cybersecurity field.
  • Extensive experience supporting federal cybersecurity programs or initiatives, preferably under government contracts or GWAC vehicles.
  • Strong knowledge of NIST cybersecurity frameworks, including RMF and NIST SP 800-series publications.
  • Experience with security architecture, vulnerability management, and cybersecurity risk assessment.
  • Familiarity with federal cybersecurity compliance requirements, including FISMA and agency cybersecurity policies.
  • 5+ years of experience with Risk Management Framework (RMF) / NIST 800-37.
  • Experience with DoD Security Technical Implementation Guides (STIGs).
  • Experience with Enterprise Mission Assurance Support Service (eMASS).
  • Experience with vulnerability assessment and remediation.
  • Experience with security event logging and monitoring.
  • Plan of Action and Milestones (POA&M) management.
  • Cloud security experience (AWS, Azure, or Red Hat OpenStack).
  • Experience with Splunk technology for security and compliance.
  • Experience with SaaS, PaaS, and cloud platforms.

Qualifications

  • Preferred: Master's degree in a related discipline.
  • Preferred certifications: Microsoft Certified Solutions Expert (MCSE) Cloud Platform and Infrastructure, AWS Certified Solutions Architect, Red Hat Certified System Administrator in Red Hat OpenStack, or equivalent.

Physical Requirements

  • Work may involve sitting or standing for extended periods of time.
  • Position may require typing and reading from a computer screen.
  • Must have sufficient mobility, including bending, reaching, and kneeling to complete daily duties.
  • May require walking moderate to long distances.
  • May include lifting up to 25 pounds as necessary.

Pay

USD $135,000.00 - USD $163,000.00 per year.

Similar jobs

Cybersecurity SME

KaiHonuaDenver, CO· 2 mo ago
Engineering$135k/yrapply on de.jobsyn.org

Cybersecurity SME

IPTAFort Belvoir, VA· 2 wk ago
Information Technologyapply on ipta.isolvedhire.com

Cybersecurity SME

JobgetherUnited States· 1 mo ago
RemoteEngineering$155k–$185k/yrapply on jobs.lever.co

Cybersecurity SME

Lucayan Technology Solutions LLCTampa, FL· 3 mo ago
Engineeringapply on ats.rippling.com

Cybersecurity SME

KBR CareersDulles, VA· 1 mo ago
Engineering$176k–$215k/yrapply on careers.kbr.com

Cybersecurity SME

Spatial Front, IncArlington, VA· 1 mo ago
Engineeringapply on recruiting.paylocity.com