Jobs · Engineering · Alabama

Senior Cybersecurity Technical Subject Matter Expert (SME)

Geeks and Nerds (GaN Corporation) · Huntsville, AL · Yesterday
On-siteEngineeringFull-time

About the role

The Senior Cybersecurity Technical Subject Matter Expert (SME) will provide expert analysis and guidance on matters related to cybersecurity and cyber resilience for all CPE AVN systems. The SME will provide guidance to safeguard information, infrastructures, applications, and mission systems and processes against cyber threats. The SME will provide threat and vulnerability analysis and support to ensure vulnerabilities are identified, appropriately assessed, mitigated and documented for acceptance by the Authorizing Official (AO).

Responsibilities

  • Monitor systems for compliance with DoD and Army standards through the analysis of RMF artifacts to include diagrams, HW/SW lists, technical scan data, and other related materials
  • Identify both baseline security requirements based on the system configuration as well as confirm that these baseline requirements are being met
  • Collaborate with cross-functional teams to understand the system and threat environment and advise on vulnerabilities, mitigations, and risks
  • Provide cybersecurity and cyber resiliency support to the CPE AVN AAMCAT team
  • Conduct threat and vulnerability analysis
  • Provide technical direction, interpretation, and alternatives to senior leaders
  • Stay informed of the latest cyber threat trends, advancements, and emerging threats in the field of cybersecurity and cyber resiliency and apply this knowledge to CPE AVN systems
  • Provide expert advice and guidance to decision-makers and stakeholders on all matters related to cybersecurity and cyber resilience for CPE AVN systems
  • Fully understand and execute all RMF steps necessary for creating A&A packages in accordance with DoD, Defense Information Systems Agency (DISA), and Army cybersecurity requirements
  • Monitor and manage system Enterprise Mission Assurance Support Service (eMASS) records
  • Conduct cybersecurity testing analysis and provide overall vulnerability and risk assessment reports
  • Analyze Plans of Action and Milestones (POA&Ms)
  • Analyze Change Requests for security impact
  • Work closely with internal and external personnel to address unique cybersecurity concerns to include the US Army CIO staff, NETCOM, DISA, and others
  • Communicate up and down within the organization; prepare detailed descriptions of issues, status updates, recommendations, and reports
  • Complete reviews of required cybersecurity documentation and artifacts to include: POA&Ms, SCA-V Reports, MOUs, MOAs, connection agreements, dataflow diagrams, network diagrams, PPPs, CSS, TEMPs, and other documents and make recommendations to the system owner, O-ISSM, P-ISSM, and AO as appropriate
  • Manage customer relationship with cyber teams, system owners, and customers

Qualifications

  • 10+ years of related experience including both the development and analysis for compliance of RMF packages, analyzing vulnerabilities, mitigations, and residual risk for IT and OT environments
  • Strong analytical skills, excellent problem-solving abilities, and a deep understanding of the latest cybersecurity technologies and best practices
  • Bachelor's degree in related technical field
  • DoD 8570.01M IAM Level III Certification
  • US Citizenship
  • Active Secret preferred with ability to obtain TS

Benefits

  • Employee-Owned company – dedicated team members are also the owners of Geeks and Nerds

Similar jobs