Senior Security Subject Matter Expert (AI/ML, Cloud & Security)
This position is based in the United States and focuses on protecting cloud-based systems and cybersecurity capabilities within demanding Federal and DoD environments.
About the Role
This is a senior technical security role combining hands-on cloud security, SOC engineering, threat detection, incident response, risk management, and secure AI development. You will design and implement security controls across cloud infrastructure, security operations, and emerging AI/ML capabilities, working closely with engineering teams to embed security throughout the product and ML lifecycle. The role also contributes to compliance, audit readiness, vulnerability management, and secure-by-design practices for mission-critical systems addressing evolving risks associated with AI-enabled technologies.
Responsibilities
- Design, implement, maintain, and continuously improve security controls across system development and operational environments.
- Secure AWS cloud environments using STIG- and NIST-aligned architectures, least-privilege IAM, and established cybersecurity best practices, while supporting environments involving Azure and/or Google Cloud.
- Perform system hardening, vulnerability scanning, security monitoring, incident response, and remediation activities using platforms such as Splunk, Security Onion, Tenable, or equivalent tools.
- Analyze security logs, develop detection rules and alerting content, and support forensic investigations and threat-hunting activities.
- Contribute to security architecture and integration for new and existing systems, including infrastructure-as-code and CI/CD deployments using technologies such as Terraform and GitLab CI/CD.
- Partner with engineering teams to integrate security requirements throughout AI/ML and cybersecurity product development lifecycles.
- Conduct security reviews of AI/ML models, pipelines, and training data, assessing model integrity, data provenance, adversarial risks, and anomaly-detection model validation.
- Support secure-by-design practices for AI-enabled SOC tools and cybersecurity products, including threat modeling, secure code reviews, least-privilege data access, audit logging, and human-approval controls for AI-assisted actions.
- Provide security oversight for patch selection and updates, training-data security and integrity, network monitoring, access controls, and AI-related system changes.
- Support compliance initiatives aligned with CMMC Level 2, SOC 2, ISO/IEC 27001, and applicable Federal and DoD security requirements.
- Contribute to security documentation, risk assessments, control assessments, audit preparation, and remediation activities.
- Work collaboratively with technical and security stakeholders to identify emerging threats, strengthen defensive capabilities, and improve the overall security posture of mission-critical systems.
Requirements
- Bachelor's degree or equivalent professional experience, combined with 7+ years of relevant cybersecurity experience.
- Strong background in security operations, incident response, detection engineering, cloud security, or related cybersecurity disciplines.
- Hands-on experience securing on-premises and AWS environments, including STIG- and NIST-aligned security architectures.
- Practical experience with enterprise security technologies such as Splunk, Security Onion, Tenable, or comparable SIEM, monitoring, and vulnerability-management platforms.
- Proficiency in Python for security automation, tooling, analytics, or ML-related applications.
- Working knowledge of AI/ML architectures and their associated security risks, including model integrity, data poisoning, adversarial inputs, and data provenance.
- Strong understanding of cloud security principles, access controls, vulnerability management, monitoring, threat detection, and incident response.
- Experience integrating security into software development and operational processes, with an understanding of DevSecOps principles.
- Familiarity with infrastructure-as-code and CI/CD technologies such as Terraform and GitLab CI/CD is preferred.
- Experience supporting Federal, DoD, or other highly regulated environments is preferred, including CDM or comparable vulnerability-management programs.
- Experience with AI/ML anomaly detection or analytics frameworks such as Splunk MLTK/DSDL, scikit-learn, TensorFlow, MLflow, embeddings/RAG, or vector databases is preferred.
- Experience contributing to AI/ML or cybersecurity product development, secure design reviews, or security practices for ML pipelines is preferred.
- Professional certifications such as CISSP, CEH, C|CISO, GIAC, GICSP, ITIL, or comparable credentials are preferred.
- Strong analytical, problem-solving, communication, and collaboration skills.
- Must hold an active Top Secret security clearance; SCI and/or Polygraph eligibility is preferred depending on program requirements.
Benefits
- Opportunity to work on mission-critical cybersecurity and AI/ML capabilities supporting Federal and DoD environments.
- Exposure to advanced cloud security, SOC engineering, threat detection, AI/ML security, and DevSecOps practices.
- Opportunity to contribute to secure-by-design architectures and emerging AI-enabled cybersecurity technologies.
- Work involving AWS and other major cloud platforms, infrastructure-as-code, CI/CD, SIEM, vulnerability management, and ML analytics technologies.
- Professional development opportunities through exposure to evolving cybersecurity standards, technologies, and government compliance frameworks.
- Opportunity to apply and expand expertise in CMMC, NIST, STIG, SOC 2, and ISO/IEC 27001-aligned security practices.
- Senior-level technical ownership within a highly security-focused environment.
- Fully remote opportunity, subject to program and security requirements.