Senior Technical Advisor
Candidate MUST be a Wisconsin resident or willing to relocate to Wisconsin prior to starting the role at their own expense. This position is 100% remote with occasional onsite visits (1-2 times) required throughout the duration of the contract.
About the Role
Seeking an expert senior technical leader and engineer to serve as a strategic advisor to the CISO and drive implementation. This role balances high-level strategic advisory with hands-on engineering, operating on a "teach-by-doing" knowledge transfer model. The primary objective is to build long-term internal capabilities while operationalizing and enforcing the newly updated Flaw Remediation (SI-2) Standard. This initiative transitions from reactive, manual vulnerability management to an AI-accelerated, continuous authorization, and automated DevSecOps posture.
Responsibilities
- CISO Strategic Advisory and Engineering
- Act as a direct technical advisor to the CISO, translating federal mandates, emerging AI threat models, and architectural gaps into actionable enterprise security directives.
- Execute a hands-on knowledge transfer model, co-engineering data pipelines and security automation alongside internal DET staff to institutionalize elite technical skills.
- Deliver real-time training and co-develop automation playbooks within security operations (SecOps) using a live demonstration approach.
- Flaw Remediation (SI-2) Standard Operationalization
- Tier Optimization & Enforcement: Architect automated tracking, logging, and validation mechanisms to implement compliance with updated SI-2 timeframes:
- Tier 1 (Highest Urgency): Ensure all public-facing vulnerabilities, CISA KEV listings, active exploits, and identity/privileged system flaws implement approved mitigations or compensating controls within 24 hours, with full remediation closed inside 7 calendar days.
- Tier 2 (High-Risk/Internal): Configure alerting and metric reporting to validate mitigation within 48 hours and full remediation within 15 calendar days.
- Tier 3 (Moderate/Low): Establish repeatable monthly scheduling to ensure remediation within 30 calendar days.
- Clean Deployment Architectures: Partner with agency development teams to pivot away from manual, in-place patching. Author and implement automated templates for clean deployments using virtualized system images, containers, and cloud-native configurations.
- DevSecOps Integration: Embed secure builds, automated software testing, code scanning, and dependency updates natively into agency deployment pipelines.
- Tier Optimization & Enforcement: Architect automated tracking, logging, and validation mechanisms to implement compliance with updated SI-2 timeframes:
- AI Capability Deployment & Toolchain Integration
- Operationalize Gemini Government and Google Codemender or equivalent directly inside active workflows, demonstrating how to leverage generative AI to automate log parsing, threat hunting, and source-code remediation.
- Engineer automated data pipelines to feed the centralized enterprise platform (incorporating telemetry from Tenable.io, Google Mandiant ASM, Microsoft Azure Arc, Splunk, and Google SecOps) to maintain a single, authoritative pane of glass.
- Ensure all AI-assisted capabilities comply strictly with privacy, data classification, and logging safeguards, preventing non-public vulnerability metrics from leaking into unvetted environments.
- Governance Safeguards & Escalation Automation
- Build automated low-code workflows to manage the SI-2 time-bound exception lifecycle, ensuring every granted exception maps back to a named owner, specific compensating controls, and an explicit financial tiedown capturing technical debt.
- Configure automated alert thresholds and workflow routing for significant business risks that exceed normal management tolerance, ensuring rapid escalation in line with the SI-2 update.
Requirements
The designated expert must demonstrate a unique blend of strategic advisory presence and deep, practical engineering capability. Must have prior experience in the following:
- Proven experience serving as a trusted technical advisor to CISOs, CIOs, or senior executive leaders within public sector or heavily federated enterprise environments.
- Documented success as a technical mentor, trainer, or engineering lead focused on pair-engineering and technical upskilling of infrastructure and security operations staff.
- Comprehensive expertise operationalizing security controls, including tiering models, compensating control validation, and time-bound risk governance structures.
- Enterprise cyber stack experience with Google Threat Intel or VirusTotal, Google SecOps, Mandiant ASM, Tenable.io, Microsoft Azure Arc, GitHub, GitHub Advanced Security, Ansible Tower, and Gemini/Anthropic AI security frameworks.
Nice to Have Skills
- Federated/Government environment experience.
- Tech stack familiarity: Google, Microsoft, AWS, Splunk.
Pay
$128.66 - $134.97 per hour
Schedule
8 AM to 5 PM
Qualifications
Bachelor's degree