Jobs · OTHR · Maryland

Subject Matter Expert (Secure the Enterprise)

Amentum · Linthicum, MD · 1 wk ago
On-siteOTHRFull-time

Essential role supporting Amentum’s prime contract as the lead technical advisor for Secure the Enterprise (STE) and Zero Trust (ZT) initiatives.

Responsibilities

  • Serve as Lead Technical Advisor for STE and ZT, advising the Government Division Chief, Technical Director, and Deputy Authorizing Official on strategies, policies, and performance.
  • Brief the Chief Information Security Officer and Chief Information Officer on STE data, trends, updates, and changes.
  • Provide highest-level STE technical support to the security community, analyzing and advising on areas including:
    • Transport Layer Security (TLS) versions and cipher suites
    • Network Flow data (NetFlow and variants)
    • Configuration of network devices
    • Audit data logs (syslog and variants) collection and analysis
    • User activity monitoring
  • Assist system personnel across the enterprise to maintain operational security posture in accordance with STE compliance regulations, policies, and playbook guidance.
  • Provide guidance and technical expertise on STE requirements impacting security compliance of information systems.
  • Develop and execute an enterprise-level STE compliance program facilitating RMF continuous monitoring to minimize security risks and ensure routine compliance.
  • Manually review submitted evidence and justifications for compliance validations, determinations of applicability, and exceptions for all STE security controls.
  • Recommend leadership approval or rejection of requests for exceptions from STE security requirements.
  • Approve or reject requests for manual validation or determination of applicability based on review and written guidance.
  • Work with information system personnel to troubleshoot and correct rejected requests for manual compliance validation, determinations of applicability, and exceptions.
  • Review automated STE compliance data for errors or inconsistencies and report findings to leadership.
  • Assess the effectiveness of general IT and specific STE security controls to determine program effectiveness.
  • Maintain, develop, and enforce STE security policies, implementation guidelines, and customer training for information system personnel in diverse operational environments.
  • Coordinate with software developers to recommend changes, develop system requirements, and test new implementations.

Requirements

  • Demonstrate a high level of independent thought, action, and judgment.
  • Design and develop full-stack data analysis solutions in Python and Django in a Linux server environment; maintain current applications.
  • Self-motivated, independent, detail-oriented, responsible team player.
  • Experience briefing and working with the highest levels of government agency leadership.
  • Ability to develop and maintain cross-organization and interagency relationships over time.
  • Working knowledge of security authorization processes and procedures as defined in the RMF in NIST SP800-37.
  • Knowledge of cloud architecture and cloud service providers.
  • Knowledge of customer enterprise tools and solutions.
  • Ability to effectively communicate with customers of various skill levels to resolve compliance issues.
  • Willingness and ability to perform deep-dive analysis on customer issues to resolve compliance challenges.
  • Knowledge of a broad spectrum of commercial security tools and their uses.
  • Experience with hardware/software security implementations.
  • Knowledge of communication protocols, encryption techniques/tools, PKI, and authorization services.
  • Familiarity with security incident management; experience collaborating with Incident Response Teams to provide viable recommendations for resolution of computer security incidents and vulnerability compliance.
  • Experience creating and presenting documentation and management reports.
  • Active TS/SCI clearance.
  • Minimum twelve (12) years of experience with System Security or related customer-interfacing technical lead position, including two (2) years of technical project leadership experience.
  • Master’s degree in Computer Engineering, Computer Science, Computer Forensics, or related field from an accredited college or university plus twelve (12) years of experience, or a Bachelor’s degree in the same fields plus fourteen (14) years of experience.

Preferred Qualifications

  • Familiarity with the Secure the Enterprise program and the Zero Trust Initiative.
  • Experience working in a help desk environment with the ability to maintain professionalism under strenuous circumstances.
  • Commitment to continuous learning and system development due to the evolving nature of cyber threats.
  • Ability to quickly learn new concepts, data formats, software, and operating environments.
  • Advanced knowledge of Microsoft Office products, especially Excel formulas for data analysis and PowerPoint for professional presentations.
  • Competency in Visual Basic for Applications (VBA).
  • Familiarity with ICD503, CNSSI1253, SP800-53, and related standards.

Pay

$220,000 - $250,000 per year. Actual compensation may vary based on job responsibilities, education, experience, skills, internal equity, market data, and applicable laws.

Benefits

  • Health, dental, and vision insurance
  • Paid time off and holidays
  • Retirement benefits (including 401(k) matching)
  • Educational reimbursement
  • Parental leave
  • Employee stock purchase plan
  • Tax-saving options
  • Disability and life insurance
  • Pet insurance

Note: Benefits may vary based on employment type, location, and applicable agreements.

Similar jobs