Cyber Security Subject Matter Expert (SME)

Nova Dine

  • Washington, District of Columbia
  • 11 days ago
  • $145,000–$175,000 Per Year
Want to know if you’re a fit?
Upload your resume and let our AI show you.

Skills

  • Access Authorizationunmatched
  • Access Controlunmatched
  • Analysis Skillsunmatched
  • Authenticationunmatched
  • Automationunmatched
  • Best Practicesunmatched
  • CCSP - Cisco Certified Security Professionalunmatched
  • CEH - Certified Ethical Hackerunmatched
  • CISA - Certified Information Systems Auditorunmatched
  • CISM - Certified Information Security Managerunmatched
  • CISSP - Certified Information Systems Security Professionalunmatched
  • Cloud Applicationsunmatched
  • Cloud Architectureunmatched
  • Cloud Computingunmatched
  • Communication Skillsunmatched
  • CompTIA Security+unmatched
  • Computer Scienceunmatched
  • Computer Securityunmatched
  • Contingency Plansunmatched
  • Continuous Improvementunmatched
  • Cryptographyunmatched
  • Data Analysisunmatched
  • Documentationunmatched
  • Endpoint Securityunmatched
  • Environmental Researchunmatched
  • External Auditunmatched
  • FISMA - Federal Information Security Management Actunmatched
  • Federal Laws and Regulationsunmatched
  • Firewallsunmatched
  • GIAC - Global Information Assurance Certificationunmatched
  • GNU C Compilerunmatched
  • Governmentunmatched
  • Huntingunmatched
  • Hybrid Cloudunmatched
  • Identity Data Managementunmatched
  • Incident Responseunmatched
  • Information Technology & Information Systemsunmatched
  • Information/Data Security (InfoSec)unmatched
  • Internal Auditunmatched
  • Internet Securityunmatched
  • Intrusion Detection Systemsunmatched
  • Knowledge Transferunmatched
  • Leadershipunmatched
  • Maintain Complianceunmatched
  • Metricsunmatched
  • Microsoft Product Familyunmatched
  • Microsoft Windows Azureunmatched
  • Network Administration/Managementunmatched
  • Network Configuration Managementunmatched
  • OSINT (Open Source Intelligence)unmatched
  • On Callunmatched
  • Operational Auditunmatched
  • Operational Supportunmatched
  • Operations Security (OPSEC)unmatched
  • Organizational Skillsunmatched
  • Policy Developmentunmatched
  • Presentation/Verbal Skillsunmatched
  • Problem Solving Skillsunmatched
  • Procedure Developmentunmatched
  • Publicationsunmatched
  • Reporting Dashboardsunmatched
  • Reporting Skillsunmatched
  • Research & Development (R&D)unmatched
  • Riskunmatched
  • Risk Analysisunmatched
  • Risk Managementunmatched
  • Security Analysisunmatched
  • Security Architectureunmatched
  • Security Attacksunmatched
  • Security Monitoringunmatched
  • Software Engineeringunmatched
  • Systems Administration/Managementunmatched
  • Technical Analysisunmatched
  • Technical Leadershipunmatched
  • Technical Presentationunmatched
  • Technical Strategyunmatched
  • Technical Supportunmatched
  • Testingunmatched
  • U.S. National Institute of Standards and Technology (NIST)unmatched
  • United States Citizenunmatched
  • VPN (Virtual Private Network)unmatched
  • Writing Skillsunmatched

Description

We are seeking a highly qualified Cyber Security Subject Matter Expert (SME) to support the Task Order for IT Operations and Cybersecurity Services. The Cyber Security SME will provide senior-level cybersecurity expertise, strategic advisory support, technical analysis, and operational leadership in support of BIS enterprise cybersecurity, compliance, cloud modernization, and zero trust initiatives.

The Cyber Security SME will support the protection of mission-critical systems, applications, cloud environments, and data assets while ensuring compliance with Federal cybersecurity mandates, including FISMA, NIST, Executive Order 14028, OMB guidance, and Department of Commerce security requirements.

*This position is contingent upon contract award.*

Responsibilities:

  • The Cyber Security SME shall provide subject matter expertise and technical leadership across cybersecurity engineering, governance, risk management, compliance, cloud security, incident response, and security operations.

Specific responsibilities include:

  • Cybersecurity Engineering and Risk Management
    • Provide advanced technical knowledge and analysis supporting BIS cybersecurity programs and initiatives.
    • Support implementation and sustainment of Zero Trust Architecture aligned to NIST SP 800-207 and Federal mandates.
    • Design, evaluate, and improve cybersecurity controls, architectures, and security engineering processes.
    • Assess and analyze vulnerabilities, threats, risks, and mitigation strategies across enterprise systems and cloud environments.
    • Conduct risk assessments and provide recommendations for risk remediation and continuous monitoring activities.
    • Support implementation and management of security controls for Microsoft GCC-High and Azure Government environments.
    • Support Identity and Access Management (IAM), Role-Based Access Control (RBAC), Multi-Factor Authentication (MFA), and endpoint security initiatives.
  • Compliance and Assessment Support
    • Develop, review, and maintain cybersecurity documentation, including:
      • System Security Plans (SSPs)
      • Risk Assessments
      • Security Assessment Reports (SARs)
      • Contingency Plans
      • POA&Ms
      • Security Test and Evaluation (ST&E) documentation
      • Vulnerability Assessment Reports
      • Interconnection Security Agreements (ISAs)
    • Ensure compliance with:
      • FISMA
      • NIST SP 800 series
      • OMB cybersecurity guidance
      • Executive Order 14028
      • Federal Zero Trust requirements
      • Department cybersecurity policies
    • Support Security Assessment and Authorization (SAA) activities for agency systems and applications.
    • Participate in internal and external audits, inspections, and assessments.
  • Security Operations and Incident Response
    • Support cybersecurity monitoring, threat detection, and incident response activities.
    • Analyze security events, vulnerabilities, and indicators of compromise.
    • Support forensic investigations and incident handling activities.
    • Assist with implementation of threat hunting and intrusion detection capabilities.
    • Support vulnerability management and remediation activities.
    • Coordinate mitigation strategies with system administrators, engineers, and security teams.
  • Technical Advisory and Program Support
    • Provide technical consultation and strategic cybersecurity guidance to Government leadership and stakeholders.
    • Participate in technical exchange meetings, working groups, architecture reviews, and program reviews.
    • Analyze data from multiple sources, including open-source intelligence, assessments, and operational reporting.
    • Prepare technical reports, briefings, dashboards, metrics, and executive-level presentations.
    • Assist in developing cybersecurity policies, procedures, standards, and best practices.
    • Support transition planning, knowledge transfer, and continuous improvement initiatives.
  • Cloud and Infrastructure Security
  • Support secure cloud migration and modernization efforts.
  • Evaluate cloud-native security technologies and recommend best practices.
  • Assist with implementation of cloud monitoring, logging, encryption, and security automation solutions.
  • Support secure configuration and management of network infrastructure, VPNs, firewalls, and hybrid environments.
  • Ensure secure operation of enterprise infrastructure and cybersecurity tools.
  • Other duties as assigned.

Qualifications:

  • Years of Experience: Minimum of eight (8) years of progressive cybersecurity experience supporting Federal IT and cybersecurity environments.
  • Education Level: Master’s degree (MS/MA) in Cybersecurity, Information Technology, Computer Science, Information Assurance, Engineering, or a related technical field.
  • Clearance Requirements: Public Trust
    • U.S. Citizenship required.
    • Must successfully complete all required background investigations and badging requirements.
  • Certification Requirements:
    • One or more of the following industry certifications are strongly preferred:
      • CISSP – Certified Information Systems Security Professional
      • CISM – Certified Information Security Manager
      • CCSP – Certified Cloud Security Professional
      • GIAC certifications
      • CEH – Certified Ethical Hacker
      • Security+
      • Azure Security Engineer Associate
      • Certified Information Systems Auditor (CISA)
  • Strong understanding of Federal cybersecurity regulations, frameworks, and standards.
  • Advanced knowledge of NIST SP 800-series publications and cybersecurity best practices.
  • Strong understanding of cloud security architecture and hybrid cloud environments.
  • Experience conducting technical analysis, security testing, and risk assessments.
  • Ability to develop and review complex cybersecurity documentation.
  • Strong written and verbal communication skills.
  • Ability to brief executive leadership and technical stakeholders.
  • Ability to work independently and collaboratively in high-visibility Federal environments.
  • Strong analytical, organizational, and problem-solving skills.
  • Support may require participation in after-hours maintenance, incident response, and on-call activities.
  • The Cyber Security SME will support government initiatives involving:
    • Enterprise cybersecurity operations
    • Cloud engineering and modernization
    • Microsoft GCC-High and Azure Government environments
    • Security monitoring and incident response
    • Zero Trust implementation
    • Continuous diagnostics and mitigation
    • Compliance and governance activities
    • IT infrastructure modernization
    • Federal cybersecurity reporting and assessment activities

Salary Range: $145,000 to $175,000

The compensation range listed for this position represents the good faith salary range Diné Development Corporation (DDC) and its subsidiaries reasonably expect to pay for the role, in accordance with applicable state and local pay transparency laws. Actual compensation will be determined based on a variety of factors, including the position's responsibilities, the candidate's education, experience, skills, internal equity, market considerations, and any applicable collective bargaining agreements or legal requirements.

About UsDiné Development Corporation (DDC) is a Navajo Nation owned family of companies that provides government agencies and commercial organizations with high-quality IT, professional, environmental, and research and development services. DDC is dedicated to empowering the Navajo Nation and communities we serve.
BenefitsEligible full-time employees receive a comprehensive benefits package, including medical, dental, vision, life and disability coverage, retirement savings with company match, paid time off, voluntary supplemental benefits, and access to an employee assistance program. The package also includes educational assistance, with tuition reimbursement.
EEO StatementThis contractor and subcontractor shall abide by the requirements of 41 CFR 60-1.4(a), 60-300.5(a) and 60-741.5(a). These regulations prohibit discrimination against qualified individuals based on their status as protected veterans or individuals with disabilities, and prohibit discrimination against all individuals based on their race, color, religion, sex, sexual orientation, gender identity, national origin, or for inquiring about, discussing, or disclosing information about compensation, or any other basis prohibited by law. We participate in E-Verify.

Numbers & Facts

LocationWashington, District of Columbia
Salary$145,000–$175,000 Per Year

Similar Jobs

See more jobs