Security Subject Matter Expert leading enterprise cybersecurity efforts for hybrid cloud environments. Architecting and implementing Zero Trust security solutions while ensuring compliance and reducing risk.
Responsibilities
The Security Subject Matter Expert (SME) is the program’s security lead for a large, hybrid enterprise (on-prem data centers and multi-cloud).
You will architect, implement, and operate a Zero Trust, RMF-aligned security solutions that keep systems reliable, data protected, and the program audit-ready at all times.
You will own the end-to-end security operating model, identity and access (including PIV/FIDO and PAM), vulnerability and patch orchestration, logging and SIEM/SOAR, supply-chain integrity (SBOM/provenance), backup/DR resilience, and continuous monitoring.
You will convert compliance into a running capability rather than a paperwork cycle.
By embedding controls in automation, policy-as-code in pipelines, signed artifacts with attestations, identity-centric access, and immutable backups, you will raise assurance while reducing toil and mean time to recover.
You’ll drive continuous compliance with authoritative evidence from VA systems (ITSM/CMDB, SIEM/EDR, vulnerability tools), cut vulnerability aging against CISA KEV targets, and raise control pass rates without slowing delivery.
During incidents, you will lead joint “swarm” response, contain issues quickly, and turn lessons into baseline changes, POA&Ms, and updated playbooks.
For executives and non-technical stakeholders, you’ll translate risk into clear narratives - what happened, what changed, how we’re safer, and publish trend lines that connect security investments to fewer outages, cleaner audits, and lower total cost of ownership.
Requirements
Education: Bachelor's Degree. In lieu of a degree, an additional four years of related experience required
Experience: 10+ years in enterprise cybersecurity engineering/operations with direct ownership of hybrid (data center + AWS/Azure) environments; 3+ years in regulated or federal programs (VA/DoD/DHS/HHS or equivalent).
Demonstrated delivery of Zero Trust architectures (per NIST SP 800-207/TIC 3.0), RMF/ATO sustainment (SP 800-53 Rev 5/53B baselines), and continuous monitoring at scale.
Hands-on leadership standing up SIEM/SOAR, EDR, vulnerability management, identity platforms (SSO/PIV/FIDO, PAM/JIT), and audited disaster recovery programs (SP 800-184).
Proven record improving outcomes: higher control pass, reduced critical vuln aging, faster MTTR, successful external assessments, and repeatable ATO renewals.
Experience operating within multi-vendor/SIAM models with cross-vendor OLAs and shared KPIs.
Technical skills: Identity & Access (ICAM): SSO (SAML/OIDC), PIV/CAC and FIDO2, JIT/PAM, least-privilege for human and workload identities; directory hygiene and join/move/leave automation.
Network & Platform Security: Segmentation and micro-segmentation, SASE/SD-WAN patterns aligned to TIC 3.0; hardened baselines (STIG/CIS) for OS, containers, and Kubernetes/OpenShift (admission control, policy engines).
Logging, Detection, and Response: Event logging per OMB M-21-31, SIEM content engineering, SOAR playbooks, EDR tuning; run tabletop exercises and purple-team improvements.
Vulnerability & Patch Orchestration: Toolchain proficiency (e.g., Tenable/Qualys, WSUS/Linux lifecycle), KEV-driven prioritization, SLAs by criticality, and automated compliance evidence (SCAP).
Technical Implementation Manager overseeing implementation of complex systems for law enforcement and corporate security. Collaborating with stakeholders to facilitate smooth transitions and optimize solutions.
Security Engineer ensuring protection of corporate environment at Creditas. Implementing security controls and elevating defensive maturity with a focus on fintech standards.
Security Engineering Lead ensuring Creditas maintains innovation and integrity in product security and incident response. Leading multi - disciplinary teams in a hybrid work environment.
Staff Engineer in IAM at Creditas responsible for identity access systems and architecting robust security solutions for cloud environments. Leading strategy and mentoring other security engineers.
Supervisor de seguridad fisica en Cargill ayudando a proteger empleados y propiedades. Coordinando autorizaciones de seguridad y respondiendo a eventos de contingencia.
Providing clerical support in the HSC Security Services department at Shared Health in Winnipeg. Ensuring effective staffing and reporting activities in a high - volume environment.
Cybersecurity Manager overseeing cybersecurity compliance and operations within Leidos' Cybersecurity Team. Responsible for ensuring systems meet defense guidelines and maintaining clearance requirements.
Information Security Awareness Specialist supporting cybersecurity awareness programs at Amadeus. Combining data analysis, communication, and collaboration to enhance security practices.
Security Controls Assessor performing security assessments and gap analysis for Federal agency clients in Washington, D.C. Designing security controls and risk management strategies to meet regulatory compliance standards.
Technicien SST responsible for implementing health and safety policies on - site at Airbus Protect. Ensuring compliance with safety regulations through audits and training while developing a safety culture.