Senior Cybersecurity Subject Matter Expert (SME)
Dynamic Solutions Technology LLC Coos County, Oregon, United States
IT Services and IT Consulting · 11-50 employees
About the role
The Senior Cybersecurity SME will provide technical leadership for enterprise cybersecurity audits, ground-truth testing, and risk-based assessments. They will also oversee the development of testing strategies, mentor junior analysts, and provide actionable recommendations for remediation.
What they look for
Requirements
Candidates must possess a bachelor's degree in a relevant field and a minimum of 7 years of experience in cybersecurity. Additionally, the role requires the ability to obtain a Public Trust clearance.
Full description
Dynamic Solutions Technology, LLC (DST) is seeking a full-time Senior Cybersecurity Subject Matter Expert to support a government client based in Tallahassee, FL. This is an exempt Hybrid Remote position.
Duties and Responsibilities:
- Serve as the senior cybersecurity subject matter expert providing technical leadership for enterprise cybersecurity audits, Ground-Truth testing, Ad Hoc testing, and risk-based cybersecurity assessments.
- Develop and oversee cybersecurity audit and testing strategies, methodologies, procedures, test plans, and technical approaches aligned with applicable federal, state, and industry cybersecurity requirements.
- Lead assessments of cybersecurity controls and capabilities using the NIST Cybersecurity Framework, applicable NIST publications, Rule 60GG-2, F.A.C., and recognized cybersecurity and professional auditing standards.
- Design and direct controlled Ground-Truth testing activities, including adversarial simulations, behavioral anomaly generation, access-control testing, monitoring validation, and detection and response capability assessments.
- Provide technical leadership for Ad Hoc testing based on agency risk assessments, remediation plans, identified vulnerabilities, emerging threats, and other relevant cybersecurity risk information.
- Evaluate the effectiveness of security controls, cybersecurity tools, processes, and operational capabilities across network, endpoint, identity and access management, cloud, application, and infrastructure environments.
- Develop detailed test procedures, test scripts, sampling methodologies, acceptance criteria, evidence requirements, and technical documentation necessary to support repeatable and defensible testing.
- Analyze security logs, alerts, vulnerability scan results, configurations, system data, and other technical evidence to determine control effectiveness and identify cybersecurity weaknesses.
- Conduct root-cause analysis of identified vulnerabilities, control deficiencies, and operational weaknesses and develop actionable, risk-based recommendations for remediation.
- Provide independent technical analysis and professional judgment to support audit findings, testing conclusions, risk determinations, and recommendations presented to the customer
- Provide technical direction and mentorship to Cybersecurity Analysts and other assessment personnel, ensuring testing activities are performed consistently, accurately, and in accordance with approved procedures.
- Coordinate with customer leadership, IT personnel, and other authorized stakeholders to facilitate testing activities while maintaining appropriate security, access-control, confidentiality, and independence requirements.
- Review and validate supporting evidence to ensure test results are complete, accurate, reproducible, traceable, and sufficient to support audit conclusions and reported findings.
- Support development of executive-level reports, technical assessment summaries, lessons learned, knowledge-transfer materials, and recommendations for improving cybersecurity assessment methodologies, tooling, coordination, and testing practices.
- Participate in quality assurance and knowledge-transfer activities, including technical peer reviews, workshops, briefings, job aids, and training designed to promote understanding and consistent application of cybersecurity testing methodologies and results.
Desired Education/Years of Experience
- Bachelor's degree in a relevant field of expertise
- Minimum of 7 years of relevant experience
Additional Requirement(s):
- Must be able to obtain a Public Trust
Similar roles
-
Senior Cyber Security Engineer
Westpac New Zealand
-
Associate - Cybersecurity
PwC Kuala Lumpur, Kuala Lumpur, Malaysia
-
Security Engineer (OAMD)
BeVera Solutions LLC Atlanta, Georgia, United States
-
Director, Application Security
Zeta Global United States · $275K–$315K/yr
-
Senior Security Engineer
Motive Toronto, Ontario, Canada · CA$146K–CA$184K/yr
-
SR Information Security Engineer
Mayo Clinic Rochester, Minnesota, United States · $134K–$195K/yr