Cybersecurity SME / Information Security Analyst

Potomac Management SolutionsWashington, DC
Onsite

About The Position

This role requires a Cybersecurity Subject Matter Expert (SME) / Information Security Analyst to provide onsite support at FMC Headquarters in Washington, DC, with limited offsite support as coordinated. The position involves evaluating incident response readiness, vulnerability management, MFA enforcement, privileged access controls, and security monitoring. The analyst will also be responsible for analyzing logging and alerting using platforms like Microsoft Sentinel, conducting vulnerability reviews with tools such as Nessus/ACAS, and developing risk matrices. A key aspect of the role is mapping security controls to frameworks and validating their implementation through system walkthroughs and documentation review. The ability to communicate technical risks to non-technical stakeholders is essential.

Requirements

  • Strong knowledge of NIST CSF, NIST 800-53, FISMA, Zero Trust, and federal cybersecurity policies.
  • Experience analyzing logging and alerting using platforms such as Microsoft Sentinel.
  • Experience conducting vulnerability reviews using tools such as Nessus/ACAS.
  • Experience developing risk matrices (High/Moderate/Low).
  • Experience mapping security controls to frameworks.
  • Experience validating implementation through system walkthroughs and documentation review.
  • Ability to produce evidence-based findings, risk registers, and mitigation recommendations.
  • Ability to communicate technical risks to non-technical stakeholders.
  • 5–7 years of experience.
  • BA/BS or equivalent experience.

Responsibilities

  • Evaluate incident response readiness.
  • Manage vulnerability assessments.
  • Ensure MFA enforcement.
  • Oversee privileged access controls.
  • Monitor security systems.
  • Analyze logging and alerting using platforms such as Microsoft Sentinel to assess visibility and detection gaps.
  • Conduct vulnerability reviews using tools such as Nessus/ACAS.
  • Develop risk matrices (High/Moderate/Low).
  • Map security controls to frameworks.
  • Validate implementation of security controls through system walkthroughs and documentation review.
  • Produce evidence-based findings, risk registers, and mitigation recommendations.
  • Communicate technical risks to non-technical stakeholders.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service