The Security Subject Matter Expert (SME) is the program’s security lead for a large, hybrid enterprise (on-prem data centers and multi-cloud). You will architect, implement, and operate a Zero Trust, RMF-aligned security solutions that keep systems reliable, data protected, and the program audit-ready at all times. You will own the end-to-end security operating model, identity and access (including PIV/FIDO and PAM), vulnerability and patch orchestration, logging and SIEM/SOAR, supply-chain integrity (SBOM/provenance), backup/DR resilience, and continuous monitoring. HOW THE SECURITY SME WILL MAKE AN IMPACT: You will convert compliance into a running capability rather than a paperwork cycle. By embedding controls in automation, policy-as-code in pipelines, signed artifacts with attestations, identity-centric access, and immutable backups, you will raise assurance while reducing toil and mean time to recover. You’ll drive continuous compliance with authoritative evidence from VA systems (ITSM/CMDB, SIEM/EDR, vulnerability tools), cut vulnerability aging against CISA KEV targets, and raise control pass rates without slowing delivery. During incidents, you will lead joint “swarm” response, contain issues quickly, and turn lessons into baseline changes, POA&Ms, and updated playbooks. For executives and non-technical stakeholders, you’ll translate risk into clear narratives - what happened, what changed, how we’re safer, and publish trend lines that connect security investments to fewer outages, cleaner audits, and lower total cost of ownership. WHAT YOU’LL NEED TO SUCCEED: 10+ years in enterprise cybersecurity engineering/operations with direct ownership of hybrid (data center + AWS/Azure) environments; 3+ years in regulated or federal programs (VA/DoD/DHS/HHS or equivalent). Demonstrated delivery of Zero Trust architectures (per NIST SP 800-207/TIC 3.0), RMF/ATO sustainment (SP 800-53 Rev 5/53B baselines), and continuous monitoring at scale. Hands-on leadership standing up SIEM/SOAR, EDR, vulnerability management, identity platforms (SSO/PIV/FIDO, PAM/JIT), and audited disaster recovery programs (SP 800-184). Proven record improving outcomes: higher control pass, reduced critical vuln aging, faster MTTR, successful external assessments, and repeatable ATO renewals. Experience operating within multi-vendor/SIAM models with cross-vendor OLAs and shared KPIs.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Mid Level
Number of Employees
5,001-10,000 employees