More jobs:
Security Subject Matter Expert; SME
Job in
Coos Bay, Coos County, Oregon, 97458, USA
Listed on 2026-01-16
Listing for:
General Dynamics Information Technology
Full Time
position Listed on 2026-01-16
Job specializations:
-
IT/Tech
Cybersecurity
Job Description & How to Apply Below
Job Overview
The Security Subject Matter Expert (SME) is the program’s security lead for a large, hybrid enterprise (on‑prem data centers and multi‑cloud). You will architect, implement, and operate a Zero Trust, RMF‑aligned security solutions that keep systems reliable, data protected, and the program audit‑ready at all times.
TimelineExpected start:
August 2026
You will convert compliance into a running capability rather than a paperwork cycle. By embedding controls in automation, policy‑as‑code in pipelines, signed artifacts with attestations, identity‑centric access, and immutable backups, you will raise assurance while reducing toil and mean time to recover.
Qualifications- Education
:
Bachelor’s Degree. In lieu of a degree, an additional four years of related experience required. - Experience
:- 10+ years in enterprise cybersecurity engineering/operations with direct ownership of hybrid (data center + AWS/Azure) environments; 3+ years in regulated or federal programs (VA/DoD/DHS/HHS or equivalent).
- Demonstrated delivery of Zero Trust architectures (per NIST SP 800‑207/TIC 3.0), RMF/ATO sustainment (SP 800‑53 Rev 5/53B baselines), and continuous monitoring at scale.
- Hands‑on leadership standing up SIEM/SOAR, EDR, vulnerability management, identity platforms (SSO/PIV/FIDO, PAM/JIT), and audited disaster recovery programs (SP 800‑184).
- Proven record improving outcomes: higher control pass, reduced critical vuln aging, faster MTTR, successful external assessments, and repeatable ATO renewals.
- Experience operating within multi‑vendor/SIAM models with cross‑vendor OLAs and shared KPIs.
- Technical Skills
:- Identity & Access (ICAM): SSO (SAML/OIDC), PIV/CAC, FIDO2, JIT/PAM, least‑privilege for human and workload identities; directory hygiene and join/move/leave automation.
- Network & Platform Security:
Segmentation and micro‑segmentation, SASE/SD‑WAN patterns aligned to TIC 3.0; hardened baselines (STIG/CIS) for OS, containers, and Kubernetes/Open Shift. - Logging, Detection, and Response:
Event logging per OMB M-21‑31, SIEM content engineering, SOAR playbooks, EDR tuning; run tabletop exercises and purple‑team improvements. - Vulnerability & Patch Orchestration:
Toolchain proficiency (e.g., Tenable/Qualys, WSUS/Linux lifecycle), KEV‑driven prioritization, SLAs by criticality, and automated compliance evidence (SCAP). - Secure SDLC & Supply Chain: SSDF (SP 800‑218) practices, artifact signing and provenance/attestations (SLSA/SBOM), trusted registries, policy‑as‑code gates in CI/CD; secrets management (KMS/Vault).
- Data & Storage Protection:
Encryption in transit/at rest (FIPS‑140 validated), key management, DLP patterns, immutable/object‑lock backups, tested DR with objective pass/fail artifacts. - Standards & Tooling Fluency: NIST CSF 2.0, SP 800‑61 (IR), SP 800‑53/53B, SP 800‑207, SP 800‑184, TIC 3.0, FIPS‑140; OSCAL for machine‑readable SSP/Con Mon.
- Security Clearance Level
:
Public Trust - Skills and Abilities
:- Clear Communicator:
Converts complex risk and telemetry into executive‑ready, plain‑language updates; writes crisp playbooks, runbooks, and policy one‑pagers. - Outcome‑Driven:
Ties security work to measurable results, control pass rate, vuln aging, incident frequency/MTTR, DR test pass, and audit findings, published on a shared scorecard. - Builder’s Mindset:
Designs controls that are easy to use and hard to bypass; prefers automation over manual checks; balances guardrails with delivery speed. - Facilitation & Influence:
Leads cross‑domain incident “swarming,” champions secure patterns with engineers, and negotiates trade‑offs that protect both security and uptime. - Governance & Rigor:
Runs change risk reviews, manages POA&M to closure, and keeps the ATO pipeline predictable with OSCAL‑based evidence and scheduled assessments. - Mission Focus:
Aligns security investments with VA outcomes including fewer disruptions for clinicians and staff, stronger protection of Veteran data, and demonstrable stewardship of taxpayer funds.
- Clear Communicator:
- Preferred Certifications
:- CISSP
- CCSP
- CISM
- CASP+
- GIAC (GCIH/GCIA/GMON/GCSA/GPCS/GCED)
- CEH
- AWS/Azure security specialty
- CAP or equivalent RMF credential
- Location
:
Austin, TX – Hybrid Remote with periodic on‑site meetings as required by the customer
- Full‑flex work week to own priorities at work and home
- 401(k) with company match
- Comprehensive health and wellness packages
- Internal mobility team dedicated to skill building and career growth
- Professional growth opportunities, including paid education and certifications
- Cutting‑edge technology to learn from
- Paid vacation and 10 company‑paid holidays
Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans
#J-18808-LjbffrTo View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×