Enterprise Horizon solves complex IT and business challenges for the DoD, Federal, and Private sectors.
Cloud Security, Risk Management Framework (RMF), Subject Matter Expert
Location
Virginia
Posted
3 days ago
Salary
0
Seniority
Senior
Job Description
Cloud Security, Risk Management Framework (RMF), Subject Matter Expert
Enterprise Horizon Consulting Group
• Provide cloud tenancy services and deliver enhanced capabilities within an Oracle Cloud Infrastructure (OCI) hosting environment. • Secure, isolate, and administer the cloud tenancy to effectively create, organize, integrate, and manage cloud resources. • Research, evaluate, and implement new OCI services and capabilities to improve operational performance and strengthen security posture. • Administer middleware and web tiers, manage single sign‑on (SSO), and create/manage users, groups, and access controls. • Apply expert knowledge of NIST RMF, C&A processes, and DoD cybersecurity requirements to assess controls, identify risks, and ensure compliance. • Support the design, implementation, and maintenance of cloud-native security configurations, including Oracle CloudGuard. • Conduct C&A reviews for large, complex information systems and ensure alignment with DoD, NIST, and FedRAMP requirements. • Provide technical leadership across cloud service engineering, including distributed systems, virtualized infrastructure, identity, observability, and security. • Manage and support Autonomous Database, Oracle Enterprise Database, and Oracle Database Cloud Service (DBCS). • Deploy and manage containerized applications using Oracle Kubernetes Engine (OKE). • Automate tasks using scripting and IaC tools such as Ansible (OCI‑compliant), HELM, and Terraform. • Apply expertise in modern computing paradigms including hybrid cloud, edge computing, microservices, and IoT‑related protocols.
Job Requirements
- Must have an active Secret clearance.
- Must possess a DoD Approved 8570 IAM Level I baseline certification (e.g., Security+ or equivalent)
- Must possess a Cloud Computing Security Certification, such as:
- Certified Cloud Security Professional (CCSP)
- Certificate of Cloud Security Knowledge (CCSK)
- OCI Specialty Certification
- Minimum 5 years of experience supporting DoD IL5 Oracle Cloud Infrastructure (OCI) administration, maintenance, and operations.
- Experience across multiple OCI technical domains, including:
- Information Systems Architecture
- Security Engineering (STIGs, DoD Cloud SRG, policies)
- Communications and Network Systems Management
- Demonstrated expertise with RMF, NIST C&A, and DoD cybersecurity frameworks.
- Experience assessing cybersecurity controls and conducting C&A reviews for large, complex systems.
- Strong understanding of FedRAMP assessment methodology, including all six domain areas:
- Architectural Concepts & Design Requirements
- Cloud Data Security
- Cloud Platform & Infrastructure Security
- Cloud Application Security
- Operations
- Legal & Compliance
- Proven ability to solve complex problems across cloud software engineering, distributed systems, identity, security, and observability.
- Experience configuring and managing cloud-native security tools, including Oracle CloudGuard.
Benefits
- Medical, Dental, & Vision
- Life Insurance, Short-term Disability, Long-term Disability
- SIMPLE IRA with Company Match
- Federal Holidays
- Vacation & Sick Leave
- $500 Referral Bonus
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Security Consultant – Engineering Design, PM
Guidepost SolutionsUncovering Facts. Assessing Risk. Protecting Facilities. Monitoring Progress.
• Design comprehensive security solutions that integrate physical security, access control, video surveillance, intercom, mass notification, and intrusion detection measures to meet client standards or mitigate identified risks. • Develop detailed security design documentation, including basis of design, system specifications, systems drawings, schematics, and installation plans, adhering to industry standards and regulatory requirements. • Lead designs (construction drawings and specifications) for technical & physical security elements (cameras, access control, intrusion detection, fences, gates, etc.) for client projects. • Understanding of Master Format CSI specifications and ability to write new content as needed. • Collaborate with clients to understand their business objectives, security requirements, and budgetary constraints, providing expert guidance and recommendations. • Collaborate with consultants within our client environment to develop design standards, evaluate costs, risk, and benefits of designs, and facilitate design discussions. • Facilitate effective project team and cross-functional interactions (Technical, Operations, BD, Marketing, etc.) by working successfully as a part of a team and business functions to achieve positive results. • Participate in maintenance of the clients’ Basis of Design, prototype design, and specifications for physical security elements. • Communication and record keeping of project decisions and directives in both written and verbal formats. • Maintain project repository of documentation in a consistent and comprehensive project delivery method. • Support business growth through pursuit of new work; and, by providing technical content to new business proposal and firm qualification packages. • Attend industry events to expand brand awareness.
Sales Executive – Offensive Security Services Consulting
UltraViolet CyberUnified Security Operations, Delivered.
• Own end-to-end sales motions: prospecting, qualification, scoping, proposal development, negotiation, and close. • Build and execute a territory plan that expands new logo acquisition and grows revenue across existing enterprise accounts. • Position the full suite of offensive security services—pen testing, red teaming, cloud security testing, and managed offensive capabilities. • Maintain a strong pipeline with 3x+ quota coverage and predictable forecasting. • Lead consultative discussions with CISOs, engineering leaders, AppSec teams, and procurement stakeholders. • Partner with technical SMEs and consulting leads to shape solutions aligned to client risk, maturity, and regulatory requirements. • Establish multi-threaded relationships within accounts to improve deal velocity and renewal rates. • Deliver compelling client presentations, statements of work, and value-based proposals. • Work closely with the consulting delivery team to scope engagements accurately and ensure high customer satisfaction. • Align with marketing on targeted campaigns, regional events, and ABM programs. • Achieve or exceed quarterly and annual bookings targets. • Maintain accuracy of CRM data, forecasting, and pipeline metrics. • Drive healthy mix of services revenue: net-new logos, expansion, and multi-project programs.
Senior Manager, Security Products, IAM
DigitalOceanThe cloud ☁️ of choice for developers, startups, and growing digital businesses around the world.
• Lead and mentor a multi-disciplinary engineering team focused on building scalable security products. • Drive the technical roadmap and execution for security features, including threat detection, identity management, and data protection. • Manage delivery timelines, inter-team dependencies, and proactive risk mitigation to ensure successful execution of product milestones. • Establish and lead sustaining engineering practices prioritizing technical debt reduction. • Collaborate with Product Management and Security Architects to define product requirements. • Ensure high standards of code quality and operational excellence.
Senior Specialist – Offensive Security
Cybersecurity Advisors Network (CyAN)An international community of cyber advisors from various disciplines and background, who want to build a better future
• Perform scoped and open-ended assessments on internal and external facing systems • Perform threat and vulnerability research to identify new ways of achieving the program’s mission and act as a source for innovation within the cybersecurity industry • Assisting in the sales process with potential or existing clients, and acting as a client’s primary program contact for projects delivered by Cyber Advisors’ Offensive Security team • Develop and implement tools that assist with execution of security assessments, including custom tools and automation • Work with the customer Blue Team to identify gaps, address findings, and improve breach response




