Cyber Security Assessment & Authorization SME

Security EngineerSecurity EngineerFull TimeRemoteMid LevelTeam 51-200

Location

United States

Posted

9 days ago

Salary

$110K - $160K / year

Seniority

Mid Level

Job Description

Cyber Security Assessment & Authorization SME

ESM

Role Description The successful candidate serves as a Cybersecurity Subject Matter Expert (SME) for the Assessment and Authorization (A&A) of information systems, ensuring compliance with Department of Defense (DoD) and Defense Logistics Agency (DLA) cybersecurity policies, procedures, and the Risk Management Framework (RMF). They execute cybersecurity authorization processes to obtain and maintain system authorizations while providing expert guidance to stakeholders throughout the authorization lifecycle. - Apply a strong understanding of NIST SP 800-53 security controls to assess and authorize complex enterprise IT environments, including cloud-hosted services, operational technology, application information systems, and outsourced IT services across large and diverse infrastructures. - Evaluate security control deficiencies, determine residual risk and the potential impact of identified vulnerabilities on system authorization, and develop risk-based recommendations to support informed decision-making. - Communicate the status, progress, and outcomes of RMF activities by briefing senior leadership and collaborating with technical and program stakeholders to ensure secure, compliant, and mission-ready information systems. Qualifications - Expert knowledge of the Department of Defense (DoD) Risk Management Framework (RMF), Assessment and Authorization (A&A) processes, and applicable DoD, DLA, and NIST cybersecurity policies and guidance, including NIST SP 800-53 security controls. - Demonstrated ability to plan, execute, and maintain cybersecurity authorizations for complex information systems, ensuring compliance throughout the system lifecycle and supporting timely authorization decisions. - Skill in assessing security controls, identifying and evaluating control deficiencies, analyzing residual risk, and developing risk-based recommendations to support informed authorization and cybersecurity risk management decisions. - Knowledge of cybersecurity principles and best practices for enterprise IT environments, including cloud-hosted services, operational technology (OT), application information systems, and outsourced IT services across large, complex infrastructures. - Ability to serve as a cybersecurity subject matter expert (SME) by providing technical guidance, interpreting cybersecurity requirements, and collaborating with system owners, program managers, engineers, and other stakeholders to achieve compliance and mission objectives. - Skill in communicating complex cybersecurity concepts and RMF activities through clear written documentation, briefings, and presentations to senior leadership, technical teams, and other stakeholders regarding authorization status, risks, and recommended courses of action. Requirements - Five (5) years of relevant certification and accreditation experience; Risk Management Framework (RMF) and NIST C&A experience; DOD cybersecurity experience. - Experience for large complex organizations. - 8570/8140 compliant certification. - Minimum Clearance: Secret. Physical Requirements - Required to stand, walk and sit; communicate verbally both in person and by telephone; use hands to finger, handle or feel objects or controls; reach with hands and arms. - Specific vision abilities required by this job include close vision, distance vision, depth perception, color vision and the ability to adjust focus. Additional Requirements - Other duties as assigned. - ESM provides equal employment opportunity to all individuals regardless of race, color, creed, religion, gender, age, sexual orientation, national origin or ancestry, disability, genetic information, veteran status, gender identification or any other characteristic protected by state, federal or local law.

Related Categories

Related Job Pages

More Security Engineer Jobs

Full TimeRemoteTeam 10,001+

• Define the roadmap and drive execution for the bot management solutions to ensure alignment with customer needs and the evolving market landscape. • Lead cross-functional collaboration with engineering, sales, and marketing teams to innovate and bring breakthrough cybersecurity solutions to market. • Engage with global customers to gather feedback, identify market opportunities, analyze competition, and anticipate emerging trends. • Design an intuitive reporting and configuration experience that simplifies complex security operations with actionable, data-driven insights. • Work closely with engineering teams to translate customer requirements into product architecture changes that support complex product initiatives. • Drive architectural decisions that balance detection accuracy, performance, scalability, and customer usability across the platform. • Own and execute the long-term platform strategy for bot management capabilities, ensuring unified efficacy and experience across multiple products and customer environments. • Coordinate priorities and dependencies across platform, detection, and infrastructure teams to successfully deliver complex, large-scale initiatives. • Understand the competitive landscape and monitor industry technology advancements and trends.

Canada
$160K - $195K / year
GTT logo

Product Marketing Manager, Security

GTT

Greater Technology Together

Full TimeRemoteTeam 1,001-5,000H1B Sponsor

• Accountable for the go-to-market product roadmap, strategy, and execution of product launches for our security portfolio. • Lead the development and execution of GTM strategies pre and post launch for product features and updates for retention, acquisition, upsell and cross sell opportunities that drive engagement and adoption. • Partner with our Audience and Vertical Marketing Manager to develop persona-based value proposition and messaging frameworks that will be leveraged both internally and externally for our security response portfolio to drive articulation positioning aligned to GTT’s KPIs. • Work closely with Product Leaders to identify needs and sharpen product offerings based on competitive landscape and feedback from customers. • Partner with our Storyteller to create new and manage existing marketing and sales enablement materials (sales documentation, product videos, website copy, blog posts, data sheets and whitepapers). • Conduct product marketing data analysis by gathering and interpreting data and presenting it in a clear and actionable manner. • Identify GTM success metrics and measure the results of your strategies and initiatives and continue to iterate to maximize results. • Establish clear understanding of our client’s needs, product offerings, and competitive landscape in order to ensure product strategies align with market demand.

Texas
Full TimeRemoteTeam 1,001-5,000H1B No Sponsor

• Lead FedRAMP Moderate and CMMC readiness assessments, including system boundary validation and control gap analysis • Design and implement cloud security architectures aligned to NIST 800-53 and NIST 800-171 requirements • Develop and own System Security Plans (SSPs), control narratives, and compliance documentation • Partner closely with client engineering, security, and compliance teams to remediate gaps and implement controls • Drive implementation of technical security measures such as encryption, IAM, logging, continuous monitoring, vulnerability management, and incident response • Advise clients on federal and DoD security mandates, including cryptographic requirements and vulnerability remediation timelines • Update and align security policies and procedures to support FedRAMP and CMMC compliance • Conduct preliminary control testing to validate effectiveness prior to formal assessments • Coordinate with Third-Party Assessment Organizations (3PAOs) and C3PAOs during independent assessments • Support assessment execution, evidence collection, remediation cycles, and authorization package submission • Mentor and review work from other consultants, raising the bar on technical quality and delivery • Conduct interviews with prospective team members, assessing candidate suitability while serving as a brand ambassador for the CSA practice and Riveron • Stay current on emerging risks and evolving control practices • Build and maintain strong industry relationships to support long-term business development

United States
$117.5K - $166.3K / year
SmarterDx logo

Staff Security Engineer

SmarterDx

Improving clinical and financial outcomes with physician-validated AI for documentation and coding.

Full TimeRemoteTeam 11-50H1B No Sponsor

• Own our approach to AI and agentic security: guardrails for agentic access to cloud and data, and the security of the AI and ML workloads in our product. • Publish the org's AI-security standard and drive its adoption by other engineering teams. • Own our detection platform (Panther): detection strategy and coverage across cloud, container, and SaaS log sources, and the standards that keep detections high-signal as we grow. • Own incident-response readiness: the plan, the playbooks, and tested tabletops tied to the HIPAA breach-notification timeline, and help lead response when a real incident happens. • Lead complex security work across teams from start to finish, resolving ambiguity and coordinating with Platform, Engineering, and Compliance. • Act as the senior security resource across cloud security and security reviews, and the security expert other engineering teams seek out for guidance on high-stakes decisions. • Mentor teammates who are growing their security depth, set team standards for detection authoring and code review, and help raise our interview and hiring bar. • Build and grow security automation that gives a small team more reach, and contribute to the tooling the team runs on. • Take part in architecture reviews and threat modeling on our highest-risk designs, and communicate the resulting security architecture so the whole team can understand it and build on it.

United States
$230K - $250K / year