Subject Matter Expert (SME) – Cybersecurity & Risk Assessment
Overview:
The Subject Matter Expert (SME) provides advanced technical expertise to support assessment operations, with a focus on cybersecurity, risk analysis, and program integrity. This role is responsible for enhancing operational processes, developing standard operating procedures (SOPs), and ensuring the confidentiality, integrity, and effectiveness of security-related initiatives. The SME works cross-functionally to evaluate systems, identify vulnerabilities, and recommend mitigation strategies in alignment with federal and industry standards.
________________________________________
Key Responsibilities:
•   Provide expert-level technical guidance and analysis to support cybersecurity and risk assessment initiatives, including supply chain risk management.Â
•   Develop, enhance, and maintain standard operating procedures (SOPs) to support assessment execution and implementation.Â
•   Conduct security assessments and hands-on testing, analyze results, document risks, and recommend appropriate countermeasures.Â
•   Identify, evaluate, and report on system vulnerabilities, threats, and security gaps.Â
•   Review and provide recommendations on program-level documentation, including:Â
o   Requirements specificationsÂ
o   System architecture and design documentsÂ
o   Test plans and security plansÂ
•   Develop and document security evaluation test plans and procedures.Â
•   Support the development and implementation of information security policies, standards, and guidance.Â
•   Ensure compliance with applicable frameworks and regulations (e.g., FISMA, NIST, OMB).Â
•   Perform risk assessments, including analyzing threats, vulnerabilities, and potential impacts.Â
•   Coordinate with cross-functional teams and stakeholders to support security testing and program objectives.Â
•   Lead or participate in technical exchange meetings, documenting outcomes and action items.Â
•   Prepare and deliver briefings to leadership on project status, risks, and key findings.Â
•   Analyze and synthesize data from multiple sources to produce clear, actionable insights for both technical and non-technical audiences.Â
•   Provide oversight for the design, development, and implementation of security support systems.Â
•   Collaborate with stakeholders to map system functionality to security controls and compliance requirements.Â
________________________________________
Qualifications:
•   Education:Â
o   Master’s degree (MS/MA) in Cybersecurity, Information Technology, Computer Science, or a related fieldÂ
•   Experience:Â
o   Minimum of 8+ years of relevant experience in cybersecurity, risk management, or assessment operationsÂ
o   Experience supporting federal or highly regulated environments preferredÂ
•   Certifications (preferred):Â
o   CISSP, CISM, CISA, CEH, or other relevant industry certificationsÂ
________________________________________
Required Skills & Expertise:
•   Strong knowledge of cybersecurity frameworks and standards (FISMA, NIST, OMB, etc.)Â
•   Experience with risk assessments, vulnerability analysis, and security testing methodologiesÂ
•   Ability to translate complex technical concepts into clear documentation and briefingsÂ
•   Familiarity with security documentation development, including risk assessments, contingency plans, and test reportsÂ
•   Strong analytical, problem-solving, and communication skillsÂ
•   Ability to work independently and collaboratively in a fast-paced environment
Location
Baltimore, Maryland (Remote)
Employment Type
Full-Time
Minimum Experience
Experienced
Learn more about this Employer on their Career Site
