Position Summary
The Cybersecurity Expert serves as the lead technical authority for information systems security engineering, automation, and architecture. This individual designs, implements, and operationalizes automated GRC frameworks, Compliance-as-Code (CaC), Policy-as-Code (PaC), and Infrastructure-as-Code (IaC) solutions aligned with Zero Trust and DoD Cybersecurity Risk Management Construct.
Key Responsibilities
- Serve as lead technical resource for designing, developing, implementing, and operationalizing the automated GRC framework (PWS Section 5.7).
- Design and implement a four-layer automation architecture:
- Infrastructure Provisioning Layer (secure IaC templates)
- Configuration Management Layer
- Compliance Validation Layer (PaC / CaC)
- Orchestration and Workflow Layer
- Translate complex regulatory requirements (RMF, NIST SP 800-53, DISA STIGs) and architectural diagrams into functional, automated, and operational code.
- Integrate and configure AWS-native security services (Audit Manager, Security Hub, Config, CloudTrail, CloudWatch) for continuous monitoring and automated evidence collection.
- Support development of real-time Compliance Scoring Dashboards and RESTful APIs.
- Participate in solution analysis and architectural reviews to ensure compliance with DoD regulations, Zero Trust principles, and DSCA policies.
- Provide technical guidance to ISSMs, ISSOs, and other stakeholders on the security posture and operational function of automated systems.
Required Qualifications
- Active SECRET clearance.
- Bachelor’s degree from an accredited institution in Information Technology, Computer Science, Engineering, or related technical discipline.
- Must possess one of the following certifications:
- AWS Certified DevOps Engineer – Professional or AWS Certified Solutions Architect – Professional
- AWS Certified Security – Specialty
- ISC² CISSP (preferably with ISSEP or ISSAP concentration)
- Twelve (12) years of demonstrated experience in systems engineering and cybersecurity, with at least seven (7) years focused on security automation, cloud engineering, and architecture.
- Five (5) years of experience serving as a lead technical authority on enterprise-level projects responsible for designing and implementing security solutions (not just assessing them).
- Five (5) years of experience translating complex regulatory requirements (RMF, NIST, DISA STIGs) and architectural diagrams into functional, automated, and operational code.
Flexible work from home options available.