ForgeApply · Job listing
Senior Cybersecurity SME/SCA
M9solutions
See all 42 open roles at M9solutions →
Tailor your resume for this M9solutions job in about a minute.
ForgeApply rewrites your resume for this exact posting, then autofills the application on M9solutions's site with it. You review everything before it's sent. Free trial, no card required.
About this role
M9 Solutions is dedicated to providing IT services and solutions to the Federal Government by mobilizing the right people, skills, clearance levels, and technologies to help organizations that desire improved performance and modern, sustainable change. M9 has provided quality IT services and support to more than 30 Federal Agencies and multiple commercial customers nationwide. Our capabilities include IT Talent Solutions, Data Delivery & Analytics, Cyber Security, Cloud Migration, Applications and Infrastructure, Software Development, and Finance & Accounting.
M9 Solutions is seeking a Senior Cybersecurity SME/SCA to work onsite in support of a government contract for a client located in Chantilly, VA . An active Top Secret clearance is required.
Responsibilities
• Strategic Advisement & Lifecycle Integration:
• Engineering Technical Reviews: Actively participate in System Requirements Reviews (SRR), Preliminary Design Reviews (PDR), and Critical Design Reviews (CDR) to ensure security is baked in, rather than bolted on.
• DevSecOps Alignment: Guide project teams in integrating automated security testing (SAST/DAST) and continuous compliance monitoring into Agile development pipelines where appropriate.
• Threat Modeling: Conduct system-level threat modeling during the design phase to identify potential attack vectors and recommend architectural mitigations before code is written or hardware is procured.
• Advanced Assessment & Risk Determination:
• Technical Validation: Move beyond paperwork by conducting deep technical reviews of vulnerability scans (e.g., ACAS/Nessus), STIG checklists, and penetration testing reports. Correlate technical findings to actual operational risk.
• RMF Execution: Demonstrate mastery of RMF policies (NIST SP 800-53 Rev 5, CNSSI 1253, DoD 8510.01, ICD 503). Assist the government Authorizing Official (AO) by translating complex technical compliance shortfalls into actionable, mission-contextualized risk decisions.
• Diverse Architectures: Evaluate the security performance, integrity, and residual risk of varied environments, including Platform Information Technology (PIT), hardware/software systems, communication networks, and satellite control systems, etc.
• Zero Trust & Next-Generation Architecture:
• Zero Trust Implementation: Drive the adoption of Zero Trust architectural pillars (User, Device, Network, Application/Workload, Data, Visibility/Analytics, and Automation/Orchestration) across all client portfolios.
• Cross Domain Solutions (CDS): Provide specialized expertise in designing, evaluating, and implementing CDS technologies. This includes complex enterprise deployments in classified compartmentalized environments and “point-to-point” solutions for isolated, tactical IT architectures.
• Emerging Technology Evaluation: Continuously monitor state-of-the-art technologies (e.g., AI/ML, edge computing, quantum-resistant cryptography) and the evolving threat landscape to ensure client systems anticipate and mitigate next-generation threats.
• Stakeholder Engagement & Liaison:
• Technical Translation: Facilitate seamless communication with the client Portfolio technical SMEs, effectively translating AO directives to engineers and engineering challenges to the AO.
• Community Representation: Serve as a key liaison between the Defense Industrial Base (DIB), government cybersecurity entities, security assessment organizations, and Special Access Program (SAP) IT working groups to maintain alignment with the broader defense innovation ecosystem.
Required Skills and Qualifications
• Active Top Secret security clearance.
• Bachelor’s degree in Information Technology, Computer Science, or related field (or equivalent experience).
• Minimum of twelve (12) years of demonstrated experience in IT, cybersecurity engineering, and Assessment & Authorization (A&A), with increasing responsibility.
• Significant and proven multi-domain experience with SAP and SCI Systems, to include PIT, Cloud environments, Cross Domain Solutions.
• Active baseline certification equivalent to DoD 8140.01 / 8570.01-M Information Assurance Workforce Improvement Program (IA WIP) for IAT Level III or IAM Level III (e.g., CISSP, CISM, GSLC, CASP+ CE).
• Aptitude for aligning cyber risk management with real-world mission outcomes, proactively tailoring security assessments to enable and protect the mission rather than imposing dogmatic compliance hurdles.
• Ability to translate complex technical vulnerabilities into clear, operational risk statements (Mission Impact) for executive leadership and the AO.
• Deep understanding of system architectures, data flows, port/protocol matrix analysis, and network boundary defense concepts.
• Proficiency in analyzing outputs from technical tools such as ACAS, SCAP, STIG Viewer, Splunk/SIEMs, and cloud security posture management (CSPM) tools.
• Expertise in securing and assessing Cloud environments (AWS, Azure IL5/IL6) and containerized applications (Kubernetes, Docker).
• Understanding of MASS, Xacta, or similar A&A workflow tools within classified and unclassified environments.
Preferred Skills and Qualifications
• Direct experience working within the defense innovation ecosystem, specifically with rapid prototyping, test environments, and Platform IT (PIT) systems.
• Proven hands-on technical experience working as a systems integrator or cybersecurity engineer, specifically with enterprise networks, cloud computing systems, and/or all-domain platform IT architectures.
GH 1024
Full-Time Employee Compensation
• M9 Solutions’ pay range for this position is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include, but are not limited to, responsibilities of the position, education, experience, knowledge, skills, abilities, as well as internal equity, location, alignment with market data, applicable bargaining agreement (if any), or other law.
• M9 B
Tailor your resume for this M9solutions role before you apply.
Tailor my resume for this jobSimilar jobs
- Senior Cybersecurity Engineer — Avav · Remote
- Senior Cybersecurity Engineer — Humana · Remote
- Senior Cybersecurity Engineer — Fluence Energy · USA-VA-Arlington | USA-GA-Alpharetta | USA-TX-Houston
- Senior Cybersecurity Engineer — CACI · Springfield, VA
- Senior Cybersecurity Engineer — Unisys · Remote
- Senior Cybersecurity Engineer — Darkwolfsolutions · Washington DC Metro Area
- Senior Cybersecurity Engineer — Accenturefederalservices · Washington, DC
- Senior Cybersecurity Engineer — The Aerospace Corporation · Chantilly, VA
More like this: Security & Cybersecurity Jobs · Browse all jobs
Free ATS checker · How to Autofill Greenhouse Job Applications (Without Sending Junk)