Cloud Response SME

Sentar

Maryland

On-site

USD 140,000 - 200,000

Full time

2 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Voluntary Medical, Dental, Vision
Flexible Spending Plan
Life Insurance
Short-Term Disability
Long-Term Disability
401(k) match
Generous PTO
Leave programs

Job summary

Sentar is seeking a Cloud Response SME to support DoD cloud defense in Quantico, VA. The role focuses on acting as the primary technical authority for engineering, optimizing, and maintaining defensive cyberspace operations (DCO) infrastructure across customer cloud environments.

You will design, implement, and maintain high-impact threat detection use cases in cloud environments, leveraging Tanium, Defender for Endpoint, Elastic/Kibana, and JRSS to protect mission-critical systems.

Qualifications

  • IAT III and CSSP Incident Responder certifications required.
  • At least five years of demonstrated experience in incident investigation in cloud environments.
  • Experience with cloud computing environments and defensible cloud security tooling.
  • Experience with Tanium, Defender for Endpoint, Elastic/Kibana, and JRSS.
  • Clearance TS/SCI eligibility.

Responsibilities

  • Develop detection use cases focused on cloud unauthorised activity.
  • Assist with investigation and response to cloud cyberspace incidents.
  • Assist with design and deployment of new DCO capabilities in cloud environments.
  • Demonstrate effectiveness by identifying/preventing Red Team activity in cloud environments.
  • annually update TTPs and training documentation.
  • Prepare and present a course on Cloud Computing security and DCO topics.

Skills

Cloud security
Incident response
DCO
Tanium
Defender for Endpoint
Elastic/Kibana
JRSS
TTPs

Education

Technical Bachelor's
IAT III certification
CSSP Incident Responder

Tools

Tanium
Microsoft Defender for Endpoint
Elastic/Kibana
JRSS

Job description

Current job opportunities are posted here as they become available.

Subscribe to our RSS feeds to receive instant updates as new positions become available.

Sentar is proud to be an employee-owned company, fostering a culture of empowerment, collaboration, and innovation. Sentar is dedicated to developing the critical talent that the connected world demands to create solutions to address the convergence of cybersecurity, intelligence, analytics, and systems engineering. We invite you to join the team where you can build, innovate, and secure your career.

Sentar is seeking a Cloud Response SME in Quantico, VA!

Role Description:

Sentar is hiring a Cloud Response SME to support our customer in Quantico, VA. The Cloud Response SME serves as the primary technical authority for engineering, optimizing, and maintaining defensive cyberspace operations (DCO) infrastructure across customer cloud environments. The SME protects mission-critical systems by designing, implementing, and maintaining high-impact threat detection use cases to capture unauthorized activity using both cloud-native tools and cross-domain enterprise solutions. This expert directly manages cloud incident investigations and response actions, leveraging a powerful specialized toolkit that includes Tanium, Microsoft Defender for Endpoint, Elastic/Kibana, and the comprehensive suites within the DoD's Joint Regional Security Stack (JRSS). Additionally, the SME operationalizes this knowledge by updating tactics, techniques, and procedures (TTPs) and conducting an advanced cloud security curriculum.

  • Develop detection use cases specifically focused on detecting unauthorized activity in cloud computing environments using the Government’s existing cloud computing defense tools (Azure Active Directory, Microsoft Sentinel, etc).
  • Assist with the investigation of and response to cyberspace incidents involving cloud computing environments and technologies.
  • Assist the Government with the design and deployment of new DCO capabilities in cloud computing environments.
  • Demonstrate effectiveness by successfully identifying and/or preventing Red Team (penetration testing) activity in the Government’s cloud computing environment.
  • At least once per calendar year, update the tactics, techniques, procedures, training, and education documentation (Microsoft Word and PowerPoint Documents stored on SharePoint or other Government approved media) related to this task.
  • At least once per calendar year, prepare and present a course, which covers the basics of Cloud Computing security and common attack scenarios as well as DCO Division specific tactics, techniques, processes, and procedures related to this task. Ensure average satisfaction rating on Government approved student satisfaction surveys meets or exceeds 90%.
  • Provide support required to maintain the Government’s CSSP accreditation per the standards set forth in the CSSP program manual, DOD -8530.01-M, (dated 17 Dec 03 or later) to include documentation and technical writing support as needed.
Qualifications:

IAT III and CSSP Incident Responder certification

IAT III certification list: CASP+ CE, CCNP Security, CISA, CISSP (or Associate), GCED, GCIH, and CCSP

CSSP IR certification list: CEH, CFR, CCNA Cyber Ops, CCNA-Security, CHFI, CySA+, GCFA, GCIH, SCYBER, and PenTest+

Clearance Level:

TS/SCI eligibility

Education:

Technical Bachelor's degree or additional years of experience

Experience:
  • At least five years of demonstrated experience in incident investigation in cloud environments.
  • Experience handling national and state level intrusions.
  • Expertise in cloud computing environments with the ability to build and maintain detection use cases to detect unauthorized activity in those environments
  • Experience with incident investigation in cloud computing environments.
  • Experience with Tanium, Microsoft Defender for Endpoint, Elastic/Kibana, and the tools included in the DoD’s Joint Regional Security Stack (JRSS).
  • Experience with the design and implementation of defensive cyberspace tools in cloud computing environments.
Benefits at Sentar:

Our unique employee ownership model attracts top talent, giving employees the freedom to take initiative and drive meaningful improvements. In addition to cultivating a thriving and inclusive work environment, Sentar offers an extensive benefits package designed to support the well-being of employees and their families. Employee ownership is the foundation of our culture, promoting participation, teamwork, and accountability while ensuring long-term financial security and a commitment to excellence.

  • Voluntary Medical, Dental, Vision, with Flexible Spending Plan options
  • Voluntary Life, Critical Illness, Accident, and Long Term Care insurance options
  • Group Term Life, Short-Term and Long-Term Disability is provided by Sentar to all qualifying employees
  • Generous 401(k) match
  • Competitive PTO plan that graduates quickly with years of service
  • Other leave programs; holiday schedule along with bereavement, maternity, jury and military duty
Sentar is an affirmative Action and Equal Opportunity Employer M/F/Vets/Persons with Disabilities

We want you to build your career at Sentar, so if you are an individual with a disability and require a reasonable workplace accommodation applying for a job or at any point in the employment process, contact the Recruiting Manager at recruiting@sentar.com . Please indicate the specifics of the assistance needed. Thank you for considering Sentar in your employment search.

Build, Innovate, Secure Your Career at Sentar.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cloud Response SME
Cloud Response SME

Sentar • Quantico (VA)

On-site
USD 140,000 - 180,000
Voluntary Medical, Dental, Vision
401(k) match
Paid time off
+1
Cloud Response SME
Cloud Response SME

Sentar • Virginia (MN)

On-site
USD 150,000 - 190,000
Medical/Dental/Vision (Voluntary)
FSA options
Life insurance
+4
Cybersecurity Incident Response & Threat Detection Analyst
Cybersecurity Incident Response & Threat Detection Analyst

Sentar • Columbus (OH)

On-site
USD 100,000 - 150,000
Employee ownership
Generous 401(k) match
Medical, Dental, Vision
+2
Red Team Adversary Emulation Tech Lead
Red Team Adversary Emulation Tech Lead

Sentar Inc. • Quantico (VA)

On-site
USD 140,000 - 230,000
Medical coverage
Dental coverage
Vision coverage
+4
Red Team Adversary Emulation Tech Lead
Red Team Adversary Emulation Tech Lead

Sentar • Quantico (VA)

On-site
USD 180,000 - 240,000
Employee ownership
401(k) match
PTO
+4
Cybersecurity Threat Hunter
Cybersecurity Threat Hunter

Sentar • Columbus (OH)

On-site
USD 110,000 - 160,000
Medical, Dental, Vision
Flex Spending Plan
Life Insurance
+6
Cyber Network Defense Analyst (CNDA)
Cyber Network Defense Analyst (CNDA)

Sentar Inc. • Fort Meade (MD)

On-site
USD 90,000 - 130,000
Health insurance options
Generous 401(k) match
Tuition reimbursement
+2
Action Officer
Action Officer

Sentar Inc. • Charleston (AR)

On-site
USD 120,000 - 150,000
Voluntary Medical, Dental, Vision
Generous 401(k) match
Tuition reimbursement
+5
Action Officer
Action Officer

Sentar • Charleston (SC)

On-site
USD 120,000 - 180,000
Employee ownership
Health benefits
401(k) match
+1
Subject Matter Expert III - Information Systems Security Engineer
Subject Matter Expert III - Information Systems Security Engineer

Sentar Inc. • Arlington (VA)

On-site
USD 150,000 - 210,000
Voluntary Medical, Dental, Vision with
Flexible Spending Plan options
Voluntary Life and Insurance options
+1