Cloud Response SME

Sentar

Virginia (MN)

On-site

USD 150,000 - 190,000

Full time

3 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Medical/Dental/Vision (Voluntary)
FSA options
Life insurance
Disability insurance
401(k) match
PTO and leave programs
Holiday schedule

Job summary

Sentar is seeking a Cloud Response SME in Quantico, VA to serve as the technical authority for cloud defense, incident investigations, and DCO tooling across government cloud environments.

Responsibilities include developing cloud detection use cases, leading investigations, designing new capabilities, and updating TTPs and training materials. Clear accountability for accreditation support and annual training delivery is required.

Qualifications

  • At least five years of demonstrated incident investigation experience in cloud environments.
  • Must hold IAT III and CSSP Incident Responder certifications.
  • Experience with cloud security tools and DoD JRSS.

Responsibilities

  • Develop detection use cases focusing on unauthorized cloud activity using Azure AD, Microsoft Sentinel and similar tools.
  • Assist in investigation of and response to cyberspace incidents in cloud environments.
  • Assist in design and deployment of new defensive cyberspace capabilities in cloud computing.
  • Demonstrate effectiveness by identifying and preventing Red Team activity in cloud environments.
  • Update tactics, techniques, and procedures (TTPs) and training documentation annually.
  • Prepare and present a course on cloud security basics and attack scenarios with 90% satisfaction.
  • Support CSSP accreditation per DoD 8530.01-M with documentation and technical writing.

Skills

Incident investigation
Cloud security

Education

IAT III
CSSP Incident Responder

Tools

Tanium
Microsoft Defender for Endpoint
Elastic Kibana
JRSS

Job description

Current job opportunities are posted here as they become available.

Subscribe to our RSS feeds to receive instant updates as new positions become available.

Sentar is proud to be an employee-owned company, fostering a culture of empowerment, collaboration, and innovation. Sentar is dedicated to developing the critical talent that the connected world demands to create solutions to address the convergence of cybersecurity, intelligence, analytics, and systems engineering. We invite you to join the team where you can build, innovate, and secure your career.

Sentar is seeking a Cloud Response SME in Quantico, VA!

Role Description:

Sentar is hiring a Cloud Response SME to support our customer in Quantico, VA. The Cloud Response SME serves as the primary technical authority for engineering, optimizing, and maintaining defensive cyberspace operations (DCO) infrastructure across customer cloud environments. The SME protects mission-critical systems by designing, implementing, and maintaining high-impact threat detection use cases to capture unauthorized activity using both cloud-native tools and cross-domain enterprise solutions. This expert directly manages cloud incident investigations and response actions, leveraging a powerful specialized toolkit that includes Tanium, Microsoft Defender for Endpoint, Elastic/Kibana, and the comprehensive suites within the DoD's Joint Regional Security Stack (JRSS). Additionally, the SME operationalizes this knowledge by updating tactics, techniques, and procedures (TTPs) and conducting an advanced cloud security curriculum.

  • Develop detection use cases specifically focused on detecting unauthorized activity in cloud computing environments using the Government’s existing cloud computing defense tools (Azure Active Directory, Microsoft Sentinel, etc).
  • Assist with the investigation of and response to cyberspace incidents involving cloud computing environments and technologies.
  • Assist the Government with the design and deployment of new DCO capabilities in cloud computing environments.
  • Demonstrate effectiveness by successfully identifying and/or preventing Red Team (penetration testing) activity in the Government’s cloud computing environment.
  • At least once per calendar year, update the tactics, techniques, procedures, training, and education documentation (Microsoft Word and PowerPoint Documents stored on SharePoint or other Government approved media) related to this task.
  • At least once per calendar year, prepare and present a course, which covers the basics of Cloud Computing security and common attack scenarios as well as DCO Division specific tactics, techniques, processes, and procedures related to this task. Ensure average satisfaction rating on Government approved student satisfaction surveys meets or exceeds 90%.
  • Provide support required to maintain the Government’s CSSP accreditation per the standards set forth in the CSSP program manual, DOD -8530.01-M, (dated 17 Dec 03 or later) to include documentation and technical writing support as needed.
Qualifications:

IAT III and CSSP Incident Responder certification

IAT III certification list: CASP+ CE, CCNP Security, CISA, CISSP (or Associate), GCED, GCIH, and CCSP

CSSP IR certification list: CEH, CFR, CCNA Cyber Ops, CCNA-Security, CHFI, CySA+, GCFA, GCIH, SCYBER, and PenTest+

Clearance Level:

TS/SCI eligibility

Education:

Technical Bachelor's degree or additional years of experience

Experience:
  • At least five years of demonstrated experience in incident investigation in cloud environments.
  • Experience handling national and state level intrusions.
  • Expertise in cloud computing environments with the ability to build and maintain detection use cases to detect unauthorized activity in those environments
  • Experience with incident investigation in cloud computing environments.
  • Experience with Tanium, Microsoft Defender for Endpoint, Elastic/Kibana, and the tools included in the DoD’s Joint Regional Security Stack (JRSS).
  • Experience with the design and implementation of defensive cyberspace tools in cloud computing environments.
Benefits at Sentar:

Our unique employee ownership model attracts top talent, giving employees the freedom to take initiative and drive meaningful improvements. In addition to cultivating a thriving and inclusive work environment, Sentar offers an extensive benefits package designed to support the well-being of employees and their families. Employee ownership is the foundation of our culture, promoting participation, teamwork, and accountability while ensuring long-term financial security and a commitment to excellence.

  • Voluntary Medical, Dental, Vision, with Flexible Spending Plan options
  • Voluntary Life, Critical Illness, Accident, and Long Term Care insurance options
  • Group Term Life, Short-Term and Long-Term Disability is provided by Sentar to all qualifying employees
  • Generous 401(k) match
  • Competitive PTO plan that graduates quickly with years of service
  • Other leave programs; holiday schedule along with bereavement, maternity, jury and military duty
Sentar is an affirmative Action and Equal Opportunity Employer M/F/Vets/Persons with Disabilities

We want you to build your career at Sentar, so if you are an individual with a disability and require a reasonable workplace accommodation applying for a job or at any point in the employment process, contact the Recruiting Manager at recruiting@sentar.com . Please indicate the specifics of the assistance needed. Thank you for considering Sentar in your employment search.

Build, Innovate, Secure Your Career at Sentar.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cloud Response SME
Cloud Response SME

Sentar • Maryland

On-site
USD 140,000 - 200,000
Voluntary Medical, Dental, Vision
Flexible Spending Plan
Life Insurance
+5
Cloud Response SME
Cloud Response SME

Sentar • Quantico (VA)

On-site
USD 140,000 - 180,000
Voluntary Medical, Dental, Vision
401(k) match
Paid time off
+1
Cybersecurity Incident Response & Threat Detection Analyst
Cybersecurity Incident Response & Threat Detection Analyst

Sentar • Columbus (OH)

On-site
USD 100,000 - 150,000
Employee ownership
Generous 401(k) match
Medical, Dental, Vision
+2
Red Team Adversary Emulation Tech Lead
Red Team Adversary Emulation Tech Lead

Sentar Inc. • Quantico (VA)

On-site
USD 140,000 - 230,000
Medical coverage
Dental coverage
Vision coverage
+4
Red Team Adversary Emulation Tech Lead
Red Team Adversary Emulation Tech Lead

Sentar • Quantico (VA)

On-site
USD 180,000 - 240,000
Employee ownership
401(k) match
PTO
+4
Cybersecurity Threat Hunter
Cybersecurity Threat Hunter

Sentar • Columbus (OH)

On-site
USD 110,000 - 160,000
Medical, Dental, Vision
Flex Spending Plan
Life Insurance
+6
Cyber Network Defense Analyst (CNDA)
Cyber Network Defense Analyst (CNDA)

Sentar Inc. • Fort Meade (MD)

On-site
USD 90,000 - 130,000
Health insurance options
Generous 401(k) match
Tuition reimbursement
+2
Action Officer
Action Officer

Sentar Inc. • Charleston (AR)

On-site
USD 120,000 - 150,000
Voluntary Medical, Dental, Vision
Generous 401(k) match
Tuition reimbursement
+5
Subject Matter Expert III - Information Systems Security Engineer
Subject Matter Expert III - Information Systems Security Engineer

Sentar Inc. • Arlington (VA)

On-site
USD 150,000 - 210,000
Voluntary Medical, Dental, Vision with
Flexible Spending Plan options
Voluntary Life and Insurance options
+1
Information Technology Cybersecurity - CIO Task Lead
Information Technology Cybersecurity - CIO Task Lead

Sentar Inc. • Columbia (MD)

On-site
USD 120,000 - 180,000
Voluntary Medical/Dental/Vision
401(k) match
Generous PTO
+3