Cybersecurity Risk & Exposure Subject Matter Expert IV

invictusic

Alexandria (VA)

On-site

USD 130,000 - 190,000

Full time

4 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

invictusic is seeking a Lead Cybersecurity Risk & Exposure SME IV in Alexandria, VA. You will serve as the senior expert for operational cyber risk and continuous monitoring supporting a DoD mission, developing methodologies to prioritize exposures and guiding remediation actions.

Responsibilities include leading complex risk assessments, coordinating with ISSOs/ISSMs, and producing executive briefings and dashboards to convey risk and progress to leadership.

Qualifications

  • Bachelor's degree in a technical discipline or equivalent with 8+ years of related experience.
  • Expert knowledge of vulnerability/exposure management, threat-informed risk analysis, RMF and DoD controls.
  • Experience with ACAS/Tenable, runZero, STIGs, SCAP, and POA&M processes is highly desirable.
  • Experience aligning SOC/IR findings with RMF and ISSO/ISSM activities.
  • Proven ability to lead complex risk assessments and remediation prioritization.

Responsibilities

  • Serve as senior SME for operational cyber risk, exposure analysis, and continuous monitoring for DoD mission.
  • Develop methodologies correlating vulnerability, asset, configuration, and threat data to prioritize exposures.
  • Lead exposure assessments, including plausible exploitation scenarios and risk-informed actions.
  • Provide expert context to SOC leaders, Threat Analysts, and engineering teams during investigations.
  • Lead analysis of ACAS/Tenable results and related data to identify weaknesses and remediation priorities.
  • Coordinate findings with ISSOs/ISSMs, system owners, and RMF stakeholders; translate findings into actions.
  • Establish checklists, guides, and reporting for exposure analysis and SOC-to-system coordination.
  • Review remediation evidence and trends to recommend enterprise or site-level actions.
  • Develop briefings and dashboards communicating exposure and remediation progress to leadership.

Skills

Vulnerability management
Threat-informed risk analysis
DoD continuous monitoring
RMF/security controls
Network security
Risk assessments
DoD/IC experience
Incident-response integration

Education

Bachelor's degree in a technical discipline

Tools

ACAS/Tenable
runZero
STIG Viewer
SCAP
POA&M processes

Job description

Lead Cybersecurity Risk & Exposure Subject Matter Expert IV

Location: Alexandria, VA

Clearance: TS/SCI with the ability to obtain and maintain a CI polygraph

Job Details
  • Serve as the senior SME for operational cyber risk, vulnerability/exposure analysis, and continuous monitoring supporting a DoD cyber defense mission
  • Establish methodologies for correlating vulnerability, asset, configuration, network reachability, system criticality, security-control, threat, and incident data to identify and prioritize the exposures most likely to create operational or mission risk
  • Lead complex exposure and impact assessments, including development of plausible exploitation scenarios, attack paths, affected-system analysis, compensating-control considerations, and risk-informed courses of action
  • Provide expert vulnerability, asset, architecture, and security-control context to SOC leadership, Cybersecurity Operations Analysts, Threat Analysts, incident responders, and engineering teams during significant investigations and proactive defensive activity
  • Lead analysis of ACAS/Tenable results, runZero asset information, STIG/configuration findings, system documentation, and other approved data to identify systemic weaknesses, exploitable conditions, and remediation priorities
  • Own the SOC-side process for coordinating material cyber findings with affected system ISSOs/ISSMs, system owners, administrators, engineers, and authorization stakeholders; ensure operational findings are translated into appropriate mitigation, continuous-monitoring, POA&M, or RMF actions without duplicating system ISSO responsibilities
  • Establish and maintain checklists, TTPs, guides, procedures, quality standards, and reporting methods for exposure analysis, risk prioritization, remediation validation, and SOC-to-system-security coordination
  • Lead review of remediation evidence, recurring vulnerabilities, exposure trends, control weaknesses, and SOC-derived findings to identify systemic risk and recommend enterprise or site-level corrective actions
  • Develop briefings, executive summaries, risk assessments, metrics, dashboards, and technical products that communicate operational exposure, remediation progress, control effectiveness, and mission impact to technical and leadership audiences
  • Advise SOC leadership on vulnerability/exposure trends, high-risk assets, recurring security weaknesses, remediation priorities, and opportunities to improve the integration of vulnerability management, threat information, and cyber defense operations
  • Mentor senior and developing analysts and provide technical quality review of exposure assessments, risk conclusions, remediation recommendations, and stakeholder coordination products
  • Experience integrating vulnerability management, continuous monitoring, RMF/ISSO processes, and SOC or incident-response operations in a DoD/IC or similarly complex enterprise environment is highly desired
Requirements
  • Bachelor's degree from an accredited institute in a technical discipline applicable to the position; an additional 4 years of may be substituted in lieu of a degree
  • Minimum of eight (8) years of relevant experience in addition to education level
  • Demonstrated expert knowledge of vulnerability/exposure management, threat-informed risk analysis, DoD continuous monitoring, RMF/security controls, network/system security, and technical risk assessment
  • Experience with ACAS/Tenable, runZero or comparable exposure/asset-discovery tools, DoD STIG/STIG Viewer, SCAP, POA&M processes, and integration of SOC/incident-response findings with ISSO/ISSM or RMF functions is highly desired
  • Demonstrated experience establishing exposure-analysis methodology, leading complex risk assessments, prioritizing remediation, and translating operational cyber findings into continuous-monitoring or RMF actions is strongly desired
  • Must possess current DoD 8570 IAT II or IAM II certification
  • Experience working in a DoD or IC environment
  • Current active TS/SCI clearance, with the ability to obtain and maintain a CI polygraph

Equal Opportunity Employer/Veteran/Disabled

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cybersecurity Risk & Exposure Subject Matter Expert IV
Cybersecurity Risk & Exposure Subject Matter Expert IV

invictusic • Colorado Springs (CO)

On-site
USD 150,000 - 190,000
Cybersecurity Risk & Exposure Subject Matter Expert IV
Cybersecurity Risk & Exposure Subject Matter Expert IV

Invictus International • Alexandria (VA)

On-site
USD 140,000 - 190,000
Cybersecurity Risk & Exposure Subject Matter Expert IV
Cybersecurity Risk & Exposure Subject Matter Expert IV

Invictus International Consulting, LLC. • Alexandria (VA)

On-site
USD 120,000 - 150,000
Cybersecurity Risk & Exposure Subject Matter Expert IV
Cybersecurity Risk & Exposure Subject Matter Expert IV

Invictus International Consulting, LLC • Alexandria (VA)

On-site
USD 153,000 - 207,000
Cybersecurity Risk & Exposure Subject Matter Expert IV
Cybersecurity Risk & Exposure Subject Matter Expert IV

Invictus International • Colorado Springs (CO)

On-site
USD 140,000 - 190,000
Cybersecurity Risk & Exposure Analyst III
Cybersecurity Risk & Exposure Analyst III

Invictus International Consulting, LLC. • Alexandria (VA)

On-site
USD 150,000 - 190,000
Cybersecurity Risk & Exposure Subject Matter Expert IV
Cybersecurity Risk & Exposure Subject Matter Expert IV

Invictus International Consulting, LLC. • Colorado Springs (CO)

On-site
USD 120,000 - 160,000
Cybersecurity Risk & Exposure Subject Matter Expert IV
Cybersecurity Risk & Exposure Subject Matter Expert IV

Invictus International Consulting, LLC • Colorado Springs (CO)

On-site
USD 162,000 - 198,000
Cybersecurity Risk & Exposure Analyst III
Cybersecurity Risk & Exposure Analyst III

invictusic • Alexandria (VA)

On-site
USD 120,000 - 170,000
Cybersecurity Risk & Exposure Analyst III
Cybersecurity Risk & Exposure Analyst III

Invictus International • Colorado Springs (CO)

On-site
USD 95,000 - 125,000