Hiring.Camp

Cybersecurity Risk & Exposure Subject Matter Expert IV

Invictus International Consulting, LLC

Location
Alexandria, VA
Type
Full-time
Department
IT
Education
Bachelor
Clearance
Required
Source
ApplicantPro

Description

 

Title: Lead Cybersecurity Risk & Exposure Subject Matter Expert IV

Location: Alexandria, VA 

Clearance: TS/SCI with the ability to obtain and maintain a CI polygraph

 

 

Job Details:

  • Serve as the senior SME for operational cyber risk, vulnerability/exposure analysis, and continuous monitoring supporting a DoD cyber defense mission
  • Establish methodologies for correlating vulnerability, asset, configuration, network reachability, system criticality, security-control, threat, and incident data to identify and prioritize the exposures most likely to create operational or mission risk
  • Lead complex exposure and impact assessments, including development of plausible exploitation scenarios, attack paths, affected-system analysis, compensating-control considerations, and risk-informed courses of action
  • Provide expert vulnerability, asset, architecture, and security-control context to SOC leadership, Cybersecurity Operations Analysts, Threat Analysts, incident responders, and engineering teams during significant investigations and proactive defensive activity
  • Lead analysis of ACAS/Tenable results, runZero asset information, STIG/configuration findings, system documentation, and other approved data to identify systemic weaknesses, exploitable conditions, and remediation priorities
  • Own the SOC-side process for coordinating material cyber findings with affected system ISSOs/ISSMs, system owners, administrators, engineers, and authorization stakeholders; ensure operational findings are translated into appropriate mitigation, continuous-monitoring, POA&M, or RMF actions without duplicating system ISSO responsibilities
  • Establish and maintain checklists, TTPs, guides, procedures, quality standards, and reporting methods for exposure analysis, risk prioritization, remediation validation, and SOC-to-system-security coordination
  • Lead review of remediation evidence, recurring vulnerabilities, exposure trends, control weaknesses, and SOC-derived findings to identify systemic risk and recommend enterprise or site-level corrective actions
  • Develop briefings, executive summaries, risk assessments, metrics, dashboards, and technical products that communicate operational exposure, remediation progress, control effectiveness, and mission impact to technical and leadership audiences
  • Advise SOC leadership on vulnerability/exposure trends, high-risk assets, recurring security weaknesses, remediation priorities, and opportunities to improve the integration of vulnerability management, threat information, and cyber defense operations
  • Mentor senior and developing analysts and provide technical quality review of exposure assessments, risk conclusions, remediation recommendations, and stakeholder coordination products
  • Experience integrating vulnerability management, continuous monitoring, RMF/ISSO processes, and SOC or incident-response operations in a DoD/IC or similarly complex enterprise environment is highly desired

 

Requirements:

  • Bachelor's degree from an accredited institute in a technical discipline applicable to the position; an additional 4 years of may be substituted in lieu of a degree
  • Minimum of eight (8) years of relevant experience in addition to education level
  • Demonstrated expert knowledge of vulnerability/exposure management, threat-informed risk analysis, DoD continuous monitoring, RMF/security controls, network/system security, and technical risk assessment
  • Experience with ACAS/Tenable, runZero or comparable exposure/asset-discovery tools, DoD STIG/STIG Viewer, SCAP, POA&M processes, and integration of SOC/incident-response findings with ISSO/ISSM or RMF functions is highly desired
  • Demonstrated experience establishing exposure-analysis methodology, leading complex risk assessments, prioritizing remediation, and translating operational cyber findings into continuous-monitoring or RMF actions is strongly desired
  • Must possess current DoD 8570 IAT II or IAM II certification
  • Experience working in a DoD or IC environment
  • Current active TS/SCI clearance, with the ability to obtain and maintain a CI polygraph

 

Equal Opportunity Employer/Veteran/Disabled

Skills

CybersecuritySOC

Similar Jobs

30

Senior Technology and Cybersecurity Risk & Controls Specialist

mtb · Bridgeport, CT, United States of America · Hybrid

5 days ago

Intern – Cybersecurity Risk (Hybrid: Onsite & Remote)

Usfoods · Rosemont IL, United States of America · Remote, Hybrid, Onsite

1 week ago

Chief Information Security Officer - Tech Risk & Cybersecurity

Santander Effect Our work touches · Arrecife P01, Spain

1 week ago

Chief Information Security Officer - Tech Risk & Cybersecurity

Santander · Arrecife P01, Spain

1 week ago

Cybersecurity Risk & Compliance Analyst

"VoltaGrid, LLC" · Houston, TX

1 week ago

AI/ML - Technology & Cybersecurity Risk Management - Vice President

JPMorgan Chase · New York, NY, United States, US

2 weeks ago

AI/ML - Technology & Cybersecurity Risk Management - Vice President

JP Morgan Chase · New York, NY, United States, US

2 weeks ago

Cybersecurity -Risk Management assessment

Vodafone · Pune, MH,IN, IN

2 weeks ago

Cybersecurity -Risk Management assessment

Vodafone · Pune, MH,IN, IN

2 weeks ago

Principal Technology and Cybersecurity Risk & Controls Specialist

mtb · Buffalo, NY, United States of America · Hybrid

2 weeks ago

Principal, Cybersecurity Risk

Fmr · 100 New Millennium Way, Bldg 2, Durham NC, United States of America

2 weeks ago

IT Audit, Cybersecurity & Risk Advisory Senior Consultant (PCI Focus)

bakertilly · USA UT Lehi, United States of America +1 · Remote

2 weeks ago

Senior OT Cybersecurity Risk Analyst

Delan Associates, Inc · Houston, TX, US · Hybrid

3 weeks ago

Chief Cybersecurity Risk Officer

Truist · Charlotte NC - 214 North Tryon Street, United States of America +4

3 weeks ago

CyberSecurity Risk Manager

ARHS · Warsaw, Masovian Voivodeship, Poland

3 weeks ago

Senior Cybersecurity Risk & Governance Analyst

Default Brand · Oxford, MS

3 weeks ago

Public Sector IT Audit, Cybersecurity & Risk Experienced Consultant

bakertilly · USA DC Washington DC, United States of America

3 weeks ago

IT Audit, Cybersecurity & Risk Senior Manager

bakertilly · USA MA Tewksbury, United States of America

4 weeks ago

Cybersecurity Risk and Compliance Manager

Patriot Machine · St. Charles, MO

4 weeks ago

Cybersecurity Risk - Senior Consultant

Guidehouse is · GH Office: Tysons Corner, VA (Headquarters), United States of America +1

4 weeks ago

Cybersecurity Risk - Senior Consultant

Guidehouse is · GH Office: Tysons Corner, VA (Headquarters), United States of America +1

4 weeks ago

Cybersecurity Risk - Managing Consultant

Guidehouse is · GH Office: Tysons Corner, VA (Headquarters), United States of America +1

4 weeks ago

Cybersecurity Risk Management Analyst

Chubb · Philadelphia, PA, United States, US

1 month ago

Cybersecurity Risk Manager

Kinaxis · Remote, CA · Remote

1 month ago

IT Audit, Cybersecurity & Risk Senior Consultant (SOC focus)

bakertilly · USA WI Milwaukee, United States of America +7

1 month ago

Senior Analyst - Cybersecurity Risk & Compliance

Freshworks CRM · Chennai, India

1 month ago

Cybersecurity Risk Assessment Specialist

Booz Allen Hamilton · USA, MS, Stennis Space Ctr (1100 Balch Blvd), United States of America

1 month ago

IT Audit, Cybersecurity & Risk Senior Consultant

bakertilly · USA MA Tewksbury, United States of America

1 month ago

IT Audit, Cybersecurity & Risk Senior Consultant

bakertilly · USA MA Tewksbury, United States of America

1 month ago

IT Audit, Cybersecurity & Risk Director

bakertilly · USA MA Tewksbury, United States of America

1 month ago
Cybersecurity Risk & Exposure Subject Matter Expert IV at Invictus International Consulting, LLC | Hiring.Camp