Cybersecurity SME

Wintrio LLC
United States
3 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
10 years minimum
Working hours
Regular working hours
Job source

Tech stack

Xacta Agile Methodology Amazon Web Services Microsoft Azure Cloud Computing Security Configuration Management Cyber Security Executive Information Systems Information Security Management Fortify (Software) Zero Trust Network Access RSA (Cryptosystem)
+19 more
Security Content Automation Protocol Security Information and Event Management SonarQube Systems Integration Software Vulnerability Management Webinspect Enterprise Software Applications Cloud Platform System Software Security Information Technology Nessus CIS Benchmarks Cloudwatch Splunk Devsecops Qualys Servicenow Static Application Security Testing Dynamic Application Security Testing

Job description

WINTrio LLC is seeking a Cybersecurity Subject Matter Expert (SME) with deep experience supporting Risk Management Framework (RMF), Authority to Operate (ATO), continuous monitoring, and federal cyber compliance programs. This role supports the full system security lifecycle, including control implementation, assessment readiness, authorization packages, Plan of Action and Milestones (POA&M) management, vulnerability remediation tracking, and audit support., * Lead RMF lifecycle activities including system categorization, control selection, implementation, assessment, authorization, and continuous monitoring.

  • Develop, review, and maintain ATO artifacts including System Security Plans (SSP), Security Assessment Reports (SAR), Risk Assessment Reports (RAR), Contingency Plans, Configuration Management Plans, Privacy Threshold Analysis (PTA), Privacy Impact Assessment (PIA), and POA&M documentation.
  • Support security control implementation and validation against NIST Special Publication 800-53, FISMA, FedRAMP, agency policy, and system-specific requirements.
  • Coordinate with Information System Security Officers (ISSOs), System Owners, Authorizing Officials, Security Control Assessors, cloud teams, and application teams.
  • Monitor continuous authorization activities, recurring assessments, vulnerability remediation, and security posture reporting.
  • Analyze security findings from tools such as ACAS, Nessus, Tenable, WebInspect, Fortify, Splunk, Xacta, eMASS, CSAM, Archer, ServiceNow, or similar platforms.
  • Manage POA&M development, remediation evidence, milestone tracking, risk acceptance packages, and closure validation.
  • Support audit readiness, control inheritance analysis, cloud security documentation, and FedRAMP package reviews.
  • Provide senior-level guidance on Zero Trust, DevSecOps, cloud security, and security architecture alignment.
  • Prepare executive dashboards, compliance reports, risk briefings, and security status updates for federal stakeholders.

Requirements

  • 10+ years of cybersecurity experience, with strong federal RMF, ATO, or continuous monitoring experience.
  • Hands-on experience with NIST RMF, NIST 800-53, FISMA, POA&M management, and security authorization processes.
  • Experience developing or reviewing ATO documentation and security control evidence.
  • Experience working with federal security stakeholders including ISSOs, System Owners, Security Control Assessors, and Authorizing Officials.
  • Strong understanding of vulnerability management, audit readiness, continuous monitoring, and risk-based remediation.
  • Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or related field., * Frameworks: NIST RMF, NIST 800-37, NIST 800-53, NIST 800-30, NIST 800-137, FISMA, FedRAMP, Zero Trust Architecture
  • GRC / ATO Tools: eMASS, Xacta, CSAM, RSA Archer, ServiceNow GRC, RegScale
  • Vulnerability Tools: ACAS, Nessus, Tenable.io, Tenable.sc, Qualys, Rapid7
  • Application Security: Fortify, WebInspect, SonarQube, SAST, DAST, SCA tools
  • SIEM / Monitoring: Splunk, ELK, Azure Monitor, AWS CloudWatch, Sentinel
  • Cloud Security: AWS GovCloud, Azure Government, FedRAMP baselines, cloud control inheritance
  • Documentation: SSP, SAR, RAR, POA&M, PTA, PIA, BIA, Contingency Plans, Incident Response Plans
  • Standards: STIG, SCAP, CIS Benchmarks, DISA guidance, agency-specific cyber policy

Preferred Certifications, Not Required

  • CISSP
  • CISM
  • CAP / Certified Authorization Professional
  • Security+
  • CASP+
  • CCSP
  • Certified Ethical Hacker (CEH)
  • AWS Security Specialty or Azure Security Engineer Associate
  • GIAC certifications such as GSEC, GSLC, or GCIH, * Experience supporting DHS, USDA, DoD, IRS, CBP, or other federal civilian agencies.
  • Experience with ongoing authorization or continuous authorization environments.
  • Experience supporting classified, sensitive, high-value asset, or mission-critical systems.
  • Experience integrating cyber compliance with Agile, DevSecOps, and cloud delivery workflows.

Benefits & conditions

  • Medical, Dental, and Vision Insurance
  • FSA and HSA options
  • 401(k) Retirement Plan
  • Paid Time Off and Vacation
  • Employee Assistance Program
  • Life and Disability Insurance

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on wintrio.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 · LIVE

4:19 min

Introduction to network security and endpoint monitoring architectures

Christoph Ruggenthaler · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

Videos

See all

Related articles

See all