Cyber Security Analyst SME

General Dynamics IT
United States
5 days ago
Apply on hbcu.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Working hours
Regular working hours
Job source

Tech stack

Microsoft Excel Agile Methodology Amazon Web Services Data Analysis Cyber Security Information Systems Computer Networks Continuous Integration Data Architecture Data Governance Database Queries R (Programming Language)
+19 more
Information Systems Security Architecture Professional Python (Programming Language) Network Security Meta-Data Management Release Management Power BI Cloud Services Security Information and Event Management SQL Databases Tableau (Software) Software Vulnerability Management Snowflake Firewalls (Computer Science) Data Lakes Statistics Packages Data Management Tools for Reporting Devsecops Databricks

Job description

integrity, while serving as the program’s subject matter expert on Information Assurance (IA), Computer Network Defense (CND), and enterprise security strategy. The Cyber Security Analyst SME will execute the following responsibilities:Maintain separate security evidence mapping for Infrastructure and Application pipelines, ensuring artifacts satisfy required controls at each stage of the CI/CD process.Enforce pipeline gating criteria so that deployments cannot proceed to production unless required security evidence and approvals are in place.Perform, monitor, test, and troubleshoot hardware and software Information Assurance (IA) problems pertaining to the Computing Environment (CE), Network Environments (NE), Data Platforms (DP), and enclave environments.Collect and analyze data and events from Computer Network Defense (CND) tools such as system alerts, firewall, and network traffic logs, and host system logs.Assess and identify the systems and networks within the NE acceptable

Requirements

configurations and policies.Develop and manage security for more than one IT functional area (e.g., data, systems, network, and/or web) across the enterprise.Lead the development and implementation of security policies and procedures (e.g., user log-on and authentication rules, security breach escalation procedures, security auditing procedures, and use of firewalls and encryption routines).Brief and present status reports on security matters, developing security risk analysis scenarios and response procedures.Track and monitor software viruses and other malicious code across the environment.Lead the evaluation of products and/or procedures to enhance productivity and effectiveness.Provide direct support to the business and IT staff for security-related issues.Partner with DevSecOps, engineering, and governance teams to integrate security and compliance requirements into the release and deployment process. QUALIFICATIONSBS/BA degree with 7+ years of experience of general experience in information systems providing project leadership monitoring computer networks and security issues and investigating and resolving security and cybersecurity incidents.Experience documenting security incidents and performing security vulnerability assessments.Experience working with Agile teams and SAFe to perform testing and uncover system and network vulnerabilities.Experience may be considered in lieu of degree.Strong working experience in AWS Cloud Security (certification preferred); 3+ years’ experience.Prior ATO experience in an AWS environment for a large agency; 4+ years’ experience.Solid understanding of NIST Standards.Prior experience with the ATO process, FedRAMP, CIS, and ISO 27001 (4+ years).Solid understanding of ICAM, SIEM, and vulnerability management tools.Experience with CSAM or similar tools.Familiarity with data governance, metadata management, and data quality practices.Experience with SQL for data querying and validation.Proficiency with BI/reporting tools such as Power BI, Tableau, or QuickSight.Familiarity with statistical analysis tools/techniques (e.g., Excel, R, Python) preferred.Experience with cloud data platforms (Snowflake, Databricks, AWS preferred).Understanding of data architecture concepts (data lake, lakehouse, warehouse).Strong analytical, problemsolving, & statistical analysis skills with attention to detail and data accuracy.Preferred: Certified Information Systems Security Professional (CISSP). COMMUNICATION & ORGANIZATIONALExcellent presentation and communication (oral and written) skills.Consultant mindset with the ability to work with high level customer stakeholders and build excellent customer relationships.Experience identifying and applying industry tools, solutions, methods best practices, and emerging technologies.Strong analytical skills and problem-solving skills with the ability to formulate and communicate recommendations for improvement.Demonstrated ability to work effectively, independently, and as part of a team.Strong communication skills, with the ability to translate technical security findings into risk-based guidance for stakeholders and program leadership.

About the company

Seize your opportunity to make a personal impact supporting the Case Management Modernization (CMM) Program. The CMM program is an initiative to support the Administrative Office of the US Courts (AO) in developing a modern cloud-based solution to support all 204+ federal courts across the United States. GDIT is your place to make meaningful contributions to challenging projects and grow a rewarding career. The Cyber Security Analyst SME will work as part of the CMM cloud engineering and security team, serving as the program’s subject matter expert on information systems security and compliance across its Infrastructure and Application environments. The CMM program maintains separate evidence mapping for Infrastructure and Application pipelines and mandates pipeline gating so that deployments cannot occur unless security criteria are met. The Cyber Security Analyst SME provides the day-to-day governance and evidence necessary to keep releases moving without compromising control

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on hbcu.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:24 min

Moving the semantic layer upstream to avoid vendor lock-in

Piotr Menclewicz Piotr Menclewicz · Europe 2026 Virtual

1:33 min

Integrating internal APIs and maintaining data sovereignty

Mahran Meißner Mahran Meißner · World Congress 2026 Europe

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

2:07 min

Integrating security practices for devsecops adoption

Nevelina Aleksandrova · LIVE

2:46 min

Transforming data architecture from on-premise to cloud

Sandhya Menon Sandhya Menon · World Congress 2026 Europe

Videos

See all

Related articles

See all