Lead Cyber Security Analysis SME

Xtreme Inc
Washington, DC, United States
about 1 month ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
10 years minimum
Working hours
Regular working hours
Job source

Tech stack

Amazon Web Services Microsoft Azure Cloud Computing Security Configuration Management Cyber Security Identity and Access Management Network Segmentation Role-Based Access Control Zero Trust Network Access Security Information and Event Management Software Vulnerability Management Data Logging
+2 more
CIS Benchmarks Vulnerability Analysis

Job description

XSI is seeking a Lead Cyber Security Analysis SME to anchor the cybersecurity engineering team supporting the Congressional Budget Office (CBO). This is a senior, hands-on engineering leadership role - not a policy, compliance, or SOC-monitoring position. You will lead technical implementation across the full security stack and own the Government-facing documentation that demonstrates control effectiveness., * Lead technical implementation across Zero Trust, IAM, SIEM/EDR/XDR, vulnerability management, cloud security, network segmentation, security baselines, and incident response.

  • Implement and maintain enterprise security controls aligned to NIST SP 800-53 and NIST SP 800-207 - access control, configuration management, system and communications protection, audit and accountability, incident response, and system and information integrity.
  • Drive Zero Trust enforcement, continuous verification of users and devices, identity-centric security, and least-privilege access (RBAC, PAM, MFA).
  • Oversee centralized logging and SIEM integration, vulnerability assessment, RMF-aligned risk analysis, system hardening, and AWS/Azure cloud security.
  • Support incident response, forensic data collection, root cause analysis (RCA), change management, and automated patching.
  • Produce SOPs, security impact analyses, implementation plans, validation criteria, rollback steps, and audit-ready control evidence.
  • Collaborate with network, cloud, application, and service desk teams to remediate risk and strengthen posture.

Requirements

Do you have experience in Vulnerability management?, * 10+ years of hands-on enterprise cybersecurity experience, including federal or highly regulated environments.

  • Demonstrated experience as a senior cybersecurity engineer or security architect leading technical implementation across multiple security domains.
  • Proven track record configuring IAM and least-privilege controls; tuning SIEM/EDR/XDR alerts; conducting incident triage and containment; coordinating vulnerability remediation; and hardening cloud or hybrid environments.
  • Strong technical writing - recommendations, implementation plans, validation criteria, and control evidence., CISSP strongly preferred. Also valued: CISM, CISA, CCSP, CASP+, GIAC certifications, Security+, AWS Certified Security - Specialty, Microsoft SC-100, SC-200, AZ-500, or equivalent.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

2:15 min

Auditing container configurations against CIS benchmark security standards

Madhu Akula · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

1:10 min

Exposing sensitive information through partial search logs

Dennis Schulz Dennis Schulz +1 · WWC Europe 2026

3:39 min

Validating data queries and infrastructure security configurations

Philipp Krenn · WWC 2023

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

Videos

See all

Related articles

See all