> Markdown version of [/jobs/ext/737739-lead-cyber-security-analysis-sme](https://www.wearedevelopers.com/jobs/ext/737739-lead-cyber-security-analysis-sme). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Lead Cyber Security Analysis SME - **Company:** Xtreme Inc - **Location:** Washington, DC, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Microsoft Azure, Cloud Computing Security, Configuration Management, Cyber Security, Identity and Access Management, Network Segmentation, Role-Based Access Control, Zero Trust Network Access, Security Information and Event Management, Software Vulnerability Management, Data Logging, CIS Benchmarks, Vulnerability Analysis - **Published:** June 29, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=5b8747a381da615f ## About the Role Do you have experience in Vulnerability management?, * 10+ years of hands-on enterprise cybersecurity experience, including federal or highly regulated environments. * Demonstrated experience as a senior cybersecurity engineer or security architect leading technical implementation across multiple security domains. * Proven track record configuring IAM and least-privilege controls; tuning SIEM/EDR/XDR alerts; conducting incident triage and containment; coordinating vulnerability remediation; and hardening cloud or hybrid environments. * Strong technical writing - recommendations, implementation plans, validation criteria, and control evidence., CISSP strongly preferred. Also valued: CISM, CISA, CCSP, CASP+, GIAC certifications, Security+, AWS Certified Security - Specialty, Microsoft SC-100, SC-200, AZ-500, or equivalent. ## Description XSI is seeking a Lead Cyber Security Analysis SME to anchor the cybersecurity engineering team supporting the Congressional Budget Office (CBO). This is a senior, hands-on engineering leadership role - not a policy, compliance, or SOC-monitoring position. You will lead technical implementation across the full security stack and own the Government-facing documentation that demonstrates control effectiveness., * Lead technical implementation across Zero Trust, IAM, SIEM/EDR/XDR, vulnerability management, cloud security, network segmentation, security baselines, and incident response. * Implement and maintain enterprise security controls aligned to NIST SP 800-53 and NIST SP 800-207 - access control, configuration management, system and communications protection, audit and accountability, incident response, and system and information integrity. * Drive Zero Trust enforcement, continuous verification of users and devices, identity-centric security, and least-privilege access (RBAC, PAM, MFA). * Oversee centralized logging and SIEM integration, vulnerability assessment, RMF-aligned risk analysis, system hardening, and AWS/Azure cloud security. * Support incident response, forensic data collection, root cause analysis (RCA), change management, and automated patching. * Produce SOPs, security impact analyses, implementation plans, validation criteria, rollback steps, and audit-ready control evidence. * Collaborate with network, cloud, application, and service desk teams to remediate risk and strengthen posture. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [A practical guide to writing secure Dockerfiles](https://www.wearedevelopers.com/videos/109-a-practical-guide-to-writing-secure-dockerfiles) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [OPA for the cloud natives](https://www.wearedevelopers.com/videos/713-opa-for-the-cloud-natives) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)