
Security Subject Matter Expert, SME
General Dynamics Information Technology
full-time
Posted on:
Location Type: Hybrid
Location: Austin • Texas • United States
Visit company websiteExplore more
Salary
💰 $165,750 - $224,250 per year
About the role
- The Security Subject Matter Expert (SME) is the program’s security lead for a large, hybrid enterprise (on-prem data centers and multi-cloud).
- You will architect, implement, and operate a Zero Trust, RMF-aligned security solutions that keep systems reliable, data protected, and the program audit-ready at all times.
- You will own the end-to-end security operating model, identity and access (including PIV/FIDO and PAM), vulnerability and patch orchestration, logging and SIEM/SOAR, supply-chain integrity (SBOM/provenance), backup/DR resilience, and continuous monitoring.
- You will convert compliance into a running capability rather than a paperwork cycle.
- By embedding controls in automation, policy-as-code in pipelines, signed artifacts with attestations, identity-centric access, and immutable backups, you will raise assurance while reducing toil and mean time to recover.
- You’ll drive continuous compliance with authoritative evidence from VA systems (ITSM/CMDB, SIEM/EDR, vulnerability tools), cut vulnerability aging against CISA KEV targets, and raise control pass rates without slowing delivery.
- During incidents, you will lead joint “swarm” response, contain issues quickly, and turn lessons into baseline changes, POA&Ms, and updated playbooks.
- For executives and non-technical stakeholders, you’ll translate risk into clear narratives - what happened, what changed, how we’re safer, and publish trend lines that connect security investments to fewer outages, cleaner audits, and lower total cost of ownership.
Requirements
- Education: Bachelor's Degree. In lieu of a degree, an additional four years of related experience required
- Experience: 10+ years in enterprise cybersecurity engineering/operations with direct ownership of hybrid (data center + AWS/Azure) environments; 3+ years in regulated or federal programs (VA/DoD/DHS/HHS or equivalent).
- Demonstrated delivery of Zero Trust architectures (per NIST SP 800-207/TIC 3.0), RMF/ATO sustainment (SP 800-53 Rev 5/53B baselines), and continuous monitoring at scale.
- Hands-on leadership standing up SIEM/SOAR, EDR, vulnerability management, identity platforms (SSO/PIV/FIDO, PAM/JIT), and audited disaster recovery programs (SP 800-184).
- Proven record improving outcomes: higher control pass, reduced critical vuln aging, faster MTTR, successful external assessments, and repeatable ATO renewals.
- Experience operating within multi-vendor/SIAM models with cross-vendor OLAs and shared KPIs.
- Technical skills: Identity & Access (ICAM): SSO (SAML/OIDC), PIV/CAC and FIDO2, JIT/PAM, least-privilege for human and workload identities; directory hygiene and join/move/leave automation.
- Network & Platform Security: Segmentation and micro-segmentation, SASE/SD-WAN patterns aligned to TIC 3.0; hardened baselines (STIG/CIS) for OS, containers, and Kubernetes/OpenShift (admission control, policy engines).
- Logging, Detection, and Response: Event logging per OMB M-21-31, SIEM content engineering, SOAR playbooks, EDR tuning; run tabletop exercises and purple-team improvements.
- Vulnerability & Patch Orchestration: Toolchain proficiency (e.g., Tenable/Qualys, WSUS/Linux lifecycle), KEV-driven prioritization, SLAs by criticality, and automated compliance evidence (SCAP).
- Secure SDLC & Supply Chain: SSDF (SP 800-218) practices, artifact signing and provenance/attestations (SLSA/SBOM), trusted registries, policy-as-code gates in CI/CD; secrets management (KMS/Vault).
- Data & Storage Protection: Encryption in transit/at rest (FIPS-140 validated), key management, DLP patterns, immutable/object-lock backups, tested DR with objective pass/fail artifacts.
- Standards & Tooling Fluency: NIST CSF 2.0, SP 800-61 (IR), SP 800-53/53B, SP 800-207, SP 800-184, TIC 3.0, FIPS-140; OSCAL for machine-readable SSP/ConMon
Benefits
- Full-flex work week to own your priorities at work and at home
- 401K with company match
- Comprehensive health and wellness packages
- Internal mobility team dedicated to helping you build your skills and own your career
- Professional growth opportunities including paid education and certifications
- Cutting-edge technology you can learn from
- Rest and recharge with paid vacation and 10 company-paid holidays
Applicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard skills
Zero Trust architectureRMF/ATO sustainmentSIEMSOAREDRvulnerability managementidentity platformsdisaster recoveryencryptionautomated compliance
Soft skills
leadershipcommunicationincident responseproblem-solvingcross-vendor collaborationnarrative translationcontinuous improvementstakeholder engagementteam coordinationrisk assessment
Certifications
Bachelor's DegreeNIST SP 800-207NIST SP 800-53NIST SP 800-184FIPS-140CISA KEVSP 800-218SLSASBOMOSCAL