The Cybersecurity Subject Matter Expert (SME) provides expert support, research and analysis of exceptionally complex problems, and processes relating to them. Serves as technical expert to the Cybersecurity Assessment Program providing technical direction, interpretation, and alternatives to complex problems. Thinks independently and demonstrates exceptional written and oral communications skills. Applies advanced technical principles, theories, and concepts. Contributes to the development of new principles, concepts, and methodologies. Works on unusually complex technical problems and provides highly innovative and ingenious solutions. Recommends cybersecurity software tools and assists in the development of software tool requirements and selection criteria to include the development of product specific STIGs from applicable DISA SRGs. Works under consultative direction toward predetermined long-range goals and objectives. Assignments are often self-initiated. Determines and pursues courses of action necessary to obtain desired results. Develops advanced technological ideas and guides their development into a final product.
Required Clearance:
- Active DoD SECRET, IT-II Non-Critical Sensitive / Tier 3 (T3)
Required Experience:
- Proven proficiency performing CCRI/ vulnerability assessment/ penetration testing on networks, databases, computer applications and IT frameworks.
- Seven (7) years IT experience
- Five (5) years Cybersecurity experience
- Strong analytical and problem-solving skills for resolving security issues.
- Strong skills implementing and configuring networks and networks components.
- Command Cyber Readiness Inspection certification in at least one of the following areas: Retina scan analysis, Operating Systems (Windows, Unix), Boundary defense (network policy, router, firewall), Internal defense (L2 switch, L3 switch), DNS (policy, BIND/Windows), HBSS (remote console, AV, ABM, PA, HIPS, ePO), Traditional security (Common, Basic, NCV, SCV), Wireless communications (BES, handhelds)
- Relevant certification from a nationally recognized authority.
- Knowledge and understanding of DOD security regulations, DISA STIGs
- Strong knowledge of SCAP
- Strong knowledge of RMF
- Expert experience in cybersecurity and evaluations
- Excellent knowledge of and proficiency with: VULNERATOR, USCYBERCOM CTO Compliance Program, Wireless vulnerability assessment, Web Services (IIS, Apache, Proxy), Database (SQL Server, Oracle), Email Services (Exchange), Vulnerability Scans (NESSUS, SCCM), Knowledge of Phishing exercises, USB Detect, Physical Security
Required Certifications:
- DISA FSO certified CCRI Team Lead
- Certification in penetration testing, such as:
- Licensed Penetration Tester (LPT)
- Certified Expert Penetration Tester (CEPT)
- Certified Ethical Hacker (CEH)
- Global Information Assurance Certification Penetration Tester (GPEN)
- Tenable Certified NESSUS Auditor Certification, such as:
- NESSUS Fundamentals
- NESSUS Advanced
- Tenable Security Center Specialist )