Senior Cybersecurity SME/SCA
M9 Solutions is dedicated to providing IT services and solutions to the Federal Government by mobilizing the right people, skills, clearance levels, and technologies to help organizations that desire improved performance and modern, sustainable change. M9 has provided quality IT services and support to more than 30 Federal Agencies and multiple commercial customers nationwide. Our capabilities include IT Talent Solutions, Data Delivery & Analytics, Cyber Security, Cloud Migration, Applications and Infrastructure, Software Development, and Finance & Accounting.
M9 Solutions is seeking a Senior Cybersecurity SME/SCA to work onsite in support of a government contract for a client located in Chantilly, VA. An active Top Secret clearance is required.
Responsibilities
- Strategic Advisement & Lifecycle Integration:
- Engineering Technical Reviews: Actively participate in System Requirements Reviews (SRR), Preliminary Design Reviews (PDR), and Critical Design Reviews (CDR) to ensure security is baked in, rather than bolted on.
- DevSecOps Alignment: Guide project teams in integrating automated security testing (SAST/DAST) and continuous compliance monitoring into Agile development pipelines where appropriate.
- Threat Modeling: Conduct system-level threat modeling during the design phase to identify potential attack vectors and recommend architectural mitigations before code is written or hardware is procured.
- Advanced Assessment & Risk Determination:
- Technical Validation: Move beyond paperwork by conducting deep technical reviews of vulnerability scans (e.g., ACAS/Nessus), STIG checklists, and penetration testing reports. Correlate technical findings to actual operational risk.
- RMF Execution: Demonstrate mastery of RMF policies (NIST SP 800-53 Rev 5, CNSSI 1253, DoD 8510.01, ICD 503). Assist the government Authorizing Official (AO) by translating complex technical compliance shortfalls into actionable, mission-contextualized risk decisions.
- Diverse Architectures: Evaluate the security performance, integrity, and residual risk of varied environments, including Platform Information Technology (PIT), hardware/software systems, communication networks, and satellite control systems, etc.
- Zero Trust & Next-Generation Architecture:
- Zero Trust Implementation: Drive the adoption of Zero Trust architectural pillars (User, Device, Network, Application/Workload, Data, Visibility/Analytics, and Automation/Orchestration) across all client portfolios.
- Cross Domain Solutions (CDS): Provide specialized expertise in designing, evaluating, and implementing CDS technologies. This includes complex enterprise deployments in classified compartmentalized environments and “point-to-point” solutions for isolated, tactical IT architectures.
- Emerging Technology Evaluation: Continuously monitor state-of-the-art technologies (e.g., AI/ML, edge computing, quantum-resistant cryptography) and the evolving threat landscape to ensure client systems anticipate and mitigate next-generation threats.
- Stakeholder Engagement & Liaison:
- Technical Translation: Facilitate seamless communication with the client Portfolio technical SMEs, effectively translating AO directives to engineers and engineering challenges to the AO.
- Community Representation: Serve as a key liaison between the Defense Industrial Base (DIB), government cybersecurity entities, security assessment organizations, and Special Access Program (SAP) IT working groups to maintain alignment with the broader defense innovation ecosystem.
Required Skills and Qualifications
- Active Top Secret security clearance.
- Bachelor’s degree in Information Technology, Computer Science, or related field (or equivalent experience).
- Minimum of twelve (12) years of demonstrated experience in IT, cybersecurity engineering, and Assessment & Authorization (A&A), with increasing responsibility.
- Significant and proven multi-domain experience with SAP and SCI Systems, to include PIT, Cloud environments, Cross Domain Solutions.
- Active baseline certification equivalent to DoD 8140.01 / 8570.01-M Information Assurance Workforce Improvement Program (IA WIP) for IAT Level III or IAM Level III (e.g., CISSP, CISM, GSLC, CASP+ CE).
- Aptitude for aligning cyber risk management with real-world mission outcomes, proactively tailoring security assessments to enable and protect the mission rather than imposing dogmatic compliance hurdles.
- Ability to translate complex technical vulnerabilities into clear, operational risk statements (Mission Impact) for executive leadership and the AO.
- Deep understanding of system architectures, data flows, port/protocol matrix analysis, and network boundary defense concepts.
- Proficiency in analyzing outputs from technical tools such as ACAS, SCAP, STIG Viewer, Splunk/SIEMs, and cloud security posture management (CSPM) tools.
- Expertise in securing and assessing Cloud environments (AWS, Azure IL5/IL6) and containerized applications (Kubernetes, Docker).
- Understanding of MASS, Xacta, or similar A&A workflow tools within classified and unclassified environments.
Preferred Skills and Qualifications
- Direct experience working within the defense innovation ecosystem, specifically with rapid prototyping, test environments, and Platform IT (PIT) systems.
- Proven hands-on technical experience working as a systems integrator or cybersecurity engineer, specifically with enterprise networks, cloud computing systems, and/or all-domain platform IT architectures.
GH 1024
Full-Time Employee Compensation
- M9 Solutions’ pay range for this position is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include, but are not limited to, responsibilities of the position, education, experience, knowledge, skills, abilities, as well as internal equity, location, alignment with market data, applicable bargaining agreement (if any), or other law.
- M9 Benefits - https://m9solutions.com/why-join-m9/#our-benefits
Salary Range
$180,000 - $190,000 USD
M9 Solutions, LLC (M9) is a Federal sub-contractor and we comply with all applicable federal laws prohibiting discrimination in employment, including Title VII of the Civil Rights Act of 1964. We also adhere to the affirmative action requirements of the Vietnam Era Veterans' Readjustment Assistance Act (VEVRAA) and Section 503 of the Rehabilitation Act, ensuring equal opportunity for veterans and individuals with disabilities. Please click here to complete M9's Voluntary Self-Identification Form and then email it to hr@m9solutions.com. If you need accommodation during the application process or encounter difficulties using our website, please contact our Human Resources Department at hr@m9solutions.com or 703-936-0880
M9 Solutions is a proud participant in the Virginia Values Veterans (V3) program and supports the Military Medics and Corpsmen (MMAC) initiative, demonstrating our commitment to hiring and supporting veterans, transitioning service members, military spouses, and dependents.
With 15+ years of proven delivery and growth, M9 Solutions is a unique small business with credible past performance and key capabilities offering project management services, solution architects, business analysts, program managers, technical architects, and technical consultants. M9 was recognized as an Inc. 5000 Fastest-Growing Private Companies in 2021, 2020, 2019, 2018, 2017, 2016, and 2012. M9 Solutions believes that work should be fun, rewarding, and something everyone can be excited about. We offer a competitive compensation package and value diverse perspectives in driving the vision of the company.
Apply for this job
*
indicates a required field
