Senior Subject Matter Expert (SME) - Data Security & DSPM Implementation
RESULTS. INNOVATION. VALUES. ACCOUNTABILITY.
That’s RIVA.
We’re a mission-driven IT services company and systems integrator supporting digital transformation and modernization for federal government agencies. Since 2009, we’ve partnered with our customers to solve complex challenges through smart, practical innovation to deliver real outcomes where they matter most. Our teams are made up of industry-leading experts who are passionate about doing great work and making a difference. We don’t just develop solutions, we support efforts that strengthen communities and serve the public good.
RIVA’s culture is built on four core values: Results, Innovation, Values, and Accountability. They guide how we work, how we collaborate, and how we measure success. Our employee-first approach is rooted in trust, ownership, and meaningful work. By investing in our people and fostering a flexible, supportive environment, employees have the opportunity to grow their skills, contribute ideas, and make an impact from day one. all while supporting missions that matter.
POSITION OVERVIEW
RIVA Solutions is seeking a Senior Subject Matter Expert (SME) specializing in enterprise data security, DSPM platforms, and cloud-native security operations. This SME provides hands-on technical leadership for the discovery, classification, and protection of sensitive data across the USPTO's hybrid environment—including approximately 4,000 Kubernetes containers, M365, AWS GovCloud, Azure Government, GCP, and on-premises systems—and serves as the program's foremost authority on Wiz Federal DSPM configuration, data platform integration, and AI artifact security for the Discovery and Classification objective (SOO 4.1.1) and AI Artifact Security objective (SOO 4.1.3).
CORE RESPONSIBILITIES
- Lead requirements definition, configuration, and operationalization of the Wiz Federal DSPM platform (FedRAMP High, Class D) for enterprise-scale data discovery and classification across the USPTO's cloud repositories, SaaS platforms, developer workspaces, M365 collaboration environment, and on-premises data stores
- Define the content-class taxonomy collaboratively with USPTO subject-matter experts; configure classification rules and measure precision and recall for each rule set prior to Product Owner approval and publication in the Discovery and Classification Configuration guide
- Extend DSPM classification coverage to the USPTO's data analytics platform: integrate Wiz with Databricks, Unity Catalog, and Delta Share to ensure structured sensitive data assets are discovered, classified, and tracked in the Wiz Security Graph risk model
- Lead AI artifact security operations: configure Snyk Agent Scan within the GitLab CI/CD pipeline to detect sensitive data and policy violations in AI-native artifact types—Markdown prompt files, cursor rules, GitHub Copilot instruction files, and Model Context Protocol (MCP) configuration files—before they reach production
- Integrate DSPM findings with Axonius asset context and Tenable vulnerability data to produce the risk-scored source inventory delivered to the COR within 60 days; maintain and update the inventory as the cloud migration sequence advances
- Oversee integration of DSPM classification results with the ServiceNow SMP remediation workflow, defining severity-to-queue routing rules, SLA targets for each alert tier, and escalation paths to security operations
- Ensure DSPM findings flow into the three-tier evidence chain: XSIAM and QRadar SIEM telemetry for operational-tier reporting, AWS CloudWatch for compliance-tier dashboard data, and AWS S3-archived outputs for executive-tier and audit reporting
- Support Netskope FedRAMP High CASB integration: align browser-path and SaaS-path DLP policies with the DSPM classification taxonomy so that enforcement actions reference the same sensitivity vocabulary across discovery and enforcement
- Deliver subject-matter briefings to USPTO IT leadership and security operations staff; support continuous knowledge transfer so the agency can independently tune classification rules, adjust enforcement policies, and generate reports after contract closeout
MINIMUM QUALIFICATIONS
- Bachelor's degree and 10 years of relevant experience, or Master's degree and 8 years of relevant experience in data security, cloud security, or a closely related field
- Hands-on experience implementing or operating DSPM platforms (e.g., Wiz, Varonis, Cyera, BigID) at enterprise scale in cloud or hybrid environments; FedRAMP or high-compliance federal environment experience strongly preferred
- Expert knowledge of data classification frameworks, sensitive data discovery techniques, and policy-based enforcement across multi-cloud environments (AWS GovCloud, Azure Government, GCP, M365)
- Experience with AI artifact security: scanning CI/CD pipeline artifacts including Markdown prompt files, IaC templates, and AI tool configuration files using tools such as Snyk
- Familiarity with data platform environments (Databricks, Unity Catalog) and their integration into enterprise DSPM and data governance workflows
- Working knowledge of SIEM telemetry pipelines (XSIAM, QRadar), ServiceNow ITSM remediation workflows, and federal reporting requirements under FISMA and FedRAMP High baselines
- Deep technical fluency in the data services subject to discovery and classification: object storage (AWS S3, Azure Blob, GCS), relational and managed database services (RDS, Azure SQL), data lake formats (Delta Lake, Parquet), M365 collaboration stores (SharePoint, OneDrive, Exchange Online), and on-premises file shares (SMB/NFS), with SQL proficiency for validation queries
- Detection engineering experience for data classification: regular expression and dictionary rule authoring, exact data match (EDM) fingerprinting, ML-assisted classifiers, and measurement of rule precision and recall against labeled sample sets
PREFERRED QUALIFICATIONS
- Direct experience with Wiz Federal DSPM, Wiz Code, or Wiz Security Graph in a FedRAMP-authorized or federal cloud environment
- Familiarity with Snyk Agent Scan, Axonius asset management, or Tenable vulnerability management as inputs to DSPM risk scoring
- CISSP, CCSP, or AWS/Azure security certification; Wiz, Databricks, or Netskope platform credentials a plus
- Experience with Kubernetes container security in a federal multi-cloud environment
- Prior experience supporting USPTO or other IP-generating federal agencies with data governance or cybersecurity programs
- Experience tuning enterprise classification programs at 10+ PB scale, including false-positive reduction campaigns and classifier performance reporting to government stakeholders
Pay range
$175,000 - $200,000 USD
EQUAL EMPLOYMENT OPPORTUNITY & ACCOMMODATION
We believe great teams are built from different backgrounds, perspectives, and lived experiences, and we mean that beyond the buzzwords.
RIVA is an equal opportunity employer. We welcome applicants of every race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, veteran status, and any other characteristic protected by law.
If you need an accommodation at any point in our process, send an email to talent@rivasolutionsinc.com, we'll be happy to help.
VETERAN SUPPORT & ACCESSIBILITY
As a federal contractor, RIVA follows the requirements of the Vietnam Era Veterans' Readjustment Assistance Act (VEVRAA) and Section 503 of the Rehabilitation Act, supporting the employment and advancement of protected veterans and individuals with disabilities. If you're a veteran, we encourage you to self-identify during the application process, it helps us track our hiring commitments and, in some cases, may support priority referral for open roles.
RIVA also invites applicants to voluntarily self-identify as having a disability during the application process, not because it affects your chances of being hired, but because it helps us measure how well we're living up to our commitments and identify where we can do better. Your response is confidential and entirely optional.
Apply for this job
*
indicates a required field