Security/Compliance SME

Posted 1ds ago

Employment Information

Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

Security/compliance SME advancing Department of the Air Force ICAM capabilities for Koniag Government Services. Aligning Zero Trust architectures, ATO processes, and governance studies with DoD policy.

Responsibilities:

  • Serve as the authoritative policy and compliance reference across three System Enhancement Studies
  • Review and interpret Government-Furnished Information and applicable DoD, DAF, and Federal regulatory references
  • Provide security and compliance guidance for CDO-L edge identity architecture, disconnected operations, break-glass access, PKI certificate validation, and synchronization methods
  • Assess security posture management requirements for CDO-L edge node operations
  • Evaluate and document Authority to Operate implications for classified NIPRNet and SIPRNet edge components
  • Provide security and compliance guidance for NPE attribute schemas, governance workflows, credential management policies, and target architecture
  • Review and validate NPE credential management governance, including credential rotation, secret vault storage, and hardcoded credential controls
  • Assess Zero Trust Architecture alignment of NPE governance, workload identity, dynamic access control, and continuous authentication
  • Define compliance requirements for NPE audit logging and monitoring, including SOC and ELICSAR integration and UEBA/AI-driven anomaly detection
  • Guide JML transformation architecture, attribute sanitization, Microsoft Entra ID integration, event-driven group management, and administrator delegation
  • Review and validate Leaver revocation architecture, including mailbox handling, DAF365 license reclamation, Entra ID token revocation, and Okta disablement sequencing
  • Assess delegated provisioning against least-privilege, separation-of-duties, and audit-trail requirements
  • Conduct cross-study compliance gap analysis and identify required controls, waivers, or ATO actions
  • Contribute security and compliance sections and regulatory mappings to three Technical Study Reports
  • Advise the Program Manager and Study Lead Engineers on emerging DoD and DAF cybersecurity policy developments
  • Support draft Performance Work Statements for subsequent implementation Task Orders
  • Verify assigned personnel hold required security clearances and notify the Government of status changes

Requirements:

  • Bachelor's degree in Cybersecurity, Information Assurance, Computer Science, Information Systems, or a related field from an accredited college or university
  • 7+ years of experience in cybersecurity, information assurance, or security compliance in Defense or Federal government IT environments
  • Demonstrated experience interpreting and applying DoD and Federal cybersecurity policy frameworks including NIST SP 800-53, NIST SP 800-63, DoDI 8520.04, DoDI 8510.01, and related mandates to enterprise IT system design and governance
  • Experience supporting Authority to Operate (ATO) processes for Defense information systems, including RMF package development, security control assessment, and accreditation timeline management
  • Active Secret security clearance, with final adjudication required prior to assignment
  • Deep knowledge of DoD and Federal cybersecurity and identity management policy frameworks
  • Strong understanding of Zero Trust Architecture principles and application to enterprise ICAM systems, disconnected edge environments, non-person entity governance, and identity lifecycle management
  • Experience with DoD Risk Management Framework (RMF) and Authority to Operate (ATO) processes
  • Knowledge of PKI-based authentication, certificate lifecycle management, DoD/DoW X.509 Certificate Policy, and Common Access Card (CAC) authentication security requirements
  • Familiarity with Okta and SailPoint IdentityIQ
  • Knowledge of DoD audit standards and log management requirements, including CJCSI 6510.01 and SIEM/SOC integration
  • Experience performing compliance gap analysis and documenting findings in formal technical reports
  • Ability to interpret and apply complex, conflicting regulatory requirements
  • Experience advising technical engineers and architects on security and compliance requirements
  • Strong technical writing skills for compliance assessments, regulatory mapping, technical study reports, and draft Performance Work Statements
  • Ability to work collaboratively across cross-functional technical teams
  • Exceptional written and oral communication skills in English
  • Ability to obtain and maintain a Secret security clearance

Benefits:

  • Medical, dental, and vision insurance
  • 401(k) retirement plan
  • Paid time off
  • Paid parental leave
  • Life and disability insurance
  • Flexible spending accounts
  • Commuter benefits
  • Tuition reimbursement