M9 Solutions

Senior Cybersecurity SME/SCA

M9 Solutions$180K — $190K *
Aerospace & Defense
11 - 15 years of experience
Job Overview by Ladders

Qualifications

  • Active Top Secret security clearance
  • Bachelor's degree in Information Technology, Computer Science, or related field
  • 12+ years in IT and cybersecurity engineering
  • Experience with SAP and SCI Systems, including PIT and Cloud environments
  • DoD 8140.01 / 8570.01-M certification (IAT Level III or IAM Level III)
  • Ability to translate technical vulnerabilities into operational risk statements
  • Expertise in cloud security and containerized applications

Responsibilities

  • Participate in System Requirements, Preliminary Design, and Critical Design Reviews to ensure integrated security
  • Guide teams in implementing automated security testing in Agile pipelines
  • Conduct system-level threat modeling to identify attack vectors
  • Review vulnerability scans and correlate findings to operational risk
  • Master RMF policies and assist in translating compliance shortfalls into risk decisions
  • Drive Zero Trust implementation across client portfolios
  • Act as liaison between technical SMEs and the client Portfolio, translating directives and challenges

Benefits

  • Comprehensive health insurance options
  • 401(k) retirement plan with employer match
  • Paid time off and flexible working schedules
  • Professional development and training opportunities
  • Collaborative and supportive work environment
Full Job Description
M9 Solutions is seeking a Senior Cybersecurity SME/SCA to work onsite in support of a government contract for a client located in Chantilly, VA. An active Top Secret clearance is required.

Responsibilities
  • Strategic Advisement & Lifecycle Integration:
    • Engineering Technical Reviews: Actively participate in System Requirements Reviews (SRR), Preliminary Design Reviews (PDR), and Critical Design Reviews (CDR) to ensure security is baked in, rather than bolted on.
    • DevSecOps Alignment: Guide project teams in integrating automated security testing (SAST/DAST) and continuous compliance monitoring into Agile development pipelines where appropriate.
    • Threat Modeling: Conduct system-level threat modeling during the design phase to identify potential attack vectors and recommend architectural mitigations before code is written or hardware is procured.
  • Advanced Assessment & Risk Determination:
    • Technical Validation: Move beyond paperwork by conducting deep technical reviews of vulnerability scans (e.g., ACAS/Nessus), STIG checklists, and penetration testing reports. Correlate technical findings to actual operational risk.
    • RMF Execution: Demonstrate mastery of RMF policies (NIST SP 800-53 Rev 5, CNSSI 1253, DoD 8510.01, ICD 503). Assist the government Authorizing Official (AO) by translating complex technical compliance shortfalls into actionable, mission-contextualized risk decisions.
    • Diverse Architectures: Evaluate the security performance, integrity, and residual risk of varied environments, including Platform Information Technology (PIT), hardware/software systems, communication networks, and satellite control systems, etc.
  • Zero Trust & Next-Generation Architecture:
    • Zero Trust Implementation: Drive the adoption of Zero Trust architectural pillars (User, Device, Network, Application/Workload, Data, Visibility/Analytics, and Automation/Orchestration) across all client portfolios.
    • Cross Domain Solutions (CDS): Provide specialized expertise in designing, evaluating, and implementing CDS technologies. This includes complex enterprise deployments in classified compartmentalized environments and "point-to-point" solutions for isolated, tactical IT architectures.
    • Emerging Technology Evaluation: Continuously monitor state-of-the-art technologies (e.g., AI/ML, edge computing, quantum-resistant cryptography) and the evolving threat landscape to ensure client systems anticipate and mitigate next-generation threats.
  • Stakeholder Engagement & Liaison:
    • Technical Translation: Facilitate seamless communication with the client Portfolio technical SMEs, effectively translating AO directives to engineers and engineering challenges to the AO.
    • Community Representation: Serve as a key liaison between the Defense Industrial Base (DIB), government cybersecurity entities, security assessment organizations, and Special Access Program (SAP) IT working groups to maintain alignment with the broader defense innovation ecosystem.

Required Skills and Qualifications
  • Active Top Secret security clearance.
  • Bachelor's degree in Information Technology, Computer Science, or related field (or equivalent experience).
  • Minimum of twelve (12) years of demonstrated experience in IT, cybersecurity engineering, and Assessment & Authorization (A&A), with increasing responsibility.
  • Significant and proven multi-domain experience with SAP and SCI Systems, to include PIT, Cloud environments, Cross Domain Solutions.
  • Active baseline certification equivalent to DoD 8140.01 / 8570.01-M Information Assurance Workforce Improvement Program (IA WIP) for IAT Level III or IAM Level III (e.g., CISSP, CISM, GSLC, CASP+ CE).
  • Aptitude for aligning cyber risk management with real-world mission outcomes, proactively tailoring security assessments to enable and protect the mission rather than imposing dogmatic compliance hurdles.
  • Ability to translate complex technical vulnerabilities into clear, operational risk statements (Mission Impact) for executive leadership and the AO.
  • Deep understanding of system architectures, data flows, port/protocol matrix analysis, and network boundary defense concepts.
  • Proficiency in analyzing outputs from technical tools such as ACAS, SCAP, STIG Viewer, Splunk/SIEMs, and cloud security posture management (CSPM) tools.
  • Expertise in securing and assessing Cloud environments (AWS, Azure IL5/IL6) and containerized applications (Kubernetes, Docker).
  • Understanding of MASS, Xacta, or similar A&A workflow tools within classified and unclassified environments.

Preferred Skills and Qualifications
  • Direct experience working within the defense innovation ecosystem, specifically with rapid prototyping, test environments, and Platform IT (PIT) systems.
  • Proven hands-on technical experience working as a systems integrator or cybersecurity engineer, specifically with enterprise networks, cloud computing systems, and/or all-domain platform IT architectures.

GH 1024

Full-Time Employee Compensation
  • M9 Solutions' pay range for this position is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include, but are not limited to, responsibilities of the position, education, experience, knowledge, skills, abilities, as well as internal equity, location, alignment with market data, applicable bargaining agreement (if any), or other law.
  • M9 Benefits - https://m9solutions.com/why-join-m9/#our-benefits


Salary Range

$180,000-$190,000 USD

About M9 Solutions

M9 Solutions is an IT consulting and staffing firm that provides services to clients in a variety of industries, including healthcare, finance, and government. The company offers a range of services, including project management, software development, and data analytics. M9 Solutions was founded in 2010 and is headquartered in Durham, North Carolina.
Learn more about M9 Solutions
Size
50 employees
Industry

Similar Jobs

More Jobs at M9 Solutions

More Aerospace & Defense Jobs

Find similar Senior Cybersecurity SME/SCA jobs: