Cybersecurity Cloud Subject Matter Expert; Sme
Listed on 2026-07-15
-
IT/Tech
Cybersecurity, Cloud Computing: Infrastructure & Operations, Systems Engineer, IT Consultant
CYBERSECURITY CLOUD SUBJECT MATTER EXPERT (SME)
- Full-time
Founded in 2017 and headquartered in Manassas, Virginia, Toomey Technologies is a SBA certified HUBZone, and Woman Owned Small Business experienced in Program Management and Solution Implementation support services. Our diverse and talented personnel provide structure to develop and execute strategies to maximize mission success and have an established track record supporting critical initiatives across a wide range of federal clients.
We develop and execute strategies to maximize mission success and apply in-depth industry knowledge, analytics and expertise to design the right solution. Once the strategy is in place, we help communicate the changes and promote adoption among stakeholders.
Serves as the primary cloud security architect responsible for ensuring that cloud-hosted IT systems, particularly the Electronic Contract Writing Module (ECWM) and related customer contracting systems, are architected, designed, and implemented with robust security controls that meet or exceed agency requirements. The SME provides comprehensive security oversight throughout the system lifecycle, from initial design through deployment and ongoing operations, with particular emphasis on cloud environments including Oracle Cloud Infrastructure (OCI), Amazon Web Services (AWS), and Microsoft Azure.
The position requires deep expertise in DoD cybersecurity frameworks, FedRAMP compliance, Risk Management Framework (RMF), and the unique security challenges inherent in cloud-based Government systems handling sensitive contracting and procurement data.
- Active Security Clearance
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related technical field
- Advanced cloud security certifications (CCSP, CISSP, SABSA, or equivalent) CISSP, CISM, or other advanced cybersecurity certification
- Experience with DoD Enterprise Dev Sec Ops Reference Design
- Knowledge of containerization security (Docker, Kubernetes) and micro services security architecture
- Cloud ATO
Experience:
Two (2) years of hands‑on experience achieving Authorization to Operate (ATO) in cloud environments (OCI, AWS, Azure, or equivalent platforms) with demonstrated success in navigating complex compliance requirements - DoD Systems ATO
Experience:
Five (5) years of experience achieving ATOs for compartmented DoD IT systems with deep understanding of DoD‑specific security requirements, assessment processes, and stakeholder coordination - Cloud Certification: Current cloud security certification from major cloud providers (Oracle Cloud Infrastructure, AWS, Azure, or equivalent) demonstrating technical proficiency and up‑to‑date knowledge of cloud security capabilities
- DoD Approved 8140/8570 Baseline Certification:
- FedRAMP Expertise: Extensive knowledge of FedRAMP assessment methodology including practical experience with FedRAMP security control requirements, assessment procedures, and authorization processes
- OCI
Experience:
Demonstrated experience working with Oracle Cloud Infrastructure (OCI) including security architecture, implementation, and compliance activities - Enterprise DoD IT
Experience:
Proven experience working with enterprise DoD IT systems, understanding of DoD architecture standards, and familiarity with DoD cybersecurity requirements and processes - Advanced expertise in cloud security architecture principles across multiple platforms (OCI, AWS, Azure, Google Cloud) with deep understanding of shared responsibility models, cloud‑native security services, and hybrid cloud security considerations
- Comprehensive knowledge of cloud security engineering best practices including identity and access management (IAM), network security, data encryption, key management, and secure application deployment patterns
- Proficiency in Infrastructure as Code (IaC) security, container security, serverless security, and cloud workload protection platforms with ability to implement security‑by‑design principles
- Expert‑level understanding of cloud security threats, attack vectors, and mitigation strategies including advanced persistent threats (APTs), insider threats, and cloud‑specific vulnerabilities
- Extensi…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).