Senior Cybersecurity Engineer / (SME) - Level III
Listed on 2026-08-21
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Senior Cybersecurity Engineer / (SME) Level III
Full-Time/Part-Time Full-Time
DescriptionThe Senior Cybersecurity Engineer / Subject Matter Expert (SME) — Level III serves as the principal cybersecurity engineering authority supporting the Department of Homeland Security (DHS) Intelligence Enterprise (DHS IE). This position provides strategic technical leadership for enterprise cybersecurity engineering initiatives, including cloud security architecture, Dev Sec Ops , Zero Trust Architecture (ZTA), Enterprise Audit (EA), Governance, Risk, and Compliance (GRC) platform administration, and emerging technology integration across classified and unclassified environments.
The Senior Cybersecurity Engineer is responsible for designing secure enterprise architectures, integrating cybersecurity throughout the software development lifecycle, advancing Zero Trust maturity, implementing enterprise audit capabilities, and administering enterprise GRC solutions. The position works closely with cybersecurity leadership, system owners, software developers, cloud engineers, Dev Sec Ops teams, Information System Security Officers (ISSOs), Information System Security Managers (ISSMs), Security Control Assessors (SCAs), and Government stakeholders to ensure DHS IE systems meet Federal, DHS, and Intelligence Community (IC) cybersecurity requirements.
The ideal candidate is a recognized technical leader with extensive experience in cloud security, Dev Sec Ops automation, Zero Trust implementation, enterprise security engineering, and emerging technologies such as Artificial Intelligence (AI) and Machine Learning (ML).
Key Responsibilities
- Serve as the senior cybersecurity engineering technical lead for DHS Intelligence Enterprise cybersecurity engineering initiatives.
- Develop and implement enterprise cybersecurity engineering strategies supporting classified, hybrid, and cloud environments.
- Integrate cybersecurity controls throughout the Dev Sec Ops software development lifecycle and Agile development processes.
- Develop, maintain, and automate security validation scripts, Infrastructure-as-Code (IaC) security controls, and continuous compliance processes.
- Design and maintain reusable secure reference architectures supporting enterprise applications and cloud-hosted systems.
- Configure, maintain, and optimize enterprise cybersecurity tools, including:
- ACAS / Nessus
- Sonar Qube
- Git Lab
- SCAP Compliance Checker
- Nmap
- Web Inspect
- Other enterprise security assessment tools
- Maintain current Security Technical Implementation Guides (STIGs), Security Content Automation Protocol (SCAP) benchmarks, Nessus plug-ins, and vulnerability signatures through scheduled updates.
- Lead Enterprise Audit (EA) engineering activities supporting Intelligence Community audit requirements, including implementation of ICS 500-27 audit standards.
- Develop, maintain, and enhance enterprise audit strategies, audit dashboards, and security monitoring capabilities.
- Collaborate with developers, system engineers, and cybersecurity teams to implement enterprise audit logging, audit handling procedures, and audit data-sharing agreements.
- Design secure cloud architectures supporting:
- Intelligence Community (IC) Cloud
- Commercial Cloud Enterprise (C2E)
- AWS Gov Cloud
- Hybrid cloud environments
- Multi-cloud architectures
- Lead implementation and continuous improvement of Zero Trust Architecture (ZTA) initiatives by:
- Developing Zero Trust Roadmaps
- Assessing organizational maturity
- Identifying capability gaps
- Defining implementation priorities
- Developing Zero Trust metrics and dashboards
- Configure, administer, and maintain the enterprise Governance, Risk, and Compliance (GRC) platform (RSA Archer or equivalent), including:
- Database administration
- Application configuration
- Patch installation
- System upgrades
- Workflow customization
- Security Control Catalog management
- User administration and training
- Configure and maintain security control libraries aligned with:
- NIST SP 800-53
- NIST RMF
- CNSSI 1253
- ICD 503
- DHS 4300C
- Intelligence Community overlays
- Evaluate emerging cybersecurity technologies, including Artificial Intelligence (AI), Machine Learning (ML), security automation, orchestration, and advanced…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).