Haystack
← Back to Jobs
Employee
Administrative

Senior Security Risk Management SME with Security Clearance

Def-Logix, Inc.Washington, DC🇺🇸United StatesPosted 21 Jul 2026

Quick Overview

Work Type
On Site
Schedule
Employee
Level
Mid Senior

Job Description

Location: Washington, DC (On-site) We are seeking an experienced Senior Security Risk Management Subject Matter Expert (SME) to provide technical expertise in security risk management, Assessment and Authorization (A&A), Federal cybersecurity compliance, and continuous monitoring. The successful candidate will support cybersecurity risk management activities across secure cloud, hybrid, and cross-domain environments while ensuring compliance with applicable Federal and Intelligence Community (IC) cybersecurity requirements. The ideal candidate will possess extensive experience applying risk management principles, implementing security controls, and supporting evolving cybersecurity practices, including the automation of Assessment and Authorization (A&A) and continuous monitoring activities. Key Responsibilities
Provide subject matter expertise in security risk management and cybersecurity compliance activities.
Support Assessment and Authorization (A&A) efforts in accordance with Federal cybersecurity requirements.
Ensure compliance with the Federal Information Security Modernization Act (FISMA) and applicable Intelligence Community (IC) cybersecurity policies and standards.
Support continuous monitoring activities across enterprise environments.
Provide expertise in Cross Domain Solutions (CDS) security requirements.
Support secure cloud and hybrid engineering initiatives from a security risk management perspective.
Apply NIST Special Publication (SP) 800 Series guidance, CNSSI 1253 security controls, and Risk Management Framework (RMF) principles.
Support emerging cybersecurity risk management practices, including automation of A&A and continuous monitoring activities.
Collaborate with Government stakeholders to develop and implement effective security risk management strategies. Minimum Qualifications
Minimum 10 years of related cybersecurity and security risk management experience.
At least 2 years of recent experience in each of the following:
Assessment and Authorization (A&A)
Federal Information Security Modernization Act (FISMA) compliance
Intelligence Community (IC) cybersecurity policy and standards
Continuous monitoring
Cross Domain Solutions (CDS)
Secure cloud and hybrid engineering
Demonstrated experience with emerging security risk management practices, including automation of A&A and continuous monitoring.
Experience applying NIST SP 800 Series guidance, CNSSI 1253 security controls, and Risk Management Framework (RMF) principles. One of the following certifications, in good standing, or comparable demonstrable experience:
Certified Information Security Manager (CISM)
Certified Authorization Professional (CAP)
Governance, Risk, and Compliance (GRC) certification Preferred Qualifications
Certifications in one or more cloud platforms, including:
Amazon Web Services (AWS)
Microsoft Azure
Microsoft Office 365
Current or prior experience supporting the U.S. Department of Homeland Security (DHS).
Demonstrated experience working within DHS organizations or supporting DHS cybersecurity risk management initiatives is highly preferred.

Skills

Microsoft Office

Similar jobs