
Senior Cybersecurity Subject Matter Expert
Posted 3 days ago

Posted 3 days ago
This is a fully remote position, open to applicants in Florida.
• Develop and implement controlled adversary simulations aligned with MITRE ATT&CK across chosen stages of the kill chain.
• Create behavioral anomalies and assess client monitoring, correlation, analysis, and escalation processes.
• Perform access control stress testing, which encompasses password spraying, Kerberoasting, legacy authentication bypass, privilege escalation path validation, and session/elevation expiry verification.
• Query and evaluate client SIEM content in relation to observed telemetry, alerts, and analyst actions.
• Classify non-detections by their root causes and document supporting evidence with synchronized timestamps.
• Independently verify agency remediation claims, including the re-execution of initial testing stimuli.
• Generate factual, timestamped findings for audit workpapers.
• Provide mentorship to Technical Testers and review evidence packages.
• Take ownership of the technique catalog and detection gap methodology as the Purple Team and Detection Lead for one position.
• Extensive knowledge in adversary simulation, kill chain testing, behavioral anomaly generation, and MITRE ATT&CK-aligned detection validation.
• Proficient in querying at least one major SIEM platform: Splunk SPL, Microsoft Sentinel KQL, or Elastic.
• Experience in assessing detection content coverage and log source completeness.
• Strong technical understanding of SIEM, EDR, network monitoring tools, and cloud-native security controls.
• Advanced expertise in Active Directory, Kerberos, Group Policy Objects, identity governance, privilege management, and Active Directory Certificate Services misconfigurations.
• Background in penetration testing, vulnerability assessments, web application reviews, API testing, and cloud security assessments.
• Proficient across Microsoft Azure, Microsoft 365, AWS, and hybrid enterprise environments.
• Capability to assess NIST CSF and state cybersecurity requirements, including Rule 60GG-2, F.A.C.
• Experience in analyzing remediation plans and validating corrective actions.
• Ability to create root cause analyses and evidence-based recommendations.
• Familiarity with forensic log reviews, incident reconstruction, and security event analysis.
• Disciplined in evidence handling, synchronized timestamping, reproducible procedures, and maintaining a defensible chain of custody.
• Over 8 years of experience in cybersecurity assessment, penetration testing, cyber defense operations, or security architecture.
• Hands-on experience in adversary emulation or purple team roles within enterprise environments.
• Experience validating detection and response capabilities.
• Proven ability to produce technical findings that withstand external audits, regulatory scrutiny, or client quality reviews.
• Must reside in Florida.
• Must possess CISSP or CISA at the time of hire.
• Must hold at least one hands-on technical certification: OSCP, CRTO, GPEN, GCIA, GCIH, GCDA, or GCPN.
• Legally authorized to work in the United States without current or future employer sponsorship.
• Preferred: CEH, SC-200, GCFA, GXPN, AWS Security Specialty, or Azure Security Specialty.
• Preferred experience in testing multi-tenant or federated government environments, authoring detection content, and supporting government cybersecurity initiatives.
• Remote position available for candidates based in Florida.
• W-2 employment status.
• Opportunity to take ownership and collaborate directly with clients and leadership.
• Chance to contribute to significant government missions.
• Opportunity to tackle complex challenges alongside skilled teams.
• Potential to make a direct impact in a growing organization.
OCHIN, Inc.
Dynanet Corporation
Solutions for Information Design, Inc.
Fuze Health
Get handpicked remote jobs straight to your inbox weekly.