
Senior Cybersecurity Subject Matter Expert
Posted Aug 21

Posted Aug 21
This is a fully remote position, open to applicants in Florida.
• Develop and implement sophisticated cybersecurity assessment and testing protocols.
• Design and carry out controlled adversary simulations aligned with MITRE ATT&CK across targeted cyber kill chain phases.
• Create behavioral anomalies and assess client monitoring detection, correlation, analysis, and escalation within established thresholds.
• Perform access control stress testing, including password spraying, Kerberoasting, legacy authentication bypass, privilege escalation path validation, and session/elevation expiry verification.
• Query and evaluate client SIEM content against observed telemetry, alerts, and analyst actions.
• Classify non-detections by their root causes and document supporting evidence with synchronized timestamps.
• Independently verify agency remediation claims, including re-executing original testing stimuli when necessary.
• Produce factual, timestamped findings for audit documentation.
• Mentor Technical Testers and review evidence packages for completeness, accuracy, and adequacy.
• One position will act as Purple Team and Detection Lead, responsible for the technique catalog and detection gap methodology alongside the Technical Lead.
• Collaborate technically with government stakeholders and cybersecurity teams across various testing environments and simultaneous engagements.
• Candidates must reside in Florida.
• Over 8 years of experience in cybersecurity assessment, penetration testing, cyber defense operations, or security architecture.
• Proven hands-on adversary emulation or purple team experience in enterprise settings.
• Demonstrated experience in validating detection and response capabilities, rather than merely confirming control configurations.
• Experience in generating technical findings that have successfully passed external audits, regulatory reviews, or client quality evaluations.
• Two certifications are mandatory upon hire: CISSP or CISA, and at least one of OSCP, CRTO, GPEN, GCIA, GCIH, GCDA, or GCPN.
• In-depth knowledge of adversary simulation, kill chain testing, behavioral anomaly generation, and MITRE ATT&CK-aligned detection validation.
• Hands-on experience querying at least one major SIEM platform: Splunk SPL, Microsoft Sentinel KQL, or Elastic.
• Experience in assessing detection content coverage and log source completeness.
• Strong technical expertise in SIEM platforms, endpoint detection and response systems, network monitoring tools, and cloud-native security controls.
• Advanced understanding of Active Directory, Kerberos, Group Policy Objects, identity governance, privilege management, and Active Directory Certificate Services misconfiguration classes.
• Experience in conducting penetration testing, vulnerability assessments, web application reviews, API testing, and cloud security assessments.
• Proficiency in Microsoft Azure, Microsoft 365, AWS, and hybrid enterprise environments.
• Ability to assess compliance with NIST CSF and state cybersecurity regulations, including Rule 60GG-2, F.A.C.
• Experience in analyzing remediation strategies and independently validating corrective actions.
• Capability to develop detailed root cause analyses and evidence-based recommendations.
• Experience in performing forensic log reviews, incident reconstruction, and security event analysis.
• Disciplined evidence handling, including synchronized timestamping, reproducible procedures, and a defensible chain of custody.
• Preferred: experience testing in multi-tenant or federated government environments.
• Preferred: experience in detection content authoring within Splunk, Microsoft Sentinel, or Elastic.
• Preferred: prior involvement in supporting government cybersecurity initiatives or independent assessment functions.
• Must be legally authorized to work in the United States without requiring current or future employer sponsorship.
• Remote position available for candidates based in Florida.
• W-2 employment status.
• Opportunity to take ownership and engage directly with clients and leadership.
• Chance to contribute to impactful government missions.
Trail of Bits
Newxel
Wealthsimple
Xcelerate Solutions
Get handpicked remote jobs straight to your inbox weekly.