Senior Cybersecurity Subject Matter Expert
Tallahassee, FL - USA
Job Summary
Location: Florida Remote
Tallahassee metro preferred within 50 miles
Candidates must reside in Florida
Compensation: $120000$150000
Employment Type: Full Time W-2
Positions: 2 FTEs
Start: Contingent upon contract award
At Emerging Tech we support government and public sector customers through technology cybersecurity and mission driven solutions. As a growing SDVOSB 8(a) and HUBZone company we provide our team with the opportunity to take ownership work directly with clients and leadership and contribute to meaningful government missions.
Were big enough to take on meaningful government work but still small enough that your expertise and ideas have a direct impact. If you enjoy solving complex problems working with talented teams and having a real role in building something thats growing youll fit right in at Emerging Tech.
The Senior Cybersecurity Subject Matter Expert will provide expert level technical execution and depth across cybersecurity assessment and testing activities.
This role will develop and execute advanced testing procedures conduct controlled adversary simulations across selected stages of the cyber kill chain validate cybersecurity controls independently evaluate agency remediation efforts and determine and document the root cause of detection outcomes.
One of the two positions will be designated as the Purple Team and Detection Lead responsible for owning the technique catalog and detection gap methodology in partnership with the Technical Lead.
Design and execute controlled adversary simulations mapped to MITRE ATT&CK across selected kill chain stages.
Generate behavioral anomalies and validate whether client monitoring detects correlates analyzes and escalates activity within defined thresholds.
Conduct access control stress testing including password spray against lockout policies Kerberoasting legacy authentication bypass privilege escalation path validation and session and elevation expiry verification.
Query and analyze client SIEM content to reconcile emitted activity against observed telemetry alerts and analyst actions.
Classify non detections by root cause and document supporting evidence with synchronized timestamps.
Independently validate agency remediation claims including re execution of original testing stimuli when remediation concerns detection capabilities.
Produce factual timestamped findings suitable for inclusion in audit workpapers.
Mentor Technical Testers and review evidence packages for completeness accuracy and sufficiency.
Deep expertise in adversary simulation kill chain testing behavioral anomaly generation and detection validation aligned with MITRE ATT&CK.
Hands on proficiency querying at least one major SIEM platform including Splunk SPL Microsoft Sentinel KQL or Elastic.
Experience assessing detection content coverage and log source completeness.
Strong technical knowledge of SIEM platforms endpoint detection and response systems network monitoring tools and cloud native security controls.
Expertise assessing logging alerting escalation and monitoring effectiveness from initial sensor activity through analyst action.
Advanced knowledge of Active Directory Kerberos Group Policy Objects identity governance and privilege management including Active Directory Certificate Services misconfiguration classes.
Experience conducting penetration testing vulnerability assessments web application reviews API testing and cloud security assessments.
Proficiency across Microsoft Azure Microsoft 365 AWS and hybrid enterprise environments.
Ability to evaluate compliance with NIST CSF and state cybersecurity requirements including Rule 60GG-2 F.A.C.
Experience analyzing remediation plans and independently validating corrective actions.
Ability to develop detailed root cause analyses and evidence based recommendations.
Experience performing forensic log reviews incident reconstruction and security event analysis.
Disciplined evidence handling including synchronized timestamping reproducible procedures and defensible chain of custody.
8 years of experience in cybersecurity assessment penetration testing cyber defense operations or security architecture.
Demonstrated hands on adversary emulation or purple team experience in enterprise environments.
Proven experience validating detection and response capabilities not solely verifying control configuration.
Experience producing technical findings that have withstood external audit regulatory or client quality review.
Must reside in the state of Florida.
Required:
Two certifications are mandatory at hire and are a condition of assignment.
One of the following:
CISSP
CISA
And at least one of the following hands on technical certifications:
OSCP
CRTO
GPEN
GCIA
GCIH
GCDA
GCPN
Preferred:
CEH
SC-200
GCFA
GXPN
AWS Security Specialty
Azure Security Specialty
Experience testing in multi tenant or federated government environments.
Detection content authoring experience in Splunk Microsoft Sentinel or Elastic.
Prior experience supporting government cybersecurity programs or independent assessment functions.
This is a remote position for Florida based candidates. The Tallahassee metro area within approximately 50 miles is preferred.
The role requires significant technical coordination with government stakeholders and cybersecurity teams across multiple testing environments and concurrent engagements.
Required Experience:
Manager
About Company
Alachua, FL-based SDVOSB delivering cybersecurity, cloud, healthcare IT modernization, and enterprise integration to federal and defense agencies. CMMI Level 3 | 10+ years.