The consultant shall perform hands-on engineering, deliver strategic CISO advisory, and provide direct mentoring across the following core operational pillars:
CISO Strategic Advisory and Engineering
- Act as a direct technical advisor to the CISO, translating federal mandates, emerging AI threat models, and architectural gaps into actionable enterprise security directives.
- Execute a hands-on knowledge transfer model, co-engineering data pipelines and security automation alongside internal DET staff to institutionalize elite technical skills.
- Deliver real time training and co-develop automation playbooks within the security operations (SecOps) using live demonstration approach.
AI Capability Deployment & Toolchain Integration
- Operationalize Gemini Government and Google Codemender or equivalent directly inside active workflows, showing security analysts and application developers how to leverage generative AI to automate log parsing, threat hunting, and source-code remediation.
- Engineer automated data pipelines to feed the centralized enterprise platform (incorporating telemetry from Tenable.io, Google Mandiant ASM, Microsoft Azure Arc, Splunk, and Google SecOps) to maintain a single, authoritative pane of glass.
- Ensure all AI-assisted capabilities comply strictly with State privacy, data classification, and logging safeguards, preventing non-public vulnerability metrics from leaking into unvetted environments.
Project Timeline
Project Description / Target Schedule
1: SI-2 Baseline & Architecture Alignment
Mapping all automated data feeds (Tenable, Mandiant, Azure Arc) into the single authoritative platform, aligned to track Tier 1, 2, and 3 findings.
Day 30
2: Co-Engineered AI Playbooks
Delivery of production-ready LLM and Frontier Cyber model runbooks and prompt libraries, co-developed with internal staff via hands-on mentoring.
Day 45
3: Automated Exception & Escalation Engine
Implementation of automated workflow paths for time-bound exceptions, financial tiedowns, and high-risk executive escalation paths.
Day 60
4: DevSecOps Clean Deployment Framework
Standardization of approved repository templates and CI/CD security gate controls to enforce clean deployment preferences.
Day 75
5: Knowledge Transfer & Sustainment Hand-off
Final technical transition briefing, configuration documentation, and validation logs proving internal staff autonomy in sustaining the SI-2 operational baseline.
Day 90 365 (Ongoing)
Minimum Qualifications and Core Competencies
The designated expert must demonstrate a unique blend of strategic advisory presence and deep, practical engineering capability:
- Executive Advisory: Proven experience serving as a trusted technical advisor to CISOs, CIOs, or senior executive leaders within public sector or heavily federated enterprise environments.
- Teach-by-Doing Expertise: Documented success as a technical mentor, trainer, or engineering lead focused on pair-engineering and technical upskilling of infrastructure and security operations staff.
- Security Control Mastery (SI-2): Comprehensive expertise operationalizing security controls, including tiering models, compensating control validation, and time bound risk governance structures.
- Advanced Tooling Fluency: enterprise cyber stack Google Threat Intel or VirusTotal, Google SecOps, Mandiant ASM, Tenable.io, Microsoft Azure Arc, GitHub, GitHub Advanced Security, Ansible Tower, and Gemini/Anthropic AI security frameworks.
- Cloud Architecture & DevSecOps Engineering
Top Required Skills & Years of Experience:
Must be able to demonstrate prior experience doing the following in a large/complex environment:
- Proven experience serving as a trusted technical advisor to CISOs, CIOs, or senior executive leaders within public sector or heavily federated enterprise environments.
- Documented success as a technical mentor, trainer, or engineering lead focused on pair-engineering and technical upskilling of infrastructure and security operations staff.
- Comprehensive expertise in operationalizing security controls, including tiering models, compensating control validation, and time bound risk governance structures.
- Enterprise cyber stack Google Threat Intel or VirusTotal, Google SecOps, Mandiant ASM, Tenable.io, Microsoft Azure Arc, GitHub, GitHub Advanced Security, Ansible Tower, and Gemini/Anthropic AI security frameworks.
- Cloud Architecture & DevSecOps Engineering
Nice to have Skills:
- Federated/Government environment
- Tech Stack to include: Google, Microsoft, AWS, Splunk