CYBERSECURITY SUBJECT MATTER EXPERT

Remote • Posted 6 hours ago • Updated 6 hours ago
Full Time
No Travel Required
Remote
$130,000 - $140,000/yr
Fitment

Dice Job Match Score™

🔢 Crunching numbers...

Job Details

Skills

  • Analytics
  • Backup
  • CISSP
  • CompTIA
  • Cyber Security
  • Decision-making
  • Documentation
  • Elasticsearch
  • End-user Training

Summary

Cybersecurity Subject Matter Expert

Splunk Platform Management Program | Senior Level (minimum eight years in role)

 

Position Summary

The Cybersecurity Subject Matter Expert is the cross-cutting threat expert who makes the program's four Splunk components operate as one security capability rather than four tools. This individual supplies the adversary knowledge the platform positions consume: aligning the detection library to MITRE ATT&CK, defining the attack scenarios behind the SOAR automation, validating behavioral analytics findings against real adversary behavior, and delivering the incident and trend insights that inform government decision-making. As a standing part of the role, the SME also performs hands-on investigation of notable events, UEBA findings, and security incidents in Splunk Enterprise and Enterprise Security, producing analyst-quality case notes, timelines, and recommended response actions. The position works in tandem with the program's Team Lead and serves as the designated backup for the ES Detection and UEBA positions.

 

Key Responsibilities

·      Align the ES detection library to the MITRE ATT&CK framework and maintain coverage mapping as the library grows.

·      Define the security attack scenarios and response decision logic that the SOAR Engineer converts into automated playbooks.

·      Validate UEBA anomaly investigations so model tuning is grounded in genuine adversary behavior rather than statistical noise.

·      Investigate notable events, UEBA findings, and security incidents; produce case notes, attack timelines, and recommended response actions; and deliver insights into incidents and trends that strengthen government decision-making.

·      Participate in recurring threat intelligence feed effectiveness reviews with the ES Detection Engineer.

·      Lead quarterly team training sessions and produce the supporting training materials.

·      Support the program's FedRAMP and NIST regulatory compliance evidence.

·      Contribute threat context and investigation outcomes to the weekly notable event trend report and the monthly program reports.

·      Conduct scoped threat hunts and analytic reviews in Splunk Enterprise and Enterprise Security as operational volume requires. Serve as the designated backup for the ES Detection Engineer and UEBA Analyst positions.

 

Demonstrated Hands-On Experience (Evaluation Emphasis)

The selected individual must demonstrate hands-on threat analysis, incident investigation, and detection content experience in a production security operations environment. The candidate shall clearly describe direct experience mapping adversary tactics, techniques, and procedures to MITRE ATT&CK; developing or directing detection and response content; investigating notable events and real security incidents using SIEM search and case documentation; and producing analytic conclusions that informed response, including the environments supported and the operational outcomes achieved. Experience limited primarily to governance, compliance documentation, policy development, or risk assessment support, without substantial operational threat analysis and investigation responsibilities, will be viewed as less competitive.

 

 

 

Required Qualifications

·      Minimum of eight years in cybersecurity, including substantial security operations, threat analysis, and hands-on incident investigation experience. Demonstrated hands-on experience is mandatory and may not be substituted.

·      Demonstrated application of the MITRE ATT&CK framework to detection engineering, incident investigation, and response planning.

·      Working familiarity with SIEM, SOAR, and behavioral analytics operations, preferably in the Splunk ecosystem, including SPL-based investigation of notable events and findings; and with FedRAMP and NIST SP 800-53 requirements.

·      Experience developing and delivering technical training to security teams.

·      Relevant industry certifications are preferred where practicable, such as CISSP, GIAC GCTI, GCIH, GCIA, GCFA, or CompTIA CySA+.

 

Clearance and Work Conditions

·      Place of performance: Remote work, based within United States.

·      Schedule: standard business hours, Monday through Friday, excluding Federal holidays.

·      Successfully complete a government background investigation

·       

Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 10229270
  • Position Id: 9106638
  • Posted 6 hours ago
Contact the job poster
CC

Colleen Crowder

Director of Human Resources @ ACI Solutions
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

Remote or Providence, Rhode Island

•

20d ago

Full-time

Remote or Washington, District of Columbia

•

Today

Full-time

USD 112,700.00 - 193,200.00 per year

Remote

•

Today

Full-time

Remote or Washington, District of Columbia

•

Today

Full-time

USD 134,600.00 - 230,800.00 per year

Search all similar jobs