Senior Cybersecurity SME/SCA
M9 Solutions · Chantilly, VA - Top Secret clearance required · United States · On-site
Pay: USD 180,000 – 190,000 a year
Posted Aug 25, 2026
Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.
M9 Solutions is dedicated to providing IT services and solutions to the Federal Government by mobilizing the right people, skills, clearance levels, and technologies to help organizations that desire improved performance and modern, sustainable change. M9 has provided quality IT services and support to more than 30 Federal Agencies and multiple commercial customers nationwide. Our capabilities include IT Talent Solutions, Data Delivery & Analytics, Cyber Security, Cloud Migration, Applications and Infrastructure, Software Development, and Finance & Accounting.
M9 Solutions is seeking a Senior Cybersecurity SME/SCA to work onsite in support of a government contract for a client located in Chantilly, VA . An active Top Secret clearance is required.
Responsibilities
Strategic Advisement & Lifecycle Integration:
Engineering Technical Reviews: Actively participate in System Requirements Reviews (SRR), Preliminary Design Reviews (PDR), and Critical Design Reviews (CDR) to ensure security is baked in, rather than bolted on.
DevSecOps Alignment: Guide project teams in integrating automated security testing (SAST/DAST) and continuous compliance monitoring into Agile development pipelines where appropriate.
Threat Modeling: Conduct system-level threat modeling during the design phase to identify potential attack vectors and recommend architectural mitigations before code is written or hardware is procured.
Advanced Assessment & Risk Determination:
Technical Validation: Move beyond paperwork by conducting deep technical reviews of vulnerability scans (e.g., ACAS/Nessus), STIG checklists, and penetration testing reports. Correlate technical findings to actual operational risk.
RMF Execution: Demonstrate mastery of RMF policies (NIST SP 800-53 Rev 5, CNSSI 1253, DoD 8510.01, ICD 503). Assist the government Authorizing Official (AO) by translating complex technical compliance shortfalls into actionable, mission-contextualized risk decisions.
Diverse Architectures: Evaluate the security performance, integrity, and residual risk of varied environments, including Platform Information Technology (PIT), hardware/software systems, communication networks, and satellite control systems, etc.
Zero Trust & Next-Generation Architecture:
Zero Trust Implementation: Drive the adoption of Zero Trust architectural pillars (User, Device, Network, Application/Workload, Data, Visibility/Analytics, and Automation/Orchestration) across all client portfolios.
Cross Domain Solutions (CDS): Provide specialized expertise in designing, evaluating, and implementing CDS technologies. This includes complex enterprise deployments in classified compartmentalized environments and “point-to-point” solutions for isolated, tactical IT architectures.
Emerging Technology Evaluation: Continuously monitor state-of-the-art technologies (e.g., AI/ML, edge computing, quantum-resistant cryptography) and the evolving threat landscape to ensure client systems anticipate…