Secure Configuration Management (SCM) Subject-Matter Expert / Technical Lead

Posted 21 Days Ago
Be an Early Applicant
Bethesda, MD
In-Office
Senior level
Security • Cybersecurity
The Role
Lead enterprise-level efforts in secure configuration management, ensuring compliance with federal standards, while developing and implementing security baselines.
Summary Generated by Built In



Position Title: Secure Configuration Management (SCM) Subject-Matter Expert / Technical Lead

Location: Bethesda, MD | Hybrid- Not Remote

Cybervance is a rapidly growing information security and information technology company based in Washington, D.C., and we are an equal opportunity employer. We design, develop, and manage the successful execution of training programs for government and private sector organizations. Cybervance believes in creating innovative solutions to deliver measured results.

We are seeking a highly experienced Secure Configuration Management (SCM) Subject-Matter Expert (SME) / Technical Lead to lead enterprise-wide efforts in secure baseline development, configuration compliance, and system hardening. The SME will serve as the primary technical authority for defining, implementing, and validating secure configurations across multiple platforms and services in accordance with federal cybersecurity standards, policies, and directives.

The ideal candidate will possess advanced knowledge of configuration management frameworks such as CIS Benchmarks, NIST SP 800-53 Rev. 5, NIST Baseline Checklist Repository, and CISA BOD 25-01 SCuBA Secure Configuration Baselines, along with hands-on experience implementing and maintaining secure configurations across diverse environments.

Responsibilities

  • Lead the design, development, and implementation of secure configuration baselines for enterprise systems, applications, and cloud environments in accordance with federal standards and agency requirements.
  • Assess foundational standards, regulations, and compulsory directives to develop agency-specific configuration baselines and implementation resources (e.g., GPOs, BigFix fixlets, scripts).
  • Develop, maintain, and enforce secure baselines for:
    • Multiple operating systems (Windows, Linux, macOS)
    • Enterprise services and applications (Microsoft 365, AWS, Azure, GCP)
    • Web browsers, databases, and other infrastructure components.
  • Manage enterprise Group Policy Objects (GPOs) and Mobile Device Management (MDM) configurations using tools such as Jamf, BigFix, and Intune.
  • Implement and automate configuration management and deviation tracking using enterprise solutions and scripts.
  • Perform baseline compliance validation using enterprise scanning tools such as Tenable.SC, Nessus, and SCAP.
  • Develop and maintain technical control sets and compliance scanning policies to ensure alignment with configuration baselines.
  • Author technical documentation, including configuration standards, SOPs, workflows, risk assessments, and executive summaries.
  • Facilitate collaborative working groups and configuration management forums, engaging stakeholders across cybersecurity, IT operations, and program offices.
  • Serve as the technical lead and subject-matter expert, guiding teams and stakeholders in implementing secure configuration standards and ensuring enterprise-wide consistency.
  • Conduct risk assessments and provide technical justifications to support risk-based decisions and configuration exceptions.
  • Continuously monitor evolving configuration guidance, frameworks, and federal directives to maintain up-to-date and compliant secure baselines.

Experience

  • Proven experience developing and maintaining secure configuration baselines across diverse operating systems and enterprise services.
  • Advanced knowledge of CIS Benchmarks, NIST SP 800-53 Rev. 5, NIST Baseline Checklist Repository, and CISA BOD 25-01 SCuBA Secure Configuration Baselines.
  • Hands-on experience developing and implementing GPOs, MDM configurations, and automation scripts to enforce security baselines.
  • Proficiency with enterprise configuration and compliance tools, such as Jamf, BigFix, Intune, Tenable.SC, Nessus, or SCAP.
  • Experience leading enterprise-level configuration compliance programs in large-scale or federal environments.
  • Demonstrated ability to collaboratively develop configuration standards that align with mission and business requirements.
  • Strong understanding of Windows, Linux, and macOS operating systems and associated hardening techniques.
  • Familiarity with cloud environments (AWS, Azure, GCP) and secure configuration of cloud services.
  • Expertise in baseline deviation tracking, compliance auditing, and configuration reporting.
  • Proven experience leading multidisciplinary collaboration forums and working groups with diverse technical and policy stakeholders.
  • Excellent written communication and professional technical writing skills, including business justifications, risk management documentation, and executive briefings.
  • Strong interpersonal and leadership skills to guide stakeholders in implementing consistent configuration management practices.

Required Skills & Qualifications

  • Bachelor’s degree in computer science, Information Technology, Cybersecurity, or a related field (preferred).
  • Current government security clearance: Public Trust.

Preferred Qualifications

  • Professional certifications such as CISSP, CISM, CISA, or CompTIA Security+.
  • Experience developing automation scripts (e.g., PowerShell, Python, or Bash) to support configuration management.
  • Familiarity with Zero Trust Architecture and integration of secure configuration standards into Zero Trust environments.
  • Experience supporting federal cybersecurity compliance programs or large hybrid enterprise environments.

Top Skills

AWS
Azure
Bash
Bigfix
Cis Benchmarks
Cisa Bod 25-01
GCP
Intune
JAMF
Nessus
Nist Baseline Checklist Repository
Nist Sp 800-53 Rev. 5
Powershell
Python
Scap
Tenable.Sc
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
Kensington, , Maryland
29 Employees
Year Founded: 2019

What We Do

Cybervance has a long history of supporting USG agencies in areas related to international capacity building programs. From foreign assistance capacity building to collaboration with partner nations, Cybervance services are comprehensive and turnkey. We provide initial assessments and planning, training across multiple cyber disciplines, equipment installations, operational support and mentoring. All of Cybervance’s services are supported by insightful reporting for program stakeholders needing to stay informed about key issues in plain English, not cyber-speak. Our logistics function handles everything needed for program success, including all equipment procurements, shipping, customs and duties processing, travel, and in-country event support.
Our services are tailored for international delivery. Our team is adept at making in-country, real-time adjustments to address regional and situational dynamics. We understand that cyber programming is part of a larger diplomatic mission, and we focus on achieving tangible programming results.
With an extensive background in law enforcement, our team brings specialized service delivery to cyber-related programs with a criminal or counterterrorism nexus.

Similar Jobs

ServiceNow Logo ServiceNow

Consultant

Artificial Intelligence • Cloud • HR Tech • Information Technology • Productivity • Software • Automation
Remote or Hybrid
Baltimore, MD, USA
27000 Employees
122K-213K Annually

PwC Logo PwC

Managed Services - Test Data Management (Delphix) Analyst - Senior Associate

Artificial Intelligence • Professional Services • Business Intelligence • Consulting • Cybersecurity • Generative AI
Hybrid
45 Locations
370000 Employees
77K-202K Annually

ZS Logo ZS

Consultant

Artificial Intelligence • Healthtech • Professional Services • Analytics • Consulting
Hybrid
4 Locations
13000 Employees

ZS Logo ZS

Manufacturing Supply Chain Technology Manager

Artificial Intelligence • Healthtech • Professional Services • Analytics • Consulting
Hybrid
6 Locations
13000 Employees

Similar Companies Hiring

Silverfort Thumbnail
Security • Sales • Information Technology • Cybersecurity • Automation
GB
507 Employees
Oso Thumbnail
Software • Security • Infrastructure as a Service (IaaS)
New York, New York
36 Employees
Credal.ai Thumbnail
Software • Security • Productivity • Machine Learning • Artificial Intelligence
Brooklyn, NY

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account