Cybersecurity Subject Matter Expert (SME)

TLDR

Provide authoritative guidance on cybersecurity practices, analyze emerging threats, and develop policies to ensure robust cybersecurity compliance across the organization.

The Corporate Cybersecurity Subject Matter Expert (SME) is responsible for providing authoritative knowledge and guidance concerning the organization’s cybersecurity posture and practices.  This role bridges technical expertise with strategic compliance and risk management, supporting both operational and governance objectives.


Key Responsibilities:

  • Serve as the authoritative expert on cybersecurity frameworks, attack vectors, and  enterprise defense strategies.
  • Analyze emerging threats, vulnerabilities, and advanced persistent threats (APT) to inform strategy.
  • Advise executive leadership and project teams on risk mitigation, regulatory compliance, and best practice security measures.
  • Develop, review, and enforce cybersecurity policies, standards, and operating procedures.
  • Conduct cybersecurity audits, assessments, and penetration testing to validate system integrity.
  • Collaborate with IT, Risk, Legal, and Business Units to ensure consistent cybersecurity application across all organizational processes.
  • Provide training, mentorship, and awareness programs to elevate overall corporate cybersecurity   literacy.
  • Maintain up-to-date knowledge of federal, state, and industry specific regulations affecting organizational cybersecurity requirements.
  • Participate in incident response activities, providing expertise to contain, mitigate, and assess cyber incidents.


Qualifications:


Education:

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or a related field.  Master’s degree preferred.


Experience:

  • Minimum 7-10 years of progressive experience in information security, cybersecurity consulting, or related domains.
  • Prior experience as a subject matter expert or senior cybersecurity specialist within corporate or government contexts.


Certifications (preferred):

  • CISSP (Certified Information Systems Security Professional)
  • CEH (Certified Ethical Hacker)
  • GIAC certifications (GSEC, GCIA, etc.)


Skills:

  • Deep knowledge of cybersecurity frameworks (NIST, ISO 27001, CIS Controls).
  • Expertise in threat intelligence, network security, cloud security, and application security.
  • Strong analytical, problem-solving, and communication skills.
  • Ability to convey complex cybersecurity concepts to non-technical stakeholders.
  • Familiarity with Pen testing, incident response, digital forensics, and security operations center (SOC) procedures.


Working Conditions:

  • Part Time: Remote
Report this job
Apply for this job