Senior Security Subject Matter Expert (AI/ML, Cloud & Security)

By Light Professional IT Services LLC · via Himalayas ·

TypeRemote job
LocationUnited States
Posted2 hours ago
Company Overview
By Light Professional IT Services LLC readies warfighters and federal agencies with technology and systems engineered to connect, protect, and prepare individuals and teams for whatever comes next. Headquartered in McLean, VA, By Light supports defense, civilian, and commercial IT customers worldwide.
Position Overview
Senior Security Subject Matter Expert (SME) to support secure cloud systems in Federal and DoD environments. This role is responsible for designing, implementing, and maintaining security controls across cloud infrastructure and cybersecurity operations systems, while supporting the secure development of AI/ML capabilities and compliance with industry and government standards.
The ideal candidate brings deep, hands-on cloud security and SOC engineering experience, a strong understanding of risk and compliance, and demonstrated ability to secure emerging technologies — including AI/ML systems, detection pipelines, and the products built on them.
Responsibilities

Design, implement, and maintain security controls across system development and operations.

Secure AWS-based cloud environments, including STIG/NIST-aligned architectures and least-privilege IAM policies; provide working knowledge of Azure and/or Google Cloud.

Perform system hardening, vulnerability scanning, monitoring, and incident response using tools such as Splunk, Security Onion, and Tenable.

Analyze logs, develop alerts and detection content, and support forensic investigations and threat hunting.

Support security architecture design and integration for new and existing systems, including infrastructure-as-code deployments (e.g., Terraform, GitLab CI/CD).

Partner with engineering teams to embed security requirements throughout the AI/ML and cybersecurity product development lifecycle, from design through deployment.

Perform security reviews of AI/ML models, pipelines, and training data prior to release, including adversarial risk, model integrity, data provenance, and anomaly-detection model validation (e.g., autoencoders, isolation forest).

Support secure-by-design practices for AI-enabled SOC tooling and cybersecurity products, including threat modeling, secure code review, least-privilege data access, audit logging, and human-approval gates for AI-assisted actions.

Provide support and oversight for systems, including:
Patching selection and updates

Training data security and integrity

Network monitoring, access controls, and monitoring

Review and approval of AI-related changes and updates

Support compliance activities aligned with CMMC Level 2, SOC 2, and ISO/IEC 27001.

Contribute to security documentation, risk assessments, and audit readiness efforts.

Required Experience/Qualifications

Bachelor's degree (or equivalent experience) plus 7+ years of relevant security experience, including SOC, incident response, or detection engineering

Hands-on experience securing on-premise/AWS environments, including STIG/NIST-aligned architectures

Experience with cloud security and enterprise security tools (e.g., Splunk, Security Onion, Tenable, or equivalent SIEM/vulnerability management platforms)

Proficiency in Python for automation, security tooling, or ML-driven analytics

Working knowledge of AI/ML system architectures and associated security risks (e.g., model integrity, data poisoning, adversarial inputs)

Preferred Experience/Qualifications

CISSP, CEH, C|CISO, or GIAC certifications (e.g., GIAC Cloud Penetration Tester)

Experience with infrastructure-as-code and CI/CD pipelines (e.g., Terraform, GitLab CI/CD)

Experience supporting Federal, DoD, or regulated environments, including CDM or similar federal vulnerability management programs

Hands-on experience with AI/ML anomaly detection or analytics frameworks (e.g., Splunk MLTK/DSDL, scikit-learn, TensorFlow, MLflow, embeddings/RAG, vector databases)

Experience contributing to AI/ML or cybersecurity product development, including secure design reviews or DevSecOps practices for ML pipelines

ITIL, GICSP, or equivalent operations/compliance certifications

Special Requirements/Security Clearance
Active Top Secret clearance (SCI/Poly preferred, depending on program requirements)

Originally posted on Himalayas
cloud-security ai-ml-security cybersecurity security-architecture soc-engineering senior-cloud-security-architect senior-cloud-security-analyst senior-threat-intelligence-subject-matter-expert senior-cloud-infrastructure-security-engineer senior-information-security-consultant senior-security-consultant principal-ai-security-architect cloud-security-engineer senior-cloud-security-software-engineer
Apply on Himalayas →

Job sourced from Himalayas. Applications happen directly on the original platform — we never collect your data.