Position Summary
The Cybersecurity Expert serves as the lead technical authority for information systems security engineering, automation, and architecture. This individual designs, implements, and operationalizes automated GRC frameworks, Compliance-as-Code (CaC), Policy-as-Code (PaC), and Infrastructure-as-Code (IaC) solutions aligned with Zero Trust and DoD Cybersecurity Risk Management Construct.
Key Responsibilities
The Cybersecurity Expert serves as the lead technical authority for information systems security engineering, automation, and architecture. This individual designs, implements, and operationalizes automated GRC frameworks, Compliance-as-Code (CaC), Policy-as-Code (PaC), and Infrastructure-as-Code (IaC) solutions aligned with Zero Trust and DoD Cybersecurity Risk Management Construct.
Key Responsibilities
- Serve as lead technical resource for designing, developing, implementing, and operationalizing the automated GRC framework (PWS Section 5.7).
- Design and implement a four-layer automation architecture:
- Infrastructure Provisioning Layer (secure IaC templates)
- Configuration Management Layer
- Compliance Validation Layer (PaC / CaC)
- Orchestration and Workflow Layer
- Translate complex regulatory requirements (RMF, NIST SP 800-53, DISA STIGs) and architectural diagrams into functional, automated, and operational code.
- Integrate and configure AWS-native security services (Audit Manager, Security Hub, Config, CloudTrail, CloudWatch) for continuous monitoring and automated evidence collection.
- Support development of real-time Compliance Scoring Dashboards and RESTful APIs.
- Participate in solution analysis and architectural reviews to ensure compliance with DoD regulations, Zero Trust principles, and DSCA policies.
- Provide technical guidance to ISSMs, ISSOs, and other stakeholders on the security posture and operational function of automated systems.
Required Qualifications
- Active SECRET clearance.
- Bachelor’s degree from an accredited institution in Information Technology, Computer Science, Engineering, or related technical discipline.
- Must possess one of the following certifications:
- AWS Certified DevOps Engineer – Professional or AWS Certified Solutions Architect – Professional
- AWS Certified Security – Specialty
- ISC² CISSP (preferably with ISSEP or ISSAP concentration)
- Twelve (12) years of demonstrated experience in systems engineering and cybersecurity, with at least seven (7) years focused on security automation, cloud engineering, and architecture.
- Five (5) years of experience serving as a lead technical authority on enterprise-level projects responsible for designing and implementing security solutions (not just assessing them).
- Five (5) years of experience translating complex regulatory requirements (RMF, NIST, DISA STIGs) and architectural diagrams into functional, automated, and operational code.
Flexible work from home options available.
About GBTI
GBTI Solutions, Inc.(GBTI) is revolutionizing how IT works, leveraging innovative and cutting edge technology to deliver time efficient, high-quality, and cost- effective business solutions to government, commercial, and non-profit clients across three continents. Since our founding in 2005, we have delivered customized solutions designed to meet each client's needs and requirements. Our innovative products, GEMS and ION each offer new insight on Human Resources and Physical Assets. GBTI works to truly understand these needs so that we can effectively solve their technical and business challenges while providing added value through a comprehensive solution approach. We deliver our solutions and products through four core practices centered upon Software Development, Data Management, Intelligent Transformation, and Research & Development (R&D): Currently, the GBTI Innovation Lab is working with leading edge technologies like Artificial Intelligence, Machine Learning, Rapid Acquisition and Blockchain for research and development.
Mission Statement
GBTI is revolutionizing how IT works, leveraging innovative and cutting edge technology to deliver time efficient, high- quality, and cost-effective business solutions.
To achieve this mission, GBTI has adopted the following core values:
Mission Statement
GBTI is revolutionizing how IT works, leveraging innovative and cutting edge technology to deliver time efficient, high- quality, and cost-effective business solutions.
To achieve this mission, GBTI has adopted the following core values:
- Quality – Everything we do must meet high and measurable quality standards and applicable requirements.
- Responsiveness – We must listen to our clients and respond quickly to their specific and changing needs. We must respond to problems very quickly and provide timely solutions.
- Care – We must care about our clients. We must care about our people. We must care about each other. We must care about the company that carries our people's dreams.
- Growth – We must help our clients, our people and our company to continually grow in value and capability.
- Fun – We must create a working environment such that clients have fun to work with us and our people have fun to work with each other.
- Improvement – We must monitor, measure, analyze, and evaluation our operations and performance continuously to achieve continual improvement of our operations and performance
As any company, GBTI often faces challenging situations and must make critical decisions. This set of core values are our guiding principles in making tough choices. This set of core values are also the foundation for our business strategy, our recruitment process, our solution methods, our management approaches, and our relationships with our clients and with our people.
(if you already have a resume on Indeed)
