Remote Position11.03.26
AI SCORE 8.5

Contract Subject Matter Expert (SME) – Secure Software Assessor - Remote

$120K–$150K/year

About the Role

We are seeking a Contract Subject Matter Expert (SME) – Secure Software Assessor - Remote to join our dynamic team. In this role, you will leverage your expertise in secure software assessment to validate and enhance our cybersecurity protocols. As a remote SME, you will play a crucial role in ensuring that our software meets the highest security standards, contributing to the overall integrity of our systems.

What You'll Do

  • Conduct thorough assessments of software applications using Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) methodologies.
  • Perform secure code reviews and software composition analysis (SCA) to identify vulnerabilities and recommend remediation strategies.
  • Collaborate with cross-functional teams to integrate security practices into the software development lifecycle (SDLC).
  • Provide guidance on DevSecOps practices and OWASP standards to enhance our security posture.
  • Engage in risk assessment and management activities, ensuring compliance with NIST RMF and other regulatory frameworks.
  • Contribute to educational technology initiatives and workforce development in cybersecurity.
  • Participate in research and development projects related to AI and data labeling in the context of software security.
  • Mentor junior team members and share best practices in secure coding and white-box testing.

Requirements

  • Minimum of 5 years of experience in cybersecurity, specifically in secure software assessment.
  • Proven expertise in SAST, DAST, secure code review, and SCA.
  • Strong understanding of the software development lifecycle (SDLC) and DevSecOps methodologies.
  • Familiarity with OWASP guidelines and risk management frameworks such as NIST RMF.
  • Relevant certifications (CISSP, GCSA) are highly desirable.
  • Excellent communication skills and ability to work collaboratively in a remote environment.
  • Experience in educational technology and STEM fields is a plus.

Nice to Have

  • Experience with cloud platforms such as AWS and tools like OpenTofu and Terraform.
  • Knowledge of Kubernetes and infrastructure defense strategies.
  • Background in AI and data projects related to cybersecurity.

What We Offer

  • Flexible work arrangement to support work-life balance.
  • Opportunity to contribute to assessment validation and cybersecurity initiatives.
  • Engagement with peers in the cybersecurity field, fostering a collaborative environment.
  • Competitive salary and potential for professional growth.
  • Access to resources for continuous learning and development.
Why This Job8.5 of 10

This Contract Subject Matter Expert role offers a unique opportunity to work remotely in the cybersecurity field, focusing on secure software assessment. With a competitive salary and flexible work arrangements, it's an attractive position for experienced professionals.

Salary Range
Required
0/1
Optional
0/1
Bonus
0/1

Who Will Succeed Here

Deep expertise in SAST and DAST tools such as Fortify, SonarQube, and OWASP ZAP, with hands-on experience conducting secure code reviews and software composition analysis to identify vulnerabilities.

Strong self-motivation and discipline to thrive in a remote work environment, with proven experience in collaborating with cross-functional teams using tools like Jira and Slack to drive security initiatives.

Extensive understanding of compliance frameworks like NIST RMF and experience implementing DevSecOps practices within AWS environments using Terraform to automate security assessments.

Learning Resources

OWASP Secure Coding Practicesguide

Career Path

Contract Subject Matter Expert (SME) – Secure Software Assessor(Now)Lead Secure Software Architect(1-2 years)Director of Security Engineering(3-5 years)

Market Overview

Market Size 2024
$5.2B
Annual Growth
14.3%
AI Adoption
45%
Investment
+30%
Labour Demand
+25%
Avg Salary
$140K

Skills & Requirements

Required
SASTDASTSecure Code Review
Growing in Demand
Cloud SecurityContainer SecurityThreat Modeling
Declining
Static Analysis Tools (Legacy)Manual Code Review

Domain Trends

Shift to DevSecOps
Organizations are increasingly integrating security into their DevOps processes, with 70% of companies adopting DevSecOps practices by 2025.
Rise of Automated Security Testing
The use of automated tools for SAST and DAST is projected to increase by 55% as companies seek to improve efficiency and reduce vulnerabilities.
Focus on Compliance and Risk Management
With regulations tightening, 60% of firms are prioritizing compliance frameworks like NIST RMF, driving demand for secure software assessors.

Industry News

Loading latest industry news...

Finding relevant articles from the last 6 months

All job postings are automatically gathered by algorithms. We do not review or verify listings, be careful when applying and do not sign-in with iCloud or Google services.