First seen by Alion on Oct 1, 2026.
We are seeking a Senior Cybersecurity Specialist with strong hands-on experience in implementing, operating, and maturing security controls across enterprise environments. The role requires deep execution capability across asset management, access control, secure development, endpoint security, security testing, AI governance, supplier risk, employee awareness, monitoring and detection, and incident response, with proven expertise in PII / HSPII protection and PCI-DSS compliance. This position plays a critical role in translating security policies, standards, and frameworks into operational, measurable, and enforceable controls.
Responsibilities:
- Asset and Access Management:
- Secure Development and DevSecOps.
- Endpoint Security.
- Security Testing and Assurance.
- AI Governance and Emerging Technology Risk.
- Supplier and Third-Party Risk Management.
- Employee Security Awareness.
Execution-driven and outcome-focused:
- Strong stakeholder collaboration.
- Risk-based decision-making.
- Clear documentation and evidence management.
- High ownership during incidents and audits.
Asset and Access Management:
- Implement and maintain asset inventory controls.
- Execute IAM controls, including RBAC, least privilege, MFA, and access reviews.
Secure Development and DevSecOps:
- Implement secure SDLC controls and integrate security tooling into CI/CD pipelines.
- Work with engineering teams to remediate vulnerabilities.
Endpoint Security:
- Deploy and manage EDR/XDR solutions.
- Enforce device hardening, encryption, and patching.
Security Testing and Assurance:
- Execute vulnerability management and penetration testing activities.
- Track remediation and maintain audit evidence.
AI Governance:
- Implement AI governance and model risk controls.
- Ensure sensitive data protection in AI workflows.
Supplier Risk Management:
- Conduct supplier security assessments and track remediation.
Employee Security Awareness:
- Support execution of awareness and phishing simulation programs.
Monitoring and Detection:
- Implement monitoring controls and tune SIEM alerts.
Incident Response:
- Participate in incident handling, drills, and post-incident reviews.
Data Protection and Compliance:
- Implement PII/HSPII controls.
- Execute PCI-DSS technical and operational requirements.
Requirements:
- Bachelor's degree in computer science or equivalent.
- 8+ years of experience in cybersecurity or information security roles.
- Proven track record of control implementation, execution, and operationalization.
- Experience working with engineering, IT, SOC, risk, and compliance teams.
- Relevant certifications (preferred): CISSP, CISM, or CISA, AZ-500 / AWS Security Specialty, CEH / Security+ / GIAC (role dependent).
- 8+ years of cybersecurity experience.
- Strong control implementation background.
- Relevant certifications (CISSP, CISM, CISA preferred).

