Cybersecurity and Trusted Digital Infrastructure Specialist
Cybersecurity and Trusted Digital Infrastructure Specialist
Opportunity track: MENA-EE
Engagement: Contingent individual consultant; engagement may be direct or through an eligible U.S. consulting firm
Location: Remote — United States, with possible international travel
Primary promotion location: Arlington, Virginia 22201
Anticipated consulting fee: $150–$325 per hour, or a negotiated fixed price by work package
The opportunity
Axyde is building a senior expert bench for anticipated U.S. government-funded project-scoping assignments involving government, utility, telecommunications, cloud, data-center, smart-city, industrial, transportation, and other critical-infrastructure cybersecurity programs across the Middle East, North Africa, Europe, Eurasia, and adjacent markets.
The selected specialist will help Axyde determine whether proposed cybersecurity and trusted-digital-infrastructure initiatives address credible risks, have an appropriate governance and technical basis, reflect realistic institutional and workforce capacity, possess an implementable acquisition and operating pathway, and are ready for a feasibility study, technical-assistance assignment, pilot, or capacity-building program.
Assignments may begin with incomplete data and require rapid, independent, and defensible conclusions. Axyde welcomes specialists whose principal strength is governance, enterprise security, cloud security, telecommunications security, operational technology, critical-infrastructure protection, security operations, incident response, identity, zero trust, or supply-chain security. Applicants are not expected to be equally expert in every cybersecurity domain.
This is an authorized project-scoping and defensive advisory role. It does not include unauthorized system access, penetration testing, exploit development, credential collection, covert activity, or handling classified or otherwise restricted information unless separately authorized in writing and supported by all required controls.
Potential responsibilities
- Assess cybersecurity objectives, threat and risk context, organizational maturity, governance, institutional capacity, operating model, workforce, and implementation readiness.
- Evaluate enterprise, cloud, telecommunications, data-center, industrial-control-system, operational-technology, and critical-infrastructure security concepts at an appropriate project-scoping level.
- Review proposed identity and access management, privileged-access management, zero-trust, network segmentation, endpoint, email, data-protection, encryption, logging, monitoring, vulnerability-management, backup, and recovery capabilities.
- Evaluate security-operations-center, national or sectoral computer-security incident-response, threat-information-sharing, incident-response, digital-forensics, and cyber-exercise concepts without requesting live credentials, exploitable vulnerability details, or restricted operational data.
- Assess cyber resilience, business continuity, disaster recovery, ransomware preparedness, third-party risk, software and hardware supply-chain security, and trusted-vendor requirements.
- Evaluate security considerations for cloud migration, sovereign cloud, data centers, 5G and telecommunications, smart cities, utilities, power systems, transportation, and other connected infrastructure.
- Review policies, authorities, institutional roles, procurement approaches, data governance, privacy, cross-border data, localization, regulatory, standards, and oversight considerations at a project-scoping level without providing legal advice.
- Assess alignment with relevant frameworks and standards, such as the NIST Cybersecurity Framework, NIST security controls, zero-trust guidance, ISO/IEC 27001, IEC 62443, or sector-specific requirements, as applicable.
- Evaluate training, certification, retention, organizational-change, public-awareness, and institutional-capacity requirements.
- Develop or independently review preliminary architecture, capability, staffing, licensing, lifecycle-cost, CAPEX, OPEX, schedule, procurement, implementation, and sustainment assumptions.
- Develop or review technical tasks, required qualifications, deliverables, schedules, and budgets for feasibility studies, technical assistance, pilots, maturity assessments, architecture studies, institutional-development programs, and workforce initiatives.
- Compare technical and implementation alternatives and identify material information gaps, decision criteria, risk mitigations, dependencies, and stage-gate recommendations.
- Assess potential participation by eligible U.S. cybersecurity, cloud, telecommunications, software, hardware, engineering, training, and advisory providers and relevant foreign-supplier risks.
- Participate in authorized, non-sensitive sponsor interviews, technical-diligence calls, and occasional site visits involving ministries, regulators, operators, utilities, security teams, project sponsors, financiers, and prospective U.S. suppliers.
- Contribute to concept consultations, initial assessments, project reports, presentations, sector deep dives, export estimates, implementation roadmaps, and monitoring indicators.
- Clearly distinguish source information, sponsor claims, high-level observations, professional judgments, assumptions, limitations, and matters requiring authorized validation by the system owner, regulator, security assessor, or other responsible authority.
Required qualifications
- At least 10 years of directly relevant cybersecurity, information-security, cloud-security, telecommunications-security, operational-technology, critical-infrastructure, security-governance, incident-response, or related experience.
- Demonstrated experience designing, operating, governing, evaluating, or independently reviewing enterprise, government, telecommunications, cloud, data-center, industrial, utility, or critical-infrastructure security programs.
- Experience translating technical, institutional, risk, procurement, and workforce findings into practical implementation plans, scopes of work, schedules, budgets, decision criteria, and risk-mitigation measures.
- Ability to communicate complex security issues to non-specialist decision-makers without exposing sensitive technical details or representing a high-level review as a formal security authorization or certification.
- Demonstrated discipline in handling confidential, security-sensitive, proprietary, and regulated information.
- Strong analytical writing, source evaluation, stakeholder-interview, and interdisciplinary collaboration skills, with the ability to work under compressed schedules.
- Contract-required status: The individual performing the work must be either a U.S. citizen or a lawful permanent resident of the United States (green-card holder). Other forms of U.S. work authorization do not satisfy the stated requirements of the anticipated contract. A consultant engaged directly as an individual must maintain a principal place of business in the United States. A consultant proposed through a firm must be employed or engaged through an entity that independently satisfies the solicitation’s U.S.-firm requirements. Meeting this requirement does not by itself establish eligibility to receive classified, controlled, export-controlled, law-enforcement-sensitive, or other restricted information; all assignment-specific access rules will apply.
Preferred qualifications
- CISSP, CISM, GIAC, CCSP, cloud-security, operational-technology, risk, privacy, audit, or another directly relevant professional credential.
- Experience with the NIST Cybersecurity Framework, NIST SP 800-53, zero-trust architecture, ISO/IEC 27001, IEC 62443, cloud-security frameworks, or comparable standards.
- Experience with operational technology, industrial control systems, utilities, telecommunications, 5G, cloud, data centers, transportation, smart cities, or other critical infrastructure.
- Experience designing or assessing security operations centers, incident-response programs, cyber workforce initiatives, national or sectoral strategies, trusted-vendor programs, or institutional-capacity programs.
- Experience preparing or independently reviewing feasibility-study, technical-assistance, pilot, maturity-assessment, architecture, procurement, or workforce-development scopes and budgets.
- Experience evaluating U.S.-supplied cybersecurity products, cloud services, telecommunications equipment, software, training, or advisory services for international projects.
- Regional experience in the Middle East, North Africa, Europe, the Western Balkans, Caucasus, Moldova, Central Asia, or adjacent markets.
Engagement conditions
This is a contingent consulting opportunity, not an offer of full-time employment. No award, assignment, minimum number of hours, or minimum compensation is guaranteed. Engagement depends on contract award, assignment fit, eligibility, conflicts, availability, required authorizations, successful completion of Axyde’s due diligence, and agreement on scope and pricing. The stated fee range is an anticipated range; the final rate or fixed price will depend on experience, role, work-package requirements, and applicable cost-reasonableness requirements.
Some assignments may require rapid analysis, interviews, irregular coordination across time zones, or international travel. Travel requirements, approvals, insurance, system and site access, information-security controls, and reimbursable costs will be addressed in the applicable consulting agreement or work order.
Participation in a U.S. Trade and Development Agency project-scoping assignment may make the participating consultant or subcontracting entity ineligible to compete—whether as a prime contractor, subcontractor, or otherwise—for certain USTDA-funded follow-on activities resulting from that assignment, unless USTDA grants a waiver. Axyde will disclose the applicable restriction and obtain written acceptance before issuing a work order.
Selected specialists may be asked for written permission to include their name, qualifications, and resume in a proposal. Applying does not by itself authorize Axyde to represent that an applicant has committed to a proposal or assignment.
Work performed under an awarded contract will be limited to authorized systems, information, and activities and will be subject to applicable confidentiality, data-rights, export-control, information-security, privacy, professional-responsibility, and conflict-of-interest requirements. Any proprietary assessment tools, software, datasets, methodologies, or background intellectual property should be identified before an assignment begins.
How to apply
Apply through Axyde’s online application form using the heading MENA-EE – Cybersecurity and Trusted Digital Infrastructure Specialist. Please provide:
- A resume or CV of no more than three pages.
- Two or three concise, non-sensitive project examples identifying your role, jurisdiction, sector or system type, program stage, principal governance or security questions, and the resulting work product or decision.
- Your principal cybersecurity, infrastructure-sector, standards-framework, institutional, and regional areas of expertise.
- Your U.S. location, travel availability, availability during the anticipated performance period, and proposed hourly rate or fixed-price basis.
- A self-attestation that you are either a U.S. citizen or a lawful permanent resident and, if you would contract directly as an individual, that your principal place of business is in the United States. Applicants proposing engagement through a firm should identify the firm and confirm that it meets the applicable solicitation definition of a U.S. firm.
- Any relevant professional certifications, current clearances or access authorizations, language capabilities, or authorized assessment experience. Do not provide certification passwords, clearance numbers, access credentials, protected personal information, or supporting identity documents with the initial application.
- Any known organizational conflicts, current client restrictions, vendor relationships, financial interests, active pursuits, or planned pursuits of potentially related USTDA-funded work.
Do not submit classified information, Controlled Unclassified Information, law-enforcement-sensitive information, passwords, credentials, cryptographic keys, exploit code, vulnerability details, network diagrams, system configurations, incident data, precise critical-facility locations, customer or personal data, export-controlled information, proprietary assessments, source-selection-sensitive information, clearance documentation, passport or green-card copies, or Social Security numbers. Public, authorized, and appropriately anonymized project descriptions are sufficient for the initial application. Axyde will request only the documentation and information needed at the appropriate stage of selection and engagement.
Axyde considers qualified applicants without regard to any status protected by applicable law. The citizenship or permanent-residence limitation above applies solely to work covered by the stated U.S. government contract requirements.
