Job descriptionJob Description
Cybersecurity AI Implementation for Accelerated Exposure Reduction
Time & Materials (One-Time Initiative) ~1,800 Hours over 12 Months
1. Purpose and Objective
The State of Wisconsin, Department of Administration (DOA), Division of Enterprise
Technology (DET), Bureau of Security (BOS) requires an expert senior technical leader
and engineer to serve as a strategic advisor to the CISO and drive the statewide
implementation of the Accelerated Exposure Reduction Plan.
This role balances high-level strategic advisory with hands on engineering, operating on
a "teach-by-doing" knowledge transfer model. The primary objective is to build long-
term internal capabilities while operationalizing and enforcing the State's newly updated
Flaw Remediation (SI-2) Standard. This initiative transitions the State from reactive,
manual vulnerability management to an AI-accelerated, continuous authorization, and
automated DevSecOps posture.
2. Scope
The consultant shall perform hands-on engineering, deliver strategic CISO advisory,
and provide direct mentoring across the following core operational pillars:
2.1 CISO Strategic Advisory and Engineering
• Act as a direct technical advisor to the CISO, translating federal mandates,
emerging AI threat models, and architectural gaps into actionable enterprise
security directives.
• Execute a hands-on knowledge transfer model, co-engineering data pipelines
and security automation alongside internal DET staff to institutionalize elite
technical skills.
• Deliver real time training and co-develop automation playbooks within the
security operations (SecOps) using live demonstration approach.
2.2 Flaw Remediation (SI-2) Standard Operationalization
• Tier Optimization & Enforcement: Architect automated tracking, logging, and
validation mechanisms to implement compliance with the State’s updated SI-2
timeframes:
o Tier 1 (Highest Urgency): Ensure all public-facing vulnerabilities, CISA
KEV listings, active exploits, and identity/privileged system flaws
implement approved mitigations or compensating controls within 24
hours, with full remediation closed inside 7 calendar days.
o Tier 2 (High-Risk/Internal): Configure alerting and metric reporting to
validate mitigation within 48 hours and full remediation within 15 calendar
days.
o Tier 3 (Moderate/Low): Establish repeatable monthly scheduling to
ensure remediation within 30 calendar days.
• Clean Deployment Architectures: Partner with agency development teams to
pivot away from manual, in-place patching. Author and implement automated
templates for clean deployments using virtualized system images, containers,
and cloud-native configurations.
• DevSecOps Integration: Embed secure builds, automated software testing,
code scanning, and dependency updates natively into agency deployment
pipelines.
2.3 AI Capability Deployment & Toolchain Integration
• Operationalize Gemini Government and Google Codemender or equivalent
directly inside active workflows, showing security analysts and application
developers how to leverage generative AI to automate log parsing, threat
hunting, and source-code remediation.
• Engineer automated data pipelines to feed the centralized enterprise platform
(incorporating telemetry from Tenable.io, Google Mandiant ASM, Microsoft Azure
Arc, Splunk, and Google SecOps) to maintain a single, authoritative pane of
glass.
• Ensure all AI-assisted capabilities comply strictly with State privacy, data
classification, and logging safeguards, preventing non-public vulnerability metrics
from leaking into unvetted environments.
2.4 Governance Safeguards & Escalation Automation
• Build automated low-code workflows to manage the SI-2 time-bound exception
lifecycle, ensuring every granted exception maps back to a named owner,
specific compensating controls, and an explicit financial tiedown capturing
technical debt.
• Configure automated alert thresholds and workflow routing for significant
business risks that exceed normal management tolerance, ensuring rapid
escalation in line with the SI-2 update.
3. Project Timeline
Project Description Target
Schedule
1: SI-2 Baseline &
Architecture
Alignment
Mapping of all automated data feeds (Tenable,
Mandiant, Azure Arc) into the single
authoritative platform, aligned to track Tier 1,
2, and 3 findings.
Day 30
2: Co-Engineered AI
Playbooks
Delivery of production-ready LLM and Frontier
Cyber model runbooks and prompt libraries,
co-developed with internal staff via hands-on
mentoring.
Day 45
3: Automated
Exception &
Escalation Engine
Implementation of automated workflow paths
for time-bound exceptions, financial tiedowns,
and high-risk executive escalation paths.
Day 60
4: DevSecOps
Clean Deployment
Framework
Standardization of approved repository
templates and CI/CD security gate controls to
enforce clean deployment preferences.
Day 75
5: Knowledge
Transfer &
Sustainment Hand-
off
Final technical transition briefing, configuration
documentation, and validation logs proving
internal staff autonomy in sustaining the SI-2
operational baseline.
Day 90–365
(Ongoing)
4. Minimum Qualifications and Core Competencies
The designated expert must demonstrate a unique blend of strategic advisory presence
and deep, practical engineering capability:
• Executive Advisory: Proven experience serving as a trusted technical advisor
to CISOs, CIOs, or senior executive leaders within public sector or heavily
federated enterprise environments.
• Teach-by-Doing Expertise: Documented success as a technical mentor, trainer,
or engineering lead focused on pair-engineering and technical upskilling of
infrastructure and security operations staff.
• Security Control Mastery (SI-2): Comprehensive expertise operationalizing
security controls, including tiering models, compensating control validation, and
time bound risk governance structures.
• Advanced Tooling Fluency: enterprise cyber stack Google Threat Intel or
VirusTotal, Google SecOps, Mandiant ASM, Tenable.io, Microsoft Azure Arc,
GitHub, GitHub Advanced Security, Ansible Tower, and Gemini/Anthropic AI
security frameworks.
• Cloud Architecture & DevSecOps Engineering
5. Performance Monitoring & Safeguards
• Knowledge Transfer Auditing: Progress will be measured not only by technical
deployment velocity but also by the documented proficiency gains of internal
DET staff who assume ownership of the deployed tools.
• Data Isolation Guardrails: The consultant is strictly forbidden from utilizing
public or unvetted commercial AI models for analyzing State code, logs, or asset
data. All engineering must occur exclusively within authorized, state-managed
enterprise security instances.
E
Requirements
Project details (project overview, who the contractor will work with, soft skills needed, etc.): The State of Wisconsin, Department of Administration (DOA), Division of Enterprise Technology (DET), Bureau of Security (BOS) requires an expert senior technical leader and engineer to serve as a strategic advisor to the CISO and drive the statewide implementation of the Accelerated Exposure Reduction Plan.
Top Required Skills & Years of Experience:
Must be able to demonstrate prior experience doing the following in a large/complex environment:
- Proven experience serving as a trusted technical advisor to CISOs, CIOs, or senior executive leaders within public sector or heavily federated enterprise environments.
- Documented success as a technical mentor, trainer, or engineering lead focused on pair-engineering and technical upskilling of infrastructure and security operations staff.
- Comprehensive expertise operationalizing security controls, including tiering models, compensating control validation, and time bound risk governance structures.
- Enterprise cyber stack Google Threat Intel or VirusTotal, Google SecOps, Mandiant ASM, Tenable.io, Microsoft Azure Arc, GitHub, GitHub Advanced Security, Ansible Tower, and Gemini/Anthropic AI security frameworks.
-Cloud Architecture & DevSecOps Engineering
Nice to have Skills:
-Federated/Government environment
-Tech Stack to include: Google, Microsoft, AWS, Splunk
Requirements
Skill Required / Desired Amount of Experience Proven work experience with enterprise data governance Required 3 Years Proven work experience with the OneTrust platform (Data Mapping, Data Discovery, Data Catalog, Assessments) Required 2 Years Proven work experience creating documentation for internal and external audiences, technical and business audiences Required 3 Years Proven work experience supporting the creation and presentation of knowledge and training Required 3 Years