Security Controls Assessor
TLDR
Act as an independent evaluator ensuring the effectiveness of security controls while leading compliance assessments and recommending risk-mitigation strategies.
- Assessment Execution: Plan and execute comprehensive security control assessments in accordance with frameworks like the Risk Management Framework (RMF) and FISMA.
- Testing & Evaluation: Review system configurations, evaluate evidence, and perform technical testing (e.g., vulnerability scanning) to validate security posture.
- Documentation & Reporting: Compile assessment results into Security Assessment Reports (SARs) and generate risk determinations for Authorizing Officials (AOs).
- Remediation & Tracking: Identify control weaknesses and support the development of Plans of Action and Milestones (POA&Ms).
- Team Leadership: Guide junior assessors, review deliverables, and coordinate assessment activities with ISSOs, system owners, and stakeholders.
- US Citizenship is required for this role.
- Education: Bachelor’s degree in cybersecurity, computer science, information systems, or a related field. (Or 6 years of experience equivalency)
- Experience: 7+ years of hands-on experience in cybersecurity, audit, or compliance, with specialized focus on RMF and NIST 800-series publications.
- Regulatory Expertise: Deep understanding of statutory guidance such as NIST SP 800-53, NIST SP 800-53A, and FISMA.
- Certifications: Industry-recognized credentials such as the Certified Information Systems Security Professional (CISSP), Certified Information Systems Auditor (CISA), or Certified Authorization Professional (CAP).
- Background Investigation: This role requires a Federal background investigation. A current or prior DHS suitability is highly preferred.
UltraViolet Cyber maintains broad salary ranges for its roles in order to account for variations in knowledge, skills, experience, market conditions and locations, as well as reflect our company's differing products, services, industries and lines of business. Candidates are typically placed into the range based on the preceding factors.
We sincerely thank all applicants in advance for submitting their interest in this position. We know your time is valuable.
UltraViolet Cyber welcomes and encourages diversity in the workplace regardless of race, gender, religion, age, sexual orientation, gender identity, disability, or veteran status.
If you want to make an impact, UltraViolet Cyber is the place for you!
UltraViolet Cyber builds a cybersecurity platform that integrates security operations for enterprises, eliminating risks associated with traditional red and blue team approaches. Targeting Fortune 500 and government clients, they deliver a combination of technology-driven solutions and expert management to enhance real-time security across diverse organizational landscapes.