Cybersecurity Assessor
Job Description
SAIC is hiring an entry-level Cybersecurity Assessor to support security assessments and continuous monitoring for federal information systems in Oklahoma City, OK on an onsite basis. This role works under close supervision, partnering with senior cybersecurity professionals to evaluate security controls, review compliance evidence, and use basic automation to improve assessment efficiency.
The position involves working across multiple teams and concurrent deadlines, helping ensure assessment activities remain well-documented, traceable, and defensible for stated objectives and federal requirements.
What you’ll do
- Assist federal staff, project managers, and cybersecurity professionals with Continuous Monitoring and Security Assessments for information systems and applications.
- Support review of policies, procedures, system documentation, artifacts, and other evidence to determine system compliance with applicable federal and organizational policies.
- Help identify and document security weaknesses, assess the significance of vulnerabilities, and clearly describe potential risk factors.
- Under guidance of senior staff, communicate identified weaknesses and recommended remediation steps to federal staff and other stakeholders.
- Maintain accurate, organized assessment documentation that is clear, defensible, and traceable to stated objectives.
- Request, review, track, and validate large volumes of assessment evidence in a systematic and organized manner.
- Assist with balancing competing assessment activities and multiple concurrent deadlines while maintaining thoroughness and quality across risk management projects.
- Work effectively as part of multiple assessment teams while maintaining ownership and accountability for assigned tasks.
- Under close supervision, perform basic technical and scripting tasks supporting assessments, including:
- Simple scripts or data processing to support evidence analysis or reporting.
- Supporting automation of evidence collection, reporting, or tracking activities.
- Helping maintain internal tools, templates, or tracking systems used by the cybersecurity team.
Required qualifications
- Associate’s degree in computer science, information systems, cybersecurity, or a related discipline with a minimum GPA of 3.5, including completion of relevant programming courses; or a higher degree (for example, a Bachelor’s) in a related field.
- Strong written and verbal communication skills.
- Familiarity with information system architecture, networking concepts, system documentation, or software development (coursework or projects acceptable).
- Ability to obtain a Public Trust clearance.
- Familiarity with Microsoft Office Suite (Word, Excel, PowerPoint, Outlook).
- Foundational knowledge of at least one security or risk management framework such as NIST SP 800-53, NIST SP 800-37, ISO 20001, or other RMF frameworks (coursework or self-study acceptable).
- Strong attention to detail with excellent organizational and documentation skills.
- Customer-focused mindset with ability to collaborate across multiple teams in a fast-paced environment.
- Ability to work effectively with both technical and non-technical teams and to receive and apply feedback from more senior staff.
Technologies
- NIST SP 800-53 Rev 5
- NIST SP 800-53
- NIST SP 800-37
- ISO 20001
- RMF frameworks
- Microsoft Office Suite (Word, Excel, PowerPoint, Outlook)
Preferred qualifications
- Experience using GRC tools, cybersecurity assessment platforms, or information system tracking tools through labs, internships, or academic projects.
- Exposure to system lifecycle implementation, including documenting and maintaining systems through RMF or similar lifecycles.
- Working knowledge of cybersecurity principles, security controls, vulnerability scanning methodologies, system architecture, and common security frameworks.
- Knowledge or experience supporting configuration management, change control processes, or software development (for example, capstone or team projects).