Senior Cybersecurity Control Assessor
Senior
Dhs Rmf
Information Security
InfoSec
Risk Management
Rmf
Security
Security Assessment
Security Assessment Reports
Security Compliance
Security Compliance Frameworks
Security Control Assessment
Security Control Compliance
Security Standards
Security Standards And Compliance
Security Standards Compliance
Security Testing
System Security Plans
Job Description
Support FEMA OCISO in Washington, D.C. by conducting independent cybersecurity control assessments and producing assessment artifacts for security and compliance.
Responsibilities
- Assess the effectiveness of IT security controls and verify compliance with NIST SP 800-53 Rev 5 and DHS RMF
- Conduct comprehensive control assessments within a system boundary and across FEMA using interviews, examinations, and testing
- Evaluate the effectiveness of security policies, procedures, and technologies to identify vulnerabilities, risks, and gaps
- Review and analyze System Security Plans (SSPs), supporting policies and procedures, and evidence artifacts for completeness and accuracy
- Identify security gaps, evaluate residual risk, and generate findings for security assessment reporting
- Develop and maintain assessment artifacts and document findings while supporting continuous monitoring and ongoing authorization efforts
- Highlight findings and recommendations, and collaborate with IT, security, and business units to support corrective actions
Requirements
- U.S. Citizenship required
- FEMA EOD suitability required; current DHS or FEMA EOD preferred
- BS/BA + 7 years of applicable experience in RMF, control assessment, audit, cybersecurity compliance, or security engineering
- Certifications such as CISSP, CISM, CISA, or equivalent
- Strong knowledge of NIST SP 800-53, NIST SP 800-37 (RMF), and the DHS 4300 Series
- Experience using security control assessment methodologies and tools
- Experience conducting security assessments and producing security assessment artifacts, including SAPs, RTMs, and SARs
- Analytical skills for identifying security gaps and evaluating residual risk
- Knowledge of assessment methodologies and risk analysis
- Experience developing POA&Ms
- Excellent analytical and problem-solving skills for vulnerability prioritization and trend analysis
- Strong communication and interpersonal skills; able to work independently and as part of a team
- Detail-oriented approach with a commitment to accuracy and thoroughness
Technologies / Artifacts
- NIST SP 800-53 Rev 5
- DHS RMF
- NIST SP 800-37 (RMF)
- DHS 4300 Series
- Security Assessment Plans (SAPs)
- Risk Traceability Matrices (RTMs)
- Security Assessment Reports (SARs)
- System Security Plans (SSPs)
- POA&Ms
Benefits
- Flexible time off benefit
- Robust learning resources
- Comprehensive benefits including healthcare, wellness, financial, retirement, family support, continuing education, and time off benefits
Additional Opportunity Details
- Serve as an independent assessor for control design, implementation, and effectiveness across assigned systems and authorization boundaries
- Support assessment procedures including interviews, examinations, and testing to verify control implementation and effectiveness
- Collaborate with system owners, ISSOs, stakeholders, and cybersecurity professionals to evaluate security control implementation effectiveness
- Work with multiple teams to identify gaps, recommend improvements, and support compliance with regulatory requirements
Desired Qualifications
- Active Secret security clearance
- Previous DHS or DoD experience
- Experience with CSAM, RegScale, eMASS, or similar GRC tools
- Knowledge of FedRAMP assessment processes and DISA STIGs and cybersecurity compliance frameworks
- Experience with continuous monitoring and ongoing authorization activities
- Knowledge of cloud security and emerging technologies
- Strong technical writing skills for assessment documentation
- Experience supporting audit activities and authorization decisions
Travel / Location / Pay
- Location: Washington, DC (onsite)
- Travel: Up to 10% local travel
- Pay range: USD 113,200 - 237,800 per year