Logo for DataLock Consulting Group

Cybersecurity Quality Assurance Analyst Independent Verification and Validation (IV&V)

Role overview

Qualifications

  • Seven or more years of relevant cybersecurity experience (senior level)
  • At least five years of experience in Information Security Governance, Risk, and Compliance, including expertise in writing technical and risk management reports
  • Experience in third party cybersecurity risk management (at least three years) and evaluating third party cyber risk
  • Hold at least one of CISSP, CISA, CISM, CTPRP, or CTPRA certifications

Responsibilities

  • Review cybersecurity assessment documentation for accuracy, completeness, and compliance
  • Conduct independent verification and validation of technical findings and risk statements
  • Evaluate evidence against federal and industry standards
  • Validate compliance with ISO, SOC, and NIST standards

About the company

DataLock Consulting Group logo

DataLock Consulting Group

Cybersecurity

Established in 2013, DataLock Consulting Group is a rapidly growing Cybersecurity consulting firm, providing security solutions to the federal government and the commercial sector. Located in the heart of Northern Virginia, DataLock is a Small Disadvantaged Business (SDB). DataLock exists to help your organization manage Cybersecurity risks while improving your security posture. We understand the complexity of securing today’s interconnected IT networks and data, so you don’t have to.

Company details

IndustryCybersecurity
Company size11 - 50

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

This is a remote position.

POSITION TITLE

Cybersecurity Quality Assurance Analyst

Independent Verification and Validation (IV&V)

SUMMARY

The Cybersecurity Quality Assurance Analyst supports independent verification and validation activities and ensures that all cybersecurity assessment products meet technical, security, and quality standards before delivery. The analyst reviews evidence, validates compliance with federal frameworks, and confirms the accuracy and consistency of risk documentation. The goal is to ensure high quality, defensible assessment outputs that meet customer and regulatory requirements.

RESPONSIBILITIES

· Review cybersecurity assessment documentation for accuracy, completeness, and compliance

· Conduct independent verification and validation of technical findings and risk statements

· Evaluate evidence against federal and industry standards

· Assess vendor cybersecurity risk and review third party risk documentation

· Validate compliance with ISO, SOC, and NIST standards

· Identify deficiencies or deviations from required quality and security standards

· Provide feedback and guidance to assessment teams to maintain quality consistency

· Maintain documentation, audit trails, and quality records

· Support internal audit activities and process improvement initiatives

· Prepare reports for management review and quality control oversight

· Recommend enhancements to assessment processes and methodologies



Requirements


· Senior level positions require seven or more years of relevant cybersecurity experience

· Advanced degree in a cybersecurity or technical field preferred, with experience or directly relevant certifications substituting for academic credentials

· At least five years of experience in Information Security Governance, Risk, and Compliance, demonstrating:

 · Expertise in writing technical and risk management reports

 · Strong analytical, problem solving, and organizational skills

 · Experience assessing and mitigating risks associated with vendor relationships and vendor control evaluations

 · Experience performing risk-based due diligence

 · Technical understanding of cybersecurity concepts and working knowledge of ISO 27001, SOC 1 and SOC 2, NIST SP 800-53, and NIST SP 800-171

· At least three years of experience in third party cybersecurity risk management, demonstrating:

 · Experience evaluating third party cyber risk

 · Experience developing and implementing sustainable third party cyber risk processes

· Experience conducting assessments using NIST SP 800-53 within a federal agency

· Strong verbal and written communication skills

· Effective technical writing and documentation capabilities

· Experience in cybersecurity control assessment environments

· Ability to document cyber assessments and communicate results clearly

· Understanding of the Systems Development Life Cycle and its application to secure systems

 

MINIMUM EDUCATION

· Advanced degree preferred

· Experience and certifications may be substituted for formal education on a case by case basis

 

CERTIFICATIONS

Candidate must hold and provide proof of at least one of the following certifications:

 

· Certified Information Systems Security Professional (CISSP)

· Certified Information Systems Auditor (CISA)

· Certified Information Security Manager (CISM)

· Certified Third Party Risk Professional (CTPRP)

· Certified Third Party Risk Assessor (CTPRA)



Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Cybersecurity Analyst Related jobs

Other jobs at DataLock Consulting Group

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.