Bachelor’s degree in Cybersecurity, IT, or related field
7+ years of experience in information security or security control assessment
Strong knowledge of NIST RMF, FISMA, and NIST SP 800-53 controls
Experience conducting security assessments and developing SARs and POAMs
Requirements:
Conduct security control assessments in accordance with NIST SP 800-53 and RMF guidelines
Perform system discovery, documentation review, and evidence collection activities
Develop and execute Security Assessment Plans (SAPs)
Conduct interviews and technical testing to evaluate control effectiveness
Job description
cFocus Software seeks a Sr. Security Control Assessor to join our program supporting the Internal Revenue Service (IRS). This position is remote. This position requires a Public Trust clearance. Qualifications:
Bachelor’s degree in Cybersecurity, IT, or related field.
7+ years of experience in information security or security control assessment
Strong knowledge of NIST RMF, FISMA, and NIST SP 800-53 controls
Experience conducting security assessments and developing SARs and POA&Ms
Familiarity with federal security authorization processes (ATO, SA&A)
Strong analytical, documentation, and communication skills
Duties:
Conduct security control assessments in accordance with NIST SP 800-53 and RMF guidelines
Perform system discovery, documentation review, and evidence collection activities
Develop and execute Security Assessment Plans (SAPs)
Conduct interviews and technical testing to evaluate control effectiveness
Document findings and develop Security Assessment Reports (SARs)
Identify vulnerabilities and document risks in Plans of Action and Milestones (POA&Ms)
Support Authorization to Operate (ATO) processes and continuous monitoring activities
Validate remediation efforts and closure of POA&Ms
Coordinate with system owners, ISSOs, and stakeholders throughout the assessment lifecycle
Provide on-demand security assessment support across multiple systems
Support rapid assessment efforts and evolving federal initiatives
Deliver level-of-effort estimates for assessment activities
Assist with backlog reduction and surge staffing needs
Participate in special projects and cross-functional security initiatives