Sr. Security Control Assessor

Ultipro

Romsley CP

On-site

GBP 65,000 - 100,000

Full time

2 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Ultipro seeks a security professional with extensive NIST RMF experience to independently lead security control assessments from start to finish using the NIST framework. The role requires strong IT security knowledge, encryption awareness, secure architecture and agile development familiarity.

Cloud proficiency (AWS/Azure/Google) and FedRAMP assessment experience are essential, along with creating security artifacts, interpreting vulnerability tools, SIEM use, and technical writing.

Qualifications

  • Bachelor’s degree in Information Technology, Cyber Security, Computer Systems or related field and/or 2+ active certifications approved by Government.
  • Minimum 5 years in Information Systems Security roles (e.g., I.S.S.O./Engineer/Auditor/Manager).
  • 5+ years with vulnerability management tools; 3+ years leading projects and briefings.

Responsibilities

  • Lead security control assessments from start to finish.
  • Create, review and update security artifacts (Plans, contingency docs, e-auth workbook, etc.).

Skills

NIST RMF
Security assessments
IT security practices
Encryption techniques
System architecture
System administration
Configuration management
Agile development
Cloud proficiency

Education

Bachelor’s degree in IT / Cyber Security
2+ active cybersecurity certifications

Tools

Fortify SCA
WebInspect
Nessus
TIO
Prisma Cloud
SonarQube
Splunk

Job description

  • Extensive experience with the NIST RMF and independently leading security control assessments from start to finish using the NIST Framework.
  • Experience in several of the following areas is required: understanding of IT security practices and procedures; knowledge of current security tools available; different communication protocols; encryption techniques/tools; secure system architecture, system engineering, system administration, configuration management, or agile application development experience.
  • Must be fully cloud proficient (AWS, Azure, Google).
  • Experienced performing FedRAMP assessments and assessments of systems hosted in the cloud.
  • Experience creating, reviewing and updating/editing security artifacts (i.e., Security Plans, Contingency Plan, Contingency Plan Test, e- Authentication workbook, FIPS 199 workbook, etc.).
  • Proficient at interpreting scan results from various vulnerability and compliance tools such as MicroFocus Fortify SCA and WebInspect, Tenable Nessus and TIO, Prisma Cloud, SonarQube.
  • Must be capable of providing corrective actions for weaknesses discovered during the assessment.
  • Must have experience with SIEM tools and performing audit log reviews.
  • Experience creating and validating remediation of POA&Ms.
  • Technical writing ability is required.
  • US Citizenship is required, along with the ability to obtain a Federal agency-specific clearance prior to starting.
Requirements
  • Must have a Bachelor’s degree in Information Technology, Cyber Security, Computer Systems or related field and/or have & maintain at least two (2) active certifications such as but not limited to CASP, GSEC, GSLC, CISSP, CAP, CEH, CISM, CISA or other comparable certification or experience which must be approved in advance by the Government on a case-by-case basis.
  • Must have at least five (5) years of specialized experience in one of the below positions: Information Systems Security Officer, Information Systems Security Engineer, Information Systems Security Auditor, or Information Systems Security Manager.
  • Must have a minimum of five (5) years of experience with analyzing, assessing, and implementing corrective actions based on vulnerability management tools.
  • Must have a minimum of three (3) years of experience with leading projects, technical writing, administrative tasks, and conducting briefings.
Strongly Desired
  • Knowledge of container platforms (EKS, Openshift, Docker) and microservice architecture.
  • Development or programming experience.
  • Familiarity with Nipper, Burp Suite Pro, Kali Linux, Solarwinds, Telos IACS, SPLUNK
  • Penetration Testing experience.
Equal Opportunity Employer

This employer is required to notify all applicants of their rights pursuant to federal employment laws.For further information, please review the Know Your Rights notice from the Department of Labor.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Security Architect- 100% Remote
Senior Security Architect- 100% Remote

Ultipro • Romsley CP

Remote
GBP 55,000 - 75,000
Senior FedRAMP & Cloud Security Controls Assessor
Senior FedRAMP & Cloud Security Controls Assessor

Ultipro • Romsley CP

On-site
GBP 65,000 - 100,000
Classified ISSO
Classified ISSO

Ultipro • Romsley CP

On-site
GBP 83,000 - 106,000
Technical Security Consultant
Technical Security Consultant

Barclay Simpson • City Of London

On-site
GBP 75,000 - 110,000
Security Assurance Adviser
Security Assurance Adviser

Experis UK • Greater London

Hybrid
GBP 156,000 - 182,000
Cyber Security Controls Tester (Contractor)
Cyber Security Controls Tester (Contractor)

Cyberfort • Stone Cross

On-site
GBP 65,000 - 90,000
Information Engineer/Data Threat Analyst- 100% Remote
Information Engineer/Data Threat Analyst- 100% Remote

Ultipro • Romsley CP

Remote
GBP 83,000 - 121,000
Senior Information Security Engineer
Senior Information Security Engineer

Selby Jennings • Greater London

On-site
GBP 80,000 - 120,000
Platform Security Engineer
Platform Security Engineer

Xoriant • Greater London

On-site
GBP 70,000 - 100,000
Security Assurance Adviser
Security Assurance Adviser

Consult • Greater London

Hybrid
GBP 111,000 - 129,000