Assessment Lead

Paragon Technology

Washington (District of Columbia)

On-site

USD 120,000 - 190,000

Full time

25 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Paragon Technology Group in Washington, DC seeks an experienced Assessment Lead to manage Security Control Assessments under the RMF and ISCA program for the Department of State. You will provide technical leadership, plan assessments, and ensure evidence-based determinations of control effectiveness.

You will oversee SAPs, SARs, ROEs, POA&Ms, and assessment artifacts, coordinate cross-functional teams, and communicate results to Government stakeholders.

Qualifications

  • Bachelor's degree in cybersecurity, information technology, information systems, computer science, engineering, or a related technical discipline.
  • 8+ years of relevant professional experience in cybersecurity, information assurance, security assessment, RMF, or related disciplines.
  • CISSP, CISA, or equivalent certification.
  • CEH or equivalent penetration-testing certification.
  • Demonstrated experience leading or performing Security Control Assessments in Federal information-system environments.
  • Experience with RMF, particularly RMF Step 4 – Assess.
  • Knowledge of NIST SP 800-37, 800-53, 800-53A, and security testing methodologies.
  • Experience developing/reviewing SAPs, SARs, POA&Ms, ROEs, control test cases, and assessment evidence.

Responsibilities

  • Serve as the primary contractor lead for Security Control Assessment activities.
  • Plan, coordinate, and oversee Security Control Assessments across systems and environments.
  • Develop and manage assessment schedules, milestones, priorities, and stakeholder coordination.
  • Lead development, review, and execution of SAPs and ROEs, including scope, controls, procedures, evidence, and timelines.
  • Ensure assessments comply with Federal and Department requirements including NIST SPs and FISMA.
  • Provide technical direction to Security Control Assessors and other personnel.
  • Review SSPs, policies, configurations, vulnerability scans, and evidence.
  • Ensure assessment conclusions are supported by objective evidence.
  • Lead meetings and briefings with Government stakeholders.
  • Coordinate with System Owners, ISSOs/ISSMs, and other stakeholders.
  • Monitor progress and mitigate schedule risks and evidence gaps.
  • Maintain independence and avoid conflicts in assessment activities.
  • Perform QA reviews for accuracy and compliance.
  • Lead preparation/delivery of SARs, risk summaries, executive briefings, and deliverables.
  • Support remediation and retesting to verify closures.
  • Validate mitigation strategies and update POA&Ms with stakeholders.
  • Support authorization decisions with technical assessment information.
  • Track findings and evidence to closure in Government repositories.

Skills

Security assessment leadership
Project coordination
Technical writing
Stakeholder communication

Education

Bachelor's degree in Cybersecurity/IT/IS/CS/Engineering

Tools

RMF Guidance Tools
NIST SP 800-37/53/53A

Job description

Assessment Lead

Full Time Professional Washington, DC, US

Assessment Lead

Paragon Technology Group is seeking an experienced Assessment Lead to support the Department of State Bureau of Diplomatic Technology, Enterprise Applications cybersecurity program under the Independent Security Control Assessment (ISCA) effort. The Assessment Lead is a Key Personnel position responsible for the overall planning, coordination, execution, quality, and delivery of Security Control Assessment activities. The position provides technical leadership and oversight of independent assessments supporting the Risk Management Framework (RMF), including RMF Step 4 – Assess, and ensures assessments provide objective, repeatable, evidence-based determinations of the effectiveness of implemented security and privacy controls.

The ISCA effort supports ongoing security control assessments, risk determination and acceptance, continuous monitoring, remediation verification, and RMF documentation for information systems under Enterprise Applications authority. Monitor security controls, conduct ongoing assessments, support risk determination and acceptance, assist with issue resolution and remediation verification, maintain documentation and evidence, and support development of SAPs, SARs, and POA&Ms.

Essential Duties and Responsibilities
  • Serve as the primary contractor lead and subject matter expert for Security Control Assessment activities.
  • Plan, coordinate, and oversee Security Control Assessments across assigned systems and environments.
  • Develop and manage assessment schedules, milestones, resource assignments, priorities, and stakeholder coordination.
  • Lead development, review, and execution of Security Assessment Plans (SAPs) and Rules of Engagement (ROEs), including assessment scope, control selection, assessment procedures, evidence requirements, testing methodologies, boundaries, timelines, and escalation procedures.
  • Ensure assessments comply with applicable Federal and Department cybersecurity requirements, including NIST SP 800-37, NIST SP 800-53, NIST SP 800-53A, FISMA requirements, and Government-approved assessment procedures.
  • Provide technical direction and oversight to Security Control Assessors and other personnel supporting assessment activities.
  • Review SSPs, policies, procedures, system configurations, architecture documentation, vulnerability scans, penetration-test results, prior findings, POA&Ms, and other assessment evidence.
  • Ensure assessors appropriately apply examination, interview, and testing methods and that assessment conclusions are supported by sufficient objective evidence.
  • Evaluate security and privacy control implementation and effectiveness and identify control deficiencies, vulnerabilities, weaknesses, and associated cybersecurity risks.
  • Conduct and lead assessment entrance meetings, status meetings, technical discussions, findings reviews, and exit briefings with Government and system stakeholders.
  • Coordinate activities with System Owners, ISSOs, ISSMs, system administrators, security engineers, technical teams, the Authorizing Official, and other Government-designated stakeholders.
  • Monitor assessment progress and proactively identify schedule risks, evidence deficiencies, technical issues, and other impediments to assessment completion.
  • Maintain assessment independence and ensure personnel do not assess controls they were directly responsible for implementing unless specifically authorized by the Government.
  • Perform quality assurance reviews to ensure assessment findings and deliverables are technically accurate, consistent, adequately supported, and compliant with Government standards.
  • Lead preparation and delivery of Security Assessment Reports (SARs), assessment findings, risk summaries, executive briefings, vulnerability matrices, and related assessment deliverables.
  • Support remediation and retesting activities to validate corrective actions and determine whether identified deficiencies have been successfully resolved.
  • Coordinate with System Owners and ISSOs to validate mitigation strategies, update POA&Ms, and support closure of findings.
  • Support evaluation of residual risk and provide technical assessment information needed for authorization and risk-based decisions by the Authorizing Official and other Government officials.
  • Track assessment findings, supporting evidence, and deliverables through closure and maintain records in Government-designated repositories and cybersecurity tools.
  • Identify recurring control deficiencies, systemic weaknesses, and assessment trends and recommend improvements to security posture, assessment consistency, and RMF execution.
  • Provide assessment status, performance metrics, risks, accomplishments, and issues to the COR and other Government-designated personnel.
Required Qualifications
  • Bachelor's degree in Cybersecurity, Information Technology, Information Systems, Computer Science, Engineering, or a related technical discipline.
  • Minimum of eight (8) years of relevant professional experience in cybersecurity, information assurance, security assessment, RMF, or related disciplines.
  • CISSP, CISA, or equivalent certification.
  • CEH or equivalent penetration-testing certification.
  • Demonstrated experience leading or performing Security Control Assessments in Federal information-system environments.
  • Demonstrated experience with the Risk Management Framework, particularly RMF Step 4 – Assess.
  • Working knowledge and practical application of NIST SP 800-37, NIST SP 800-53, NIST SP 800-53A, and security testing methodologies.
  • Experience developing or reviewing SAPs, SARs, POA&Ms, Rules of Engagement, control test cases, assessment evidence, residual-risk documentation, and security authorization packages.
  • Experience assessing technical, management, and operational security controls using examination, interview, and testing techniques.
  • Experience interpreting vulnerability scanning and penetration-testing results and translating technical findings into documented cybersecurity risk.
  • Ability to lead multidisciplinary assessment teams and communicate effectively with technical personnel, system owners, ISSOs/ISSMs, senior Government stakeholders, and Authorizing Officials.
  • Strong technical writing, analytical, organizational, and quality-assurance skills.
Security Requirements
  • Must be able to obtain and maintain the security clearance and/or Department of State personnel security eligibility required for the position.
Work Location and Schedule

The position is primarily contractor-site based; however, because the Assessment Lead is designated Key Personnel, the individual must reside within a reasonable commuting distance of State Annex 17, 600 19th Street NW, Washington, D.C., and must be available for onsite meetings, mission-critical activities, and other Government-directed support as required.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Assessment Lead
Assessment Lead

Paragon Technology Group, Inc. • Washington

On-site
USD 140,000 - 200,000
Assessment Lead
Assessment Lead

ADP, Inc. • Washington

On-site
USD 120,000 - 180,000
Senior Security Control Assessment Lead
Senior Security Control Assessment Lead

Paragon Technology • Washington

On-site
USD 120,000 - 190,000
SCA Lead
SCA Lead

Disruptive Solutions, LLC • Sterling (VA)

Hybrid
USD 150,000 - 190,000
Security Control Assessor
Security Control Assessor

Apavo Corporation • Arlington (VA)

On-site
USD 130,000 - 185,000
Assessment Lead
Assessment Lead

Connected Logistics • Springfield (VA)

Hybrid
USD 155,000 - 165,000
Assessment Lead
Assessment Lead

Connected Logistics • Washington

Hybrid
USD 155,000 - 165,000
Health benefits
401(k) plan
Paid time off
Security Assessor (RMF / GRC)
Security Assessor (RMF / GRC)

Digital-Global-Connectors • McLean (VA)

Hybrid
USD 120,000 - 155,000
Senior RMF Security Assessment Lead
Senior RMF Security Assessment Lead

Paragon Technology Group, Inc. • Washington

On-site
USD 140,000 - 200,000
Senior Security Controls Assessor
Senior Security Controls Assessor

ECS Corporate Services • Fairfax (VA)

On-site
USD 160,000 - 190,000