Assessment Lead

Paragon Technology Group, Inc.

Washington (District of Columbia)

On-site

USD 140,000 - 200,000

Full time

6 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Paragon Technology Group, Inc. seeks an experienced Assessment Lead to plan, coordinate, and deliver Security Control Assessments under the ISCA effort for the State Department's Enterprise Applications cybersecurity program.

The role provides technical leadership, develops SAPs and SARs, and ensures evidence-based determinations of control effectiveness across RMF steps. Onsite duties are expected in Washington, DC area.

Qualifications

  • Bachelor's degree in a technical discipline and eight years' cybersecurity experience.
  • Experience leading or performing Security Control Assessments in Federal environments.
  • Familiarity with NIST SP 800-37/800-53/800-53A and RMF steps.

Responsibilities

  • Plan, coordinate, and oversee Security Control Assessments across systems and environments.
  • Lead SAPs, ROEs, control testing, evidence collection, and assessment artifacts.
  • Ensure assessments meet government requirements and provide objective evidence.
  • Provide direction to assessors and coordinate with government stakeholders.
  • Prepare SARs, risk summaries, and supporting documentation for authorization.

Skills

Security control assessments
RMF knowledge
Technical leadership
Analytical writing
Stakeholder coordination

Education

Bachelor's degree in Cybersecurity
CISSP
CISA
CEH

Job description

Assessment Lead

Paragon Technology Group is seeking an experienced Assessment Lead to support the Department of State Bureau of Diplomatic Technology, Enterprise Applications cybersecurity program under the Independent Security Control Assessment (ISCA) effort. The Assessment Lead is a Key Personnel position responsible for the overall planning, coordination, execution, quality, and delivery of Security Control Assessment activities. The position provides technical leadership and oversight of independent assessments supporting the Risk Management Framework (RMF), including RMF Step 4 - Assess, and ensures assessments provide objective, repeatable, evidence-based determinations of the effectiveness of implemented security and privacy controls.

The ISCA effort supports ongoing security control assessments, risk determination and acceptance, continuous monitoring, remediation verification, and RMF documentation for information systems under Enterprise Applications authority. Monitor security controls, conduct ongoing assessments, support risk determination and acceptance, assist with issue resolution and remediation verification, maintain documentation and evidence, and support development of SAPs, SARs, and POA&Ms.

Essential Duties and Responsibilities
  • Serve as the primary contractor lead and subject matter expert for Security Control Assessment activities.
  • Plan, coordinate, and oversee Security Control Assessments across assigned systems and environments.
  • Develop and manage assessment schedules, milestones, resource assignments, priorities, and stakeholder coordination.
  • Lead development, review, and execution of Security Assessment Plans (SAPs) and Rules of Engagement (ROEs), including assessment scope, control selection, assessment procedures, evidence requirements, testing methodologies, boundaries, timelines, and escalation procedures.
  • Ensure assessments comply with applicable Federal and Department cybersecurity requirements, including NIST SP 800-37, NIST SP 800-53, NIST SP 800-53A, FISMA requirements, and Government-approved assessment procedures.
  • Provide technical direction and oversight to Security Control Assessors and other personnel supporting assessment activities.
  • Review SSPs, policies, procedures, system configurations, architecture documentation, vulnerability scans, penetration-test results, prior findings, POA&Ms, and other assessment evidence.
  • Ensure assessors appropriately apply examination, interview, and testing methods and that assessment conclusions are supported by sufficient objective evidence.
  • Evaluate security and privacy control implementation and effectiveness and identify control deficiencies, vulnerabilities, weaknesses, and associated cybersecurity risks.
  • Conduct and lead assessment entrance meetings, status meetings, technical discussions, findings reviews, and exit briefings with Government and system stakeholders.
  • Coordinate activities with System Owners, ISSOs, ISSMs, system administrators, security engineers, technical teams, the Authorizing Official, and other Government-designated stakeholders.
  • Monitor assessment progress and proactively identify schedule risks, evidence deficiencies, technical issues, and other impediments to assessment completion.
  • Maintain assessment independence and ensure personnel do not assess controls they were directly responsible for implementing unless specifically authorized by the Government.
  • Perform quality assurance reviews to ensure assessment findings and deliverables are technically accurate, consistent, adequately supported, and compliant with Government standards.
  • Lead preparation and delivery of Security Assessment Reports (SARs), assessment findings, risk summaries, executive briefings, vulnerability matrices, and related assessment deliverables.
  • Support remediation and retesting activities to validate corrective actions and determine whether identified deficiencies have been successfully resolved.
  • Coordinate with System Owners and ISSOs to validate mitigation strategies, update POA&Ms, and support closure of findings.
  • Support evaluation of residual risk and provide technical assessment information needed for authorization and risk-based decisions by the Authorizing Official and other Government officials.
  • Track assessment findings, supporting evidence, and deliverables through closure and maintain records in Government-designated repositories and cybersecurity tools.
  • Identify recurring control deficiencies, systemic weaknesses, and assessment trends and recommend improvements to security posture, assessment consistency, and RMF execution.
  • Provide assessment status, performance metrics, risks, accomplishments, and issues to the COR and other Government-designated personnel.
Required Qualifications
  • Bachelor's degree in Cybersecurity, Information Technology, Information Systems, Computer Science, Engineering, or a related technical discipline.
  • Minimum of eight (8) years of relevant professional experience in cybersecurity, information assurance, security assessment, RMF, or related disciplines.
  • CISSP, CISA, or equivalent certification.
  • CEH or equivalent penetration-testing certification.
  • Demonstrated experience leading or performing Security Control Assessments in Federal information-system environments.
  • Demonstrated experience with the Risk Management Framework, particularly RMF Step 4 - Assess.
  • Working knowledge and practical application of NIST SP 800-37, NIST SP 800-53, NIST SP 800-53A, and security testing methodologies.
  • Experience developing or reviewing SAPs, SARs, POA&Ms, Rules of Engagement, control test cases, assessment evidence, residual-risk documentation, and security authorization packages.
  • Experience assessing technical, management, and operational security controls using examination, interview, and testing techniques.
  • Experience interpreting vulnerability scanning and penetration-testing results and translating technical findings into documented cybersecurity risk.
  • Ability to lead multidisciplinary assessment teams and communicate effectively with technical personnel, system owners, ISSOs/ISSMs, senior Government stakeholders, and Authorizing Officials.
  • Strong technical writing, analytical, organizational, and quality-assurance skills.
Security Requirements
  • Must be able to obtain and maintain the security clearance and/or Department of State personnel security eligibility required for the position.
Work Location and Schedule

The position is primarily contractor-site based; however, because the Assessment Lead is designated Key Personnel, the individual must reside within a reasonable commuting distance of State Annex 17, 600 19th Street NW, Washington, D.C., and must be available for onsite meetings, mission-critical activities, and other Government-directed support as required.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Assessment Lead
Assessment Lead

Paragon Technology • Washington

On-site
USD 120,000 - 190,000
Assessment Lead
Assessment Lead

ADP, Inc. • Washington

On-site
USD 120,000 - 180,000
Senior Security Control Assessment Lead
Senior Security Control Assessment Lead

Paragon Technology • Washington

On-site
USD 120,000 - 190,000
Assessment Lead
Assessment Lead

Logc2 • Washington, Northern (KY)

Hybrid
USD 155,000 - 165,000
SCA Lead
SCA Lead

Disruptive Solutions, LLC • Sterling (VA)

Hybrid
USD 150,000 - 190,000
Security Control Assessor
Security Control Assessor

Apavo Corporation • Arlington (VA)

On-site
USD 130,000 - 185,000
Senior RMF Security Assessment Lead
Senior RMF Security Assessment Lead

Paragon Technology Group, Inc. • Washington

On-site
USD 140,000 - 200,000
Assessment Lead
Assessment Lead

Connected Logistics • Springfield (VA)

Hybrid
USD 155,000 - 165,000
Assessment Lead
Assessment Lead

Connected Logistics • Washington

Hybrid
USD 155,000 - 165,000
Health benefits
401(k) plan
Paid time off
Security Assessor (RMF / GRC)
Security Assessor (RMF / GRC)

Digital-Global-Connectors • McLean (VA)

Hybrid
USD 120,000 - 155,000