Assessment Lead

Connected Logistics

Washington (District of Columbia)

Hybrid

USD 155,000 - 165,000

Full time

28 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health benefits
401(k) plan
Paid time off

Job summary

Connected Logistics seeks an Assessment Lead to drive Security Control Assessments under RMF for DoS systems. You will provide technical leadership, develop assessment plans, and ensure evidence-based determinations of control effectiveness, aligned with NIST and FISMA requirements.

As a key contractor lead, you will coordinate with government personnel, prepare SARs, and guide teams through assessment activities to support authorization and risk-based decisions.

Qualifications

  • Bachelor's in computer science, IT, cybersecurity or related field and 8+ years conducting security control assessments.
  • Demonstrated experience with NIST SP 800-53A assessment procedures.
  • Active CISSP, CISA or equivalent, and CEH or equivalent penetration testing certification.

Responsibilities

  • Lead and serve as primary contractor lead for Security Control Assessment activities.
  • Plan, coordinate, and oversee Security Control Assessments across information systems.
  • Develop and maintain SAPs including scope, controls, procedures and ROE.
  • Ensure assessments comply with NIST SP 800-37/53/53A and FISMA requirements.
  • Lead SARs, risk summaries, and executive-level briefings with government stakeholders.
  • Coordinate with System Owners, ISSOs, ISSMs, admins, and security teams.

Skills

Security leadership
RMF Assessments
NIST SP knowledge
Evidence-based testing

Education

Bachelor's degree in CS/IT/cybersecurity

Tools

NIST SP 800-37
NIST SP 800-53
NIST SP 800-53A

Job description

Contingent Contract Award

National Capital Region(Hybrid/Onsite/Telework if approval)

Connected Logistics is seeking highly skilled and versatile Assessment Lead, to assist in providing the Department of State Directorate of Technology (DT), Enterprise Architecture (EA), Cyber Security Team (CST) comprehensive cybersecurity support services to protect critical consular systems and data. The CST Cyber portfolio ensures compliance with federal mandates including the Federal Information Security Modernization Act (FISMA) and the Risk Management Framework (RMF), encompassing security monitoring, incident response, threat detection, vulnerability management, and continuous authorization activities.

The Assessment Lead (AL) shall serve as Key Personnel responsible for the overall planning, coordination, execution, quality, and delivery of Security Control Assessment activities performed under this PWS. The AL shall provide technical leadership and oversight of assessment activities in accordance with applicable cybersecurity requirements, Department policies and procedures, and government-approved assessment methodologies.

The Assessment Lead (AL) shall lead and oversee Security Control Assessments in support of the Risk Management Framework (RMF), including RMF Step 4 - Assess, and shall ensure assessments provide the Government with an independent, objective, repeatable, and evidence-based determination of the effectiveness of implemented security and privacy controls.

Key Responsibilities
  • Serve as the primary contractor lead and subject matter expert for Security Control Assessment activities performed under this PWS.
  • Plan, coordinate, and oversee the execution of Security Control Assessments across assigned information systems and environments.
  • Develop and maintain assessment schedules, milestones, resource assignments, and assessment priorities in coordination with the Government.
  • Lead the development, review, and execution of Security Assessment Plans (SAPs), including assessment scope, control selection, assessment procedures, evidence requirements, testing methodology, and Rules of Engagement (ROE), as applicable.
  • Ensure assessment activities are performed in accordance with applicable versions of NIST Special Publication (SP) 800-37, NIST SP 800-53, NIST SP 800-53A, FISMA requirements, Department policies, and Government-established cybersecurity assessment procedures.
  • Provide technical direction and oversight to Security Control Assessors and other contractor personnel supporting assessment activities.
  • Review system security documentation, policies, procedures, technical configurations, architecture documentation, vulnerability scan results, penetration testing results, prior assessment findings, Plans of Action and Milestones (POA&Ms), and other supporting evidence necessary to determine control effectiveness.
  • Ensure assessors appropriately apply examination, interview, and testing procedures and that assessment conclusions are supported by sufficient and appropriate objective evidence.
  • Evaluate the implementation and effectiveness of security and privacy controls and identify control deficiencies, vulnerabilities, weaknesses, and associated cybersecurity risks.
  • Ensure assessment findings clearly document the condition identified, supporting evidence, applicable control or requirement, risk, and assessment determination.
  • Lead assessment entrance meetings, status meetings, technical discussions, findings reviews, and assessment exit briefings with Government and system stakeholders.
  • Coordinate assessment activities with System Owners, Information System Security Officers (ISSOs), Information System Security Managers (ISSMs), system administrators, security engineers, technical teams, and other Government-designated stakeholders.
  • Monitor assessment progress and proactively identify schedule risks, evidence deficiencies, technical issues, or other conditions that may affect successful completion of an assessment.
  • Maintain assessment independence and ensure assessment personnel do not assess controls for which they were directly responsible for implementing, except where specifically authorized by the Government.
  • Perform quality assurance reviews of assessment work products to ensure findings are technically accurate, consistent, adequately supported, and compliant with Government assessment standards.
  • Review and approve contractor-developed assessment documentation prior to submission to the Government.
  • Lead the preparation and delivery of Security Assessment Reports (SARs), assessment findings, risk summaries, executive-level briefings, and other required assessment deliverables.
  • Support validation and retesting activities to determine whether identified deficiencies have been successfully remediated.
  • Support the Government in evaluating residual risk and provide technical assessment information necessary to support authorization and risk-based decisions by the Authorizing Official (AO) and other designated Government officials.
  • Track assessment findings and deliverables through closure and ensure assessment records and supporting evidence are maintained in Government-designated repositories and cybersecurity tools.
  • Identify recurring control deficiencies, systemic weaknesses, and assessment trends and provide recommendations to the Government for improving security posture, assessment consistency, and RMF execution.
  • Ensure assessment activities and sensitive security information are handled in accordance with applicable Federal and Department security, privacy, records management, and information-handling requirements.
  • Provide assessment status, metrics, risks, accomplishments, and issues to the COR and other Government-designated personnel as required.
Requirements
  • Bachelor's in computer science, IT, cybersecurity or related field +8 years' conducting security control assessments.
  • Demonstrated experience with NIST SP 800-53A assessment procedures.
  • Additional demonstrated experience with NIST Special Publication (SP) 800-37, NIST SP 800-53, and FISMA requirements.
  • Must have active CISSP, CISA or equivalent, and CEH or equivalent penetration testing certification.
  • Current Secret clearance.
  • Experience working with the DoS preferred.
Total Rewards Statement

We believe in fairness and clarity throughout our hiring process. The anticipated salary range for this position is $155,000.00-$165,000.00 USD. This is a good-faith range based on factors such as your experience, geographic location, and any applicable contractual requirements, and may vary slightly.

Beyond salary, we provide a robust benefits package and encourage ongoing professional development, because your growth and well-being matter to us. We're excited to support you in building a rewarding career with us!

Connected Logistics respects the need for confidentiality for all applicants.

Connected Logistics has been named a 2026 WTOP Top Workplace in the medium sized business category. Our mission is clear: we deliver mission-focused IT, cybersecurity, logistics, and enterprise modernization support to federal agencies. When we invest in our people and create an environment where they feel valued and empowered, we deliver stronger outcomes for our clients and the missions we support.

Connected Logistics offers an excellent benefits package that includes health, dental, vision, life, and disability insurance, a great 401(k) package, and generous Paid Time Off.

EOE/Disability/Veterans

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Assessment Lead
Assessment Lead

Connected Logistics • Springfield (VA)

Hybrid
USD 155,000 - 165,000
Assessment Lead
Assessment Lead

Logc2 • Washington, Northern (KY)

Hybrid
USD 155,000 - 165,000
Cybersecurity Engineer
Cybersecurity Engineer

Connected-Logistics • Columbus (OH)

On-site
USD 110,000 - 155,000
Health benefits and 401(k)
Paid time off
Travel opportunities
Program Manager DT/EA/CST
Program Manager DT/EA/CST

Connected Logistics • Springfield (VA)

Hybrid
USD 175,000 - 185,000
Program Manager DT/EA/CST
Program Manager DT/EA/CST

Connected Logistics • Washington

Hybrid
USD 175,000 - 185,000
Health, dental, vision, life, anddisb
401(k) package
Paid Time Off
Program Manager DT/EA/CST
Program Manager DT/EA/CST

Socket.dev • Springfield (VA)

Hybrid
USD 175,000 - 185,000
Health, dental, vision insurance
401(k) plan
Paid Time Off
Assessment Lead
Assessment Lead

Paragon Technology • Washington

On-site
USD 120,000 - 190,000
Assessment Lead
Assessment Lead

Paragon Technology Group, Inc. • Washington

On-site
USD 140,000 - 200,000
Security Controls Assessor
Security Controls Assessor

ECS • Washington

Hybrid
USD 150,000 - 168,000
Assessment Lead
Assessment Lead

ADP, Inc. • Washington

On-site
USD 120,000 - 180,000