Cybersecurity Assessor

CompQsoft Inc

New York (NY)

Hybrid

USD 120,000 - 160,000

Full time

33 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

CompQsoft Inc. is seeking a Cybersecurity Assessor to evaluate enterprise systems, networks, and applications for vulnerabilities and regulatory compliance, with a focus on documenting findings and actionable remediation plans.

The role emphasizes RMF lifecycle control assessments, POA&M tracking, and cross-functional communication using Archer/ServiceNow, Power BI, and MS Excel. Based in New York, you will collaborate with business and IT teams to strengthen security controls and reduce

Qualifications

  • Experience with NIST SP 800-53 and 800-37 and regulatory compliance interpretation.
  • Expertise in third-party risk assessments and remediation tracking.
  • Ability to document findings and provide actionable remediation plans.

Responsibilities

  • Conduct security and compliance assessments across internal systems and third-party vendors.
  • Analyze findings and support remediation efforts; track POA&M documentation.
  • Collaborate with business and technical teams to translate requirements into concrete actions.
  • Maintain risk documentation and dashboards to communicate security posture.

Skills

GRC methodologies
Security control auditing
Third-party risk assessments
POA&M management
Risk reporting
Cross-functional coordination
Data-driven risk reporting

Tools

Archer
ServiceNow
OneTrust
Prevalent
Power BI
Excel
Visio
JIRA

Job description

Certification: CISA, CRISC, CGEIT, CISSP, CompTIA Security+, CCSK, CAP/ISC2 CGRC

The Cybersecurity Assessor evaluates enterprise systems, networks, and applications to identify vulnerabilities, assess risks, and

ensure compliance with security policies and regulatory standards. They provide actionable recommendations and collaborate with

technical and business teams to strengthen security controls and reduce organizational risk.

Requirements
Key Requirements
  • Expertise in GRC methodologies, security control auditing, and third-party risk assessments. Proven ability to interpret federal compliance mandates (NIST SP 800-53, 800-37) and evaluate technical and administrative controls. Strong competency in conducting "Security Impact Analyses" and managing Plan of Action and Milestones (POA&M) documentation. Compliance & Assessment Support: Conduct security and compliance assessments across internal systems and third-party vendors, supporting adherence to organizational and regulatory requirements.
  • Third-Party Risk Assessments: Evaluate the security practices of external service providers and assist with managing vendor[1]related risks throughout the assessment of lifecycle.
  • Findings & Remediation Tracking: Analyze assessment results, document findings, and support remediation efforts by tracking issues and helping teams prioritize corrective actions.
  • Cross-Functional Coordination: Work with business and technical stakeholders to clarify compliance requirements and support the resolution of identified risks within accepted thresholds.
  • Risk Documentation & Reporting: Use risk management tools and reporting dashboards to maintain assessment documentation, track risk metrics, and contribute to security posture reporting.
  • Cross-Functional Synergy: Serve as a bridge between Business Analysts and Cybersecurity Engineers, translating compliance requirements into actionable remediation tasks while maintaining organizational risk thresholds.
  • GRC Tool Proficiency: Use industry-standard GRC platforms (e.g., Archer, ServiceNow) and Third-Party Risk tools (e.g., OneTrust, Prevalent) to centralize documentation and streamline assessment workflows.
  • Data-Driven Risk Reporting: Convert complex assessment findings into actionable insights with Power BI and Excel, maintaining dashboards that communicate enterprise security posture to stakeholders.
  • Security Control Execution & Validation: Perform daily RMF lifecycle control assessments, including evidence collection, walkthroughs, testing of technical/administrative controls, and POA&M tracking to ensure risk remains within tolerance.

Experience: 5+ years

Certifications: CISA, CRISC, CGEIT, CISSP, CompTIA Security+, CCSK, CAP/ISC2 CGRC

Technologies: GRC Platforms (Archer/ServiceNow), Third-Party Risk Tools (OneTrust/Prevalent), MS Excel (Advanced), MS Power BI, MS Visio, JIRA, and Microsoft Office Suite.

CompQsoft provides equal opportunity in all aspects of employment and in the working environment to all employees and applicants. CompQsoft does not take any non-merit factors like race, color, religion, sex (gender), mental/physical disability, and age into account for purposes of recruitment, hiring and development.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cyber Risk Management Analyst
Cyber Risk Management Analyst

CompQsoft Inc • New York (NY)

Hybrid
USD 120,000 - 160,000
Cybersecurity GRC Assessor - Risk & Compliance
Cybersecurity GRC Assessor - Risk & Compliance

CompQsoft Inc • New York (NY)

Hybrid
USD 120,000 - 160,000
GRC Lead
GRC Lead

Acuren • Houston (TX)

On-site
USD 120,000 - 180,000
GRC (Governance, Risk, and Compliance) Consultant
GRC (Governance, Risk, and Compliance) Consultant

Zoho • United States

Remote
USD 120,000 - 180,000
Security Business Analyst
Security Business Analyst

CompQsoft Inc • New York (NY)

Hybrid
USD 110,000 - 150,000
Senior Cybersecurity Risk & Governance Analyst
Senior Cybersecurity Risk & Governance Analyst

mTrade • Oxford (MS)

On-site
USD 110,000 - 160,000
GRC Analyst
GRC Analyst

The Emery Company, LLC • Houston (TX)

On-site
USD 85,000 - 110,000
Cybersecurity Governance Analyst
Cybersecurity Governance Analyst

Veriipro • Fort Lauderdale (FL)

On-site
USD 90,000 - 130,000
Cybersecurity Risk Manager
Cybersecurity Risk Manager

Jobright.ai • Chicago (IL)

On-site
USD 120,000 - 180,000
Competitive benefits starting day one
Governance, Risk and Compliance Analyst Senior
Governance, Risk and Compliance Analyst Senior

Cone Health • Greensboro (NC)

On-site
USD 90,000 - 130,000