Duration: 18 Months | Possible for Extension
Travel: Occasional travel, including overnight stays, may be required
TWO OPENINGS
PAYRATE RANGE: $60-68 PER HOUR ON W2
Rate Flexibility:The manager is willing to review candidates above the target rate, particularly when they bring strong DevSecOps automation and/or AI assessment experience.
Experience Required:
- Security control assessment experience
- NIST 800-37 / 800-53 / 800-53A
- IT/Cloud security assessment experience
- Evidence review and control scoring
- Risk analysis and reporting
Preferred:
- AI security assessments
- Automated evidence collection
- Security assessment automation
- Data analytics for enterprise risk
Key Responsibilities
- Conduct comprehensive security control assessments to identify risks, vulnerabilities, weaknesses, and compliance gaps.
- Review and evaluate security controls, policies, procedures, and supporting documentation.
- Analyze assessment results and prioritize risks based on business and information security requirements.
- Provide recommendations and guidance to stakeholders on SAFR requirements, security best practices, and remediation activities.
- Review data and security evidence to support assessment and compliance decisions.
- Assist with implementing and integrating new security processes with existing organizational processes.
- Participate in projects involving new security processes, controls, and compliance initiatives.
- Develop and communicate security-related process changes to impacted stakeholders.
- Support risk management and continuous authorization activities.
- Collaborate with cross-functional teams to address security findings and improve the organization's overall security posture.
- Maintain strong documentation and attention to detail throughout the assessment and compliance lifecycle.
Required Qualifications
- Bachelor's degree in Computer Science, Information Security, Cybersecurity, or a related field, or equivalent experience.
- 3–5+ years of relevant information security experience.
- Proven hands‑on experience conducting security assessments and control evaluations.
- Strong knowledge of NIST SP 800-37, NIST SP 800-53, and/or NIST SP 800-53A.
- Experience with security compliance, risk management, governance, and continuous authorization.
- Experience reviewing security evidence/data and advising stakeholders on security requirements and best practices.
- Strong understanding of security controls, policies, procedures, risk assessment, and remediation.
- Excellent communication, collaboration, negotiation, and stakeholder‑management skills.
- Strong analytical and problem‑solving abilities with exceptional attention to detail.
Preferred Qualifications
- CISSP, CISA, or CISM certification.
- Experience working in a policy, security assurance, regulatory, financial, or quasi‑governmental environment.
- Familiarity with cloud security and cloud service providers.
- Knowledge of SAFR lifecycle compliance and testing.
- Experience with security governance, risk, and compliance (GRC) processes.