Managing Security Consultant - Assessor

NCC Group

Alpharetta, Northern (GA, KY)

Hybrid

USD 155,000 - 195,000

Full time

2 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Flexible Working
25 days holiday
Pension
Life Assurance
Cycle to Work
Green Car Scheme

Job summary

NCC Group is seeking an accomplished Managing Security Consultant / Senior Assessor to lead FedRAMP-related engagements and advisory work within its Government Services practice in the United States. The role centers on federal cybersecurity compliance, cloud security assessments, and risk management, with leadership responsibilities across assessment teams and client relationships.

The ideal candidate will have extensive experience with FedRAMP, NIST frameworks, and secure cloud architectures.

Qualifications

  • Significant experience with FedRAMP assessment methodologies and advisory services.
  • Strong knowledge of NIST SP 800-53 controls and assessment practices.
  • Proven ability to lead multi-disciplinary security assessment teams and deliver both assurance and advisory engagements.
  • Experience with government programs and regulated environments.

Responsibilities

  • Lead FedRAMP authorisation and continuous monitoring assessments as Lead Assessor.
  • Oversee teams evaluating cloud services against FedRAMP and NIST requirements.
  • Review assessment evidence, reports, and testing methodologies for quality and accuracy.
  • Provide advisory readiness services for FedRAMP Rev5, RMF, and related frameworks.
  • Support pre-sales activities, scopes, and SOWs; contribute to proposal development.
  • Mentor junior assessors and drive assessment methodology improvements.
  • Engage with clients at executive levels and support business development.

Skills

FedRAMP Assessments
NIST SP 800-53
Cloud Security
Risk Management
Team Leadership
Client Engagement

Education

CISSP
Baltimore Cyber Range Certification

Job description

Managing Security Consultant - Assessor

Department: Cyber Services and Capabilities

Employment Type: Full Time

Location: USA Alpharetta

Reporting To: Bill Cameron

Description

Location - New York, Chicago, Atlanta or Alpharetta

NCC Group (US) is seeking an experienced and highly respected Managing Security Consultant / Senior Assessor to support and help lead the delivery of Federal cybersecurity assessment and advisory services within its accredited FedRAMP Third Party Assessment Organization (3PAO) practice.

This position represents a senior technical and consulting role within the Government Services organization. The successful candidate will be recognized as a trusted subject matter expert in Federal cybersecurity compliance, cloud security assessments, and risk management. The individual will lead complex assessment engagements, provide strategic advisory services, mentor assessment teams, contribute to business development efforts, and support the continued growth and maturity of NCC Group's government security offerings.

The role requires a deep understanding of FedRAMP assessment methodologies, Federal cybersecurity frameworks, cloud technologies, and independent auditing principles. The ideal candidate combines technical expertise with strong leadership, communication, and client relationship management capabilities.

Key Responsibilities
Assessment Leadership
  • Serve as a Lead Assessor for FedRAMP authorisation and continuous monitoring assessments
  • Lead assessment teams responsible for evaluating cloud service providers against FedRAMP and NIST requirements
  • Conduct independent evaluation of security controls, cloud architectures, operational processes and risk management programmes
  • Review testing methodologies, assessment evidence and assessment reports for accuracy and quality
  • Ensure assessment activities comply with FedRAMP, 3PAO and organisational quality requirements
  • Identify deficiencies, risks and opportunities for improvements and communicate findings clearly to clients and stakeholders
  • Support quality assurance activities and peer reviews across Government Services engagements
Advisory Services
  • Provide advisory and readiness services related to:
  • FedRAMP- Rev5 and FedRAMP20x
  • CMMC / DFARS 7012 cybersecurity requirements
  • Secure cloud adoption and governance
  • NIST Risk Management Framework (RMF
  • Assist organisations in developing compliance roadmaps and remediation strategies
  • Advise clients on cybersecurity governance, risk management and control implementation
Business Development and Client Engagement
  • Support pre-sales activities, including opportunities qualification, customer briefings, project scoping and proposal development
  • Develop Statements of Work (SOWs), project plans, assumptions and costs.
  • Participate in client workshops and executive-level discussions
  • Act as a trust advisor to customers throughout engagement lifecycles
  • Contribute thought leadership to support the growth of NCC Group’s Government Services practice
Team Leadership
  • Support the mentorship and coaching of Junior assessors and consultants
  • Support workforce development and assessment methodology improvements
  • Assist practice leadership with service delivery planning and operational initiatives
  • Promote assessment consistency, quality and professional excellence across engagement teams
Skills, Knowledge and Expertise
Professional Experience
  • Demonstrated expertise in information security, cybersecurity consulting, auditing, compliance, risk management, or related disciplines including management of IT organizations.
  • Experience with FedRAMP Assessments and or Advisory Services.
  • Must have extensive experience of auditing and/or assessment experience,
  • Experience leading multi-disciplinary security assessment teams
  • Experience delivering both assurance (assessment) and advisory consulting engagements
  • Experience operating in highly regulated environments requiring exceptional attention to detail and documentation quality
Government & Industry Experience
  • U.S. Citizen authorized to work in the United States.
  • Ability to successfully complete required background investigations.
  • Strong understanding of U.S. Government cybersecurity programs and compliance requirements.
  • Experience supporting Federal agencies, defense contractors, cloud service providers, or other government-regulated organizations.
  • Familiarity with government acquisition and cybersecurity compliance environments.
  • Understanding of software supply chain and cloud ecosystem security considerations.
Cloud & Technical Experience
  • Demonstrated experience assessing and securing cloud computing environments across SaaS, PaaS, IaaS, cloud-native, and hybrid architectures
  • Strong understanding of security controls, risk assessment, and remediation within enterprise environments.
Functional Expertise

Candidates must demonstrate significant expertise in:

  • FedRAMP authorization processes and assessment methodologies.
  • NIST SP 800-53 security controls and control assessment practices.
  • NIST 800-171 and NIST 800-171A
  • Federal cybersecurity compliance programs.
  • Security risk management and risk-based decision making.
  • Security assessment report development and quality review.
  • Executive briefing and stakeholder communications.
Desirable:
  • Experience advising on CMMC requirements and implementation.
  • Experience working with DFARS cybersecurity requirements.
  • Understanding of Federal Executive Orders impacting cybersecurity and software supply chain security.
  • Experience supporting GovRAMP assessments.
  • Familiarity with ISO/IEC 17020 requirements and accreditation standards.
  • Experience supporting accredited conformity assessment organizations or testing laboratories.
Required Certifications
  • Certified Information Systems Security Professional (CISSP)
  • Baltimore Cyber Range Technical Proficiency Certification
Benefits
What do we offer in return?

We have a high-performance culture which is balanced evenly with world-class well-being initiatives and benefits:

  • Flexible Working: Balance your work and personal life with our flexible working options.
  • Generous Holiday Allowance: Enjoy 25 days of holiday, plus bank holidays, with the option to buy up to 5 additional days of annual leave.
  • Medicash & Critical Illness Scheme
  • Financial & Investment Benefits: Enjoy peace of mind with our Pension, Life Assurance, and Share Save Scheme.
  • Community & Volunteering Programmes: Make a difference in your community with our volunteering opportunities.
  • Green Car Scheme: Drive green and save money with our eco-friendly car scheme.
  • Cycle Scheme: Stay fit and healthy with our cycle-to-work scheme.
  • Special Time Off: Take time off for those big moments in life, like getting married/entering into a civil partnership, becoming a grandparent, and welcoming home a new pet.
  • Family Planning: Benefit from our generous maternity and paternity leave, as well as time off and support for those undergoing fertility treatments.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Managing Security Consultant - Assessor
Managing Security Consultant - Assessor

Socket.dev • Alpharetta (GA)

On-site
USD 120,000 - 180,000
Flexible Working
25 days holiday + bank holidays
Pension
+6
Managing Security Consultant - Assessor
Managing Security Consultant - Assessor

nccgroup • Alpharetta (GA)

On-site
USD 140,000 - 210,000
Strategic Cyber Advisory Director
Strategic Cyber Advisory Director

NCC Group • California (MO)

On-site
USD 180,000 - 280,000
Flexible working
401k
Health & Dental Insurance
+7
Strategic Cyber Advisory Director
Strategic Cyber Advisory Director

NCC Group • New York (NY)

Hybrid
USD 180,000 - 250,000
Flexible working
401k
Health & dental Insurance
+7
Strategic Cyber Advisory Director
Strategic Cyber Advisory Director

NCC Group • Illinois

Hybrid
USD 180,000 - 240,000
Flexible working
Financial & Investment
401k
+8
Strategic Cyber Advisory Director
Strategic Cyber Advisory Director

NCC Group • Northern (KY)

Hybrid
USD 150,000 - 230,000
Flexible working
401k
Health & Dental Insurance
+7
TASS (Current Contract) - Cloud Assessment Lead Cybersecurity Engineer – Sr (Cloud Security Ass[...]
TASS (Current Contract) - Cloud Assessment Lead Cybersecurity Engineer – Sr (Cloud Security Ass[...]

AGE Solutions LLC • Fort Meade (MD)

On-site
USD 115,000 - 130,000
26 Days Paid Leave
Performance Bonuses
401(k) with Match
+3
Security Control Assessor
Security Control Assessor

Novul Solutions • Arlington (TX)

On-site
USD 120,000 - 180,000
Paid Time Off (PTO)
Holidays
401(k) match
+2
Senior FedRAMP Assessor & Cloud Security Leader
Senior FedRAMP Assessor & Cloud Security Leader

Socket.dev • Alpharetta (GA)

On-site
USD 120,000 - 180,000
Flexible Working
25 days holiday + bank holidays
Pension
+6
Cyber Cloud Assessment Engineer, Sr.
Cyber Cloud Assessment Engineer, Sr.

Age Solutions • Fort Meade (MD)

On-site
USD 110,000 - 150,000
26 Days Paid Leave
Performance Bonuses
401(k) with Match
+4