Security Assessor

Sprymethods

Washington (District of Columbia)

On-site

USD 90,000 - 130,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Spry Methods is seeking a Security Assessor to join our DC team. You will conduct security assessments, review documentation, and interview personnel to evaluate controls and risks in cloud and on-prem environments.

The ideal candidate has 5+ years of security assessor experience, strong RMF and SA&A skills, and proficiency in NIST controls. You will prepare plans, reports, and POA&Ms and help customers understand risk and mitigation strategies.

Qualifications

  • Minimum 5 years of security assessor experience.
  • Experience in RMF process and in full cycle SA&A.
  • Experience testing NIST controls across admin and technical perspectives.
  • Ability to analyze vulnerability scans, interpret risks and perform manual checks.
  • Experience creating Security Assessment Plans, Reports and POA&Ms.
  • Strong cloud security experience (Azure in AWS environments).
  • CSAM knowledge is a plus.

Responsibilities

  • Conduct security assessments across cloud and on-prem environments.
  • Review documentation, perform interviews, and collect evidence.
  • Evaluate RMF compliance and prepare POA&Ms and formal reports.
  • Communicate risk findings and mitigation options to customers.
  • Lead SA&A activities through the full assessment lifecycle.

Skills

IT Security
Risk Management
Contingency Planning
Secure Data Communications
SA&A
Vulnerability Analysis
Risk Mitigation
Assessment Reports
RMF
Cloud Security
NIST Controls

Education

Bachelor's Degree
Specialized Experience (4 yrs)

Job description

Who We’re Looking For (Position Overview):

Spry Methods is on the search for a Security Assessor to join our team in DC.



  • Strong working knowledge of IT Security requirements, technical security countermeasures, risk managements processes, contingency planning, and secure data communications

  • Demonstrated experience conducting full cycle SA&A

  • Testing will include network, system, applicationand NIST control testing from administrative and technical perspectives

  • Experience analyzing vulnerability scans and interpreting risks and employing manual checks to validate vulnerability data

  • Be able to assist the customer withunderstanding risk and providing risk mitigation

  • Will create Security Assessments Plans, Reports, and POA&Ms

  • The securityassessment team conducts documentation reviews, inspections, and interviews with key personnel knowledgeable/ responsible for the various controls

  • Personnel interviewed are asked to showevidence of compliance,demonstration security features, provide access to (or screenshotsof) configuration files and system logs, and perform tests

  • Thedetermination of compliance will be based upon responses to questions and analysis ofsupporting evidence..

  • Knowledge of CSAMis a plus

  • Strong cloud experience - conducting security assessments of MS Azure in AWS environments.

  • At least 5 years experience

  • Bachelor's Degree or 4 years of specialized experience

  • Strong security assessor background

  • Must understand the Risk Management Framework (RMF) process

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Assessor
Security Assessor

Method, Inc. • Washington

On-site
USD 110,000 - 150,000
Security Assessor: RMF & Cloud Risk Expert
Security Assessor: RMF & Cloud Risk Expert

Method, Inc. • Washington

On-site
USD 110,000 - 150,000
Security Assessor – RMF, NIST & Cloud Risk Expert
Security Assessor – RMF, NIST & Cloud Risk Expert

Sprymethods • Washington

On-site
USD 90,000 - 130,000
Senior Cloud Security Assessor
Senior Cloud Security Assessor

Method, Inc. • Washington

Hybrid
USD 150,000 - 190,000
Senior Cloud Security Assessor
Senior Cloud Security Assessor

Method, Inc. • Washington

On-site
USD 140,000 - 190,000
Lead Cloud Security Assessor, FedRAMP Expert
Lead Cloud Security Assessor, FedRAMP Expert

Method, Inc. • Washington

On-site
USD 140,000 - 190,000
TS/SCI Security Control Assessor
TS/SCI Security Control Assessor

Insight Global • Denver (CO)

On-site
USD 110,000 - 150,000
Security Control Assessor
Security Control Assessor

Omniscius Consulting • Arlington (VA)

On-site
USD 120,000 - 180,000
Senior Security Controls Assessor (TS/SCI #26-143)
Senior Security Controls Assessor (TS/SCI #26-143)

Strategic Analysis, Inc. • Arlington (VA)

On-site
USD 120,000 - 180,000
Security Control Assessor
Security Control Assessor

Caliber Systems Inc. • Denver (CO), Northern (KY)

Hybrid
USD 94,000 - 127,000