Security Assessor – RMF, NIST & Cloud Risk Expert

Sprymethods

Washington (District of Columbia)

On-site

USD 90,000 - 130,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Spry Methods is seeking a Security Assessor to join our DC team. You will conduct security assessments, review documentation, and interview personnel to evaluate controls and risks in cloud and on-prem environments.

The ideal candidate has 5+ years of security assessor experience, strong RMF and SA&A skills, and proficiency in NIST controls. You will prepare plans, reports, and POA&Ms and help customers understand risk and mitigation strategies.

Qualifications

  • Minimum 5 years of security assessor experience.
  • Experience in RMF process and in full cycle SA&A.
  • Experience testing NIST controls across admin and technical perspectives.
  • Ability to analyze vulnerability scans, interpret risks and perform manual checks.
  • Experience creating Security Assessment Plans, Reports and POA&Ms.
  • Strong cloud security experience (Azure in AWS environments).
  • CSAM knowledge is a plus.

Responsibilities

  • Conduct security assessments across cloud and on-prem environments.
  • Review documentation, perform interviews, and collect evidence.
  • Evaluate RMF compliance and prepare POA&Ms and formal reports.
  • Communicate risk findings and mitigation options to customers.
  • Lead SA&A activities through the full assessment lifecycle.

Skills

IT Security
Risk Management
Contingency Planning
Secure Data Communications
SA&A
Vulnerability Analysis
Risk Mitigation
Assessment Reports
RMF
Cloud Security
NIST Controls

Education

Bachelor's Degree
Specialized Experience (4 yrs)

Job description

Spry Methods is seeking a Security Assessor to join our DC team. You will conduct security assessments, review documentation, and interview personnel to evaluate controls and risks in cloud and on-prem environments.

The ideal candidate has 5+ years of security assessor experience, strong RMF and SA&A skills, and proficiency in NIST controls. You will prepare plans, reports, and POA&Ms and help customers understand risk and mitigation strategies.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Assessor: RMF & Cloud Risk Expert
Security Assessor: RMF & Cloud Risk Expert

Method, Inc. • Washington

On-site
USD 110,000 - 150,000
Security Assessor
Security Assessor

Sprymethods • Washington

On-site
USD 90,000 - 130,000
Security Assessor
Security Assessor

Method, Inc. • Washington

On-site
USD 110,000 - 150,000
Lead Cloud Security Assessor, FedRAMP Expert
Lead Cloud Security Assessor, FedRAMP Expert

Method, Inc. • Washington

On-site
USD 140,000 - 190,000
Senior Cloud Security Assessor
Senior Cloud Security Assessor

Method, Inc. • Washington

Hybrid
USD 150,000 - 190,000
Senior Cloud Security Assessor
Senior Cloud Security Assessor

Method, Inc. • Washington

On-site
USD 140,000 - 190,000
Senior Security Controls Assessor – RMF, NIST, SA&A
Senior Security Controls Assessor – RMF, NIST, SA&A

ECS • Washington

Hybrid
USD 150,000 - 168,000
Security Control Assessor
Security Control Assessor

RMantra Solutions • Virginia (MN)

On-site
USD 100,000 - 130,000
Senior Security Specialist - RMF, NIST & Cloud Risk
Senior Security Specialist - RMF, NIST & Cloud Risk

AnaVation LLC • Washington

On-site
USD 140,000 - 180,000
Medical insurance (employee and depend
Dental insurance (employee and depend)
Disability insurance
+5
Federal Security Controls Assessor (RMF/NIST) - Remote
Federal Security Controls Assessor (RMF/NIST) - Remote

Viateq Corporation • Washington

Hybrid
USD 100,000 - 130,000
Medical insurance
Dental insurance
Vision insurance
+3