Job Summary:
The Lead Security Assessor will serve as the primary authority for security control assessments compliance with a specific framework and mapping evidence to various regulatory requirements. This role involves leading assessment methodologies creating control mappings developing interview scripts validating artifacts and producing detailed control-level narratives. The assessor will also prepare reporting artifacts provide oversight for sampling strategies validate inherited controls from cloud providers review system security plan inputs and support executive briefings by translating technical results into business risk.
Location:Madison Wisconsin United States
Responsibilities:
- Lead assessment methodology and ensure compliance with a specific framework.
- Create control mappings and maintain traceability matrices.
- Develop interview scripts validate artifacts and assess compliance.
- Produce detailed control-level narratives (pass/partial/fail with risk scoring).
- Prepare reporting artifacts.
- Provide oversight for sampling strategy and test depth per SOW.
- Validate inherited controls from cloud providers.
- Review SSP inputs and verify alignment with assessment evidence.
- Support executive briefings by translating technical results into business risk.
Required Skills & Certifications:
- Deep expertise in NIST 800-53 Rev5 MARS-E 2.2 specific control cycles and ARC-AMPE requirements.
- Able to interpret and test a large number of controls per cycle.
- Experience validating security documentation boundary controls IAM auditing logging and monitoring.
- Familiarity with vulnerability findings segmentation designs and change management validation.
- CISSP Certification.
- Security Certification (Minimum baseline).
Preferred Skills & Certifications:
- CISA or CCSK/CCSP Certification.
- Certified NIST 800-53 Practitioner / HITRUST CCSFP Certification.
Special Considerations:
- None specified.
Scheduling:
- Not specified.
Job Summary: The Lead Security Assessor will serve as the primary authority for security control assessments compliance with a specific framework and mapping evidence to various regulatory requirements. This role involves leading assessment methodologies creating control mappings developing intervi...
Job Summary:
The Lead Security Assessor will serve as the primary authority for security control assessments compliance with a specific framework and mapping evidence to various regulatory requirements. This role involves leading assessment methodologies creating control mappings developing interview scripts validating artifacts and producing detailed control-level narratives. The assessor will also prepare reporting artifacts provide oversight for sampling strategies validate inherited controls from cloud providers review system security plan inputs and support executive briefings by translating technical results into business risk.
Location:Madison Wisconsin United States
Responsibilities:
- Lead assessment methodology and ensure compliance with a specific framework.
- Create control mappings and maintain traceability matrices.
- Develop interview scripts validate artifacts and assess compliance.
- Produce detailed control-level narratives (pass/partial/fail with risk scoring).
- Prepare reporting artifacts.
- Provide oversight for sampling strategy and test depth per SOW.
- Validate inherited controls from cloud providers.
- Review SSP inputs and verify alignment with assessment evidence.
- Support executive briefings by translating technical results into business risk.
Required Skills & Certifications:
- Deep expertise in NIST 800-53 Rev5 MARS-E 2.2 specific control cycles and ARC-AMPE requirements.
- Able to interpret and test a large number of controls per cycle.
- Experience validating security documentation boundary controls IAM auditing logging and monitoring.
- Familiarity with vulnerability findings segmentation designs and change management validation.
- CISSP Certification.
- Security Certification (Minimum baseline).
Preferred Skills & Certifications:
- CISA or CCSK/CCSP Certification.
- Certified NIST 800-53 Practitioner / HITRUST CCSFP Certification.
Special Considerations:
- None specified.
Scheduling:
- Not specified.
View more
View less