SecureIT · 7 hours ago
Senior FedRAMP Assessor, Technical
Maximize your interview chances
Information Technology
Insider Connection @SecureIT
Get 3x more responses when you reach out via email instead of LinkedIn.
Responsibilities
Lead a team comprised of 3-5 team members during client interviews and assessment of controls for assigned FedRAMP engagements
Manage project tasks and hours to ensure utilization targets are achieved, assessments are being effectively executed, and sufficient testing has been performed to support our assessment
Prepare and review the Security Assessment Plan (SAP), Risk Exposure Table (RET), and Security Assessment Report (SAR)
Provide technical guidance to the team during the development of interview questions to ensure requested evidence/artifacts are specific to assigned controls
Execute test procedures, as appropriate, against in-scope cloud components in accordance with FedRAMP, FISMA, and NIST 800-53A R4/R5 requirements for the more complex technical and operational controls
Interface with clients throughout the entire engagement to address questions/comments related to assessment findings and/or client issues
Escalate client and/or project issues in a timely manner
Review and validate all artifacts and evidence collected during the assessment are complete and meet FedRAMP requirements
Perform QA of assessment work throughout the project lifecycle
Maintain strong depth of knowledge regarding NIST 800-53 Rev 5 and FedRAMP requirements
Provide mentorship, technical guidance, and coaching to team members
Qualification
Find out how your skills align with this job's requirements. If anything seems off, you can easily click on the tags to select or unselect skills to reflect your actual expertise.
Required
7+ years of progressive experience in technical security assessment within a professional services capacity, including 2+ years of experience with FedRAMP
Excellent oral and written communication skills on deep technical subject matter and higher-level general security and risk management-related concepts
Bachelor’s degree in Computer Science, Information Systems, Cybersecurity or a related discipline or 3-4 years of equivalent years of experience
Current knowledge of and experience with FedRAMP (Rev 5) requirements and strong level knowledge of NIST 800-53 control families
Strong analytical skills
Extensive understanding of cloud computing technologies
In-depth knowledge and experience assessing (or advising on) cloud architecture, configurations, and technical cyber/compliance requirements and best practices
Industry recognized professional certification—min. CISSP and one other. The additional certification should be from the following list: CompTIA Advanced Security Practitioner (CASP+) Continuing Education (CE), GIAC Certified Enterprise Defender (GCED), GIAC Certified Incident Handler (GCIH), GIAC Security Leadership (GSLC), Certified Information Systems Auditor (CISA), Certified Information Security Manager (CISM), Certified Cloud Security Professional (CCSP), CISSP-Information Systems Security Architecture Professional (CISSP-ISSAP), CISSP-Information Systems Security Engineering Professional (CISSP-ISSEP), CISSP-Information Systems Security Management Professional (CISSP-ISSMP), CyberSec First Responder (CFR), Certified Chief Information Security Officer (CCISO)
Preferred
Successful completion of the Baltimore Cyber Range (BCR) program.
Other professional certifications: Cisco Certified Network Associate Security (CCNA Security), Cisco Certified Network Associate Cyber Security Operations (CCNA Cyber Ops), Cybersecurity Analyst (CySA+), GIAC Systems and Network Auditor (GSNA), GIAC Certified Intrusion Analyst (GCIA), Certified Secure Software Lifecycle Professional (CSSLP), Certified Information Systems Security Officer (CISSO), CompTIA Cloud+ (Cloud+), Global Industrial Cyber Security Professional (GICSP), Securing Cisco® Networks with Threat Detection Analysis (SCYBER)