IT System Assessor
Core
Evaluate enterprise IT infrastructure systems by conducting independent security control assessments, developing Security Assessment Reports (SARs), and creating Plans of Action and Milestones (POAMs) to ensure compliance with NIST standards and minimize risks to sensitive data.
Role type
Senior IC IT System Assessor (Security Assessment and Authorization)
Builds
Security Assessment Reports (SARs), Plans of Action and Milestones (POAMs), Authority to Operate (ATO) packages, and Standard Operating Procedures (SOPs) for SA&A.
Domain
Federal IT Cyber Security / Risk Management Framework (RMF)
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Security Assessment and Authorization (SA&A), Risk Management Framework (RMF), NIST SP 800-53, NIST SP 800-37, Privacy Impact Assessments (PIAs), Incident Response planning, Contingency planning, Cloud systems (AWS/Azure/Google), SaaS platforms, Public Trust adjudication
Preferred skills
CISA, CISSP, CompTIA Security+, CompTIA Network+, Certified Cloud Certificates, ICAM solutions (Active Directory, SailPoint, CyberArk), Vulnerability scanning, Security monitoring tools (Splunk, Tenable, Sentinel), Power BI, API configuration
Technologies
NIST SP 800-53, NIST SP 800-37, FIPS 199, FedRAMP, AWS, Azure, Google Cloud, Microsoft 365, Active Directory, SailPoint, CyberArk, Splunk, Tenable, Sentinel, CloudWatch, Security Center, Power BI, Power App
Responsibilities
Conduct security control assessments through an independent team; Perform interviews and test controls; Develop and maintain SOPs for SA&A; Identify key roles and develop cybersecurity responsibility matrices; Advise senior management on privacy and data protection best practices.
Seniority
Senior, hands-on IC