Assessment Lead

Athena Technology Group

$110K — $130K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • Active Secret security clearance required
  • Bachelor's degree or higher essential
  • 10+ years of experience in RMF and SCA activities
  • US citizenship mandatory
  • Experience with a dispersed workforce preferred

Responsibilities

  • Lead and oversee Security Control Assessments according to the Risk Management Framework (RMF)
  • Serve as the primary contact and subject matter expert for assessment activities
  • Plan and coordinate execution of assessments across information systems
  • Develop and maintain assessment schedules and priorities with the Government
  • Ensure compliance with NIST and FISMA requirements during assessment activities
  • Provide technical direction to Security Control Assessors
  • Review and validate system security documentation and prior findings
  • Monitor assessment progress and proactively identify potential issues
  • Lead assessment meetings and discussions with Government stakeholders
  • Deliver comprehensive Security Assessment Reports (SARs) and briefings

Benefits

  • Performance bonuses and annual salary reviews
  • Health, dental, and vision insurance
  • Disability and life insurance options
  • 401(k) plan with company match
  • Opportunities for professional growth and development
  • Collaborative and inclusive work environment
Full Job Description
Employment Type: Full-Time
** This position is contingent upon award of the contract.

Job Summary
We are seeking an Assessment Lead to join our team. In this role, you will oversee subject matter experts and technical personnel who provide direct information technology assistance to Government clients. This person is responsible for the overall planning, coordination, execution, quality and delivery of Security Control Assessment Activities preformed. This individual shall provide technical leadership and oversight of assessment activities in accordance with the applicable Federal cybersecurity requirements, department policies and procedures and Government-approved assessment methodologies.
** This position is contingent upon award of the contract.
Key Responsibilities
  • Lead and oversee Security Control Assessments in support of the Risk Management Framework (RMF), including RMF Step 4 - Assess, and shall ensure assessments provide the Government with an independent, objective, repeatable, and evidence-based determination of the effectiveness of implemented security and privacy controls
  • Serve as the primary contractor lead and subject matter expert for Security Control Assessment activities performed under this PWS.
  • Plan, coordinate, and oversee the execution of Security Control Assessments across assigned information systems and environments.
  • Develop and maintain assessment schedules, milestones, resource assignments, and assessment priorities in coordination with the Government.
  • Lead the development, review, and execution of Security Assessment Plans (SAPs), including assessment scope, control selection, assessment procedures, evidence requirements, testing methodology, and Rules of Engagement (ROE), as applicable.
  • Ensure assessment activities are performed in accordance with applicable versions of NIST Special Publication (SP) 800-37, NIST SP 800-53, NIST SP 800-53A, FISMA requirements, Department policies, and Government-established cybersecurity assessment procedures.
  • Provide technical direction and oversight to Security Control Assessors and other contractor personnel supporting assessment activities.
  • Review system security documentation, policies, procedures, technical configurations, architecture documentation, vulnerability scan results, penetration testing results, prior assessment findings, Plans of Action and Milestones (POA&Ms), and other supporting evidence necessary to determine control effectiveness.
  • Ensure assessors appropriately apply examination, interview, and testing procedures and that assessment conclusions are supported by sufficient and appropriate objective evidence.
  • Evaluate the implementation and effectiveness of security and privacy controls and identify control deficiencies, vulnerabilities, weaknesses, and associated cybersecurity risks.
  • Ensure assessment findings clearly document the condition identified, supporting evidence, applicable control or requirement, risk, and assessment determination.
  • Lead assessment entrance meetings, status meetings, technical discussions, findings reviews, and assessment exit briefings with Government and system stakeholders.
  • Coordinate assessment activities with System Owners, Information System Security Officers (ISSOs), Information System Security Managers (ISSMs), system administrators, security engineers, technical teams, and other Government-designated stakeholders.
  • Monitor assessment progress and proactively identify schedule risks, evidence deficiencies, technical issues, or other conditions that may affect successful completion of an assessment.
  • Maintain assessment independence and ensure assessment personnel do not assess controls for which they were directly responsible for implementing, except where specifically authorized by the Government.
  • Perform quality assurance reviews of assessment work products to ensure findings are technically accurate, consistent, adequately supported, and compliant with Government assessment standards.
  • Review and approve contractor-developed assessment documentation prior to submission to the Government.
  • Lead the preparation and delivery of Security Assessment Reports (SARs), assessment findings, risk summaries, executive-level briefings, and other required assessment deliverables.
  • Support validation and retesting activities to determine whether identified deficiencies have been successfully remediated.
  • Support the Government in evaluating residual risk and provide technical assessment information necessary to support authorization and risk-based decisions by the Authorizing Official (AO) and other designated Government officials.
  • Track assessment findings and deliverables through closure and ensure assessment records and supporting evidence are maintained in Government-designated repositories and cybersecurity tools.
  • Identify recurring control deficiencies, systemic weaknesses, and assessment trends and provide recommendations to the Government for improving security posture, assessment consistency, and RMF execution.
  • Ensure assessment activities and sensitive security information are handled in accordance with applicable Federal and Department security, privacy, records management, and information-handling requirements.
  • Provide assessment status, metrics, risks, accomplishments, and issues to the COR and other Government-designated personnel as required.
Qualifications
Required:
  • Active Secret
  • Bachelor's degree or higher
  • 10 years of professional experience in RMF and SCA activities
  • Must be a US citizen
Desired:
  • Experience supporting a client with disperse workforce in a variety of locations
Physical and Environmental Conditions
  • Normal Office Environment. Requires Sitting, Standing, Near Acuity, Speaking with colleagues and customers, Listening, Sight, Use of hands/fingers.

Additional Benefits
  • Performance Bonuses and annual salary reviews
  • Health, dental, and vision insurance
  • Short Term Disability, Long Term Disability, and Life Insurance
  • 401(k) plan with company match
  • Opportunities for professional growth and development
  • A collaborative and inclusive work environment

Similar Jobs

More Jobs at Athena Technology Group

More Information Technology Jobs

Find similar Assessment Lead jobs: