Cherokee Nation Businesses

Assessment Lead

Cherokee Nation Businesses$110K — $130K *
Education, Government & Non-Profit
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in cybersecurity or related field.
  • 8 years of cybersecurity assessment experience.
  • CISSP, CISA, or equivalent certification required.
  • CEH or equivalent penetration-testing certification.
  • Active Top Secret (TS) clearance mandatory.
  • U.S. citizenship required.
  • Experience with NIST and federal penetration-testing methodologies preferred.
  • Familiarity with CISA directives and federal audit requirements preferred.

Responsibilities

  • Lead independent Security Control Assessments under RMF Step 4.
  • Develop Security Assessment Plans and Reports.
  • Assess NIST SP 800-53 security controls.
  • Conduct interviews and examine technical evidence.
  • Validate vulnerability findings and remediation evidence.
  • Present findings and risk recommendations to stakeholders.
  • Maintain independence between assessment and control-implementation functions.

Benefits

  • Medical, Dental, and Vision insurance coverage.
  • 401K retirement plan options available.
  • Potential for additional benefits as provided.
Full Job Description
Job Description

Assessment Lead

The Assessment Lead is a senior security-control assessor responsible for conducting independent assessments of federal information systems. This position leads technical and compliance assessments, tests the effectiveness of NIST security controls, evaluates technical evidence, documents findings, and communicates system risk to senior government stakeholders.
Compensation & Benefits

Pay commensurate with experience.

Full-time benefits include Medical, Dental, Vision, 401K, and other possible benefits as provided. Benefits are subject to change with or without notice.
Assessment Lead Responsibilities Include:
  • Lead independent Security Control Assessments under RMF Step 4.
  • Develop Security Assessment Plans and Security Assessment Reports.
  • Assess NIST SP 800-53 security controls and control enhancements.
  • Review SSPs, implementation statements, policies, procedures, diagrams, inventories, and technical evidence.
  • Conduct interviews, examine artifacts, and test technical and administrative controls.
  • Identify control deficiencies and assign defensible risk ratings.
  • Validate vulnerability findings, remediation evidence, and POA&M closures.
  • Conduct vulnerability assessments, compliance testing, penetration testing, and other technical security testing.
  • Review Tenable, Nessus, Wiz, STIG, CVE, KEV, Red Team, Blue Team, and similar results.
  • Present assessment findings and risk recommendations to ISSMs, system owners, and Authorizing Officials.
  • Maintain appropriate independence between the assessment function and the ISSO or control-implementation function.
  • Perform other job-related duties as assigned.
Assessment Lead Experience, Education, Skills, Abilities Requested:
  • Bachelor's degree in cybersecurity, information technology, computer science, engineering, auditing, or a related field.
  • Minimum of 8 years of relevant cybersecurity assessment experience.
  • CISSP, CISA, or equivalent senior security-assessment certification.
  • CEH or an equivalent penetration-testing certification.
  • Active Top Secret (TS) security clearance is required. Candidates must possess the required clearance to be considered for this position.
  • U.S. citizenship required.
  • Must be available to support Department of State operational requirements.
  • Department of State or other federal civilian agency assessment experience preferred.
  • Experience with NIST SP 800-115 and federal penetration-testing methodologies preferred.
  • Experience assessing cloud, application, infrastructure, and DevSecOps environments preferred.
  • Familiarity with CISA directives, High Value Assets, CDM, zero trust, and federal audit requirements preferred.
  • Experience assessing large, complex, or globally distributed environments preferred.
  • Equivalent penetration-testing certifications may include OSCP, GPEN, PenTest+, GWAPT, GXPN, or other recognized hands-on penetration-testing credentials, subject to customer approval.
  • Must pass pre-employment qualifications of Cherokee Federal.


Similar Searchable Job Titles:
  • Security Assessment Lead
  • Security Control Assessor
  • Senior Security Assessor
  • RMF Assessment Lead
  • Cybersecurity Assessment Manager

Keywords:
  • Security Control Assessment (SCA), RMF Step 4, SAP, SAR
  • NIST 800-53, NIST 800-115, control testing, assessment evidence
  • Penetration testing, vulnerability assessment, STIG, POA&M validation
  • Tenable, Nessus, Wiz
  • CISSP, CISA, CEH, OSCP, GPEN, Top Secret (TS) Clearance


Pipeline Position Notice:
This is a pipeline position intended to identify qualified candidates for anticipated future opportunities. This posting does not represent a current vacancy. Candidates who meet the qualifications may be contacted as positions become available and program requirements are finalized.

About Cherokee Nation Businesses

Cherokee Nation Businesses is a diversified holding company that manages a range of businesses and investments in various sectors, including gaming, hospitality, aerospace, real estate, technology, healthcare, natural resources, and more. The company is owned by the Cherokee Nation, the largest Native American tribe in the United States. Cherokee Nation Businesses is committed to creating economic opportunities and improving the quality of life for Cherokee citizens and the surrounding communities.
Learn more about Cherokee Nation Businesses
Size
7,000 employees
Industry

Similar Jobs

More Jobs at Cherokee Nation Businesses

  • Cherokee Nation Businesses
    Management Analyst III
    $89K *
    Fort Washington, MD 20744 (Prince Georges County)
    Education, Government & Non-Profit
    In-Person
  • Cherokee Nation Businesses
    Assessment Lead
    $110K — $130K *
    Fort Washington, MD 20744 (Prince Georges County)
    Education, Government & Non-Profit
    In-Person
  • Cherokee Nation Businesses
    ISSO Lead
    $110K — $130K *
    Fort Washington, MD 20744 (Prince Georges County)
    Information Technology
    In-Person
  • Cherokee Nation Businesses
    SOC Manager
    $110K — $130K *
    Fort Washington, MD 20744 (Prince Georges County)
    Information Technology
    In-Person
  • Cherokee Nation Businesses
    Equipment Specialist/Technician
    $80K — $90K *
    Shaw Afb, SC 29152 (Sumter County)
    Aerospace & Defense
    In-Person

More Education, Government & Non-Profit Jobs

Find similar Assessment Lead jobs: