CSSP Auditor

TekSynap$120K — $170K *
Technical Services
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Active Top-Secret Clearance with SCI eligibility required
  • DoD 8140/8570 CSSP Auditor or equivalent certifications
  • Certified Information Systems Auditor (CISA) certification
  • 7+ years of experience in cybersecurity auditing or 5+ years with a Master's degree
  • Minimum three years supporting DoD or Federal cybersecurity programs

Responsibilities

  • Establish and audit the CSSP Data Quality Scoring (DQS) framework
  • Manage and validate CSSP Evidence Objects for traceability
  • Lead the lifecycle management of Standard Operating Procedures (SOPs)
  • Map operational controls to NIST SP-800-53 Rev. 5 compliance
  • Support audit readiness and government-directed inspections
  • Conduct quality assurance audits across cybersecurity teams
  • Facilitate continuous improvements and recommend corrective actions

Benefits

  • Full-time office environment with a low noise level
  • Estimated work hours Monday to Friday 0800 - 1600
  • Limited travel (less than 10%) required
  • Reasonable accommodations for individuals with disabilities
  • Participation in compliance and readiness assessments
Full Job Description
Responsibilities & Qualifications

Position Summary

The CSSP Auditor provides independent oversight, compliance validation, and operational quality assurance across the Cybersecurity Service Provider (CSSP) environment. The position is responsible for establishing a continuous audit and inspection-ready posture by validating cybersecurity operations, telemetry quality, evidence traceability, regulatory compliance, and operational performance metrics. The CSSP Auditor works across the Protect, Detect, Respond, and Sustain functions to ensure cybersecurity operations align with DoD requirements, NIST guidance, CSSP Evaluator Scoring Metrics (ESM), and organizational quality standards.

 

Key Responsibilities:

  • Data Quality Scoring (DQS) & Telemetry Auditing: Establish, govern, and audit the CSSP Data Quality Scoring (DQS) framework to evaluate the trustworthiness of ingested security telemetry. Perform continuous audits of telemetry sources against mandatory DQS metrics, including Parsing Success Rate (PSR), Field Completeness Score (FCS), Schema Adherence Score (SAS), and Timeliness Score (TS). Track, analyze, and manage the remediation of low-DQS sources and data-loss visibility gaps. Validate data collection, normalization, enrichment, and correlation processes to ensure critical security events are accurately represented throughout the detection lifecycle.
  • Evidence Object & Traceability Verification: Manage and validate CSSP Evidence Objects to ensure all defensive cyber actions are fully documented and package-proven. Ensure absolute traceability from ingested telemetry up to cybersecurity risk-reduction decisions. Verify complete traceability from source telemetry through analyst actions, incident response activities, and cybersecurity risk-reduction decisions. Conduct routine audits of evidence packages to ensure compliance with internal policies and external assessment requirements.
  • SOP Lifecycle Management & SharePoint Governance: Lead the full lifecycle of Standard Operating Procedures (SOPs), playbooks, and internal operational workflows. Develop, implement, and track an annual review plan for all CSSP documentation. Manage the SharePoint Master SOP Library, maintaining version control, access permissions, and formal archival processes. Verify that all published SOPs are synchronized with current DED requirements and operational capabilities.
  • NIST SP-800-53 Rev. 5 & 800-53A Compliance: Map CSSP operational controls and evidence logs directly to NIST SP-800-53 Rev. 5 control families, focusing heavily on Audit and Accountability, System and Information Integrity, and Incident Response. Embed NIST SP-800-53A assessment methods (Examine, Interview, and Test) into internal audit procedures to support continuous authorization and federal compliance mandates, including OMB M-26-14. Focus heavily on Audit and Accountability (AU), System and Information Integrity (SI), Incident Response (IR), Configuration Management (CM), and Risk Assessment (RA) controls.
  • Audit Readiness: Lead activities supporting CSSP Evaluator Scoring Metrics (ESM) assessments, Cyber Operational Readiness Assessments (CORA), JFHQ-DODIN evaluations, and other government-directed inspections. Coordinate evidence collection, validation, scoring reviews, and corrective action tracking. Maintain a continuous inspection-ready posture and reduce organizational dependence on pre-audit preparation cycles. Define, monitor, and report on internal performance metrics, enforcing strict alignment with DTM 26-003.
  • Independent Quality Assurance: Conduct recurring audits across Protect, Detect, Respond, and Sustain teams. Assess procedural compliance, documentation quality, operational consistency, analyst performance evidence, and adherence to service delivery requirements. Validate execution against approved processes, operational standards, and organizational objectives.
  • Continuous Improvement and Lessons Learned: Identify recurring compliance deficiencies, operational trends, systemic weaknesses, and process inefficiencies. Develop lessons learned reports and corrective action recommendations. Facilitate continuous process improvement initiatives that strengthen cybersecurity effectiveness, audit readiness, and mission performance.

 

Required Qualifications:

  • Clearance: Active Top-Secret Clearance with SCI eligibility required.
  • Compliance & Certifications:
    • DoD 8140/8570 CSSP Auditor or equivalent certifications is required
    • Certified Information Systems Auditor (CISA) is required
  • Experience: Minimum of 7+ years of progressive experience in cybersecurity auditing, continuous monitoring, or compliance assessment (or 5+ years with a Master's degree), with a minimum of three (3) years supporting DoD or Federal cybersecurity programs. Experience supporting audit, inspection, or accreditation activities within a Security Operations Center (SOC), Cybersecurity Service Provider (CSSP), Cyber Defense Program, or related environment.
  • Education: BA/BS College degree required.
  • Technical Auditing Capabilities: Proven experience auditing database/SIEM logs, data ingestion schemas, and validating compliance data flows. Familiarity with data dictionaries, data validation rules, and automated log analysis is highly preferred.

Preferred Technical Experience/Knowledge (3 or more areas desired):

  • DoD Cybersecurity Service Provider (CSSP) operations
  • Risk Management Framework (RMF)
  • NIST SP 800-53 Rev. 5 and NIST SP 800-53A
  • DoDI 8530.01 and applicable CSSP guidance
  • CNSSI 1253
  • Security Technical Implementation Guides (STIGs)
  • Continuous Monitoring programs
  • Incident Response processes
  • Vulnerability Management programs
  • Audit, compliance, and inspection readiness activities
  • MITRE ATT&CK Framework
Overview

We are seeking a CSSP Auditor to join our Prime Contract with the Defense Threat Reduction Agency.

 

Additional Job Information

WORK ENVIRONMENT AND PHYSICAL DEMANDS

The work environment characteristics described here are representative of those an employee encounters while performing the essential functions of the job. Reasonable accommodation may be made to enable individuals with disabilities to perform the essential functions.

  • Location: Fort Belvoir, VA
  • Type of environment: Office
  • Noise level: Low
  • Work schedule: Schedule is Monday – Friday (0800 - 1600). May be requested to work evenings and weekends to meet program and contract needs.
  • Amount of Travel: Less than 10%

PHYSICAL DEMANDS

The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.

While performing the duties of this job, the employee is regularly required to use hands to handle, feel, touch; reach with hands and arms; talk and hear. The employee is regularly required to stand; walk; sit; climb or balance; and stoop, kneel, crouch, or crawl. The employee is regularly required to lift up to 10 pounds. The employee is frequently required to lift up to 25 pounds; and up to 50 pounds. The vision requirements include close vision, distance vision, peripheral vision, depth perception, and ability to adjust focus.

 

WORK AUTHORIZATION/SECURITY CLEARANCE

  • U.S Citizenship Required
  • Top Secret Clearance with SCI Eligibility.

WAGE INFORMATION

Target salary range: $120,000.00 - $170,000.00.  The salary range displayed is an estimate only and is not a guarantee of compensation or salary and will be determined on several factors regarding the individual’s particular combination of education, knowledge, skills, competencies and experience, as well as contract parameters and organizational requirements.  The displayed salary is one component of the total compensation package for employees. 

 

OTHER DUTIES

Please note this job description is not designed to cover or contain a comprehensive listing of activities, duties or responsibilities that are required of the employee for this job. Duties, responsibilities and activities may change at any time with or without notice.

 

TekSynap is a drug-free workplace. We reserve the right to conduct drug testing in accordance with federal, state, and local laws. All employees and candidates may be subject to drug screening if deemed necessary to ensure a safe and compliant working environment.

 

Many positions require specific certifications and/or the ability to obtain a security clearance.  Security clearances may only be granted to U.S. citizens.  Applicants who accept an offer of employment may be subject to investigations performed by TekSynap and/or the Government to verify the candidate meets the required qualifications and other eligibility requirements. 

 

About TekSynap

TekSynap Careers

Joining TekSynap provides a unique opportunity to work with a team of professionals who are leaders in delivering advanced technological solutions. TekSynap, renowned for its commitment to innovation and leadership, offers a variety of job opportunities that cater to ambitious technology enthusiasts eager to drive digital transformation.

Explore Job Opportunities

TekSynap is actively hiring and offers a range of positions that encourage professional growth and skill development. Interested candidates can explore open positions that match their skills and career aspirations. TekSynap values diversity and inclusion, ensuring that all employment practices empower individuals from various backgrounds.

Experience Professional Growth

At TekSynap, career growth is not just a possibility but a priority. With comprehensive professional development and diversity training programs, employees are equipped to ascend in their careers through continuous learning and leadership opportunities. The company supports its team with the tools needed to succeed in their roles and beyond.

Internship Programs

For those starting their career journey, TekSynap’s internship programs provide a robust foundation in the tech industry. Interns gain hands-on experience, working alongside seasoned experts and participating in projects that foster real-world skills. These internships often lead to full-time positions, offering a seamless transition into the professional world.

Cultivating a Supportive Culture

TekSynap is dedicated to fostering a workplace culture that promotes teamwork, creativity, and employee well-being. The benefits at TekSynap go beyond the standard; they are designed to support a healthy work-life balance and include initiatives that cater to the holistic well-being of the team.

Networking and Innovation

Employees at TekSynap enjoy a dynamic work environment where innovation is at the forefront. Networking within the company is encouraged through various team-building and collaborative projects, enhancing the creative process and leading to groundbreaking solutions in the technology sector.

Prepare for Your Interview

For those looking to join TekSynap, preparing a tailored resume and honing interview skills is crucial. The company seeks candidates who are curious, creative, and ready to contribute to a team that is at the cutting edge of technology solutions.

Stay Connected with TekSynap Careers

Keep up to date with the latest insights, career tips, and company news by subscribing to the TekSynap careers blog. Personalize your subscription to receive updates that align with your professional interests and career goals.

Join TekSynap

Discover the rewarding career opportunities at TekSynap by searching for jobs that align with your professional skills and interests. TekSynap is looking for passionate, driven individuals ready to make a significant impact in the tech industry.

SEARCH TEKSYNAP JOBS

READ CAREERS BLOG

Job Alert Emails

Sign up for job alerts and get the latest news and updates from TekSynap tailored to your preferences. Explore the exciting and rewarding opportunities that await at TekSynap, where innovation meets expertise.
Learn more about TekSynap
Size
1,001 employees
Industry

Similar Jobs

More Jobs at TekSynap

More Technical Services Jobs

Find similar CSSP Auditor jobs: