Security Assessor

Spry Methods

$100K — $120K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • At least 5 years of experience in IT security roles
  • Bachelor's Degree or 4 years of specialized experience in a relevant field
  • Proven background as a security assessor
  • Strong understanding of Risk Management Framework (RMF) processes
  • Knowledge of Continuous Security Assessment and Monitoring (CSAM) is a plus

Responsibilities

  • Conduct thorough Security Assessments & Authorizations (SA&A)
  • Test networks, systems, applications, and NIST controls from various perspectives
  • Analyze vulnerability scans and interpret associated risks
  • Perform manual checks to validate vulnerability data
  • Assist customers in understanding and mitigating risks
  • Create Security Assessment Plans, Reports, and Plans of Action and Milestones (POA&Ms)
  • Conduct documentation reviews and interviews with key personnel regarding security controls

Benefits

  • Collaborative team environment
  • Opportunities for professional development
  • Ability to work on high-impact security projects
  • Flexible work arrangements
  • Exposure to cutting-edge security technologies
Full Job Description
Who We're Looking For (Position Overview):

Spry Methods is on the search for a Security Assessor to join our team in DC.

What Your Day-To-Day Looks Like (Position Responsibilities):

  • Strong working knowledge of IT Security requirements, technical security countermeasures, risk managements processes, contingency planning, and secure data communications
  • Demonstrated experience conducting full cycle SA&A
  • Testing will include network, system, application and NIST control testing from administrative and technical perspectives
  • Experience analyzing vulnerability scans and interpreting risks and employing manual checks to validate vulnerability data
  • Be able to assist the customer with understanding risk and providing risk mitigation
  • Will create Security Assessments Plans, Reports, and POA&Ms
  • The security assessment team conducts documentation reviews, inspections, and interviews with key personnel knowledgeable/ responsible for the various controls
  • Personnel interviewed are asked to show evidence of compliance, demonstration security features, provide access to (or screenshots of) configuration files and system logs, and perform tests
  • The determination of compliance will be based upon responses to questions and analysis of supporting evidence..
  • Knowledge of CSAM is a plus
  • Strong cloud experience - conducting security assessments of MS Azure in AWS environments.


What You Need to Succeed (Minimum Requirements):

  • At least 5 years experience
  • Bachelor's Degree or 4 years of specialized experience
  • Strong security assessor background
  • Must understand the Risk Management Framework (RMF) process


Similar Jobs

More Jobs at Spry Methods

More Information Technology Jobs

Find similar Security Assessor jobs: