OverviewSteampunk is seeking a Security Control Assessor to support a government customer, ensuring risk within the system is maintained at an acceptable level. This role requires initiative, organization, strong communication across all levels of the organization, and sound judgment with sensitive and confidential information in a fast-paced environment.
Contributions
As a member of one of ourassessmentteams, you will playan importantroleinperforming a wide array ofcybersecurity duties including:
- Lead security assessments in accordance with NIST SP 800-53, NIST RMF (SP 800-37), FedRAMP, and agency-specific guidance.
- Evaluate technical, operational, and management controls across cloud, on-premises, and hybrid environments, including hands-on review of technical control evidence (e.g., encryption configurations, SIEM logging, identity/access management, network boundary controls, STIG compliance).
- Develop Assessment Plans and Security Assessment Reports (SARs), and document findings and risk in compliance with FISMA, FedRAMP, and organizational standards.
- Coordinate with ISSOs, System Owners, and Authorization Officials to review evidence and remediate control deficiencies.
- Analyze vulnerability scans, configuration baselines, and penetration test results to determine control effectiveness and recommend remediation.
- Present findings and risk analysis to management and Authorization Officials.
- Support continuous monitoring and control validation for ongoing authorization.
Qualifications
- Bachelor's Degree and 5 years of relevant experience; OR
- No degree with a total of 9 years of relevant experience; OR
- Master's degree and 3 years of relevant experience
- One of the following certifications (may be obtained within six (6) months of hire):
- Certified Information System Security Professional (CISSP)
- CompTIA Advanced Security Practitioner (CASP)
- Certified Information Systems Auditor (CISA)
- Certified Information Security Manager (CISM)
- Strong knowledge of NIST SP 800-53, FIPS 199/200, and NIST SP 800-30/37/39/53/60; familiarity with DHS Directive 4300A.
- Hands-on experience reviewing security control artifacts and providing independent evaluations for system authorization packages, including in cloud environments (AWS, Azure).
- Proficiency with assessment/scanning tools (e.g., Nessus, Tenable.SC, Splunk, SCAP scanners) and analytical skill to interpret vulnerabilities and compliance gaps.
- Demonstrated ability to review technical controls directly, as a core part of the role for example: verifying FIPS-validated encryption, auditing SIEM logging architecture, reviewing IAM/MFA enforcement (AD, Okta, Azure AD), analyzing firewall/ACL/Security Group configurations, and evaluating DISA STIG results.
Preferred:
- Experience as a Security Control Assessor and performing risk analysis/assessment.
- Working knowledge of AWS/Azure GovCloud and enterprise application stacks (e.g., Maven, Jenkins, Ansible, Tomcat, IIS, F5, Oracle, MSSQL, PostgreSQL).
- Familiarity with AI/ML concepts and their security implications.
- Working knowledge of JIRA, ServiceNow, or equivalent.
About steampunk
Steampunk relies on several factors to determine salary, including but not limited to geographic location, contractual requirements, education, knowledge, skills, competencies, and experience. The projected compensation range for this position is $105,000 to $160,000. The estimate displayed represents a typical annual salary range for this position. Annual salary is just one aspect of Steampunk9s total compensation package for employees. Learn more about additional Steampunk benefits here.
Identity Statement
As part of the application process, you are expected to be on camera during interviews and assessments. We reserve the right to take your picture to verify your identity and prevent fraud.