Job Closed

This listing is no longer active.

Freedom logo
Freedom

Strategy / Sustainability / M&A / Business Process Management / Organization Change Management / Digital Transformation.

Security Control Assessor – Subject Matter Expert

Security EngineerSecurity EngineerOtherRemoteSeniorTeam 51-200H1B SponsorCompany SiteLinkedIn

Location

United States

Posted

81 days ago

Salary

0

Seniority

Senior

Job Description

Security Control Assessor – Subject Matter Expert

Freedom

• Ease Learning is seeking a qualified Subject Matter Expert (SME) with applied, real-world experience in Security Control Assessor to participate in a skills assessment validation engagement. • Complete a practitioner-level skills assessment used for validation and standard-setting purposes. • Complete a short post-assessment survey providing feedback on the assessment experience. • This role does not involve teaching, instructional design, content creation, or ongoing advisory responsibilities.

Job Requirements

  • The SME should be a current practitioner with applied, real-world experience related to the following knowledge areas and skills:
  • Develop methods to monitor and measure risk, compliance, and assurance efforts
  • Develop specifications ensuring risk, compliance, and assurance efforts conform with security, resilience, and dependability requirements
  • Draft statements of preliminary or residual security risks for system operation
  • Maintain information systems assurance and accreditation materials
  • Monitor and evaluate system compliance with IT security, resilience, and dependability requirements
  • Conduct Privacy Impact Assessments (PIA) for appropriate security controls protecting PII
  • Perform validation steps comparing actual results with expected results and analyze differences
  • Plan and conduct security authorization reviews and assurance case development
  • Provide accurate technical evaluation of software, systems, or networks documenting security posture and vulnerabilities
  • Recommend new or revised security, resilience, and dependability measures based on review results
  • Verify application/network/system security postures are implemented as stated and document deviations
  • Develop security compliance processes and/or audits for external services (e.g., cloud providers, data centers)
  • Knowledge of computer networking concepts, protocols, and network security methodologies
  • Knowledge of risk management processes (e.g., methods for assessing and mitigating risk)
  • Knowledge of cybersecurity principles, cyber threats, and vulnerabilities
  • Knowledge of cyber defense and vulnerability assessment tools, including open source tools
  • Knowledge of organization's evaluation and validation requirements
  • Knowledge of cybersecurity principles used to manage risks related to use, processing, storage, and transmission of data
  • Knowledge of known vulnerabilities from alerts, advisories, errata, and bulletins
  • Knowledge of IT security principles and methods (e.g., firewalls, DMZs, encryption)
  • Knowledge of current industry methods for evaluating and implementing IT security assessment and monitoring tools
  • Knowledge of system and application security threats and vulnerabilities (e.g., buffer overflow, XSS, SQL injection)
  • Skill in determining how a security system should work including resilience and dependability capabilities
  • Skill in discerning protection needs (security controls) of information systems and networks
  • Knowledge of network security architecture concepts including topology, protocols, components (e.g., defense-in-depth, Zero Trust)
  • Knowledge of relevant laws, policies, procedures related to critical infrastructure
  • Knowledge of risk assessments and authorization per Risk Management Framework processes
  • Knowledge of penetration testing principles, tools, and techniques
  • Knowledge of security architecture concepts and enterprise architecture reference models
  • Knowledge of security models (e.g., Bell-LaPadula, Biba, Clark-Wilson)

Benefits

  • This is a flat-fee engagement, paid upon successful completion of the assessment and survey

Related Categories

Related Job Pages

More Security Engineer Jobs

OtherRemoteTeam 11-50H1B Sponsor

Who We Are Anza is a Solana R&D lab pushing the boundaries of blockchain performance and scalability. Anza was founded by experienced executives and core engineers solving the toughest problems in Web3. Crypto ecosystems rely on robust protocols, and we believe those are best built out in the open, with multiple contributors. We pioneer advanced solutions to meet the evolving demands of decentralized applications. The Role As a Security Engineer at Anza, you will play a crucial role in safeguarding the Solana ecosystem by designing and implementing robust security measures. You will work closely with core developers, ecosystem teams, and external auditors to identify and mitigate vulnerabilities in distributed systems protocols and blockchain client software. Your expertise will help shape security best practices and advance the security posture of blockchain technology. Responsibilities - Design and implement security and defense-in-depth controls to prevent and limit vulnerabilities. - Conduct advanced security research on Solana and other Rust-based smart contract platforms. - Work closely with core contributors to perform in-depth internal security audits. - Work with external security audits in collaboration with top-tier third-party firms. - Effectively communicate security risks and solutions to both technical and non-technical stakeholders. - Uphold the highest standards of integrity, trust, and professionalism in all security practices.

California
Job Closed
OtherRemoteTeam 11-50H1B Sponsor

Who We Are Anza is a Solana R&D lab pushing the boundaries of blockchain performance and scalability. Anza was founded by experienced executives and core engineers solving the toughest problems in Web3. Crypto ecosystems rely on robust protocols, and we believe those are best built out in the open, with multiple contributors. We pioneer advanced solutions to meet the evolving demands of decentralized applications. The Role As a Security Engineer at Anza, you will play a crucial role in safeguarding the Solana ecosystem by designing and implementing robust security measures. You will work closely with core developers, ecosystem teams, and external auditors to identify and mitigate vulnerabilities in distributed systems protocols and blockchain client software. Your expertise will help shape security best practices and advance the security posture of blockchain technology. Responsibilities - Design and implement security and defense-in-depth controls to prevent and limit vulnerabilities. - Conduct advanced security research on Solana and other Rust-based smart contract platforms. - Work closely with core contributors to perform in-depth internal security audits. - Work with external security audits in collaboration with top-tier third-party firms. - Effectively communicate security risks and solutions to both technical and non-technical stakeholders. - Uphold the highest standards of integrity, trust, and professionalism in all security practices.

New York
Job Closed
Full TimeRemoteTeam 201-500H1B Sponsor

• Support the InfoSec GRC Lead in operating and improving the organization’s governance, risk, and compliance program • Review client MSAs and related security requirements • Support internal and client audits • Drive risk and exception management workflows • Support supplier/third-party security reviews • Maintain documentation and evidence for ISO/IEC 27001 & ISO/IEC 42001 • Support continual improvement activities • Extract and document security requirements from client MSAs • Identify gaps and risks; coordinate with Legal and Privacy teams • Collect evidence for audit requests; ensure traceability between requirements, controls, and evidence • Maintain risk registers and support exception workflows • Assess third-party security submissions; track supplier risk ratings and remediation actions • Map regulatory requirements (HIPAA, GDPR, APPI) to internal controls • Produce operational reports on audit status/risk metrics • Contribute to process improvements

United Kingdom
Job Closed
OtherRemoteTeam 201-500H1B No Sponsor

• Reports to Offensive Security Manager • Grow penetration testing practice • Propose and take ownership of internal project initiatives • Conduct debrief reviews with clients • Lead client debrief calls for standard engagements

California
Job Closed