TestPros, Inc. logo
TestPros, Inc.

Independent IT Assessment and Managed Services for Cybersecurity, DFARS, CMMC, Accessibility, Test Automation, and More.

Security Controls Assessor / OSCAL (Remote)

Security AnalystSecurity AnalystFull TimeRemoteMid LevelTeam 51-200Since 1988H1B No SponsorCompany SiteLinkedIn

Location

United States

Posted

66 days ago

Salary

0

Seniority

Mid Level

Job Description

Security Controls Assessor / OSCAL (Remote)

TestPros, Inc.

Company Overview: TestPros is a successful and growing business, established in 1988 to provide Information Technology (IT) technical support services to a wide range of Commercial and U.S. Federal, State, and Local Government customers. Our capabilities include Program Management, Program Oversight, Process Audit, Intelligence Analysis, Cyber Security, NIST 800-53, NIST SP 800-171 / CMMC Consulting/Assessment/Compliance, PCI Compliance, HIPAA, SOC 2, GLBA, Zero Trust, Resiliency, Computer Forensics, Software Supply Chain Assurance, Software Testing, Test Automation, Section 508 and WCAG Accessibility Assessment and Remediation, Localization Testing, Independent Verification and Validation (IV&V), Quality Assurance (QA), Compliance, and Research and Development (R&D) services. TestPros is an Equal Opportunity Employer. Position: Part time (as needed, 1099 or Corp. to Corp) Job Summary: The ideal candidate will have strong hands-on experience conducting independent security control compliance assessments using guidelines from NIST (800-53, 800-171) and assessment automation via OSCAL (Open Security Controls Assessment Language). You must have security controls and OSCAL experience in both U.S. Government and Commercial environments. FedRAMP experience is a plus... Required Qualifications - Proven OSCAL experience (at least two years). - 5+ years of hands-on security controls assessment and development of Security Assessment Plan (SAP), Security Assessment Report (SAR) and Plan of Actions and Milestones (POA&M). - Experience with RegScale, Paramify, or similar tools. - Experience with government, public sector, or municipal IT environments is highly preferred. - Ability to write clear, professional, and actionable technical reports. - Full U.S. Citizenship, and ability to pass an extensive background check. Preferred Skills - Experience with NIST 800-53 based ATO assessment, NIST 800-171/CMMC assessment, and/or HIPAA assessment. - Ability to produce a set of interoperable, extensible, machine-readable formats that supports a broad range of control-based risk management processes (XML-, JSON-, and YAML-based formats that allow for lossless translations between XML, JSON, and YAML representations). - Familiarity with U.S. Government security policy requirements. - Experience coordinating with multi-agency or cross-organizational IT teams. - Expertise with common tools such as Kali Linux, Burp Suite, Nmap, Metasploit, Nessus/Tenable, and Wireshark. Engagement Details - Estimated Start: April 2026 - Estimated Duration: TBD - Work Location: Fully Remote - Clearances: Not required, but government experience is a plus Benefits TestPros offers a competitive salary, medical/dental/vision insurance, life insurance, paid time off, paid holidays, 401(k) retirement plan with company match, opportunities for professional growth, cell phone discounts, and much more! All benefits are per TestPros current policies and are subject to change without notice. Benefits are available to full-time employees.​ TestPros, Inc. is an Equal Opportunity Employer. EEO Statement All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, sexual orientation, gender identity, marital status, age, national origin, or protected veteran status.

Related Job Pages

More Security Analyst Jobs

The Vanguard Group logo

Corporate Travel Security Specialist

The Vanguard Group

Founded in 1975, The Vanguard Group is now one of the largest investment management companies in the world, with millions of investor clients and thousands of "

Security Analyst66 days ago

Title: Corporate Travel Security Specialist Location: Malvern, PA Job Description: time type Full time job requisition id 176385 Global Risk and Security (GR&S) at Vanguard enables business strategy, protects client and Vanguard interests (e.g., assets and data), and stewards a strong risk culture. Our teams leverage enterprise-wide insights, deep expertise, and trusted advice so that across Vanguard leaders and crew drive faster, stronger, risk-informed decisions. Within GR&S, the Enterprise Security and Fraud (ES&F) sub-division is responsible for the global protection of Vanguard crew, property, data, and client assets. We are the trusted advisors that protect the pride of Vanguard with state-of-the-art security and fraud capabilities. We are a world-class destination of highly engaged, passionate, and diverse talent expected to continuously learn and develop in an ever-changing security landscape. Our crew are our greatest resource – by joining our team you will build collaborative long-term relationships and enjoy a suite of benefits that includes comprehensive health and wellness care, work-life balance, and an investment in your future at its core. Core Responsibilities - Monitor global security, geopolitical, health, and environmental developments that may impact business travel - Conduct travel risk assessments and provide destination‑specific guidance and briefings for employees traveling to medium and high risk destinations - Support travelers during incidents, emergencies, or disruptions, including coordination with internal teams and external partners - Assist with travel security incident management, escalation, and documentation - Contribute to the development and continuous improvement of travel security policies, procedures, and tools - Lead travel tracker onboarding and education efforts, supporting awareness of the Travel Security Program through presentations and mobile app adoption - Coordinate secure transportation and hotel security assessments when required - Partner with internal stakeholders to manage ad hoc travel security projects that enhance the effectiveness of the Travel Security Program. - Collaborate with corporate security, travel management, HR, CSOC, and regional stakeholders - Produce travel security advisories and operational updates for travelers and leadership; as warranted - Maintain travel security dashboards, tracking reports, and traveler risk updates Qualifications - Minimum of five years’ experience in corporate security, travel risk management, intelligence analysis, executive protection, military, law enforcement, or a related field - Bachelor’s degree in Security Management, Criminal Justice, Homeland Security, Risk Management, Emergency Management, or a related discipline - Strong analytical, decision-making, and situational awareness skills - Excellent written and verbal communication skills - Ability to manage multiple priorities in a fast-paced environment - Comfortable working across time zones and responding to time-sensitive situations - International experience or global risk exposure preferred Special Factors Sponsorship Vanguard is not offering visa sponsorship for this position. About Vanguard At Vanguard, we don't just have a mission—we're on a mission. To work for the long-term financial wellbeing of our clients. To lead through product and services that transform our clients' lives. To learn and develop our skills as individuals and as a team. From Malvern to Melbourne, our mission drives us forward and inspires us to be our best. How We Work Vanguard has implemented a hybrid working model for the majority of our crew members, designed to capture the benefits of enhanced flexibility while enabling in-person learning, collaboration, and connection. We believe our mission-driven and highly collaborative culture is a critical enabler to support long-term client outcomes and enrich the employee experience.

Pennsylvania
Full TimeRemoteTeam 11-50

cFocus Software seeks a Sr. Security Control Assessor to join our program supporting the Internal Revenue Service (IRS). This position is remote. This position requires a Public Trust clearance. Qualifications: - Bachelor’s degree in Cybersecurity, IT, or related field. - 7+ years of experience in information security or security control assessment - Strong knowledge of NIST RMF, FISMA, and NIST SP 800-53 controls - Experience conducting security assessments and developing SARs and POA&Ms - Familiarity with federal security authorization processes (ATO, SA&A) - Strong analytical, documentation, and communication skills Duties: - Conduct security control assessments in accordance with NIST SP 800-53 and RMF guidelines - Perform system discovery, documentation review, and evidence collection activities - Develop and execute Security Assessment Plans (SAPs) - Conduct interviews and technical testing to evaluate control effectiveness - Document findings and develop Security Assessment Reports (SARs) - Identify vulnerabilities and document risks in Plans of Action and Milestones (POA&Ms) - Support Authorization to Operate (ATO) processes and continuous monitoring activities - Validate remediation efforts and closure of POA&Ms - Coordinate with system owners, ISSOs, and stakeholders throughout the assessment lifecycle - Provide on-demand security assessment support across multiple systems - Support rapid assessment efforts and evolving federal initiatives - Deliver level-of-effort estimates for assessment activities - Assist with backlog reduction and surge staffing needs - Participate in special projects and cross-functional security initiatives

United States
Job Closed
Full TimeRemoteTeam 11-50

cFocus Software seeks a Tier 1 SOC Analyst to join our program supporting Housing and Urban Development (HUD). This position is remote. This position requires a Public Trust clearance. Qualifications: - Bachelor’s degree in Cybersecurity, Information Technology, or related field (or equivalent experience). - 1–2 years of experience in a SOC, cybersecurity operations, or IT security role. - Experience with SIEM platforms (e.g., Splunk), EDR tools, and log analysis. - Understanding of networking, operating systems, and cybersecurity fundamentals. - Familiarity with incident response lifecycle and security monitoring processes. Duties: - Perform continuous security monitoring of network, endpoint, and cloud environments in a 24/7/365 SOC. - Analyze and triage security alerts generated from SIEM, SOAR, EDR, and other security tools. - Identify potential security incidents including malware, phishing, unauthorized access, and anomalous behavior. - Execute initial incident response procedures and escalate incidents to Tier 2/3 analysts as required. - Monitor and analyze security logs, events, and alerts for suspicious activity. - Support threat detection and response activities using threat intelligence and analytics. - Assist with vulnerability monitoring, including tracking Known Exploited Vulnerabilities (KEVs) and vulnerability disclosures. - Document all incidents, findings, and actions taken in ticketing systems (e.g., ServiceNow). - Support log aggregation, correlation, and analysis activities. - Assist with dark web monitoring and indicator tracking as directed. - Participate in shift handoffs and maintain situational awareness across SOC operations. - Follow established SOPs, playbooks, and incident response procedures. - Support compliance with federal cybersecurity requirements and policies.

United States
Full TimeRemoteTeam 11-50

cFocus Software seeks a Tier 2 SOC Analyst to join our program supporting Housing and Urban Development (HUD). This position is remote. This position requires a Public Trust clearance. Qualifications: - Bachelor’s degree in Cybersecurity, Information Technology, or related field (or equivalent experience). - 2+ years of experience in a SOC, cybersecurity operations, or IT security role. - Experience with SIEM platforms (e.g., Splunk), EDR tools, and log analysis. - Understanding of networking, operating systems, and cybersecurity fundamentals. - Familiarity with incident response lifecycle and security monitoring processes. Duties: - Perform continuous security monitoring of network, endpoint, and cloud environments in a 24/7/365 SOC. - Analyze and triage security alerts generated from SIEM, SOAR, EDR, and other security tools. - Identify potential security incidents including malware, phishing, unauthorized access, and anomalous behavior. - Execute initial incident response procedures and escalate incidents to Tier 2/3 analysts as required. - Monitor and analyze security logs, events, and alerts for suspicious activity. - Support threat detection and response activities using threat intelligence and analytics. - Assist with vulnerability monitoring, including tracking Known Exploited Vulnerabilities (KEVs) and vulnerability disclosures. - Document all incidents, findings, and actions taken in ticketing systems (e.g., ServiceNow). - Support log aggregation, correlation, and analysis activities. - Assist with dark web monitoring and indicator tracking as directed. - Participate in shift handoffs and maintain situational awareness across SOC operations. - Follow established SOPs, playbooks, and incident response procedures. - Support compliance with federal cybersecurity requirements and policies.

United States