Everforth Apex, a division of Everforth and formerly Apex Systems, an IT staffing and workforce solutions firm, provides recruiting and staffing services to lar
CMMC Certified Assessor
Location
Virginia
Posted
64 days ago
Salary
$100 - $250 / hour
Seniority
Senior
Job Description
CMMC Certified Assessor
Everforth
Title: CMMC Certified Assessor (CCA)-PLACEMENT Employee Type: Contract Remote: Yes Location: Mclean, VA, US Pay Range: $100 - $250 per hour Job#: 3021610 Job Description: Apex Systems is looking for a CMMC Certified Assessor (CCA) to join our client's team! Role Overview The CMMC Certified Assessor (CCA) will support our Secure Compliance team in becoming an authorized C3PAO. This is a short-term engagement focused on fulfilling the requirement for three CCAs on our roster. Minimum Requirements · Active CMMC Certified Assessor (CCA) credential in good standing · Demonstrated experience performing CMMC assessments or similar compliance audits · Strong understanding of NIST SP 800-171 and CMMC Level 2 requirements · Ability to work independently and meet deadlines in a remote environment · Ability to work standard core CST hours Key Responsibilities · Participate in CMMC Level 2 assessments in accordance with 32 CFR and CMMC guidelines · Collaborate with internal CCAs and Lead Assessor to ensure compliance and quality · Review evidence, document findings, and contribute to assessment reports · Maintain confidentiality and adhere to conflict-of-interest requirements · Provide subject matter expertise on CMMC practices and controls Nice to Have Skills · Prior experience with C3PAO organizations or DIB clients · Familiarity with cybersecurity frameworks (ISO 27001, FedRAMP, etc.) · Excellent written communication for assessment documentation · Experience with secure collaboration tools and evidence management platforms Everforth Apex is a world-class IT services company that serves thousands of clients across the globe. When you join Everforth Apex, you become part of a team that values innovation, collaboration, and continuous learning. We offer quality career resources, training, certifications, development opportunities, and a comprehensive benefits package. Our commitment to excellence is reflected in many awards, including ClearlyRated's Best of Staffing® in Talent Satisfaction in the United States and Great Place to Work® in the United Kingdom and Mexico. Everforth Apex uses a virtual recruiter as part of the application process. Click here for more details. Everforth Apex Benefits Overview: Everforth Apex offers a range of supplemental benefits, including medical, dental, vision, life, disability, and other insurance plans that offer an optional layer of financial protection. We offer an ESPP (employee stock purchase program) and a 401K program which allows you to contribute typically within 30 days of starting, with a company match after 12 months of tenure. Everforth Apex also offers a HSA (Health Savings Account on the HDHP plan), a SupportLinc Employee Assistance Program (EAP) with up to 8 free counseling sessions, a corporate discount savings program and other discounts. In terms of professional development, Everforth Apex hosts an on-demand training program, provides access to certification prep and a library of technical and leadership courses/books/seminars once you have 6+ months of tenure, and certification discounts and other perks to associations that include CompTIA and IIBA. Everforth Apex has a dedicated customer service team for our Consultants that can address questions around benefits and other resources, as well as a certified Career Coach. You can access a full list of our benefits, programs, support teams and resources within our ‘Welcome Packet’ as well, which an Everforth Apex team member can provide.
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Adjunct Global Campus Instructor
University of Arizona- SIROW (Southwest Institute for Research on Women)Research, Action, and Advocacy for Social Change.
Title: Adjunct Global Campus Instructor - Master in Psychology (Remote) Location: USA Remote Job Description: The Adjunct Global Campus Instructor position is a part-time, temporary adjunct employment opportunity. The Adjunct Global Campus Instructor member perform duties relating to online instruction including but not limited to posting faculty guidance and expectations, participating in classroom discussion boards, grading assignments, and promptly responding to student inquiries. This is an online adjunct teaching position, and other duties may be assigned according to experience and qualifications. Special Instructions to Applicant: The application window is anticipated to close on Friday, May 22, 2026 (11:59 PM MST). Essential Job Duties: - Deliver high-quality, engaging online instruction. - Connect the learning experience to workforce skills and professional advancement. - Foster a supportive and inclusive learning environment for adult learners. - Prioritize student learning, achievement, and timely feedback. - Maintain strong communication with students and respond promptly to inquiries. - Ensure academic integrity and uphold university policies. - Collaborate with academic support teams to enhance student experience. - Creatively use available tools and strategies to enhance relationships, create a community of learners willing to take tasks and actively engage with one another. - Provide instructive feedback that challenges and inspires students while providing specific suggestions to improve the quality of their work and thinking. - Adhere to all faculty requirements such as facilitating and engaging in classroom discussion boards, grading assignments and discussions, and responding to student inquiries in a timely manner. - Effectively and consistently utilize expertise in subject matter by providing personal experience and connecting course knowledge to real-world examples. Enhance course content and resources to encourage student comprehension and application of course learning outcomes. - Participate in professional development as required. Knowledge, Skills, and Abilities (KSAs): - Ability to create inclusive, engaging, and supportive online learning environments that foster student success and belonging. - Ability to communicate effectively and compassionately with diverse adult learners from varying backgrounds and academic preparedness levels. - Ability to align academic content with workforce needs and industry trends to ensure program relevance and graduate preparedness. - Skill in using educational technology and learning management systems to deliver high-quality online instruction and feedback. - Ability to interpret student success data and use insights to improve teaching practices and curricular design. - Commitment to a student-centered Culture of Care, including proactive outreach, timely feedback, and individualized support. - Excellent verbal and written communication skills, with the ability to foster student engagement and clarity in a remote learning environment. - Strong organizational and time management skills with the ability to meet deadlines and balance multiple responsibilities within a flexible, evolving work environment. The University of Arizona has been recognized for our innovative work-life programs. Minimum Qualifications: - A Doctorate degree in Psychology or related field. - Practical professional work experience in a relevant field. Preferred Qualifications: - Online teaching experience at a Master's level in several of the following areas: Development Psychology, Social Psychology, Personality Theories, Learning and Cognition, Biological Bases of Behavior, Psychopharmacology, Research Methods, Psychological Testing and Assessment, Psychopathology, or Psychology and Health - At least three years of practical work experience in a relevant field. Rate of Pay: $19.25 - $29.97 Compensation Type: Hourly at .475 Full-Time Equivalency (FTE) Compensation Guidance: The Rate of Pay Field represents the University of Arizona’s good faith and reasonable estimate of the range of possible compensation at the time of posting. The University considers several factors when extending an offer, including but not limited to, the role and associated responsibilities, a candidate’s work experience, education/training, key skills, and internal equity. Career Stream: Adjunct Global Campus Instructor Level: Chapter 3 Job Function: Instructional and Assessment Services Job Family: UAGC Online Instructor Notice of Availability of the Annual Security and Fire Safety Report: In compliance with the Jeanne Clery Campus Safety Act (Clery Act), each year the University of Arizona releases an Annual Security Report (ASR) (https://clery.arizona.edu/asr) for each of the University’s campuses. These reports disclose information including Clery crime statistics for the previous three calendar years and policies, procedures, and programs the University uses to keep students and employees safe, including how to report crimes or other emergencies and resources for crime victims. As a campus with residential housing facilities, the Main Campus ASR also includes a combined Annual Fire Safety report with information on fire statistics and fire safety systems, policies, and procedures.
Senior Business Applications Security Engineer
AlphaSenseThe market intelligence and search platform trusted by over 3,500 leading organizations
• Design and implement a comprehensive business application security program where none exists • Take full ownership of security posture across 200+ business applications (SaaS, cloud, and on-premise) • Define what 'secure' means for business applications and ensure every tool meets that bar • Embed security into procurement, integration, and lifecycle management processes • Partner with stakeholders across IT, Engineering, Finance, HR, Sales, and Marketing to change application security mindset
• As a Security Engineer specializing in Google SecOps, you will be a trusted advisor to our clients, guiding them through the implementation, optimization, and ongoing management of their Google security solutions. • Infrastructure Provisioning: Design, configure, and deploy Google security tools and platforms for clients, ensuring seamless integration with their existing environments. This may include configuring Google Cloud Security Command Center, Chronicle Security Operations, BeyondCorp Enterprise, and other relevant Google security services. • Provide expert-level support for client inquiries and issues related to Google SecOps tools and configurations. Diagnose and resolve technical challenges efficiently and effectively. • Offer proactive security guidance and recommendations to clients based on Google's security best practices and industry standards. Help clients understand and mitigate potential risks within their Google Cloud environments. • Collaborate with clients to understand their security objectives and develop tailored Google SecOps strategies. Advise on product selection, feature utilization, and roadmap planning to maximize their security investments. • Build and maintain strong, positive relationships with clients, acting as a primary technical point of contact for Google SecOps initiatives. • Create and maintain comprehensive documentation for client environments, configurations, and best practices. Share knowledge and expertise with internal teams. • Continuously research and stay up-to-date with the latest Google security product updates, features, and threat landscape trends.
Role Description At Sabio Group, we build and operate AI-powered customer experience platforms for some of the world's most demanding enterprise brands. As we push deeper into agentic AI, multi-cloud architectures and high-volume conversational systems, the attack surface evolves with us — and we need people who can think like adversaries to keep our customers, our data and our reputation safe. We're hiring a Red Team Security Engineer to join our Information Security & Cyber Security team in South Africa. You'll be the offensive counterpart to our defensive function: stress-testing the solutions we design, build and operate — from cloud-native services to LLM-powered agents — by attacking them the way a real adversary would, and partnering with engineering teams to fix what you find. This is a hands-on role for someone who is genuinely curious about how systems break, comfortable writing code as well as reading it, and excited about the new class of vulnerabilities emerging in AI and agentic systems. Qualifications - Demonstrable hands-on experience in offensive security — penetration testing, red teaming, or adversary simulation — against modern web, API and cloud-based systems. - Strong understanding of common vulnerability classes (OWASP Top 10, authZ flaws, SSRF, deserialization, injection, cryptographic misuse) and how to chain them into real impact. - Solid grasp of cloud security in at least one major provider (AWS, Azure or GCP): IAM, networking, key management, container and serverless services, common misconfigurations and attack paths. - Practical understanding of AI/LLM systems — how they work, where they fail, and the new risks they introduce (prompt injection, jailbreaks, insecure tool use, training/RAG data exposure). - Coding capability in at least one of Python, Go, JavaScript/TypeScript or similar — comfortable writing exploits, tooling and automation, not just running other people's tools. - Confidence with offensive tooling — Burp Suite, nmap, Nuclei, BloodHound, Metasploit, custom scripts — and the judgement to know when to build vs. buy. - Familiarity with CI/CD, containers and IaC (Docker, Kubernetes, Terraform or equivalent) and how to attack and defend them. - An evaluation mindset: you measure security posture with reproducible tests, metrics and evidence — not gut feel. - Comfort with agentic development workflows — using AI coding assistants and AI co-work / pair-development models (Claude Code, Copilot, Cursor or equivalent) as part of your day-to-day delivery. - Clear written and verbal communication in English: able to brief engineers, executives and (where relevant) customers on findings and risk. - A strong ethical compass and discipline around scope, rules of engagement, evidence handling and responsible disclosure. Requirements - Plan and execute red team engagements, penetration tests and adversary simulations against our platforms, products and corporate environment. - Identify, exploit and document vulnerabilities across web applications, APIs, cloud infrastructure, identity systems and AI/LLM-based services. - Develop realistic attack scenarios — initial access, privilege escalation, lateral movement, data exfiltration — mapped to frameworks such as MITRE ATT&CK. - Build and maintain custom tooling, exploits and automation where off-the-shelf tools fall short. - Leverage AI pen testing tooling and frameworks as a force amplifier within your role. - Active, hands-on use of AI-powered offensive security tooling as a core part of your workflow — leveraging LLMs and agentic assistants to accelerate reconnaissance, exploit development, code review, payload generation and report writing. - Familiarity with emerging AI red-team frameworks and platforms — e.g. PyRIT, Garak, Promptfoo, NVIDIA Aegis, Microsoft Counterfit, HackerOne / Bugcrowd AI testing toolkits, or equivalent — and a practical sense of when to use which. - Experience building or extending automated AI red-team harnesses: prompt-injection test suites, jailbreak corpora, tool-abuse scenarios, multi-turn attack agents, and regression eval sets for LLM and agentic systems. - Pragmatic judgement on the limits and risks of AI-assisted offensive work — hallucinated findings, false confidence, data leakage into third-party models — and the discipline to validate AI output before acting on it. - Curiosity to keep pace with a fast-moving space: new models, new attack techniques, new defensive controls — and a willingness to bring those learnings back into the team. - Probe LLM-powered and agentic systems for prompt injection, jailbreaks, tool/function-call abuse, context leakage, insecure output handling and supply-chain risks. - Test RAG pipelines, knowledge bases and integrations for data exfiltration, poisoning and unauthorized access paths. - Contribute to internal threat models for agentic architectures and help shape secure-by-default patterns for multi-agent and tool-using systems. - Stay close to evolving standards and guidance (e.g. OWASP Top 10 for LLMs, NIST AI RMF, emerging agent interoperability protocols). - Perform deep-dive security testing of cloud workloads across AWS, Azure and/or GCP — IAM, network, container, serverless and data-layer concerns. - Review CI/CD pipelines, IaC (Terraform, CloudFormation, Bicep) and Kubernetes deployments for misconfigurations and exploitable weaknesses. - Conduct source-assisted ("grey-box") testing — reading code to find logic flaws, authZ gaps and unsafe integrations. - Triage findings, assign realistic severity, and write clear, reproducible reports with concrete remediation guidance. - Partner with engineering teams to validate fixes, advise on secure design and pair on hardening work — not just throw findings over the wall. - Drive continuous improvement of detection coverage by working with the blue team / SOC on purple-team exercises. - Build automation that turns one-off tests into repeatable, scheduled checks — exposure scanning, attack-path analysis, agent red-teaming harnesses. - Integrate offensive testing into the SDLC: SAST/DAST/IAST, dependency scanning, secrets detection, container and IaC scanning. - Treat evaluation and regression of security controls as a first-class deliverable — measured, not assumed. - Work alongside the Head of Information Security, AI Ethics leads, platform engineering and product teams to embed security early. - Produce clear design reviews, threat models, runbooks and post-engagement reports for both technical and executive audiences. - Operate within strict rules of engagement, with care for production stability, customer data and legal/regulatory obligations. Benefits - Remote/Flexible work - Discovery Medical Aid - Connectivity Allowance - 15 days paid holiday a year (this includes three Sabio days) - Momentum EAP


