Security Control Assessor

Location

Worldwide

Posted

13 days ago

Salary

0

Seniority

Mid Level

Job Description

Security Control Assessor

Rampant Technologies

Role Description Implements, maintains, and assesses security controls supporting enterprise and government systems in alignment with approved baselines, organizational requirements, and federal cybersecurity standards. Supports system authorization activities, including the development, maintenance, and delivery of System Security Plans (SSPs), Plans of Action and Milestones (POA&Ms), and related security documentation required for Authorization to Operate (ATO) approval. - Monitors system security posture, identifies risks, vulnerabilities, and compliance gaps, and coordinates remediation activities with system owners, technical teams, cybersecurity operations, and governance stakeholders. - Supports continuous monitoring, vulnerability management, configuration management, change management, audit preparation, and security reporting activities. - Assesses the security impact of system changes and ensures systems are prepared for security assessments, audits, and Authorizing Official reviews. - Serves as a cybersecurity liaison between system teams, cybersecurity operations, and governance bodies to support secure system operations, compliance, and delivery of System Security Plans to the Y-12 Field Office for Approval to Operate. This is a remote position. Qualifications - Five (5+) to ten (10+) years of experience in cybersecurity, information systems security, security control assessment, ISSO support, system authorization, or programs and contracts of similar scope, type, and complexity is required. - Firm understanding of NIST SP 800-37 and NIST SP 800-53. - Experience implementing, maintaining, and assessing security controls aligned with approved security baselines and organizational requirements. - Experience supporting system authorization activities, including preparation and maintenance of System Security Plans (SSPs), POA&Ms, and other ATO-related documentation. - Experience monitoring system security posture and identifying risks, vulnerabilities, compliance gaps, and remediation requirements. - Experience tracking and managing POA&Ms and coordinating remediation activities with system owners, technical stakeholders, and cybersecurity teams. - Experience supporting continuous monitoring activities, vulnerability management, security reporting, and audit readiness. - Experience assessing the security impact of system changes and supporting configuration and change management processes. - Experience preparing systems for security assessments, audits, and Authorizing Official reviews. - Ability to serve as a security liaison between system teams, cybersecurity operations, and governance bodies. - Experience working in secure government, DOE, or federal cybersecurity environments preferred. Education, Certifications, & Credentials - Associate’s, Bachelor’s, or Master’s degree in Cybersecurity, Information Technology, Computer Science, Engineering, or a related technical field preferred. - Technical field experience may be weighted greater than minimum education requirements. - No clearance is required for this position. This is a remote position. All duties and responsibilities may not be captured in this job description. To find out more, please reach out to the recruiter for this role.

Related Categories

Related Job Pages

More Security Engineer Jobs

Tenable logo

Principal Security Consultant

Tenable

Cloud Security | Operational Technology | Identity Security | and more

Full TimeRemoteTeam 1,001-5,000Since 2002H1B Sponsor

• The Principal Consultant, acting as a technical advisor, is tasked with developing, mentoring, and training the Professional Services team, including overseeing their onboarding and maintaining up to date expertise on service offerings. • This role supports Delivery Management and Resource Management in achieving delivery Theatre objectives and revenue targets, while also handling client escalations by liaising between the delivery team and other Tenable functions. • Additionally, the Principal Consultant focuses on advancing Tenable Subk partners through training and certification onboarding and seeks opportunities to enhance the Professional Services structure through training tutorials and the creation of new methodologies. • This role also includes some client billable work, shared with the responsibilities outlined.

New Jersey + 4 moreAll locations: New Jersey | New York | Maryland | Massachusetts | Pennsylvania
$145K - $193.7K / year
Full TimeRemoteTeam 5,001-10,000H1B Sponsor

• Defining and owning the security architecture spanning Kubernetes infrastructure, inference runtimes, control plane APIs, and model lifecycle pipelines • Establishing threat models, security standards, and hardening guidelines across all platform teams and ensuring consistent adoption through reviews and automated enforcement • Leading security design reviews for critical systems including model serving environments, multi-tenant isolation, authentication and authorization frameworks, and data handling pipelines • Driving AI-specific security initiatives including defense against prompt injection, model extraction, adversarial inputs, data poisoning, and model supply chain attacks • Owning compliance readiness for regulatory frameworks (FedRAMP, SOC 2, GDPR), and emerging AI governance standards, partnering with legal and compliance teams • Developing and maturing the platform's security incident response capabilities including detection, investigation, and remediation playbooks for both traditional and AI-specific threats • Collaborating with Akamai's broader security organization to align inference platform security practices with enterprise standards and share learnings across product lines

Massachusetts
$132.1K - $237.9K / year

Role Description En PROCESIA buscamos incorporar varios profesionales en Consultoría Técnica especializados en gestión de identidades y ciberseguridad para participar en proyectos tecnológicos donde el reto no es mantener las luces encendidas, sino construir plataformas robustas, seguras y bien diseñadas desde el principio: Sí, hablamos de OpenIAM. Buscamos personas técnicas, sí. Pero también personas con criterio, curiosidad y ganas de construir cosas bien hechas. Las que preguntan ¿y si lo hacemos mejor? en lugar de ¿siempre se hizo así?. Buscamos personas que disfruten analizando, diseñando, implementando y evolucionando soluciones tecnológicas complejas. Gente cómoda tanto entendiendo arquitectura como entrando al detalle técnico cuando toca: - Titulación universitaria en Ingeniería o Formación Profesional técnica equivalente reconocida en España. - Mínimo 4 años de experiencia en proyectos TI. - Al menos 2 años trabajando en proyectos de consultoría de ciberseguridad relacionados con plataformas IAM. - Experiencia práctica con OpenIAM. - Capacidad de análisis técnico, diseño y resolución de incidencias complejas. - Conocimiento de entornos de identidad, accesos y operación de soluciones de seguridad. Y si además has participado en proyectos para la Administración de Justicia o en fases de arquitectura y diseño tendrás mucho terreno ganado. ¿Cuál será tu día a día? - Participarás en proyectos donde la identidad digital es crítica, colaborando con equipos especializados y trabajando sobre soluciones que requieren análisis, precisión técnica y visión de conjunto: - Analizar requisitos técnicos y funcionales relacionados con IAM y ciberseguridad. - Diseñar e implementar soluciones sobre plataformas OpenIAM. - Participar en tareas de desarrollo, configuración y operación técnica. - Colaborar en arquitecturas de identidad y gestión de accesos. - Resolver incidencias complejas y optimizar procesos existentes. - Documentar soluciones y participar en la mejora continua del servicio. - Trabajar junto a equipos multidisciplinares en proyectos de alta relevancia tecnológica. Traducido: habrá retos técnicos interesantes, decisiones importantes y alguna reunión que podría haber sido un email. Somos honestos. Qualifications - Titulación universitaria en Ingeniería o Formación Profesional técnica equivalente reconocida en España. - Mínimo 4 años de experiencia en proyectos TI. - Al menos 2 años trabajando en proyectos de consultoría de ciberseguridad relacionados con plataformas IAM. - Experiencia práctica con OpenIAM. - Capacidad de análisis técnico, diseño y resolución de incidencias complejas. - Conocimiento de entornos de identidad, accesos y operación de soluciones de seguridad. Requirements - Participar en proyectos donde la identidad digital es crítica. - Colaborar con equipos especializados. - Analizar requisitos técnicos y funcionales relacionados con IAM y ciberseguridad. - Diseñar e implementar soluciones sobre plataformas OpenIAM. - Participar en tareas de desarrollo, configuración y operación técnica. - Colaborar en arquitecturas de identidad y gestión de accesos. - Resolver incidencias complejas y optimizar procesos existentes. - Documentar soluciones y participar en la mejora continua del servicio. - Trabajar junto a equipos multidisciplinares en proyectos de alta relevancia tecnológica. Benefits - Contrato indefinido desde el inicio. - Proyecto estable, sólido y con visión a largo plazo. - Modalidad remota y flexibilidad horaria real. - Jornada intensiva todos los viernes y durante el verano. - Formación continua, certificaciones y clases de inglés. - Participación en proyectos estratégicos de ciberseguridad e identidad digital. - Plan de carrera adaptado a tu evolución técnica y profesional. - Seguro médico completo sin copagos. - Cultura colaborativa y participativa basada en Management 3.0. - Equipos cercanos donde compartir conocimiento no es opcional. - Nochebuena y Fin de Año libres. - Café y té en oficina para afrontar deployments, incidencias y reuniones de arquitectura con dignidad.

Spain
SupportYourApp logo

Information Security Incident Specialist

SupportYourApp

SupportYourApp is an industry leader in premium outsourced customer support that provides tech companies with reliable, cost-effective services. A multinational

Role Description Our team is continuously growing alongside our expanding client base, so we are looking for an Information Security Incident Specialist who is eager to apply their technical expertise, develop in the field of security, and work with real incidents and modern tools. What you will do: - Manage security and operational incidents end-to-end, including investigation, coordination, and response; - Communicate directly with Clients and stakeholders during Data Breach incidents; - Conduct Root Cause Analysis, develop preventive measures, and prepare management reports; - Analyze Clients’ workflows and incident trends to identify risks and improve security processes; - Assess the security of software, platforms, and third-party vendors; - Review new hiring locations for compliance with data protection and security standards; - Develop incident response procedures and maintain internal security documentation and knowledge base. Qualifications - Proven experience in investigating and handling information security incidents (from 1 year); - Experience in developing incident management procedures and documentation; - Analytical mindset and the ability to make fast decisions to mitigate incident impact; - Strong self-organization skills and the ability to prioritize work independently; - Understanding of data privacy principles and breach notification requirements; - English proficiency at level B2 or higher. Requirements - Proficiency in OSINT methodologies for investigations; - Experience in assessing the security of software, platforms, and third-party vendors; - Basic knowledge of security tools logic (SIEM, EDR, DLP, NGFW, VPN, VDI). Benefits - Providing services during business hours; - Opportunity to cooperate fully remotely; - Inclusive international environment; - Compensation in USD; - Rewards for referring friends; - Balance between project workload and personal time, but also – internal health policy; - Responsive leadership interested in your growth and long-lasting cooperation; - Greenhouse conditions for self-development; - A culture built on trust, with no time-tracking requirements. *The items listed in this section may vary depending on the terms of your engagement. Certain benefits and conditions typically apply to employees; independent contractors may not be eligible for all of these. The specific terms, including compensation, benefits, and work conditions, will be clearly defined in your agreement if selected.

Worldwide