Cybersecurity Assessor – CMMC
Location
United States
Posted
1 day ago
Salary
$90K - $115K / year
Seniority
Senior
Job Description
Cybersecurity Assessor – CMMC
Vaultes
• Conduct security control assessments for commercial and government customers to determine the overall effectiveness of the controls and the vulnerability state of components, applications and databases residing within a system boundary. • Develop, document and review System Rules of Engagement (ROE), Security Assessment Plans (SAPs) and Security Assessment Reports (SARs). • Conduct kick-off meetings, develop associated schedules and resource plans to complete the assessments. • Responsible for quality control on the assessment and associated deliverables. • Develop practical and risk-based approaches for security control implementation and vulnerability remediation. • Review and provide feedback system boundaries, common controls, the security categorization of information systems, applicable security control baseline based on system categorization. • Review cyber/system/network security body of evidence and documentation for accuracy and completeness. • Lead Post Assessment Meetings with the customer. • Provide Plan of Action and Milestones (POA&M) support to ensure mitigations are completed or the teams are working to mitigate all vulnerabilities in a timely fashion and within customer policy timelines. • Perform continuous monitoring to ensure implemented security controls remain functional throughout the lifecycle of the information system. • Perform other duties as assigned.
Job Requirements
- Must be a US Citizen
- Must be able to obtain and maintain favorable suitability determination by the CyberAB
- BS/BA degree in Information Technology or related Cybersecurity field
- 5+ years of auditing and/or assessment experience
- Thorough knowledge of cloud environments (services/security)
- Strong background working with NIST 800-171 and/or NIST 800-53
- Must have an active CCP certification listed in the CMMC Marketplace
- Must have at least the following industry certifications for CCP CompTIA Security + (Sec+)
- Must have at least one of the following industry certifications for CCA: Certified Information System Security Professional (CISSP), CompTIA Advanced Security Practitioner (CASP+ CE), Security X, CompTIA Cybersecurity Analyst (CySA+), Certified Information Systems Auditor (CISA), Certified Information Security Manager (CISM), Certified Cloud Security Professional (CCSP), Mile Two Certified or Certified Information Systems Security Officer (C|CISSO)
Benefits
- Paid time off
- Paid holidays
- Work-from-home opportunities
- 401k with matching incentive
- Competitive Medical/dental/vision benefits
- Company provided life insurance
- Company provided short-term disability
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Information Security Manager
Aqua Finance, Inc.Aqua provides flexible financing programs to dealers, contractors, and retailers so families can realize their dreams.
• Lead and manage Security Analysts responsible for security operations center (SOC) activities and security administration • Oversee daily security monitoring, event triage, escalation handling, and incident response coordination • Establish team priorities, assign work, and ensure timely completion of operational security tasks and remediation activities • Develop and report on security operations metrics, trends, and performance indicators • Oversee administration of security tools, including monitoring platforms, endpoint protection, vulnerability management, and access controls • Manage user access administration, privileged access review support, and periodic access validation processes • Ensure security controls are functioning effectively and that issues are tracked, escalated, and remediated • Maintain team procedures, runbooks, and documentation for security operations and incident response • Support the implementation, tuning, and effectiveness of security tools and monitoring capabilities • Lead incident detection and response activities, including escalation to leadership when appropriate • Coordinate with IT and system owners on containment, remediation, recovery, and lessons learned • Monitor emerging threats and vulnerabilities and direct team focus accordingly • Support audit readiness, assessments, and operational response exercises • Manage, coach, and develop Security Analysts, including performance management and career development • Promote consistency in investigation, documentation, escalation, and communication practices • Partner with the CISO on staffing, workload planning, and operational maturity initiatives • Collaborate with Audit, Risk, Compliance, and IT teams on control validation and issue remediation • Support third-party reviews and audit follow-up activities • Escalate material risks, control gaps, and resource concerns to the CISO • Ensure alignment with organizational policies, standards, and regulatory requirements
Information Systems Security Engineer
Booz Allen HamiltonBooz Allen Hamilton is an award-winning provider of strategic innovation, management consulting, technology, and engineering services. Founded in 1914, the comp
Work will help ensure secure deployment of advanced capabilities that support national operations, enhance readiness, and defend vital infrastructure.
Strategic Security Advisor
GuidePoint SecurityFounded in 2011 and headquartered in Herndon, Virginia, GuidePoint Security furnishes commercial and federal organizations with customized information security
Title: Strategic Security Advisor (New York Metro) - Northeast region Location: USA, Remote Job Description: GuidePoint Security provides trusted cybersecurity expertise, solutions and services that help organizations make better decisions and minimize risk. By taking a three-tiered, holistic approach for evaluating security posture and ecosystems, GuidePoint enables some of the nation’s top organizations, such as Fortune 500 companies and U.S. government agencies, to identify threats, optimize resources and integrate best-fit solutions that mitigate risk. Location: New York City, NY (Local candidates only) About the Role We are seeking an exceptional Strategic Security Advisor to serve as a senior individual contributor and trusted cybersecurity advisor to our most strategic customers. In this role, you will leverage your deep expertise and executive presence to develop consultative relationships with customer leaders and identify opportunities to deliver GuidePoint Security solutions that address their most critical security challenges. Key Responsibilities - Strategic Customer Partnership: Establish and maintain deep, consultative relationships with customer executives and security leaders, serving as their primary trusted advisor on cybersecurity matters - Opportunity Development: Identify and uncover opportunities where GuidePoint Security solutions can address customer cybersecurity needs and business objectives - Advisory Excellence: Provide expert guidance on cybersecurity strategy, risk management, and security program development tailored to each customer's unique environment - Thought Leadership: Represent GuidePoint Security as a subject matter expert in the cybersecurity community through speaking engagements, publications, and industry events - Cross-functional Collaboration: Partner closely with sales, delivery, and product teams to ensure seamless customer experiences and drive solution alignment - Market Intelligence: Stay current on emerging threats, industry trends, and regulatory requirements affecting customers in the region, and proactively communicate relevant insights to customers - Mentorship & Influence: Serve as a senior resource and mentor to colleagues, contributing to the development of best practices, methodologies, and advisory frameworks across the organization Other Responsibilities - Identify opportunities for program efficiency, alignment, and optimization across client engagements. - Advocate internally for client requirements, ensuring the right technical, architectural, and strategic resources are assigned. - Guide the creation of roadmaps and strategic plans that support client growth and security maturity. - Support vendor relationship management to ensure solution fit, partner accountability, and long-term success. - Partner with Architects and Presales Engineers to correctly identify, socialize, and document client requirements. - Collaborate with Sales leadership to support regional and account-specific resource alignment. - Work with Service Delivery and Engagement Leadership to define achievable program outcomes and ensure continuity from presales to delivery. Coordinate with vendor partners to shape and maintain long-term strategic relationships. Required Qualifications - 10+ years of experience in cybersecurity, with at least 5 years in advisory, consulting, or senior customer-facing roles - Ability to challenge assumptions, clarify goals, and advocate for measurable outcomes. - Demonstrated success in building and managing executive-level customer relationships that drive measurable business outcomes - Deep expertise across multiple cybersecurity domains (e.g., risk management, compliance, incident response, security architecture) - Strong business acumen with ability to translate technical concepts into business value for diverse stakeholders - Excellent communication and presentation skills with C-level executives - Established network and reputation in the New York City cybersecurity community - Must be local to the New York City metropolitan area Preferred Qualifications - Relevant certifications such as CISSP, CISM, CISA, or similar - Experience with security frameworks (NIST, ISO 27001, CIS Controls) - Background in professional services or consulting - Track record of driving significant revenue growth through advisory relationships We use Greenhouse Software as our applicant tracking system and Zoom Scheduler for HR screen request scheduling. At times, your email may block our communication with you. Please be sure to check your SPAM folder so that you don't miss updates on your application. Why GuidePoint? GuidePoint Security is a rapidly growing, profitable, privately-held value added reseller that focuses exclusively on Information Security. Since its inception in 2011, GuidePoint has grown to over 1,200 employees, established strategic partnerships with leading security vendors, and serves as a trusted advisor to more than 6,200 customers. Firmly-defined core values drive all aspects of the business, which have been paramount to the company’s success and establishment of an enjoyable workplace atmosphere. At GuidePoint, your colleagues are knowledgeable, skilled, and experienced and will seek to collaborate and provide mentorship and guidance at every opportunity. This is a unique and rare opportunity to grow your career along with one of the fastest growing companies in the nation. Some added perks…. - Remote workforce primarily (U.S. based only, some travel may be required for certain positions, working on-site may be required for Federal positions) - Group Medical Insurance options: Zero Deductible PPO Plan (GuidePoint pays 90% of the premium for employees and 70% for family plans (spouse/children/family) or High Deductible Health Plan with HSA (GuidePoint pays 100% of the employees premiums and 75% for family plans (spouse/children/family). If you choose the High Deductible / HSA plan, GPS will contribute in 4 equal quarterly installments: ($850 per EE annually / $1750 per family annually (includes spouse/children/family options) - Group Dental Insurance: GuidePoint pays 100% of the premium for employees and 75% of family plans - 12 corporate holidays and a Flexible Time Off (FTO) program - Healthy mobile phone and home internet allowance - Eligibility for retirement plan after 2 months at open enrollment - Pet Benefit Option
Title: Systems Administrator/Security Integration Engineer SME Location: Alexandria, VA Job Description: Job Type Full-time, Contract Description ROLE & RESPONSIBILITIES The Senior Network Architect / Security Integration Engineer (SME) serves as the technical lead for the architecture, design, integration, testing, and deployment of Software Defined Networking (SDN), Zero Trust Architecture (ZTA), Software Defined Perimeter (SDP), and Micro-Segmentation capabilities within federal/DOD environments. This role is responsible for translating mission requirements into secure, scalable network architectures while developing and enforcing advanced security policies that support Zero Trust initiatives. The position serves as the senior technical authority for software-defined networking, security segmentation, traffic flow analysis, policy engineering, endpoint validation, and enterprise integration activities. The successful candidate will lead technical design efforts, develop test strategies, oversee engineering documentation, troubleshoot complex network and security issues, and coordinate directly with government stakeholders, engineering teams, cybersecurity personnel, and enterprise service owners. Enterprise Architecture & Design • Lead end-to-end design of SDN, ZTA, SDP, and micro-segmentation architectures across DoDIN and DHS enterprise environments • Develop High-Level Designs (HLDs) and Low-Level Designs (LLDs) for software-defined networking and security environments • Define network segmentation, policy enforcement, and Zero Trust security architectures • Ensure interoperability with enterprise transport services, security infrastructure, and mission systems • Translate mission requirements into secure, scalable, and supportable technical architectures Software Defined Networking (SDN) Leadership • Architect and guide deployment of software-defined networking solutions including Cisco SD-WAN, Cisco Software Defined Access (SDA), VMware NSX or equivalent technologies • Establish automation strategies using APIs, Ansible, Python, and Infrastructure-as-Code methodologies • Drive standardization of templates, configurations, deployment models, and operational procedures Zero Trust Architecture (ZTA) & Security Integration Leadership • Lead design and implementation of Zero Trust Architecture capabilities across enterprise environments • Architect Software Defined Perimeter (SDP) solutions utilizing AppGate or equivalent Zero Trust technologies • Design and implement micro-segmentation architectures utilizing Illumio or equivalent segmentation platforms • Develop security policies based on application dependencies, user identity, device posture, and mission requirements • Translate cybersecurity requirements into enforceable security policies and access control models • Analyze traffic flows and dependency mappings to create hardened least-privilege security architectures • Integrate identity services, PKI infrastructure, certificates, authentication services, and access control mechanisms into Zero Trust environments Test Plan Development & Validation Engineering • Develop comprehensive technical test plans and endpoint validation strategies • Establish security enforcement testing procedures and operational validation methodologies • Lead lab testing, pilot deployments, and operational acceptance testing activities • Validate segmentation boundaries, access control policies, and application dependency mappings • Develop repeatable test frameworks supporting mission and operational use cases Cybersecurity & Compliance • Ensure designs align with Risk Management Framework (RMF), DISA STIG requirements, NIST Zero Trust Architecture guidance and DoD Cybersecurity policies • Support Authorization to Operate (ATO) activities and accreditation efforts • Integrate security controls including encryption, identity enforcement, segmentation, and policy management • Support compliance documentation and security engineering reviews • Coordinate firewall path validation, identity integrations, PKI services, and directory service dependencies • Provide technical leadership during design reviews, IPT meetings, PMO syncs, and engineering reviews Traffic Flow Analysis & Security Engineering • Analyze live network traffic and application dependencies • Develop dependency matrices and communication flow mappings • Engineer highly accurate security policies based on observed application behavior • Validate routing, switching, security, and authentication paths supporting enterprise applications Advanced Troubleshooting & Operations Support • Serve as Tier III escalation authority for SDN, SDP, and micro-segmentation deployments • Utilize Wireshark and packet-level analysis to troubleshoot communication failures • Diagnose routing issues, policy conflicts, firewall enforcement problems, authentication failures, and application connectivity issues • Validate client-to-controller communication paths and security policy enforcement mechanisms Technical Leadership & Delivery Excellence • Serve as lead architect across programs, projects, and task orders • Mentor engineers and provide technical oversight for implementation teams • Validate solutions in lab environments, integration facilities, and operational test environments • Drive delivery discipline ensuring architectures are executable, supportable, secure, and scalable Documentation & Governance • Produce and maintain: - Architecture diagrams - High-Level Designs (HLD) - Low-Level Designs (LLD) - Test plans - Validation plans - Security policy documentation - Technical implementation plans • Review and approve engineering artifacts generated during pilots and production deployments • Support Configuration Control Boards (CCB) and Engineering Review Boards (ERB) • Provide technical inputs to executive briefings and strategic planning efforts Please note: This opening is contingent upon contract award (expected award & start date is June/July 2026). Requirements • Bachelor’s Degree in Engineering, Computer Science, Information Systems, Cybersecurity, or related field • Master’s Degree preferred • 10+ years of progressive experience supporting enterprise networking, cybersecurity environments and firewall technologies • 5+ years designing or implementing Software Defined Networking (SDN), Zero Trust Architecture (ZTA) and Enterprise Security Architectures • Experience supporting federal regulated enterprise environments; ability to work in secure DoDIN environments required • Active Secret clearance or higher Technical Requirements Deep expertise in: • Routing and Switching (BGP, OSPF, MPLS) • Layer 2 and Layer 3 network architectures • Network segmentation and security architecture • Stateful firewalls and policy enforcement • Zero Trust Architecture • Software Defined Perimeter concepts • Micro-segmentation architectures • PKI and certificate-based authentication • Active Directory and LDAP integration • Wireshark or equivalent packet capture and analysis tools • Automation (Ansible, Python, REST APIs) • VMware environments • AWS GovCloud • Microsoft Azure Government • Infrastructure orchestration technologies • Hands-on experience with Cisco SD-WAN, Cisco SDA, Cisco ISE, Firepower (FTD), Palo Alto, or equivalent firewall platforms Preferred Skills • Experience supporting large-scale SD-WAN deployments • Experience implementing Zero Trust initiatives within federal environments • Experience with AppGate, Illumio, Guardicore, Zscaler, or equivalent technologies • Experience developing micro-segmentation policies from application dependency mapping • Experience supporting federal C5I environments • Experience in lab-based integration and validation environments Required Certifications • Cisco Certified Network Professional (CCNP Enterprise or Security) • CompTIA Security+ Preferred Certifications • Cisco CCIE Enterprise Infrastructure • Cisco CCIE Security • CISSP • VMware VCP-NV • Zero Trust Architecture or similar Work Environment • Hybrid work environment with some travel to customer and integration lab locations as required • Participation in after-hours maintenance windows, cutovers, and incident response activities as required



