Intelligence-led, precision-fit cybersecurity.
Cybersecurity Assessor
Location
Texas
Posted
3 days ago
Salary
$80K - $120K / year
Seniority
Senior
Job Description
Cybersecurity Assessor
Apollo Information Systems
• Independently plan and lead hands-on cybersecurity assessments across enterprise, cloud, and public-sector environments — including election infrastructure at the county, city, and state level. • Evaluate the design and operating effectiveness of technical controls spanning identity and access management, endpoint protection, patch and vulnerability management, secure configuration, network segmentation, data protection, logging/monitoring, and incident response. • Review and interpret technical configurations and artifacts — firewall rulesets, GPOs, hardening baselines, cloud security configurations, IAM policies, and logging setups — to validate control implementation. • Conduct stakeholder interviews and documentation reviews to understand policy, process, and control maturity. • Assess client environments against established frameworks and standards including NIST CSF 2.0, CIS Controls, ISO 27001, CMMC, CJIS, HIPAA, and PCI DSS. • Produce detailed assessment reports with prioritized risk findings, maturity ratings, and pragmatic, business-aware recommendations. • Map findings to client risk and business context, translating technical gaps into clear remediation roadmaps. • Present findings and recommendations to client stakeholders ranging from technical practitioners to executive leadership. • Drive continuous improvement of Apollo’s assessment methodologies, workbooks, tooling, and report templates. • Mentor junior assessors and perform peer review of assessment deliverables. • Collaborate with consultants, engineers, advisors, and project managers to deliver high-quality engagements. • Stay current with emerging threats, technologies, and regulatory developments.
Job Requirements
- Experience in cybersecurity, with demonstrable experience leading or performing security assessments (confirm threshold)
- Direct, hands-on experience assessing environments against one or more recognized frameworks (NIST CSF, CIS Controls, ISO 27001, CMMC, CJIS, HIPAA, or PCI DSS)
- Strong working knowledge of security controls across operating systems, network infrastructure, cloud services, and identity systems.
- Ability to independently review and assess technical configurations and documentation (firewall rules, GPOs, hardening baselines, logging setups, cloud configs)
- Excellent written communication and the ability to produce client-ready reports, plus the ability to explain technical findings in plain language to non-technical audiences.
- Experience working with clients in a consulting capacity and managing multiple concurrent engagements.
- One or more relevant certifications — e.g., Security+, CySA+, CISA, GIAC (e.g., GSEC), or assessor-specific credentials such as CMMC CCP/CCA.
- Hands-on familiarity with Microsoft 365 and Azure (and exposure to AWS or GCP).
- Experience with security tooling — vulnerability scanners, SIEM/EDR platforms, and configuration analyzers.
- Experience supporting public sector clients, election infrastructure, or regulated industries.
Benefits
- Comprehensive medical, dental, and vision coverage, the company covers 100% of employee premiums and 90% of dependent premiums on base plans
- Unlimited PTO, 7 paid sick days, and 11 paid holidays
- 401(k) with 4% company match after 90 days, immediately vested
- Company‑paid life insurance at 1x annual salary
- Company‑paid Short‑Term Disability (STD) and Long‑Term Disability (LTD) coverage
- $125 monthly home‑office tech stipend for internet, equipment, and other technology needs
- Amazing colleagues, a collaborative environment, and a supportive, growth‑focused culture
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
• Be the link between Information Security (IS) and the business. • Serve as the dedicated and ongoing Information Security point of contact for Product and Engineering squads. • Actively participate in team ceremonies, planning sessions and product reviews — not as an occasional guest, but as a relevant member of the conversation. • Translate security requirements into language and context that make sense for development teams, product managers (PMs) and product leaders. • Identify, assess, and communicate security risks clearly to non-technical stakeholders. • Build and track risk treatment plans with the areas, prioritizing based on real business impact. • Ensure Product and Engineering teams understand the risks they are assuming with each decision — and that those choices are made consciously. • Act as a facilitator between squads and the IAM team for access provisioning and reviews — removing friction while maintaining necessary controls. • Support teams in incorporating security practices throughout the development lifecycle (security by design, threat modeling, architecture reviews). • Act as a guide on compliance and Information Security policies, with a pragmatic view of the real needs of those building the products. • Foster a security culture that is perceived as an enabler, not an obstacle. • Promote continuous, contextualized security awareness for Product and Engineering teams. • Identify recurring risk patterns and propose systemic improvements, not just ad-hoc fixes.
Security & Compliance Engineer
Grant Street GroupGrant Street Group specializes in cloud-based government solutions for tax collection, e-payments, and auctions.
• Support the day-to-day security posture of systems and services across cloud and on-prem environments. • Review vulnerability findings from scanners, penetration tests, and other assessments, and help drive remediation to closure. • Partner with infrastructure, platform, and engineering teams on secure configuration, access control, logging, monitoring, and incident readiness. • Support compliance and assessment activities related to GovRAMP/FedRAMP, PCI DSS, internal reviews, and third-party examinations. • Use AWS security tooling effectively, support day-to-day security processes, and help translate security and compliance requirements into practical, durable operational outcomes. • Maintain documentation, procedures, and other operational artifacts so they stay aligned with the environment and current control expectations.
Security and Compliance Consultant
Planet TechnologiesFor 24 years, we have built our reputation on establishing trust. Trust with our clients and among our team.
• Serve as a primary technical lead on client engagements involving Microsoft security, compliance, and data protection solutions • Design and implement data security, governance, and compliance strategies aligned with Microsoft 365 and Azure capabilities • Advise clients on secure adoption of Microsoft Copilot, including data exposure risks, governance controls, and compliance considerations • Architect and deploy solutions leveraging tools such as: Microsoft Purview, Microsoft Defender suite and Microsoft Sentinel • Translate regulatory and compliance requirements into actionable technical solutions (e.g., ISO frameworks, government regulations, internal controls) • Conduct data discovery, classification, and protection strategy design • Collaborate with project managers and stakeholders to deliver high-quality outcomes • Contribute to pre-sales efforts, including solution design, scoping, and level-of-effort estimates • Create technical documentation, implementation guides, and client training materials • Act as a subject matter expert (SME) and mentor to other engineers • Develop and refine repeatable offerings around data security, compliance, and Copilot readiness • Stay current on evolving Microsoft security, compliance, and AI governance capabilities
• Define, analyze, and review secure software architectures for centralized automotive computing platforms • Perform threat modeling and security architecture analysis for mixed-criticality, multi-tenant automotive software systems • Partner with safety architects to reason about the interaction between security controls, safety mechanisms, failure modes, and recovery behavior • Define OS security policy, access control, isolation, and privilege models across Android, Linux, QNX, and virtualized environments • Build security systems that maintain integrity and availability for safety-critical vehicle software • Analyze security trade-offs involving performance, latency, memory footprint, boot time, diagnosability, and functional safety requirements • Guide engineering teams on secure build, secure coding, threat mitigation, and security review practices • Collaborate across software, hardware, safety, security, and systems teams to meet NVIDIA and automotive industry standards




