Security Control Assessor
Location
United States
Posted
46 days ago
Salary
0
Seniority
Mid Level
Job Description
Security Control Assessor
KITC, LLC
Role Description This is a remote position. We are seeking an experienced Security Control Assessor (SCA) to support cybersecurity assessments for state agencies. The assessor will evaluate compliance against 108 cybersecurity controls aligned to NIST CSF 2.0 and perform effectiveness testing on approximately 40 selected controls. The ideal candidate has strong experience conducting cybersecurity assessments, evaluating security governance and technical safeguards, and documenting findings and recommendations in accordance with NIST cybersecurity standards. Key Responsibilities - Conduct cybersecurity control assessments using 108 NIST CSF 2.0–aligned controls - Perform effectiveness testing for ~40 administrative, technical, and operational controls - Review policies, procedures, configurations, evidence artifacts, and operational practices - Conduct interviews and walkthroughs with agency personnel - Identify gaps, weaknesses, and remediation needs - Evaluate maturity and operational effectiveness of cybersecurity controls - Prepare findings reports, risk observations, and remediation recommendations - Maintain detailed assessment evidence and workpapers - Support risk discussions and provide cybersecurity best-practice guidance - Participate in meetings with project leadership and stakeholders - Ensure assessments follow consistent, objective, and standardized methodologies Deliverables - Control assessment worksheets - Evidence review documentation - Effectiveness testing results - Risk and gap findings - Remediation recommendations - Executive and technical assessment reports Work Location: Remote, with potential onsite visits to Florida state agency locations. Qualifications - Bachelor’s degree in Cybersecurity, IT, Information Assurance, or related field - Minimum 3 years conducting cybersecurity or information security assessments - Experience with: - NIST CSF 2.0 - NIST SP 800-171 or 800-53 - Security control assessments and testing - Risk assessments and compliance evaluations - Strong understanding of: - Governance and policy review - Identity and access management - Vulnerability management - Incident response - Logging and monitoring - Excellent written and verbal communication skills - Strong documentation and reporting abilities - Ability to analyze technical and non-technical cybersecurity evidence Requirements - Candidates must pass a state background investigation. Preferred Qualifications - Experience supporting state government or public sector agencies - Certifications: CISSP, CISA, CISM, CAP, Security+ - Experience with frameworks: NIST CSF, SP 800-171, SP 800-53, CJIS, SOC 2 Benefits - Remote work - Opportunity to support statewide cybersecurity initiatives - Professional development and growth opportunities - Collaborative and mission-driven environment
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Account Executive, Data Security – Majors
ZscalerZscaler helps leading organizations in 180+ countries securely transform their networks and applications for a mobile and cloud-first world. Founded in 2008, th
• Serve as the primary specialist for customers, partners, and internal teams to drive revenue growth across the data security product portfolio • Partner with domain-expert solution engineers to capture customer requirements and craft compelling value propositions that close complex business deals • Own the regional quota and territory achievement by building and implementing account-based strategies to land and expand data security solutions • Collaborate synergistically with primary sales teams and leadership to ensure a unified and effective Zscaler presence in the market • Engage stakeholders across the organization, selling effectively to both C-suite executives and technical practitioners
• Monitor and triage security alerts from SIEM, EDR, and other tools; escalate and respond as needed. • Investigate security incidents, determine root cause, document findings, and develop IOCs to prevent recurrence. • Support escalations from internal employees or customers with security-related concerns. • Assist with security reviews related to infrastructure and system changes. • Build, enhance, and maintain internal security tooling and scripting repositories. • Contribute to the development of detection content, alert tuning, and automation pipelines. • Drive annual security team goals and cross-functional initiatives. • Author and maintain clear, actionable documentation and knowledge bases. • Mentor junior team members and share expertise across the organization. • Participate in a rotating on-call schedule for security operations support.
• Design and implement security solutions to enable customers to securely deploy and govern Claude Enterprise • Assess existing security, identity, data, cloud and SaaS architectures and advise on best-in-class solutions for securing enterprise AI tooling across customers in a wide range of industries • Conduct comprehensive evaluations of AI tools (e.g. Claude, Claude Enterprise), platform configurations, data access patterns, connector usage, security controls, processes and personnel to deliver informed recommendations leveraging your expertise in security engineering and AI governance • Design and implement security controls for enterprise AI platforms, including SSO, SCIM, RBAC, MFA, conditional access, admin roles, user lifecycle management, retention policies, audit logging, workspace controls, DLP, and acceptable-use enforcement • Assess and govern AI platform features such as file uploads, custom assistants, projects, GPTs, connectors, browsing, code execution, data analysis, plugins, agents, API access, and external sharing • Review and secure AI integrations with enterprise repositories and collaboration platforms, including Google Drive, SharePoint, OneDrive, Slack, Teams, GitHub, GitLab, Jira, Confluence, Salesforce, Snowflake, Databricks, and BI platforms • Manage and lead end-to-end AI Security Implementation efforts as part of a project team; including activities such as identity integration, access control design, data protection controls, AI platform configurations, connector governance, monitoring / logging and incident response workflows
Developer Intern, Data Security
1PasswordProductive businesses use 1Password to secure employees at scale.
• Be partially responsible for the underlying cryptography across our products. • Help build cryptographic libraries and implement the latest algorithms directly into our client applications with security, performance and usability in mind. • Develop proof-of-concepts and implement new industry specifications into code. • Conduct code and design reviews to ensure good cryptographic hygiene and standards across our codebase.



