Senior Security Controls Assessor @Cherokee Federal
All Others
Salary usd 150,000 - 1..
Remote Location
🇺🇸 USA Only
Employment Type full-time
Posted 6d ago

[Hiring] Senior Security Controls Assessor @Cherokee Federal

6d ago - Cherokee Federal is hiring a remote Senior Security Controls Assessor. 💸 Salary: usd 150,000 - 155,000 per year 📍Location: USA

Role Description

This position requires an active Public Trust clearance or the ability to obtain a Public Trust clearance to be considered.

The Senior Security Controls Assessor provides independent assessments of MARAD information systems in support of system authorization, reauthorization, and continuous monitoring activities. This role evaluates management, operational, and technical security controls in accordance with NIST Risk Management Framework (RMF) requirements, supports Authority to Operate (ATO) decisions, develops assessment documentation and reports, and collaborates with MARAD, DOT, and cybersecurity stakeholders to ensure compliance, risk visibility, and mission assurance.

Responsibilities

  • Assess MARAD systems in one of three states: Initial Authorization, Reauthorization, or Continuous Monitoring Assessment (CMA).
  • Provide annual assessment support to the NSMV and MARAD CIO programs, including on-site evaluations at the Philadelphia shipyard and other locations.
  • Conduct independent assessments of specified MARAD information systems following the System Authorization process.
  • Review existing information-system core documentation to support the development of security assessment plans and schedules.
  • Review and establish annual assessment schedules in support of required deliverables and artifacts.
  • Identify noncompliance with security requirements and recommend possible mitigation strategies.
  • Validate the security requirements of information systems.
  • Verify that systems meet applicable security requirements.
  • Conduct independent and comprehensive assessments of management, operational, and technical security controls.
  • Execute and analyze network and system assessments to validate appropriate security-control implementation.
  • Develop Security Assessment Plans and Security Assessment Reports compliant with NIST standards.
  • Develop Security Assessment Plans (SAPs) that clearly define the assessment scope, exclusions, controls being assessed, and proposed schedules.
  • Follow the approved SAP when assessing security controls for targeted information systems.
  • Use approved techniques to collect and catalog supporting evidence.
  • Develop Security Assessment Reports (SARs) documenting assessment findings and evidence supporting the implementation status of each assessed control.
  • Develop and update qualitative Risk Assessment Reports (RARs) compliant with NIST SP 800-30.
  • Develop recommendation reports supporting Plan of Action and Milestones (POA&M) development.
  • Develop executive-summary documents and presentations that provide an overview of assessment activities, findings, risks, and mitigation recommendations.
  • Enter assessment data into the Cyber Security Assessment and Management (CSAM) database.
  • Provide presentations, reports, evaluations, reviews, meeting minutes, and working papers supporting all assigned tasks.
  • Apply MARAD and DOT Assessment and Authorization guidance and policies to achieve program objectives.
  • Collaborate actively with the designated Information Systems Security Manager (ISSM).
  • Perform other job-related duties as assigned.

Qualifications

  • Bachelor’s degree in Cybersecurity or a related IT field may be substituted for four years of experience.
  • Bachelor’s degree in an IT-related field.
  • Certified Information Systems Auditor (CISA), Advanced in AI Audit (AAIA), or an equivalent certification.
  • Twelve years of related work experience.
  • Prior experience supporting U.S. Navy or Coast Guard maritime cybersecurity assessments.
  • Must possess or be able to obtain a Public Trust clearance.
  • Prior Department of Transportation experience is a plus.
  • Must pass Cherokee Federal’s pre-employment qualifications.

Benefits

  • Pay commensurate with experience: $150,000 - $155,000.
  • Full-time benefits include Medical, Dental, Vision, 401(k), and other possible benefits as provided.
  • Benefits are subject to change with or without notice.

Company Description

Criterion is part of Cherokee Federal, the division of tribally owned federal contracting companies owned by Cherokee Nation Businesses. As a trusted partner for more than 60 federal clients, Cherokee Federal LLCs are focused on building a brighter future, solving complex challenges, and serving the government’s mission with compassion and heart. To learn more about Criterion, visit cherokee-federal.com.

Before You Apply
️
🇺🇸 Be aware of the location restriction for this remote position: USA Only
‼ Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Senior Security Controls Assessor @Cherokee Federal
All Others
Salary usd 150,000 - 1..
Remote Location
🇺🇸 USA Only
Employment Type full-time
Posted 6d ago
Apply for this position
Did not apply ✓
Applied ✓
Sent Follow-Up ✓
Interview Scheduled ✓
Interview Completed ✓
Offer Accepted ✓
Offer Declined ✓
Application Denied ✓
Unlock 125,000+ Remote Jobs
️
🇺🇸 Be aware of the location restriction for this remote position: USA Only
‼ Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply ✓
Applied ✓
Sent Follow-Up ✓
Interview Scheduled ✓
Interview Completed ✓
Offer Accepted ✓
Offer Declined ✓
Application Denied ✓
Unlock 125,000+ Remote Jobs
×
Apply to the best remote jobs
before everyone else

Access 125,000+ vetted remote jobs and get daily alerts.

4.9 ★★★★★ from 500+ reviews

⚡ 126,523+ remote jobs, refreshed hourly

🔔 Real-time alerts: Apply first

🛡️ Vetted companies, no scams, true remote only

Unlock All Jobs Now

Maybe later