
Cyber Lead Auditor / Test Lead
Posted 18 hours ago

Posted 18 hours ago
This is a fully remote position, open to applicants in Florida.
• Provide independent technical and assurance leadership for a cybersecurity assurance initiative for the state of Florida.
• Transform OCIG objectives into audit-compliant testing strategies and detailed procedures.
• Oversee evidence collection and analysis processes.
• Ensure factual findings are substantiated and traceable to relevant criteria within a multi-agency framework.
• Lead the review and analysis of agency documentation, such as risk assessments, remediation plans, previous findings, corrective actions, inventories, and strategic plans.
• Guide the creation of the Agency Risk Understanding Memorandum.
• Design Ground-Truth and Ad Hoc Testing Strategies and authorize detailed testing procedures.
• Align procedures and outcomes with NIST CSF criteria, Rule 60GG-2, F.A.C., and other applicable approved criteria.
• Ensure testing adheres to OCIG authorization, avoids redundancy with operational testing, and complies with agency-specific Rules of Engagement.
• Examine evidence for relevance, reliability, sufficiency, attribution, timestamps, chain of custody, and reproducibility.
• Validate reports and ensure advisory recommendations are clearly marked.
• Conduct independent quality assurance reviews of technical deliverables and document approvals.
• Facilitate technical briefings, workshops, job aids, and knowledge transfer sessions.
• Assist in urgent analysis of logs, timelines, after-action reports, remediation evidence, and incident-specific control challenges.
• Bachelor’s degree in cybersecurity, information assurance, audit, information systems, or a related field.
• Active Certified Information Systems Security Professional (CISSP) certification.
• At least two additional active certifications from: GIAC GMON, GCIH, GCIA, GSEC, CEH, SSCP, or CompTIA Security+.
• Minimum of 10 years of progressive experience in cybersecurity, encompassing security operations, incident response, vulnerability management, intrusion analysis, adversary simulation, technical assessments, or audit support.
• At least 5 years of experience supporting or conducting audits, compliance reviews, independent assessments, or assurance activities in government or similarly regulated environments.
• Capability to design defensible test procedures, assess control performance, differentiate fact from opinion, and convey technical results to senior stakeholders.
• Proficient understanding of professional auditing or assurance standards and evidence requirements.
• Willingness to undergo the government-mandated background investigation process.
• Preferred: CISSP along with one monitoring/intrusion credential (GMON or GCIA) and one incident-handling credential (GCIH).
• Preferred: Experience in purple-team or adversary-emulation leadership utilizing MITRE ATT&CK and threat-informed kill chains.
• Preferred: Experience in government incident-command operations.
• Preferred: CISA, CIA, or similar audit credential.
• Preferred: Familiarity with Active Directory, cloud platforms, APIs, web applications, databases, endpoints, SIEM/EDR, vulnerability scanners, and evidence repositories.
• Equal opportunity employer with nondiscrimination protections.
• Opportunity to engage in a cybersecurity assurance program for the state of Florida.
• Access to technical briefings, workshops, job aids, and knowledge transfer opportunities.
Deckers Brands
Get handpicked remote jobs straight to your inbox weekly.