
Senior Security Advisor – Lead Control Assessor
Posted 17 hours ago

Posted 17 hours ago
This is a fully remote position, open to applicants in South Carolina.
• Lead and perform cybersecurity control evaluations against a specified subset of essential controls in alignment with NIST SP 800-53 Rev. 5
• Evaluate the status of control implementation utilizing standardized criteria and validation methods in accordance with NIST SP 800-53A Rev. 5
• Conduct tests on information systems through documentation reviews, system walkthroughs, and interviews with stakeholders
• Assess the sufficiency and appropriateness of evidence using consistent judgment
• Oversee assessment planning, initiation, execution coordination, and closure activities
• Coordinate assessment tasks and assignments among Control Assessors
• Act as the main point of contact for client stakeholders throughout assessment engagements
• Review and endorse assessment narratives, findings, and control conclusions prior to quality assurance submission
• Ensure consistent execution across various clients to facilitate trend analysis and benchmarking
• Uphold assessment methodologies, scope limitations, and validation standards
• Address quality assurance feedback while ensuring the accuracy, clarity, and consistency of deliverables
• Lead and engage in client interviews, system walkthroughs, and collaborative sessions
• Communicate assessment scope, expectations, and evidence requirements to stakeholders
• Present assessment results, findings, and risk implications to executive leadership and board members
• Mentor and guide Control Assessors in assessment techniques, documentation standards, and professional judgment
• Escalate risks, issues, and questions regarding control interpretation to program leadership
• 7+ years of professional experience in cybersecurity, information security, IT audit, or risk and compliance
• 2+ years of experience leading or conducting cybersecurity control assessments or IT audits, with proven responsibility for control testing and validation
• Bachelor’s degree in Information Security, Information Systems, Computer Science, or a related field, or equivalent professional experience
• Relevant professional certifications such as CISSP, CISM, CISA, CRISC, or equivalent are strongly preferred
• Demonstrated experience in testing and evaluating security controls in accordance with NIST SP 800-53 Rev. 5
• Familiarity with assessment procedures consistent with NIST SP 800-53A Rev. 5
• Experience in executing repeatable, methodology-driven assessment programs across multiple organizations or systems
• Excellent written and verbal communication skills, including experience in presenting assessment results to executive and board-level audiences
• Ability to maintain confidentiality and professionalism with sensitive client information
• Capable of prolonged periods at a desk and working on a computer
• Majority of work hours will be from 9:00 AM EST to 5:00 PM EST
• Primarily remote work
• Flexibility in scheduling
• Periodic travel to client sites based on client needs
NVIDIA
BMO U.S.
Abnormal Security
World Wildlife Fund
Get handpicked remote jobs straight to your inbox weekly.