2 open positions available
Lead RMF lifecycle and security assessments to maintain ATO status and develop contingency plans ensuring cybersecurity policy compliance. | Bachelor's degree with 6+ years progressive cybersecurity or ISSO/ISSM experience and U.S. citizenship for clearance. | We are seeking a highly skilled and experienced Information Systems Security Officer (ISSO) - Senior to join our team. In this critical role, you will be responsible for executing the full RMF lifecycle across all information systems and applications, leading security assessment activities with the goal of maintaining a 100% Authority to Operate (ATO) status. As a senior leader, you will ensure the rigorous application of cybersecurity policies, manage system remediation efforts, design critical contingency plans, and champion cybersecurity awareness across the organization. Education: · Bachelor’s Degree (BA/BS) OR equivalent verifiable work experience Experience: · Six (6) years of progressive experience in information assurance, cybersecurity engineering, or ISSO/ISSM roles. Clearance Requirements: · Must be a U.S. citizen (no dual citizenship). · Ability to pass a background investigation. · Able to obtain and maintain DHS Suitability/Entry on Duty (EOD). Soft Skills: · High level of attention to detail and strong organizational skills. · Strong leadership and project management capabilities to drive remediation actions and manage inspection timelines. · Excellent communication and presentation skills, with a proven ability to draft technical status reports and confidently brief clients and senior stakeholders. Position Responsibilities Security Program Oversight & Leadership · Policy Application: Ensure the rigorous application of cybersecurity policies, principles, and practices in the delivery of all IT cybersecurity services. · Operational Posture: Develop and implement programs as required to ensure that systems, networks, and data users are aware of, understand, and adhere to systems cybersecurity policies and procedures. · Resilience Planning: Develop system security contingency plans and disaster recovery plans to ensure organizational resilience. Strategic Advisory & Risk Management · Executive & Client Consultation: Help conduct the appropriate remediation actions associated with findings from inspections and evaluations, generate status reports, and brief clients on the security health of information systems or programs. · Risk Management Framework (RMF) Expertise: Provide subject matter expertise and knowledge of RMF to perform Risk Management Framework activities for all information systems and applications. · Operations & Controls: Follow RMF to identify, implement, assess, and manage cybersecurity capabilities and services, expressed as security controls, and authorizing the operation of an information system. Assessments, Audits, & Compliance · Authorization Support: Lead the security assessment and authorization activities for information systems, maintaining 100% ATO status. · Audit Readiness: Lead cybersecurity-related audits, inspections, assessments, operations, and orders processing. · Standards Alignment: Ensure information systems comply with client requirements and industry standards. Technical Areas of Expertise · Deep subject matter expertise and advanced knowledge of RMF and NIST security controls. · Proven track record of leading systems successfully through the assessment and authorization process to secure and maintain a 100% ATO status. · Demonstrated experience authoring enterprise-level documentation, including Contingency Plans and Disaster Recovery Plans. · Experience coordinating and leading responses to formal cybersecurity audits, technical inspections, and orders processing. Joining Avint is a win-win proposition! You will feel the personal touch of a small business and receive BIG business benefits, from competitive salaries, full health insurance, generous time off, and observation of federal holidays. Additionally, we encourage every Avint employee to further their professional development. To assist you in achieving your goals, we offer reimbursement for courses, exams, and tuition. Interested in a class, conference, program, or degree? Avint will invest in YOU and your professional development! Salary Range $110,000-$125,000
Lead security control assessments for complex systems and cloud infrastructures ensuring compliance with NIST and FedRAMP frameworks and mentor junior assessors. | Bachelor's degree with 8-10 years cybersecurity experience including 6 years hands-on with complex systems, U.S. citizenship, and relevant certifications. | Avint is seeking a highly motivated Senior Security Controls Assessor (SCA) in support of a critical federal contract. The Senior SCA is a subject matter expert responsible for executing comprehensive, independent assessments of the organization’s most complex information systems, applications, and cloud infrastructures. Operating as a senior-level individual contributor, this role focuses on verifying the implementation, correctness, and effectiveness of technical, operational, and management security controls. The Senior SCA handles the most complex, critical, or sensitive system assessments, serving as a technical mentor to junior assessors and a primary technical advisor to system owners during the Risk Management Framework (RMF) lifecycle. Education: · Bachelor’s degree (BS/BA) OR equivalent professional experience. · Security+; higher certifications such as CISSP, CAP, or CASP desired. Experience: · Minimum of 8-10 years of dedicated experience in cybersecurity, information assurance, or IT auditing. · At least six (6) years of dedicated experience performing hands-on security controls assessments of the most complex (C4) systems. Clearance Requirements: · Must be a U.S. citizen (no dual citizenship). · Ability to pass a background investigation. · Able to obtain and maintain DHS Suitability/Entry on Duty (EOD). Soft Skills: · Strong analytical, critical thinking, and problem-solving skills with a high level of technical professional skepticism. · Excellent technical writing skills, with the ability to clearly document complex technical findings and defend assessment results to stakeholders. · Exceptional interpersonal and diplomatic skills, allowing for productive collaboration with system administrators, developers, and management. Position Responsibilities Security Assessment and Validation · Lead comprehensive security control assessments of complex information systems using interview, examination, and testing methods. · Verify compliance with established frameworks such as NIST SP 800-37, NIST SP 800-53, NIST SP 800-171, FISMA, and/or FedRAMP, depending on organizational requirements. · Analyze system architectures, network diagrams, configuration settings, and policies to identify vulnerabilities and compliance gaps. · Review vulnerability scanning results (e.g., Nessus, Qualys) and penetration testing reports to validate the implementation of technical controls. Technical Mentorship and Quality Assurance · Act as a senior technical escalation point and mentor for mid- and junior-level Security Controls Assessors on the team. · Perform peer reviews of assessment documentation, test results, and reports generated by other team members to ensure technical accuracy and consistency. · Support the SCA Team Lead in defining, refining, and standardizing assessment methodologies, testing procedures, and reporting templates. Reporting and Risk Management · Author, review, and finalize high-quality Security Assessment Reports (SAR) detailing assessment findings, risks, and recommended remediations. · Present assessment findings and risk postures to Authorizing Officials (AO), system owners, and other stakeholders in clear, actionable terms. · Assist system owners in the development of realistic Plans of Action and Milestones (POA&M) to remediate identified deficiencies. · Collaborate with the Risk Management team to ensure assessment data accurately informs the organization’s continuous monitoring strategy. Continuous Improvement and Strategy · Stay current on emerging cyber threats, vulnerabilities, regulatory changes, and assessment techniques. · Identify opportunities to automate assessment processes and integrate modern tooling into the assessment lifecycle. · Participate in the development and refinement of enterprise information security policies, standards, and guidelines. Technical Areas of Expertise · Advanced knowledge of security control frameworks (specifically NIST SP 800-53, NIST SP 800-37, and NIST SP 800-171). · Familiarity with cloud security concepts (AWS, Azure, Google Cloud) and cloud compliance frameworks (FedRAMP). · Knowledge of operating system security, network protocols, access control mechanisms, and vulnerability management tools. Joining Avint is a win-win proposition! You will feel the personal touch of a small business and receive BIG business benefits, from competitive salaries, full health insurance, generous time off, and observation of federal holidays. Additionally, we encourage every Avint employee to further their professional development. To assist you in achieving your goals, we offer reimbursement for courses, exams, and tuition. Interested in a class, conference, program, or degree? Avint will invest in YOU and your professional development! Salary Range $125,000-$141,00
Create tailored applications specifically for Avint with our AI-powered resume builder
Get Started for Free