Full-Time

Senior Security Control Assessor

Deadline 11/13/27
Pariveda Solutions

Pariveda Solutions

51-200 employees

Cybersecurity, IT services for federal gov.

No salary listed

No H1B Sponsorship

Remote in USA

Remote

US Top Secret Clearance, US Citizenship, UK Top Secret Clearance Required

Category
IT & Security (1)
Requirements
  • Must be able to obtain a High Risk/Public Trust Security Clearance
  • 7+ years of relevant IT/cybersecurity experience.
  • Certification in one of the following: A+, Net+, or Security+
  • Degree in a technical/cyber-related field (or equivalent experience/certifications).
  • Proficiency in assessing security controls against standards (e.g., NIST SP 800-53, CIS Cyber Security Controls, Cybersecurity Framework).
  • Strong skills in vulnerability scanning, penetration testing principles, and interpreting results.
  • Ability to conduct risk, impact, and compliance assessments.
  • Skill in technical documentation, briefings, and audit reporting.
  • Proficiency in security architecture review and system design evaluation.
  • Knowledge of secure coding principles and application security (e.g., OWASP Top 10).
  • Experience applying confidentiality, integrity, availability, authenticity, and non-repudiation principles to systems and networks.
  • Familiarity with compliance frameworks and security assessment tools.
  • Strong analytical, technical writing, and communication skills are essential.
  • Knowledge of Risk Management Framework (RMF) and Security Assessment & Authorization (SA&A) processes.
  • Knowledge of security architecture concepts, enterprise reference models, and assessment methodologies.
  • Knowledge of network security protocols, models, and configurations (including defense-in-depth).
  • Working knowledge of government compliance standards and assessment processes.
  • Knowledge of cyber threats, vulnerabilities, and operational impacts of lapses.
  • Knowledge of information security principles and methods (e.g., encryption, access control, PKI).
  • Knowledge of applicable laws, directives, and compliance requirements (e.g., NIST SP 800-161, FISMA, FedRAMP).
  • Knowledge of system and application security threats (e.g., injection flaws, cross-site scripting, buffer overflow).
  • Knowledge of IT supply chain security and risk management practices.
  • Knowledge of cyber defense and vulnerability assessment tools.
  • Working knowledge of IRS Safeguards
  • Must be a U.S. citizen.
Responsibilities
  • Perform security reviews to identify architectural gaps and provide recommendations for risk mitigation.
  • Conduct risk analyses (e.g., threats, vulnerabilities, probability of occurrence) during significant system/application changes.
  • Plan and execute security authorization reviews, assurance case development, and audits for system installations and networks.
  • Provide input to the Risk Management Framework (RMF) and related documentation, including lifecycle support plans, CONOPS, and operational procedures.
  • Review authorization packages and assurance documents to confirm risk levels are acceptable for systems, applications, and networks.
  • Verify that system, network, and application security postures are implemented as designed, documenting deviations and recommending corrective actions.
  • Perform security reviews to identify architectural gaps and provide recommendations for risk mitigation.
  • Assess the effectiveness of implemented security controls across management, operational, and technical areas.
  • Support compliance activities by ensuring security configuration guidelines and standards are followed.
  • Evaluate configuration management and release processes for security impacts.
  • Define/document how new systems or interfaces affect the organization’s current security posture.
  • Develop security compliance processes and perform audits of external services (e.g., CSPs, data centers).
  • Ensure Plans of Action & Milestones (POA&Ms) and remediation plans are established for vulnerabilities.
  • Participate in Risk Governance processes by presenting risks, mitigations, and technical assessments.
  • Support acquisition and procurement efforts to ensure information security requirements are integrated.
  • Produce reports, briefings, and technical documentation reflecting assessment results and recommendations.
Desired Qualifications
  • Active Secret or Top Secret security clearance.
  • CISSP or CISM
  • Ability to evaluate and synthesize risk assessment data into actionable findings.
  • Ability to clearly communicate technical and risk information to technical and non-technical audiences.
  • Ability to assess vulnerabilities and recommend corrective actions.
  • Ability to apply judgment in ambiguous or evolving situations.
  • Ability to interpret and apply relevant cybersecurity laws, regulations, and policies.
  • Ability to collaborate across teams and work effectively with external service providers.
  • Ability to design, conduct, and evaluate test plans, assessments, and compliance audits.
  • Ability to lead complex assessments, provide strategic recommendations, and advise leadership on enterprise-wide security control effectiveness.

SkyePoint Decisions provides IT services focused on the federal government. It delivers cybersecurity architecture and engineering, critical infrastructure and operations, and applications development and maintenance. Its products are not a single gadget but enterprise-wide solutions and targeted services that help agencies run missions securely, from any location. The company brings together deep technical know-how, understanding of government needs, and an empowered workforce to produce results. It differentiates itself by specializing in federal clients, maintaining ISO 9001:2015 and ISO/IEC 27001:2013 certifications, and fostering a collaborative culture that emphasizes accountability and value for clients. The goal is to help government agencies complete their missions more efficiently and securely, anytime and anywhere.

Company Size

51-200

Company Stage

N/A

Total Funding

N/A

Headquarters

Dranesville, Virginia

Founded

2009

Simplify Jobs

Simplify's Take

What believers are saying

  • AWS for Health support advances NLP solutions for eVisits in healthcare.
  • Generative AI platform on Amazon Bedrock boosts TC Energy efficiencies.
  • Agentic AI integrates EHR to detect sepsis early, reducing mortality.

What critics are saying

  • SkyePoint Decisions steals federal clients using ISO 27001 certification.
  • Accenture and Deloitte poach talent for scaled federal IT projects.
  • Slalom outcompetes in AI/ML platforms for healthcare and energy clients.

What makes Pariveda Solutions unique

  • B Corp certification embeds inclusive practices into Pariveda's culture.
  • 3D Engagement Model delivers outcome-oriented client relationships flexibly.
  • New tagline aligns purpose with potential for collaborative partnerships.

Help us improve and share your feedback! Did you find this helpful?

Your Connections

People at Pariveda Solutions who can refer or advise you

Benefits

Health Insurance

Dental Insurance

Vision Insurance

Life Insurance

Disability Insurance

Health Savings Account/Flexible Spending Account

Unlimited Paid Time Off

Flexible Work Hours

Paid Holidays

401(k) Company Match

Professional Development Budget

Company News

Bakersfield.com
Nov 20th, 2024
Manohar Kumar and Durriya Badani Join SkyePoint Decisions in Strategic Senior Leadership Roles

Manohar Kumar, Senior Vice President of Operations, joins SkyePoint with twenty years of expertise in delivering complex, global programs and industry-leading technology solutions.

SkyePoint Decisions
May 24th, 2023
Federal Agencies Face Challenges Managing Cloud Security and Risk. SkyePoint and Caveonix Can Help.

SkyePoint has partnered with Caveonix and their Caveonix Cloud capabilities to provide an integrated platform for hybrid multi-cloud security, compliance, and governance capabilities.

SkyePoint Decisions
Jan 24th, 2023
SkyePoint Decisions Announces New Members of C-Suite Team

SkyePoint Decisions Inc., a leader in cybersecurity architecture, engineering, and critical infrastructure, announces Heather Conigliaro is moving into a larger role as Chief Strategy Officer and Heather Newlin was hired as Chief Operating Officer.

SkyePoint Decisions
Apr 4th, 2022
SkyePoint Decisions, Inc. promotes Jason Weaver to Chief Technology Officer

SkyePoint Decisions, a leader in cybersecurity risk management solutions, announced the promotion of Jason Weaver to Chief Technology Officer.

SkyePoint Decisions
Jun 15th, 2021
Skyepoint promoted Frank Sturek to Chief Operations Officer on Jun 15th 21'.

SkyePoint Decisions, Inc. (SkyePoint Decisions) announced today the promotions of Frank Sturek to President and Heather Conigliaro to Chief Operations Officer.