> Markdown version of [/jobs/ext/1914163-cybersecurity-and-it-assessor](https://www.wearedevelopers.com/jobs/ext/1914163-cybersecurity-and-it-assessor). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity and IT Assessor - **Company:** VMD Corp - **Location:** United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Excel, Agile Methodology, Amazon Web Services, Microsoft Azure, Cloud Computing, Configuration Management, Cyber Security, Information Systems, Identity and Access Management, Information Security Management, Internet Security, Information Systems Security Architecture Professional, Zero Trust Network Access, Software Vulnerability Management, Cloud Platform System, HybridCloud, Information Technology, CIS Benchmarks, Vulnerability Analysis - **Published:** August 4, 2026 - **Apply:** https://www.careerbuilder.com/job-details/senior-cybersecurity-and-it-assessor--c0365800-3e22-419a-b446-d263eb9a3288 ## About the Role * Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Engineering, or a related discipline, with 10+ years of relevant professional experience, including 8+ years of dedicated cybersecurity experience. Additional directly related experience may be substituted for the degree requirement. * At least one DoD 8570 / 8140 compliant certification at the IAT Level III or IAM Level III level, such as CISSP, CISM, CASP+, CISA, GSLC, or GCIH. * Demonstrated expert-level experience leading and conducting IT and cybersecurity inspections, independent assessments, compliance reviews, and audit activities. * Deep working knowledge of federal cybersecurity requirements, mandates, and compliance frameworks, including FISMA, NIST SP 800-37, NIST SP 800-53, NIST SP 800-115, CNSSI 1253, and applicable OMB policies and memoranda. * Exceptional verbal and written communication skills, with the ability to clearly and professionally engage with senior stakeholders, customers, technical teams, and executive leadership. * Active or current DOE Q Clearance or Top Secret clearance with SCI eligibility, and the ability to successfully obtain and maintain a polygraph, as required. * U.S. Citizenship required., * Demonstrated subject matter expertise in federal cybersecurity baseline requirements, with preferred experience supporting Department of Energy (DOE) environments, directives, and mission systems. * Strong knowledge of organizational maturity assessment models, particularly those used to evaluate cybersecurity, information technology, and enterprise risk management capabilities. * Exceptional written communication skills, including proven experience developing cybersecurity policies, standards, procedures, implementation guidance, and process documentation for technical and executive stakeholders. * Hands-on experience in secure configuration management and system hardening, including application, validation, and tailoring of appropriate DISA STIGs, CIS benchmarks, and other secure baseline standards across enterprise environments. * Demonstrated experience securing cloud environments, including implementation and assessment of secure configurations across AWS, Azure, or hybrid federal cloud platforms. * Working knowledge of Zero Trust principles, architectures, and maturity frameworks, with experience evaluating or supporting implementation aligned to federal Zero Trust strategies. * Experience supporting enterprise vulnerability management programs, including demonstrated proficiency with Tenable Security Center / Tenable.sc, vulnerability analysis, prioritization, and remediation validation workflows. * Prior experience serving in an Information System Security Manager (ISSM) or equivalent cybersecurity leadership role, with responsibility for governance, risk oversight, and enterprise security program execution. The Ideal Candidate Will Excel By Demonstrating * A high level of initiative, professionalism, and self-motivation, with the ability to independently drive complex cybersecurity assessment activities to completion. * Exceptional attention to detail. * A commitment to continuous learning, with the ability to remain current on emerging cybersecurity technologies, threat trends, assessment methodologies, and federal security mandates. * Strong written and verbal communication skills, including the ability to translate technical findings into clear, actionable guidance. * Natural leadership and team influence, with the ability to lead assessment efforts and facilitate stakeholder engagement., Affirmative Action, Agile Programming Methodologies, Amazon Web Services (AWS), Analysis Skills, Benchmarking, Best Practices, CISA - Certified Information Systems Auditor, CISM - Certified Information Security Manager, CISSP - Certified Information Systems Security Professional, Cloud Computing, Communication Skills, Computer Science, Computer Security, Configuration Management, Continuous Improvement, DOE Clearance, DOE-Q (Top Secret Restricted Data), Defense Information Systems Agency (DISA), Detail Oriented, DoD Directive 8140, DoD Directive 8570, Documentation, Emerging Technology, Enterprise Protection, Equal Employment Opportunity (EEO), Establish Priorities, FISMA - Federal Information Security Management Act, Federal Compliance Regulations, Federal Government, GCIH - GIAC Certified Incident Handler, GSLC - GIAC Security Leadership Certificate, Government, Hybrid Cloud, IAT - Information Assurance Technical, Information Technology & Information Systems, Internet Security, Leadership, Maintain Compliance, Mentoring, Microsoft Windows Azure, Operations Processes, Organizational Skills, Performance Metrics, Policy Development, Presentation/Verbal Skills, Quality Assurance, Risk, Risk Management, Security Analysis, Security Monitoring, Sensitive Compartmented Information (SCI), Strategic Planning, Systems Administration/Management, Team Player, Technical Delivery, Technical Writing, Time Management, Top Secret Clearance, Trend Analysis, U.S. National Institute of Standards and Technology (NIST), United States Citizen, United States Department of Energy (DOE), Willing to Travel, Work From Home, Writing Skills ## Description As a Senior Cybersecurity and IT Assessor, you will support a government cybersecurity assessment and oversight program focused on strengthening enterprise security governance, operational resilience, and mission assurance. In this role, you will serve as an independent assessor responsible for evaluating the deployment, effectiveness, and operational maturity of cybersecurity implementations across government systems, enterprise platforms, cloud environments, and security programs, ensuring compliance with applicable federal requirements, mandates, and laws You will support the continued evolution of the assessment program through the development of maturity models, assessment methodologies, and process documentation, while collaborating with a team of assessors to foster a culture of knowledge sharing, continuous improvement, and technical excellence., * Conduct in-depth technical, operational, and programmatic inspections, assessments, and audits of agency systems, applications, and enterprise services. * Provide task leadership, work allocation, and mentorship to team members across assigned assessments; perform quality assurance reviews of deliverables; and ensure the timely, accurate completion of assessment activities and associated reporting milestones. * Collect, analyze, and present accurate, risk-informed IT and cybersecurity technical and programmatic information. * Support the maturation and continuous improvement of the cybersecurity assessment program, partnering closely with federal leadership and staff to strengthen methodologies, governance processes, reporting standards, and enterprise assessment capabilities. * Develop, document, and maintain program processes, procedures, standards, and assessment methodologies * Support enterprise strategic planning and program oversight initiatives, including cybersecurity capability roadmaps, governance enhancements, performance measures, and long-range modernization objective to strengthen cybersecurity posture, operational maturity, and implementation effectiveness. * Provide executive-level input on program status, risk posture, performance metrics, and trend analysis, including the identification of recurring findings, systemic gaps, and strategic improvement opportunities. * Obtain and maintain DOE Derivative Classifier certification(s) as required to support mission and program responsibilities. * Maintain required professional certifications through continuous professional education (CPE) and ongoing professional development, while remaining current on emerging threats, evolving technologies, federal mandates, and cybersecurity best practices. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [A practical guide to writing secure Dockerfiles](https://www.wearedevelopers.com/videos/109-a-practical-guide-to-writing-secure-dockerfiles) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [OPA for the cloud natives](https://www.wearedevelopers.com/videos/713-opa-for-the-cloud-natives) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)