Cyber Information Systems Analyst - SME - Assessment Function (SCA-Separate)

QBE LLC
Chicago, IL, United States
7 days ago
Apply on www.jofdav.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
10 years minimum
Compensation
$108,000.0 - $124,000.0
Working hours
Regular working hours
Job source

Tech stack

CompTIA Security+ Cyber Security Information Systems Information Technology

Job description

  • Plan and conduct independent security control assessments.

  • Develop Security Assessment Plans and test procedures.

  • Review security documentation and supporting control evidence.

  • Interview system personnel and evaluate control implementation.

  • Perform technical and procedural testing of applicable controls.

  • Document assessment findings and supporting evidence.

  • Develop Security Assessment Reports and risk statements.

  • Maintain organizational independence between assessment and system implementation functions.

  • Evaluate remediation evidence for identified deficiencies.

  • Coordinate assessment schedules and activities with system stakeholders.

Requirements

  • Associate degree in cybersecurity, information technology, computer science, information systems, business, communications, or a related field, or an additional two or more years of relevant experience in place of the degree requirement.

  • At least 10 years of relevant experience aligned to the responsibilities of this position.

  • Extensive experience conducting independent security control assessments.

  • Expert knowledge of federal RMF and security control assessment practices.

  • Experience developing Security Assessment Plans and Security Assessment Reports.

  • Strong technical testing, risk analysis, and documentation skills.

  • CompTIA Security+ certification.

  • GIAC Information Security Professional (GISP) certification.

  • Ability to obtain and maintain the required federal background investigation, Public Trust determination, or security clearance associated with the position.

Preferred Qualifications

  • Experience serving as a Security Control Assessor or supporting an independent assessment organization.

  • Experience assessing Low- and Moderate-impact federal systems.

  • Experience with HHS, NIH, or another federal civilian agency.

Physical Requirements

  • Ability to remain in a stationary position for extended periods while working at a computer.

  • Ability to communicate effectively through virtual and in-person meetings.

  • Ability to perform duties in an office, remote, or hybrid environment based on program requirements.

  • Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions of the position.

Benefits & conditions

The projected compensation range for this position is $115,000.00 - $130,000.00. There are differentiating factors that can impact a final salary/hourly rate, including, but not limited to, Contract Wage Determination, relevant work experience, skills and competencies that align to the specified role, geographic location (for remote opportunities), education and certifications as well as Federal Government Contract Labor categories. In addition, QBE invests in its employees beyond just compensation. QBE’s benefits offerings include, dependent upon position, Health Insurance, Life Insurance, Paid Time Off, Holiday Pay, short-term and long-term Disability, Retirement and Savings, Learning and Development opportunities, wellness programs as well as other optional benefit elections., $115,000.00

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.jofdav.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

59 sec

Proving regulatory compliance to auditors and chief officers

Mike Bursell Mike Bursell · World Congress 2026 Europe

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

5:13 min

Audience Q&A on maturity assessments and external consultants

Mathias Tausig · LIVE

2:28 min

Preventing sensitive information disclosure in RAG systems

Deepu Deepu · World Congress 2025

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

Videos

See all

Related articles

See all