> Markdown version of [/jobs/ext/2298785-assessment-lead](https://www.wearedevelopers.com/jobs/ext/2298785-assessment-lead). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Assessment Lead - **Company:** Cherokee Federal - **Location:** Washington, DC, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, Cyber Security, Information Systems, Distributed Systems, Comptia Pentest+ CE, Red Team (Cyber Security), Zero Trust Network Access, SAP (Applications), GWAPT, Information Technology, Nessus, Devsecops, Blue Team (Cyber Security), Plan of Action and Milestones, Vulnerability Analysis - **Published:** August 29, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9128013/assessment-lead ## About the Role * Bachelor's degree in cybersecurity, information technology, computer science, engineering, auditing, or a related field. * Minimum of 8 years of relevant cybersecurity assessment experience. * CISSP, CISA, or equivalent senior security-assessment certification. * CEH or an equivalent penetration-testing certification. * Active Top Secret (TS) security clearance is required. Candidates must possess the required clearance to be considered for this position. * U.S. citizenship required. * Must be available to support Department of State operational requirements. * Department of State or other federal civilian agency assessment experience preferred. * Experience with NIST SP 800-115 and federal penetration-testing methodologies preferred. * Experience assessing cloud, application, infrastructure, and DevSecOps environments preferred. * Familiarity with CISA directives, High Value Assets, CDM, zero trust, and federal audit requirements preferred. * Experience assessing large, complex, or globally distributed environments preferred. * Equivalent penetration-testing certifications may include OSCP, GPEN, PenTest+, GWAPT, GXPN, or other recognized hands-on penetration-testing credentials, subject to customer approval. * Must pass pre-employment qualifications of Cherokee Federal. ## Description The Assessment Lead is a senior security-control assessor responsible for conducting independent assessments of federal information systems. This position leads technical and compliance assessments, tests the effectiveness of NIST security controls, evaluates technical evidence, documents findings, and communicates system risk to senior government stakeholders. Compensation & Benefits Pay commensurate with experience. Full-time benefits include Medical, Dental, Vision, 401K, and other possible benefits as provided. Benefits are subject to change with or without notice. Assessment Lead Responsibilities Include: * Lead independent Security Control Assessments under RMF Step 4. * Develop Security Assessment Plans and Security Assessment Reports. * Assess NIST SP 800-53 security controls and control enhancements. * Review SSPs, implementation statements, policies, procedures, diagrams, inventories, and technical evidence. * Conduct interviews, examine artifacts, and test technical and administrative controls. * Identify control deficiencies and assign defensible risk ratings. * Validate vulnerability findings, remediation evidence, and POA&M closures. * Conduct vulnerability assessments, compliance testing, penetration testing, and other technical security testing. * Review Tenable, Nessus, Wiz, STIG, CVE, KEV, Red Team, Blue Team, and similar results. * Present assessment findings and risk recommendations to ISSMs, system owners, and Authorizing Officials. * Maintain appropriate independence between the assessment function and the ISSO or control-implementation function. * Perform other job-related duties as assigned., * Security Control Assessor * Senior Security Assessor * RMF Assessment Lead * Cybersecurity Assessment Manager Keywords: * Security Control Assessment (SCA), RMF Step 4, SAP, SAR * NIST 800-53, NIST 800-115, control testing, assessment evidence * Penetration testing, vulnerability assessment, STIG, POA&M validation * Tenable, Nessus, Wiz * CISSP, CISA, CEH, OSCP, GPEN, Top Secret (TS) Clearance ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [Building Security Champions](https://www.wearedevelopers.com/videos/193-building-security-champions) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Why Attend a Developer Event in 2026?](https://www.wearedevelopers.com/magazine/688-why-attend-a-developer-event-in-2026)