Information System Security Specialist - IV
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
We are seeking a highly skilled and experienced Information System Security Specialist - IV (Senior Consultant) to lead the development, implementation, and management of advanced cybersecurity measures within our organization. Serving as the lead assessor responsible for conducting cybersecurity maturity assessments for client organizations using the NIST Cybersecurity Framework (NIST CSF), related NIST standards, and maturity-based assessment methodologies. The individual performs interviews, documentation reviews, technical analyses, and risk evaluations while developing actionable recommendations to improve organizational cybersecurity posture., * Plan and execute cybersecurity maturity assessments for client organizations and agencies.
- Conduct stakeholder interviews, workshops, and evidence collection activities.
- Analyzes and defines security requirements for Multilevel Security (MLS) issues.
- Evaluate cybersecurity programs against NIST CSF, NIST SP 800-53, NIST SP 800-171, and other applicable frameworks.
- Assess organizational capabilities using maturity-based evaluation methodologies.
- Identify cybersecurity gaps, risks, and areas for improvement.
- Develop detailed assessment reports, executive summaries, and corrective action recommendations.
- Present assessment results to executive leadership and technical stakeholders.
- Support the development of cybersecurity dashboards, metrics, and reporting artifacts.
- Document assessment findings within governance, risk, and compliance (GRC) systems.
- Ensure quality, consistency, and completeness of assessment deliverables.
- Maintain compliance with applicable security, privacy, and data-protection requirements.
- Collaborate with client Information Security Officers (ISOs), project teams, and program leadership throughout the assessment lifecycle.
Requirements
- Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, Engineering, or related discipline.
- Minimum five (5) years of experience performing cybersecurity assessments, audits, risk assessments, or security consulting engagements.
- Demonstrated experience applying NIST Cybersecurity Framework and related cybersecurity standards.
- Experience conducting interviews, collecting evidence, and developing assessment findings.
- Strong technical writing and presentation skills.
- Experience preparing executive-level reports and recommendations.
- Proficiency with Microsoft Office Suite and cybersecurity reporting tools., * CISSP, CISM, CISA, CRISC, GSLC, or comparable cybersecurity certification.
- Experience with ServiceNow GRC or other governance and compliance platforms.
- Experience supporting state, local, or federal government clients.
- Familiarity with cybersecurity capability maturity models and risk management frameworks.
This role demands a proactive approach to cybersecurity challenges combined with a commitment to continuous learning. If you are passionate about protecting organizational assets through innovative security solutions while adhering to industry standards-apply now to join our dedicated cybersecurity team.
Benefits & conditions
401(k), Health insurance, 401(k) matching, Paid time off, Vision insurance, Dental insurance, Life insurance, Employee assistance program Full-time Remote, * 401(k)
- 401(k) matching
- Dental insurance
- Employee assistance program
- Health insurance
- Life insurance
- Paid time off
- Vision insurance
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Dev Digest 134 - Where pixels sing?
Is Software Engineering Over-Saturated?
Best Paying Jobs in Technology
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.