Cyber Security Consultant
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
- Support federal agencies reviewing the GO.gov FedRAMP security package.
- Investigate and resolve agency-specific security questions and concerns.
- Work across GSA staff, contractors, engineers, and vendors to drive issues to resolution.
- Guide TMCs through NIST 800-171 readiness and MFR-related activities.
- Lead discovery with vendors that may have immature security programs or poorly documented environments.
- Review architecture, data flows, IAM, encryption, cloud configurations, integrations, and supporting evidence.
- Develop clear technical responses, findings, meeting summaries, and security documentation.
- Lead client and stakeholder meetings as needed.
Requirements
This is a highly client-facing role supporting federal agency onboarding and commercial Travel Management Companies (TMCs). The ideal candidate combines strong federal cybersecurity experience with enough technical depth to independently investigate security concerns, guide vendors through security requirements, and communicate clearly with government and technical stakeholders., * Strong federal cybersecurity experience, including RMF, NIST 800-53, ATO processes, SSPs, security controls, POA&Ms, and assessment evidence.
- Strong technical understanding of cloud and enterprise security concepts.
- Ability to independently investigate ambiguous technical and security issues.
- Experience working directly with engineers, ISSOs, ISSMs, assessors, vendors, and federal stakeholders.
- Excellent verbal and written communication skills.
- Strong professional presence and ability to lead client-facing discussions.
- Public Trust eligibility.
Preferred
- AWS security and architecture experience.
- FedRAMP experience.
- NIST 800-171 experience.
- Federal civilian agency experience.
- Security consulting or technical assessment experience.
What We’re Looking For
This is not a compliance-only or documentation-focused ISSO role.
We need someone who can take ownership of a security problem, determine what needs to be investigated, engage the right people, understand the technical details, and return with a defensible answer or recommendation.
The successful candidate will receive mentorship on the GO.gov environment and program-specific processes but should be capable of operating independently once oriented.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
9 Ways to Make Money Hacking
What Are The Top Skills Required For Azure Developers?
Walking Into The Era of Supply Chain Risks
Understanding and Mitigating Common Web Vulnerabilities