Senior Security Advisor – Lead Control Assessor

Posted 8hrs ago

Employment Information

Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

Senior Security Advisor leading NIST 800-53 cybersecurity control assessments for Soteria’s clients. Coordinating assessors, validating evidence, and presenting findings to executives and boards.

Responsibilities:

  • Lead and execute cybersecurity control assessments against a defined subset of key controls aligned to NIST SP 800-53 Rev. 5
  • Assess control implementation status using standardized criteria and validation methodologies aligned to NIST SP 800-53A Rev. 5
  • Test information systems through documentation review, system walkthroughs, and stakeholder interviews
  • Determine evidence sufficiency and appropriateness using consistent judgment
  • Lead assessment planning, kickoff, execution coordination, and closeout activities
  • Coordinate assessment activities and task assignments across Control Assessors
  • Serve as primary point of contact for client stakeholders during assessment engagements
  • Review and approve assessment narratives, findings, and control determinations before quality assurance submission
  • Ensure consistent execution across multiple clients to support trend analysis and benchmarking
  • Enforce assessment methodologies, scope boundaries, and validation standards
  • Address quality assurance feedback and ensure deliverable accuracy, clarity, and consistency
  • Lead and participate in client interviews, system walkthroughs, and working sessions
  • Communicate assessment scope, expectations, and evidence requirements to stakeholders
  • Present assessment results, findings, and risk implications to executive leadership and board-level stakeholders
  • Mentor and guide Control Assessors on assessment techniques, documentation standards, and professional judgment
  • Escalate risks, issues, and control interpretation questions to program leadership

Requirements:

  • 7+ years of industry experience in cybersecurity, information security, IT audit, or risk and compliance
  • 2+ years of experience leading or performing cybersecurity control assessments or IT audits, with demonstrated responsibility for control testing and validation
  • Bachelor’s degree in Information Security, Information Systems, Computer Science, or a related field, or equivalent professional experience
  • Relevant professional certifications such as CISSP, CISM, CISA, CRISC, or equivalent strongly preferred
  • Proven experience testing and evaluating security controls aligned to NIST SP 800-53 Rev. 5
  • Experience applying assessment procedures consistent with NIST SP 800-53A Rev. 5
  • Experience executing repeatable, methodology-driven assessment programs across multiple organizations or systems
  • Strong written and verbal communication skills, including experience presenting assessment results to executive and board-level audiences
  • Maintains confidentiality and professionalism with sensitive client information
  • Prolonged periods of being at a desk and working on a computer
  • Majority of work time will be 9:00 AM EST to 5:00 PM EST

Benefits:

  • Primarily remote work
  • Flexibility in scheduling
  • Periodic travel to client sites based on client needs