远程工作雷达

高级网络安全评估负责人

Senior Cybersecurity Assessment Lead

开发工程限定地区(需当地身份)
公司VMD Corp
薪资未公开
工作地点United States
地域资格限定地区(需当地身份)
时区要求日间重叠约 9 小时,基本正常作息
用工类型Full Time
发布时间今天
数据来源Himalayas
前往 Himalayas 查看并投递 →
注意地域限制:该职位明确限定在 United States 招聘。如果你是位于中国大陆的求职者,通常需要当地工作身份才能投递,或需与雇主确认是否接受独立合同(Contractor)形式合作。

作为一家以愿景、使命和进取精神为驱动的公司,VMD自2002年以来一直为联邦政府提供信息技术解决方案,涵盖敏捷工程、网络安全和关键基础设施保护领域。我们的使命现已扩展,并与Xcelerate Solutions合并,以彻底革新端到端的企业安全。我们致力于保护国家公民、关键基础设施和资源。

为什么加入VMD?

在VMD,现在是Xcelerate Solutions的一部分,你有机会在职业生涯中茁壮成长,成为改变游戏规则的人。我们员工的素质和才能是成功的关键。我们秉持以员工为先的文化,优先提供促进职业发展的专业培训机会。

我们通过与客户合作,提供具有变革性的解决方案,来保护美国公民和国家最重要的关键基础设施。我们相信,我们对实现客户目标和解决其最严峻挑战的热情和承诺定义了我们的本质。我们不仅梦想远大,而且付诸行动——通过团队合作、奉献精神和韧性。

你对任务的贡献:

作为高级网络安全评估负责人,你将支持一项政府网络安全评估和监督计划,重点加强企业安全治理、运营弹性和任务保障。在此职位上,你将担任独立评估员、项目贡献者和项目经理,负责评估政府系统、企业平台、云环境和安全计划中的网络安全实施的部署、有效性和运营成熟度,确保符合相关的联邦要求、指令和法律。你将被期望积极参与并领导评估工作,同时推动评估相关项目的规划到完成。此外,你还将参与制定和传达项目战略,将战略目标转化为可操作的计划、优先事项、流程和可衡量的结果。

你将通过开发成熟度模型、评估方法、战略计划和流程文档,支持评估项目的持续发展,同时与评估团队合作,培养知识共享、持续改进和技术卓越的文化。

查看英文原文

As a Vision, Mission, and Driven company, VMD has been delivering information technology solutions to the Federal government in Agile Engineering, Cybersecurity, and Critical Infrastructure Protection since 2002. Our mission has now expanded, and we have merged with Xcelerate Solutions to revolutionize end-to-end enterprise security. Together we are committed to protecting our nation’s citizens, critical infrastructure, and resources.

Why Join VMD Corp?

At VMD, now a part of Xcelerate Solutions, you have the opportunity to thrive in your career and become a Game Changer. The quality and talent of our people is what drives our success. We embrace an employee-first culture and make it a priority to provide professional development opportunities that foster career growth.

We help protect American Citizens and the nation’s most critical infrastructure by working alongside our customers and delivering game changing solutions to strengthen their missions. We believe our passion and commitment to achieving our customers' goals and solve their most critical challenges defines who we are. We don’t just dream big, we act on it – through teamwork, dedication, and resilience.

Your Impact to the Mission:

As a Senior Cybersecurity Assessment Lead, you will support a government cybersecurity assessment and oversight program focused on strengthening enterprise security governance, operational resilience, and mission assurance. In this role, you will serve as a independent assessor, program contributor, and project leader responsible for evaluating the deployment, effectiveness, and operational maturity of cybersecurity implementations across government systems, enterprise platforms, cloud environments, and security programs, ensuring compliance with applicable federal requirements, mandates, and laws. You will be expected to actively participate in and lead assessments while also helping drive assessment-related initiatives from planning through completion. In addition, you will contribute to the development and communication of program strategy, translating strategic objectives into actionable plans, priorities, processes, and measurable outcomes.

You will support the continued evolution of the assessment program through the development of maturity models, assessment methodologies, strategic plans, and process documentation, while collaborating with a team of assessors to foster a culture of knowledge sharing, continuous improvement, and technical excellence. The successful candidate will be comfortable operating at both the strategic and tactical levels—helping define where the program needs to go while actively engaging in the work required to get there.

Responsibilities:

  • Conduct in-depth technical, operational, and programmatic inspections, assessments, and audits of agency systems, applications, and enterprise services.
  • Provide task and project leadership, work allocation, and mentorship to team members across assigned assessments and program initiatives; establish priorities, track actions and dependencies, remove obstacles, and drive work to timely completion. Perform quality assurance reviews of deliverables and ensure the timely, accurate completion of assessment activities and associated reporting milestones.
  • Collect, analyze, and present accurate, risk-informed IT and cybersecurity technical and programmatic information.
  • Support the maturation and continuous improvement of the cybersecurity assessment program, partnering closely with federal leadership and staff to strengthen methodologies, governance processes, reporting standards, and enterprise assessment capabilities.
  • Help define, develop, and communicate program strategy and strategic objectives, translating leadership priorities and mission requirements into actionable roadmaps, initiatives, and measurable outcomes.
  • Develop, document, and maintain program processes, procedures, standards, and assessment methodologies, with an emphasis on creating repeatable, scalable approaches that improve program effectiveness and execution.
  • Lead and/or contribute to projects and strategic initiatives supporting the assessment program, including developing project plans, coordinating stakeholders, managing action items and dependencies, monitoring progress, and driving deliverables through completion.
  • Support enterprise strategic planning and program oversight initiatives, including cybersecurity capability roadmaps, governance enhancements, performance measures, and long-range modernization objectives to strengthen cybersecurity posture, operational maturity, and implementation effectiveness.
  • Provide executive-level input on program status, risk posture, performance metrics, and trend analysis, including the identification of recurring findings, systemic gaps, and strategic improvement opportunities. Develop recommendations and supporting analysis to inform strategic decisions and program priorities.
  • Serve as a senior technical and programmatic advisor to assessment leadership and customer stakeholders, helping identify opportunities to improve cybersecurity governance, assessment effectiveness, operational maturity, and mission outcomes.
  • Obtain and maintain DOE Derivative Classifier certification(s) as required to support mission and program responsibilities.
  • Maintain required professional certifications through continuous professional education (CPE) and ongoing professional development, while remaining current on emerging threats, evolving technologies, federal mandates, and cybersecurity best practices.

Minimum Requirements:

  • Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, Engineering, or a related discipline, with 10+ years of relevant professional experience, including 8+ years of dedicated cybersecurity experience. Additional directly related experience may be substituted for the degree requirement.
  • At least one DoD 8570 / 8140 compliant certification at the IAT Level III or IAM Level III level, such as CISSP, CISM, CASP+, CISA, GSLC, or GCIH.
  • Demonstrated expert-level experience leading and conducting IT and cybersecurity inspections, independent assessments, compliance reviews, and audit activities, including the ability to independently plan, execute, and close assessment engagements.
  • Demonstrated experience leading projects or complex initiatives, with the ability to develop work plans, coordinate stakeholders, manage competing priorities and dependencies, track progress, and drive deliverables to completion.
  • Demonstrated ability to contribute to and/or develop organizational or program strategy, including translating mission objectives and leadership priorities into actionable plans, roadmaps, initiatives, and measurable outcomes.
  • Deep working knowledge of federal cybersecurity requirements, mandates, and compliance frameworks, including FISMA, NIST SP 800-37, NIST SP 800-53, NIST SP 800-115, CNSSI 1253, and applicable OMB policies and memoranda.
  • Exceptional verbal and written communication skills, with the ability to clearly and professionally engage with senior stakeholders, customers, technical teams, and executive leadership.
  • Active or current DOE Q Clearance or Top Secret clearance with SCI eligibility, and the ability to successfully obtain and maintain a polygraph, as required.
  • U.S. Citizenship required.

Desired Qualifications and Skills:

  • Demonstrated subject matter expertise in federal cybersecurity baseline requirements, with preferred experience supporting Department of Energy (DOE) environments, directives, and mission systems.
  • Strong knowledge of organizational maturity assessment models, particularly those used to evaluate cybersecurity, information technology, and enterprise risk management capabilities.
  • Demonstrated experience developing strategic plans, capability roadmaps, program strategies, or similar strategic planning artifacts for cybersecurity, information technology, or enterprise security programs.
  • Exceptional written communication skills, including proven experience developing cybersecurity policies, standards, procedures, implementation guidance, strategic documentation, and process documentation for technical and executive stakeholders.
  • Demonstrated project management experience, including planning and executing cross-functional initiatives, coordinating stakeholders, managing schedules and dependencies, tracking risks and action items, and driving projects to successful completion.
  • Hands-on experience in secure configuration management and system hardening, including application, validation, and tailoring of appropriate DISA STIGs, CIS benchmarks, and other secure baseline standards across enterprise environments.
  • Demonstrated experience securing cloud environments, including implementation and assessment of secure configurations across AWS, Azure, or hybrid federal cloud platforms.
  • Working knowledge of Zero Trust principles, architectures, and maturity frameworks, with experience evaluating or supporting implementation aligned to federal Zero Trust strategies.
  • Experience supporting enterprise vulnerability management programs, including demonstrated proficiency with Tenable Security Center / Tenable.sc, vulnerability analysis, prioritization, and remediation validation workflows.
  • Prior experience serving in an Information System Security Manager (ISSM) or equivalent cybersecurity leadership role, with responsibility for governance, risk oversight, strategic planning, and enterprise security program execution.

The Ideal Candidate Will Excel By Demonstrating

  • A high level of initiative, professionalism, and self-motivation, with the ability to independently drive complex cybersecurity assessment activities, projects, and strategic initiatives from planning through completion.
  • The ability to operate effectively at both the strategic and tactical levels—helping define strategy and direction while actively participating in assessments and executing the work necessary to achieve program objectives.
  • Strong project leadership and execution skills, with the ability to establish priorities, organize work, coordinate stakeholders, manage dependencies, resolve obstacles, and consistently drive commitments and deliverables to completion.
  • Strategic thinking and strong business judgment, with the ability to translate broad mission objectives into practical strategies, actionable plans, and measurable outcomes.
  • Exceptional attention to detail.
  • A commitment to continuous learning, with the ability to remain current on emerging cybersecurity technologies, threat trends, assessment methodologies, and federal security mandates.
  • Strong written and verbal communication skills, including the ability to translate technical findings and complex programmatic issues into clear, actionable guidance for both technical and executive audiences.
  • Natural leadership and team influence, with the ability to lead assessment efforts, facilitate stakeholder engagement, build consensus, and positively influence outcomes without relying solely on formal authority.
  • A willingness to remain hands-on as an assessor, contributing directly to assessments, analysis, interviews, evidence review, findings development, and reporting activities as needed.

Travel and Telecommuting:

  • Travel: Significant (between 25%-50%)
  • Telecommute Options: Remote, with frequent travel. Work will be conducted at various sites across the continental US. Position is currently considered remote when not traveling.

Xcelerate Solutions and its subsidiaries are Equal Employment Opportunity/Affirmative Action Employers. We evaluate qualified applicants without regard to race, color, national origin, religion, age, equal pay, disability, veteran status, sex, sexual orientation, gender identity, genetic information, or expression of another protected characteristic. As part of this commitment to the full inclusion of all qualified individuals, Xcelerate provides reasonable accommodations if needed because of an applicant's or an employee's disability. Xcelerate Solutions maintains a drug-free workplace.

Originally posted on Himalayas

本页面信息整理自 Himalayas,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。 本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。

← 返回全部职位