Security RMF Controls Assessor (0011)
OCT Consulting, LLCAbout the role
OCT Consulting, LLC is an SBA-certified, 8(a) small business management and technology consulting firm that provides support to Federal Government clients. We provide consulting services in the areas of Strategy, Process Improvement, Change Management, Program and Project Management, Acquisition/Procurement, and Information Technology.
Responsibilities and Duties
OCT Consulting currently has an opening for a junior Security Risk Management Framework (RMF) Controls Assessor to support a Federal government client. The responsibilities for the RMF Controls Assessor include:
- Work with the Assessor Lead to conduct the Authorization & Assessments (A&As) for the annual Federal Information Security Modernization Act (FISMA) systems assessment
- Establish the schedule and resources for the A&A of the annual FISMA systems assessment
- Conduct verbal discussions/meetings to address progress of the A&A effort
- Prepare and update various security documentation such as Systems Security Plans (SSPs), Security Assessment Report (SAR), Plan of Action and Milestones (POA&Ms), Risk Assessments, Private Impact Assessments (PIAs), and more
- Prepare Security Assessment Plans (SAP) to document test and assessment procedures
- Collect artifacts as proof that security controls are performing effectively
- Conduct custom interviews based on initial analysis of the system’s security plan to assess compliance with security controls
- Conduct system specific review and assessment of applicable controls at each site to be assessed, including and remote assessments (if applicable)
- Conduct FISMA systems Continuous Monitoring implementation and assessment
- Validate inventories for the annual FISMA systems assessments
- Gather and analyze sufficient artifacts to verify technical control implementation against agency security policies
- Review relevant policies, schedule activities, and provide recommendations for courses of action
- Complete comprehensive test plans for identified security controls following National Institute of Standards and Technology (NIST 800-53), Federal Risk and Authorization Management Program (FedRAMP) guidance, and/or agency-specific guidance
- Perform risk analysis (e.g., threat, vulnerability, and probability of occurrence).
- Produce complete, accurate, and timely findings reports
- Develop documents and document templates
- Promote an environment of continuous process improvement, learning and team collaboration
Requirements
Qualifications and Skills
- One (1) or more years of experience with RMF preferred
- One (1) or more years of experience with Cybersecurity preferred
- One (1) or more years of experience with A&A preferred
- One (1) or more years of experience with NIST standards preferred
- Familiarity with the Cyber Security Assessment and Management (CSAM) System for system assessments, or other equivalent tools, preferred
- Knowledgeable with information security and assurance principles and associated supporting technologies
- Flexibility to adapt to contingencies resulting from changes or modifications to the schedule and assessment requirements.
- Excellent customer service and organization skills
- Excellent oral and written communication skills
- Experience in presenting control requirements and deficiencies to both technical and non-technical audiences
Education and Certifications
- One or more of the following certifications preferred:
- Security+
- Certified Analytics Professional (CAP)
- Certified Information Systems Security Professional (CISSP)
- Certified Information Security Manager (CISM)
- GIAC Security Essentials Certification (GSEC)
- GIAC Certified Incident Handler (GCIH)
- Certified Ethical Hacker (CEH)
- GIAC Security Leadership (GSLC)
Benefits
Salary Range: $70,000-$95,000
Benefits
The position includes competitive compensation and a full suite of benefits:
- Medical, Dental, and Vision insurance
- Retirement savings 401K plan provided by an industry leading provider with 3% employer contributions.
- Paid Time Off
- Life Insurance, Short- and Long-Term disability benefits
- Training Benefits
About OCT
OCT Consulting is a certified SBA 8(a), minority owned, small, disadvantaged business providing professional services and information technology solutions to the federal government and commercial clients. Founded in 2013, we bring the advantage of agility in operations along w
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s