Soteria - Security Solutions & Advisory
Tailored Security Solutions Managed Detection and Response
Senior Security Advisor – Lead Control Assessor
Location
South Carolina
Posted
26 days ago
Salary
Not specified
Bachelor Degree7 yrs expEnglishCyber Security
Job Description
• Lead and execute cybersecurity control assessments against a defined subset of key controls aligned to established frameworks (NIST SP 800-53 Rev. 5).
• Assess control implementation status using standardized criteria and validation methodologies. (NIST SP 800-53A Rev. 5).
• Test information systems using documentation review, system walk-throughs, and stakeholder interviews to assess the design and operating effectiveness of NIST SP 800-53 Rev. 5 security controls.
• Apply consistent judgment to determine evidence sufficiency and appropriateness.
• Lead planning, kickoff, execution coordination, and closeout activities for assigned assessment engagements.
• Coordinate assessment activities and task assignments across Control Assessors to meet delivery timelines.
• Serve as the primary point of contact for client stakeholders during assessment engagements.
• Review and approve assessment narratives, findings, and control determinations prior to quality assurance submission.
• Ensure assessments are executed consistently across multiple clients to support trend analysis and benchmarking.
• Enforce adherence to defined assessment methodologies, scope boundaries, and validation standards.
• Support quality assurance reviews by addressing feedback and ensuring accuracy, clarity, and consistency of deliverables.
• Lead and participate in client interviews, system walkthroughs, and working sessions in a professional, structured manner.
• Clearly communicate assessment scope, expectations, and evidence requirements to stakeholders.
• Present assessment results, key findings, and risk implications to executive leadership and board-level stakeholders in a clear, concise, and professional manner.
• Mentor and guide Control Assessors on assessment techniques, documentation standards, and professional judgment.
• Escalate risks, issues, or control interpretation questions to program leadership as appropriate.
Job Requirements
- 7+ years of industry experience in cybersecurity, information security, IT audit, or risk and compliance.
- 2+ years of experience leading or performing cybersecurity control assessments or IT audits, with demonstrated responsibility for control testing and validation.
- Bachelor’s degree in Information Security, Information Systems, Computer Science, or a related field, or equivalent professional experience.
- Relevant professional certifications such as CISSP, CISM, CISA, CRISC , or equivalent strongly preferred.
- Proven experience testing and evaluating security controls aligned to NIST SP 800-53 Rev. 5 and applying assessment procedures consistent with NIST SP 800-53A Rev. 5.
- Experience executing repeatable, methodology-driven assessment programs across multiple organizations or systems.
- Strong written and verbal communication skills, including experience presenting assessment results to executive and board-level audiences.
- Maintains confidentiality and professionalism with sensitive client information.
Benefits
- Remote work flexibility
- Professional development opportunities
- Health insurance
- Retirement plans
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Security Engineer26 days ago
Full TimeRemoteTeam 1,173Since 1981
Lead global cybersecurity and privacy efforts, manage a team of engineers, develop a cybersecurity roadmap, oversee vulnerability scanning/remediation, ensure regulatory compliance, support incident response, and report security posture to senior leadership.
FirewallsIntrusion Detection SystemsAnti-Virus SoftwareAuthentication SystemsLog ManagementContent FilteringVulnerability ScanningVulnerability ManagementPatch ManagementNetwork SecurityCryptographyApplication SecurityNistGdprCcpa
Security Engineer26 days ago
Full TimeRemoteTeam 1-10Since 1999H1B No Sponsor
Managing Security Consultant guiding cybersecurity architecture for Government modernization effort
AzureCloudCyber SecurityKubernetesOracleVault
United States
Security Engineer26 days ago
Full TimeRemoteTeam 11-50H1B No Sponsor
IT Security Manager overseeing compliance in cybersecurity for Rubris Inc.
Cyber Security
United States
Security Engineer26 days ago
Full TimeRemoteTeam 11-50Since 2021H1B No Sponsor
Senior Security Engineer responsible for security in AI-powered search platform
AWSCloudJavaScriptKubernetesPythonTerraform