Security Assurance Consultant
Remote
Fortreum
Fortreum simplifies the cybersecurity requirements process for cloud technologies to achieve authorization that enables US Public Sector business.Fortreum is a trusted leader in cloud and cybersecurity services, ranked in the Top 5 FedRAMP Third Party Assessment Organizations (3PAO). We provide independent, third-party and vendor-agnostic regulatory assessment and advisory services, coupled with advanced cybersecurity offensive and compliance technical services to our clients. Our comprehensive service portfolio includes regulatory compliance (FedRAMP, FISMA, SOC, ISO, HIPAA, CMMC) and technical security services (Penetration Testing, Red Teaming, Social Engineering, Attack Surface Analysis and others).
Working with Fortune 500 companies and leading cloud service providers, we've built our reputation on our service-delivery excellence and unwavering commitment to client success. Our rapid growth creates exceptional opportunities for driven professionals to make their mark in the cybersecurity industry with a focus on our core values:
Quality matters most Customer-driven mindset Autonomy to do your job Personal accountability/stewardship
The Opportunity On our team, you will have the opportunity to work with the best and brightest in the field. Fortreum team members have supported the biggest cloud providers in the world, and you will have the opportunity to learn from the best. We are growing rapidly and are looking for candidates with a background in performing security assessments in support of FedRAMP and NIST-based frameworks to support our growing customer base.
Key Responsibilities This role will specialize in FedRAMP, HIPAA, and other NIST-based assessment activities. Specifically, you would:
- Work closely with all members of the team supporting one or all of the following work activities:
- -Developing security assessment plans (SAPs)
- -Conducting interviews of key stakeholders and technical personnel
- -Performing technical tests alongside security engineers
- -Recording meeting minutes and maintain work papers
- -Developing security assessment reports (SARs)
- Maintain a consistent writing style and approach to documenting the results of the security assessment
- Collaborate with delivery team members to drive customer satisfaction and meet project deliverables
- Ensure quality products and services are delivered on time and within allotted hours
- Establish and maintain positive collaborative relationships with clients and stakeholders
- Continuous professional development in pursuing industry specific certifications
- Consistently work to improve assessment interviewing techniques to establish efficiencies in gathering required information
- Prepare deliverables and conduct peer-review of team member’s deliverables
- Perform project outbriefs with clients to notify them of the outcome of their compliance activities
- Manage priorities, tasks, and assigned hours on projects to achieve delivery utilization targets
- This is a customer facing role. You may be required to travel to client locations and deliver professional services when needed.
Basic Qualifications
- Bachelor’s Degree or equivalent job experience
- 3+ years of professional services experience
- 2+ years of consulting experience leveraging NIST SP 800-53
- Proficient in Microsoft 365 product suite
- One of the following certifications:
- -Cisco Certified Network Associate Security (CCNA Security)
- -Cisco Certified Network Associate Cyber Security Operations (CCNA Cyber Ops)
- -Cybersecurity Analyst (CySA+)
- -GIAC Certified Incident Handler (GCIH)
- -GIAC Systems and Network Auditor (GSNA)
- -GIAC Certified Intrusion Analyst (GCIA)
- -Certified Information Systems Auditor (CISA)
- -Certified Information System Security Professional (CISSP or Associate)
- -Certified Secure Software Lifecycle Professional (CSSLP)
- -Certified Information Systems Security Officer (CISSO)
- -CyberSec First Responder (CFR)
- -CompTIA Advanced Security Practitioner (CASP+)
- -CompTIA Cloud+ (Cloud+)
- -Global Industrial Cyber Security Professional (GICSP)
- -Securing Cisco Networks with Threat Detection Analysis (SCYBER)
Preferred Skills
- Ability to quickly take on new technologies and concepts
- Ability to manage multiple priorities simultaneously
- Proven analytical and problem-solving skills
- Ability to develop and maintain strong relationships with team members and clients
- Comfortable supporting fast-paced team environments
- Advanced technical certifications, such as:
- -AWS solutions architect
- -Google cloud engineer
- -Microsoft solutions architect
An Affirmative Action and Equal Opportunity EmployerFortreum is an Affirmative Action and Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, or protected veteran status and will not be discriminated against on the basis of disability. If you’d like to view a copy of the company’s affirmative action plan or policy statement, please email hr@fortreum.com. If you have a disability and you believe you need a reasonable accommodation in order to search for a job opening or to submit an online application, please e-mail hr@fortreum.com or call 703-594-1460. This email and phone number is created exclusively to assist disabled job seekers whose disability prevents them from being able to apply online. Only messages left for this purpose will be returned. Messages left for other purposes, such as following up on an application or technical issues not related to a disability, will not receive a response.
In compliance with federal law, all persons hired will be required to verify identity and eligibility to work in the United States and to complete the required employment eligibility verification form upon hire.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: AWS CASP+ CISA CISSP Cloud CMMC Compliance CompTIA CSSLP FedRAMP FISMA GCIA GCIH GCP GIAC GICSP GSNA HIPAA Industrial NIST NIST 800-53 Pentesting Red team Security assessment Security Assessment Report SOC Threat detection
Perks/benefits: 401(k) matching Career development Cell phone stipend Competitive pay Flex vacation Health care Home office stipend Insurance Salary bonus
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.