NIST 800-53 Security Assessor

velero • United State
Remote
Apply
AI Summary

We are seeking an experienced NIST 800-53 Security Assessor to support federal security authorization assessments. The role involves evaluating system compliance against the NIST SP 800-53A framework and producing formal assessment findings. The assessor will work closely with system owners and compliance stakeholders to determine the accuracy of documented security implementations.

Key Highlights
Perform security control assessments aligned to NIST SP 800-53A Rev. 5
Conduct structured interviews with control owners and system administrators
Develop formal assessment findings for failed or partially implemented controls
Key Responsibilities
Audit Framework & Control Assessment
Interview Execution
Testing & Evidence Validation
Privacy Control Validation
Findings Development & Reporting
Technical Skills Required
NIST 800-53 NIST SP 800-53A Rev. 5 Excel
Benefits & Perks
Fully remote delivery
4–6 week engagement duration
Nice to Have
Experience supporting federal authorization programs
Familiarity with ARC-AMPE or similar control baselines
Knowledge of privacy frameworks and PII handling requirements

Job Description


We are seeking an experienced NIST 800-53 Security Assessor to support a series of federal security authorization assessments. This role is responsible for evaluating system compliance against the NIST SP 800-53A Rev. 5 framework, executing control testing procedures, validating privacy protections, and producing formal assessment findings.

The assessor will work closely with system owners, engineers, and compliance stakeholders to determine the accuracy of documented security implementations and identify control gaps requiring remediation.


Key Responsibilities:

Audit Framework & Control Assessment

  • Perform security control assessments aligned to NIST SP 800-53A Rev. 5.
  • Design and execute assessment procedures using the three approved methods:
  1. Inspect
  2. Interview
  3. Test
  • Assess controls across all 20 ARC-AMPE control families.


Interview Execution

  • Conduct structured interviews with:
  1. Control owners
  2. System administrators
  3. Security engineers
  4. Compliance stakeholders
  • Validate implementation statements and operational practices.


Testing & Evidence Validation

  • Perform technical and administrative testing of implemented controls.
  • Review and validate artifacts including:
  1. System logs
  2. Configuration files
  3. Security tool outputs
  4. Policies and procedures
  • Confirm whether SSP implementation statements are factually accurate.


Excel-Based Evidence Mapping

  • Map evidence artifacts to control requirements.
  • Evaluate System Security Plan (SSP/SSPP) implementation narratives.
  • Track testing results and compliance status using structured workbooks.


Privacy Control Validation

  • Assess controls within the PT (PII Processing & Transparency) family.
  • Verify lawful processing, storage, and protection of beneficiary data.
  • Confirm compliance with data residency requirements, including offshore restrictions.


Findings Development & Reporting

  • Develop formal assessment findings for failed or partially implemented controls.
  • Document:
  1. Control deficiency
  2. Risk impact
  3. Likelihood and severity
  4. Recommended corrective actions (non-implementation advisory)
  • Contribute to final security assessment reports.


Required Qualifications

  • Minimum 5 years of direct experience assessing NIST 800-53 controls.
  • Hands-on expertise with NIST SP 800-53A Rev. 5 testing procedures.
  • Proven experience designing control assessment test cases.
  • Experience reviewing and validating System Security Plans (SSPs).
  • Strong background in evidence analysis and artifact review.
  • Experience conducting stakeholder interviews in audit environments.
  • Advanced proficiency in Excel for control and evidence mapping.


Preferred Qualifications

  • Experience supporting federal authorization programs (e.g., ATO-driven environments).
  • Familiarity with ARC-AMPE or similar control baselines.
  • Knowledge of privacy frameworks and PII handling requirements.
  • Relevant certifications such as:
  1. CISSP
  2. CISA
  3. CCSP
  4. Security+

Each engagement lasting 4–6 weeks.

Fully remote delivery with scheduled stakeholder sessions.

Deliverables

  • Completed control assessment workpapers.
  • Evidence mapping matrices.
  • Interview documentation.
  • Technical testing results.
  • Formal findings and risk statements.
  • Input to final Security Assessment Report (SAR).

If you are a detail-oriented security assessor with deep NIST expertise and experience executing federal-grade control assessments, we encourage you to apply.


Similar Jobs

Explore other opportunities that match your interests

Senior IT Security Engineer - DLP and CASB

Cyber Security
•
2h ago

Premium Job

Sign up is free! Login or Sign up to view full details.

•••••• •••••• ••••••
Job Type ••••••
Experience Level ••••••

CSAA Insurance Group, a AAA In...

United State
Visa Sponsorship Relocation Remote
Job Type Full-time
Experience Level Mid-Senior level

cyber focus ai

United State

IT Security Compliance Analyst

Cyber Security
•
17h ago
Visa Sponsorship Relocation Remote
Job Type Full-time
Experience Level Mid-Senior level

cyber focus ai

United State

Subscribe our newsletter

New Things Will Always Update Regularly