NIST CSF Remediation and Assessment Support

Overview

On Site
Full Time

Skills

UI
Information Technology
Network
Microsoft
Tier 1
Cloud Computing
Recruiting
Training
Partnership
Communication
Project Scoping
LOS
Leadership
Risk Assessment
NIST 800-53
IT Security
Documentation
Regression Analysis
Reporting
Cyber Security
Interfaces
Gap Analysis
Roadmaps
Risk Management
ERM
Identity Management
Cloud Security
HIPAA
Continuous Monitoring
Dashboard
Regulatory Compliance
Auditing
Oracle Linux

Job Details

CCS Global Tech is a rapidly growing Information Technology company with a diverse portfolio of technology products and services and a large network of industry partnerships. With over 22 years of being a successful business with a global talent pool and presence, CCS is a certified Microsoft Gold Partner and specializes in delivering expert Microsoft based solutions for technical and business needs. We have been recognized by Inc. 500 Magazine as one of the fastest growing small companies in the Unites States.
we are a Tier 1 vendor for the City and County of San Francisco for Cloud Services, Staffing Services and Training Services. For this multi-year opportunity with a diverse set of needs to address, we are currently focusing on establishing partnerships with individuals as well as companies who can help us enhance our overall service portfolio, cut lead times, and ultimately help us deliver successfully. We currently hold sizable Government accounts in the San Francisco bay area including City and County of San Francisco, San Mateo County, and Santa Clara County.
We take great pride in our global reach and local influence. Your experience alongside our highly skilled and talented internal team who guide you along the way, offers key insights into what helps you stand out in a competitive job market.
If you are a partner company, please submit resumes with contact information of your own W2 Consultants only. Submitted consultants are expected to have excellent communication skills.

Project Scope:

The Los Angeles Unified School District (LAUSD) seeks qualified proposers to provide NIST CSF Remediation and Assessment Support. The Contractor shall provide resource(s) with the technical skills and personal leadership to perform all related services. LAUSD intends to use the results of this solicitation process to award a work order to the responsive and responsible proposer. The proposed work order will require one (1) resource working hybrid; onsite work will be at LAUSD Beaudry HQ and Soto Office.

Roles/Responsibilities:

The District seeks a firm that will perform the required work closely collaborating with LAUSD project team members and will perform the responsibilities below:

Policy Development

  • Review existing LAUSD cybersecurity policies, procedures, standards, risk assessments, and other related compliance documents.
  • Identify current IT Security policy gaps against NIST CSF 2.0 and assist in developing policies, procedures, standards, and other compliance documents to address those gaps

NIST Alignment

  • Meet with key stakeholders.
  • Define scope, priorities, and resource needs.
  • Review the 2024 NIST Gap Assessment results.
  • Revalidate gaps to confirm current state and material changes.
  • Map all gaps to the appropriate NIST CSF categories and/or NIST 800-53 controls.
  • Prioritize gaps based on risk, regulatory impact, and operational dependency.
  • Develop remediation plans, including resource needs, timelines, and responsible parties.

NIST Assessment

  • Interview key personnel from IT, security, compliance, and business units.
  • Validate documentation with observed processes and supporting evidence.
  • Rate each NIST CSF Category/Subcategory using a maturity model (e.g., 1 5 scale: Partial to Adaptive).
  • Compare 2025 maturity levels to previous years to identify progress or regression.

Maturity Assessment against NIST CSF 2.0

  • Create and deliver a comprehensive assessment report including: o Executive summary
  • Maturity scorecard
  • Identified gaps and risks
  • Remediation recommendations and risk prioritization
  • Present findings in an executive-level briefing.

Mandatory Skills:

  1. Five years of experience performing assessments, alignments, and policy development with the NIST Cybersecurity Framework (CSF) across all departments, systems, and third-party interfaces.
  2. Five years of experience with conducting state assessment, target profile development, Gap analysis and Implementation roadmap with control mappings to various processes. Demonstrated expertise with Framework integration with Enterprise Risk Management (ERM), Identity and Access Management (IAM) and Cloud security controls. Ensure interoperability with compliance (HIPAA, COPPA, FERPA, CIIPA, GDPR, etc.)
  3. Experience in establishing the Metrics and Continuous Monitoring providing dashboard for dashboards for executive visibility (CISO, CIO, board), planning regular maturity assessment and establishing metrics for each CSF function and subcategory.
  4. Experience in governance and program design
  5. Experience in NIST CSF framework integration
  6. Experience in technology alignment with NIST CSF
  7. Experience in establishing metrics and executive dashboard creation.
  8. Experience with compliance and audit requirements
  9. Experience with understanding larger systems and their dependencies.
  10. Experience with developing governance framework documents, SOPs and policies.

Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.

About CCS Global Tech