Security Control Assessor

Sacramento, CA, US • Posted 5 hours ago • Updated 5 hours ago
Contract W2
Contract Independent
Contract Corp To Corp
6 Months
50% Travel Required
On-site
Depends on Experience
Fitment

Dice Job Match Score™

🔢 Crunching numbers...

Job Details

Skills

  • Security Control Assessor

Summary

Position: Security Control Assessor

Duration: 6 months with extension Possible

Location: Sacramento, CA (Hybrid)

Can attend the Sacramento office for two consecutive days each month, generally the first Wednesday and Thursday.

 

Position Overview

The Independent Security & Privacy Assessor will conduct independent, risk-based security and privacy assessments of complex cloud-based systems that process confidential or regulated data. This position must operate independently from personnel responsible for designing, implementing, administering, or operating the controls being assessed.

 

Key Responsibilities:

  • Security & Privacy Assessments
  • Conduct independent security and privacy assessments.
  • Assess complex cloud-based systems handling confidential or regulated data.
  • Perform assessments using:
  • CMS ARC-AMPE
  • NIST SP 800-53 Revision 5
  • Plan and execute assessment activities.
  • Evaluate security-control effectiveness.
  • Identify control weaknesses, vulnerabilities, and gaps.
  • Develop risk-based remediation recommendations.
  • CMS Compliance Documentation
  • Prepare required CMS assessment documentation.
  • Prepare and maintain the Security Assessment Workbook.
  • Support annual compliance and authorization activities.
  • Maintain assessment workpapers and supporting evidence.
  • Participate in quality reviews and assessment reporting.
  • Independence Requirements
  • Maintain reporting lines separate from operational security-support personnel.
  • Remain independent from individuals who designed, implemented, administered, or operated the controls being assessed.
  • Support separate engagement leadership and escalation paths.
  • Maintain objective assessment workpapers and findings.
  • Provide independent recommendations for corrective action and remediation.

 

Required Qualifications

  • Experience conducting independent security/privacy assessments.
  • Strong knowledge of CMS ARC-AMPE and/or NIST SP 800-53 Revision 5.
  • Experience assessing cloud-based systems.
  • Experience evaluating security controls and identifying vulnerabilities.
  • Experience developing risk-based remediation recommendations.
  • Experience preparing formal assessment documentation.
  • Direct experience with Security Assessment Workbooks is highly desirable.
  • Experience in regulated public-sector, healthcare, or health-exchange environments is preferred.
  • Relevant security certifications are desirable.
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 10365731
  • Position Id: 3225-14481-1787861402
  • Posted 5 hours ago
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

Sacramento, California

Today

Easy Apply

Contract, Third Party

Sacramento, California

Today

Easy Apply

Contract, Third Party

Remote

Yesterday

Easy Apply

Contract

$130

Maryland

Today

Contract

Search all similar jobs