JOB TITLE: Principal Cybersecurity Assessment Methodologist
LOCATION: Florida (remote/hybrid acceptable) - limited travel for QA reviews and client briefings as needed
TRAVEL: Minimal; primary function is methodology oversight and quality review rather than field assessment
JOB TYPE: Contract / Engagement-Based (Government Consulting Services)
CONTRACT RATE BASIS: Principal Consultant tier
JOB SUMMARY
Judit Inc. is seeking a Principal Cybersecurity Assessment Methodologist to serve as the technical quality authority for a large-scale, multi-site government IT security risk assessment. This role owns the consistency, rigor, and defensibility of every assessment finding across more than 30 independent entities. This is a senior individual-contributor role for a late-career cybersecurity professional who prioritizes technical integrity over field management responsibilities.
KEY RESPONSIBILITIES
Own and enforce a single, consistent set of risk-scoring criteria applied uniformly across all assessed entities, in conformance with NIST SP 800-30 risk assessment methodology
Serve as quality assurance gate owner: review and approve every entity-level assessment package before it is included in the aggregate client-facing report
Provide methodology authority on NIST alignment, cross-entity consistency, and overall defensibility of findings
Own resolution protocols for any written client deficiency notices, including defined internal correction timelines and escalation procedures
Define assessment approach for entities with limited or incomplete documentation, ensuring no risk category is left unscored
REQUIRED QUALIFICATIONS
20+ years in cybersecurity and IT security auditing across federal/DoD and enterprise environments
Demonstrated end-to-end NIST Risk Management Framework (RMF) experience, including system categorization through Authorization to Operate (ATO), NIST SP 800-53/800-53A control assessment, POA&M management, and continuous monitoring
Active professional certifications required (minimum of three): CISSP, CISA, CISM, ISSEP, CGEIT, CGRC, CDPSE
FedRAMP and/or CMMC assessment experience
Demonstrated prior experience owning assessment methodology (not solely executing it) on at least one multi-entity or multi-site engagement
Willingness and ability to pass Level 2 background screening (Livescan/FBI) prior to accessing confidential information
Enrollment in / compliance with E-Verify requirements
PREFERRED QUALIFICATIONS
M.S. in Information Systems, Cybersecurity, or related field
C|CISO or equivalent executive-level security credential
Prior experience serving as an independent quality reviewer or methodology arbiter, distinct from field assessment execution