Principal Cybersecurity Assessment Methodologist

Judit Inc

Tallahassee, FL

JOB DETAILS
SKILLS
CISA - Certified Information Systems Auditor, CISM - Certified Information Security Manager, CISSP - Certified Information Systems Security Professional, Computer Security, Consulting, Customer Relations, Documentation, Establish Priorities, Federal Bureau of Investigation (FBI), Government, ISSEP - Information Systems Security Engineering Professional, Information Technology & Information Systems, Internet Security, Quality Assurance, Risk, Risk Analysis, Risk Management Framework (RMF), Sales Presentation, Security Analysis, U.S. National Institute of Standards and Technology (NIST)
LOCATION
Tallahassee, FL
POSTED
16 days ago

JOB TITLE: Principal Cybersecurity Assessment Methodologist

LOCATION: Florida (remote/hybrid acceptable) - limited travel for QA reviews and client briefings as needed

TRAVEL: Minimal; primary function is methodology oversight and quality review rather than field assessment

JOB TYPE: Contract / Engagement-Based (Government Consulting Services)

CONTRACT RATE BASIS: Principal Consultant tier

JOB SUMMARY

Judit Inc. is seeking a Principal Cybersecurity Assessment Methodologist to serve as the technical quality authority for a large-scale, multi-site government IT security risk assessment. This role owns the consistency, rigor, and defensibility of every assessment finding across more than 30 independent entities. This is a senior individual-contributor role for a late-career cybersecurity professional who prioritizes technical integrity over field management responsibilities.

KEY RESPONSIBILITIES

  • Own and enforce a single, consistent set of risk-scoring criteria applied uniformly across all assessed entities, in conformance with NIST SP 800-30 risk assessment methodology

  • Serve as quality assurance gate owner: review and approve every entity-level assessment package before it is included in the aggregate client-facing report

  • Provide methodology authority on NIST alignment, cross-entity consistency, and overall defensibility of findings

  • Own resolution protocols for any written client deficiency notices, including defined internal correction timelines and escalation procedures

  • Define assessment approach for entities with limited or incomplete documentation, ensuring no risk category is left unscored

REQUIRED QUALIFICATIONS

  • 20+ years in cybersecurity and IT security auditing across federal/DoD and enterprise environments

  • Demonstrated end-to-end NIST Risk Management Framework (RMF) experience, including system categorization through Authorization to Operate (ATO), NIST SP 800-53/800-53A control assessment, POA&M management, and continuous monitoring

  • Active professional certifications required (minimum of three): CISSP, CISA, CISM, ISSEP, CGEIT, CGRC, CDPSE

  • FedRAMP and/or CMMC assessment experience

  • Demonstrated prior experience owning assessment methodology (not solely executing it) on at least one multi-entity or multi-site engagement

  • Willingness and ability to pass Level 2 background screening (Livescan/FBI) prior to accessing confidential information

  • Enrollment in / compliance with E-Verify requirements

PREFERRED QUALIFICATIONS

  • M.S. in Information Systems, Cybersecurity, or related field

  • C|CISO or equivalent executive-level security credential

  • Prior experience serving as an independent quality reviewer or methodology arbiter, distinct from field assessment execution

About the Company

J

Judit Inc