Supplier Risk Management Assessor Pinnacle Technical ResourcesSupplier Risk Management AssessorMcLean, Virginia$55–$60 / hourContractorThe Supplier Risk Management role involves analyzing and assessing risks, including technology, privacy security, resiliency, and other operational risks that the organization and its suppliers may face. The specific compensation for this position will be determined by several factors, including the scope, complexity, and location of the role, as well as the cost of labor in the market; the skills, education, training, credentials, and experience of the candidate; and other conditions of employment.
NewJunior Security Control Assessor System OneJunior Security Control AssessorBethesda, MD$100,000 / yearYou’ll work under a senior assessor and help evaluate security control implementation, validate evidence, and document results in alignment with NIST Risk Management Framework (RMF) and NIST SP 800-53 Rev. Education: Bachelor’s in Cybersecurity, IT, Computer Science, Information Systems (or similar) OR 4 additional years of relevant experience in lieu of a degree.
NewMid-Level Security Control Assessor System OneMid-Level Security Control AssessorBethesda, MDRemote$135,000–$140,000 / yearRequirements Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or related discipline, or four (4) additional years of relevant experience. System One, and its subsidiaries including Joulé and Mountain Ltd., are leaders in delivering outsourced services and workforce solutions across North America.
IT Risk & Compliance Analyst NORC at the University of ChicagoIT Risk & Compliance AnalystWashington, D.C.$77,000–$95,000 / yearWorking closely with engineering, cloud operations, infrastructure, development, and business teams, the analyst will help assess security control effectiveness, coordinate compliance activities, collect and validate evidence, track remediation efforts, and support ongoing audit readiness. Coordinate monthly, quarterly, annual, and ongoing FedRAMP Continuous Monitoring activities, including evidence collection, security control assessments, vulnerability management, POA&M management, metrics reporting, and security documentation updates.
GRC Risk Analyst Security Assurance, LLCGRC Risk AnalystPotomac, MD$65,000–$90,000 / yearFull timeThe ideal candidate is an early-career information security or Governance, Risk, and Compliance (GRC) professional who possesses strong analytical, organizational, and communication skills, and is seeking to build a long-term career in enterprise information security governance and risk management. The successful candidate will be self-motivated, detail-oriented, and capable of learning and consistently applying established County policies, procedures, and risk assessment methodologies.
Senior Associate, Claims & Risk Management HITT ContractingSenior Associate, Claims & Risk ManagementFalls Church, VA$77,000–$112,000 / yearThe Senior Associate, Claims & Risk Management meaningfully contributes to analytical support to the Insurance & Risk Management team and leadership as needed on periodic reporting of claim and incident trends. Bachelor’s degree in Risk Management, Business, Finance, Economics, Safety, or related fields preferred, but not required; in lieu of a degree, additional work experience is acceptable.
Senior IT Risk and Compliance Analyst NORC at the University of ChicagoSenior IT Risk and Compliance AnalystWashington, D.C.$97,000–$120,000 / yearWith world-class benefits, a business casual environment, and an emphasis on continuous learning, NORC is a place where people join for the stellar research and analysis work for which we’re known, and stay for the relationships they form with their colleagues who take pride in the impact their work is making on a global scale. Experience conducting incident response across vendors, internal stakeholders, and program owners, including implementing, and coordinating the response plan, overseeing the technical response, and coordinating with legal, technical, and communications teams.
Senior Manager, Risk Management HITT ContractingSenior Manager, Risk ManagementFalls Church, VA$115,000–$165,000 / yearMaintain and optimize enterprise-wide P&C insurance programs including general liability, workers’ compensation, auto, property, umbrella, professional liability, pollution liability, cyber, management liability, and builder’s risk across all HITT operating companies (general contracting, self-perform construction, manufacturing, and logistics). The ideal candidate brings broad P&C expertise with strong construction industry acumen, is comfortable leading technical discussions with carriers, brokers, and legal counsel, and is a passionate advocate for sound risk management.
NewCybersecurity Risk - Managing Consultant GuidehouseCybersecurity Risk - Managing ConsultantWashington, DC$130,000–$216,000 / yearCertified in one of the following OR another relevant certification: Certified Information Systems Security Professional (CISSP), Certified in Risk and Information Systems Controls (CRISC), Certified Authorization Professional (CAP) / Certified in Governance, Risk and Compliance (CGRC), Certified Information Systems Auditor (CISA) What Would Be Nice To Have: Experience consulting at large federal agencies such as the Department of State, Department of Justice or Department of Homeland Security on cybersecurity audits and / or IT controls Demonstrated experience in the areas of external client-facing management and/or consulting for large firms The annual salary range for this position is $130,000.00-$216,000.00. What You Will Do: Oversee, manage and lead the development and execution of cybersecurity risk management, risk governance, risk assessments and HVA oversight and assessments, including maintaining and improving enterprise-level risk register, coordinating and planning enterprise and organizational unit risk assessments, overseeing specified technology risk assessments, and overseeing HVA oversight program functions.
NewCybersecurity GRC Analyst System OneCybersecurity GRC AnalystOwings Mills, MDRemote$51.35 / hourThis role is responsible for conducting risk assessments, enhancing security practices, evaluating controls, and helping protect organizational data from unauthorized access, disclosure, or misuse. The ideal candidate will have experience in cybersecurity governance, risk management, compliance, IT audit, and security controls, along with exposure to ServiceNow and database environments.
Information Systems Security Officer System OneInformation Systems Security OfficerAnnapolis Junct, MD$200,000 / yearIn this role, you’ll help ensure information systems stay compliant throughout the Risk Management Framework (RMF) lifecycle—supporting ATO packages, continuous monitoring, assessments, and audit readiness . System One, and its subsidiaries including Joulé and Mountain Ltd., are leaders in delivering outsourced services and workforce solutions across North America.
NewSenior Enterprise Data Privacy Analyst System OneSenior Enterprise Data Privacy AnalystMerrifield, VAThe ideal candidate has hands-on experience standing up or enhancing privacy programs in the second line of defense at highly regulated financial environments and can operate strategically while also delivering practical implementation artifacts. The contractor will support the maturation of the organization’s privacy framework, governance processes, privacy risk management capabilities, regulatory compliance obligations, third?party privacy oversight, Privacy Impact Assessment (PIA)/Privacy Risk Assessment (PRA) programs, and privacy reviews of Artificial Intelligence initiatives.
Supplier Risk Management Assessor MindlanceSupplier Risk Management AssessorMcLean, VAAnalyze and assess risks (including technology, privacy security, resiliency, and other operational risks) that the organization and suppliers (vendors) may face. " Strong working knowledge of risk management and previous experience working with risk (i.e., risk assistant or risk analyst).
Supplier Risk Management (SRM) Assessor - Hybrid Genesis10Supplier Risk Management (SRM) Assessor - HybridMcLean, VATemporaryContractorFull timeRanked a Top Staffing Firm in the U.S. by Staffing Industry Analysts for six consecutive years, Genesis10 puts thousands of consultants and employees to work across the United States every year in contract, contract-for-hire, and permanent placement roles. With more than 300 active clients, Genesis10 provides access to many of the Fortune 100 firms and a variety of mid-market organizations across the full spectrum of industry verticals.
NewSupplier Risk Management Assessor PinnacleSupplier Risk Management AssessorMcLean, VA$55–$60 / hourThe Supplier Risk Management role involves analyzing and assessing risks, including technology, privacy security, resiliency, and other operational risks that the organization and its suppliers may face. The specific compensation for this position will be determined by several factors, including the scope, complexity, and location of the role, as well as the cost of labor in the market; the skills, education, training, credentials, and experience of the candidate; and other conditions of employment.
NewSecurity Controls Assessor - Senior SMS DATA PRODUCTS GROUP, INCSecurity Controls Assessor - SeniorSpringfield, VAThe successful senior level candidate will be responsible for evaluating, testing, and validating the effectiveness of security controls, with a strong emphasis on applying the Risk Management Framework (RMF) and have experience in leading a team of Assessors. Experience as senior or lead member of a team, including experience coaching and providing guidance to less experienced or new team resources, reviewing work products, tracking deadlines, and coverage, reporting, facilitating onboarding / offboarding procedures, etc.
Security Control Assessor (SCA) CymertekSecurity Control Assessor (SCA)Annapolis Junction, MarylandSecurity Assessor, Information Security Auditor, Security Compliance Analyst, Security Analyst, Risk and Compliance Officer, Security Control Evaluator, IT Auditor, Security Assurance Specialist, Security Risk Assessor, Compliance Manager, ect. In this role, you will be responsible for assessing and evaluating the effectiveness of security controls across various systems, identifying vulnerabilities, and ensuring compliance with relevant security frameworks and regulations.
Security Control Assessor Life Cycle EngineeringSecurity Control AssessorSpringfield, VALife Cycle Engineering (LCE) is a privately held, employee-owned company with an emphasis on "doing the right thing the right way”, which applies to the way we treat our customers and employees. Physical Demands and Expectations: Regular physical activity to include walking, climbing stairs, bending, stooping, reaching, lifting (up to 15 pounds), and standing; occasional prolonged sitting.
Security Control Assessor Novul SolutionsSecurity Control AssessorArlington, VAThis role is responsible for conducting in-depth security control assessments, validating control implementation, reviewing system security documentation, and supporting the development and maintenance of complete and accurate Authorization to Operate packages. Assess program compliance with security controls associated with registered Ports, Protocols, and Services, including the proper generation, retention, protection, and handling of system log files.
Security Control Assessor (SCA) — Level II RividiumSecurity Control Assessor (SCA) — Level IIWashington, District of ColumbiaThe Security Control Assessor provides expert guidance on security control implementation, risk management, continuous monitoring, and authorization package development while working closely with System Owners, Information System Security Officers (ISSOs), Information System Security Managers (ISSMs), Security Engineers, Government Authorizing Officials (AOs), Security Control Assessor Representatives (SCARs), Branch Chiefs, and the DHS I&A Chief Information Security Officer (CISO). This position conducts comprehensive security control assessments for classified and unclassified information systems, cloud environments, Cross Domain Solutions (CDS), and C-LAN extension sites in support of the NIST Risk Management Framework (RMF) and DHS/Intelligence Community (IC) cybersecurity requirements.