Managing Security Consultant - Assessor

Posted Yesterday
Be an Early Applicant
Alpharetta, GA, USA
Hybrid
Senior level
Information Technology • Professional Services • Software • Cybersecurity
The Role
Leads FedRAMP authorization and continuous monitoring assessments for cloud service providers, evaluating security controls, architectures, processes, evidence, and risk management against federal requirements. Provides cybersecurity compliance and cloud security advisory services, develops remediation strategies, reviews assessment reports, leads client engagements, supports business development, and mentors assessment teams. The role also contributes to quality assurance, methodology improvements, executive briefings, and growth of government cybersecurity services.
Summary Generated by Built In
Location - New York, Chicago, Atlanta or Alpharetta 
 
NCC Group (US) is seeking an experienced and highly respected Managing Security Consultant / Senior Assessor to support and help lead the delivery of Federal cybersecurity assessment and advisory services within its accredited FedRAMP Third Party Assessment Organization (3PAO) practice. 
This position represents a senior technical and consulting role within the Government Services organization. The successful candidate will be recognized as a trusted subject matter expert in Federal cybersecurity compliance, cloud security assessments, and risk management. The individual will lead complex assessment engagements, provide strategic advisory services, mentor assessment teams, contribute to business development efforts, and support the continued growth and maturity of NCC Group's government security offerings. 
The role requires a deep understanding of FedRAMP assessment methodologies, Federal cybersecurity frameworks, cloud technologies, and independent auditing principles. The ideal candidate combines technical expertise with strong leadership, communication, and client relationship management capabilities. 

Key Responsibilities
Assessment Leadership 
  • Serve as a Lead Assessor for FedRAMP authorisation and continuous monitoring assessments  
  • Lead assessment teams responsible for evaluating cloud service providers against FedRAMP and NIST requirements  
  • Conduct independent evaluation of security controls, cloud architectures, operational processes and risk management programmes  
  • Review testing methodologies, assessment evidence and assessment reports for accuracy and quality 
  • Ensure assessment activities comply with FedRAMP, 3PAO and organisational quality requirements  
  • Identify deficiencies, risks and opportunities for improvements and communicate findings clearly to clients and stakeholders 
  • Support quality assurance activities and peer reviews across Government Services engagements  

Advisory Services
 
  • Provide advisory and readiness services related to:  
FedRAMP- Rev5 and FedRAMP20x 
CMMC / DFARS 7012 cybersecurity requirements  
Secure cloud adoption and governance  
NIST Risk Management Framework (RMF 
  • Assist organisations in developing compliance roadmaps and remediation strategies  
  • Advise clients on cybersecurity governance, risk management and control implementation  

Business Development and Client Engagement
 
  • Support pre-sales activities, including opportunities qualification, customer briefings, project scoping and proposal development  
  • Develop Statements of Work (SOWs), project plans, assumptions and costs. 
  • Participate in client workshops and executive-level discussions 
  • Act as a trust advisor to customers throughout engagement lifecycles  
  • Contribute thought leadership to support the growth of NCC Group’s Government Services practice 

Team Leadership:
 
  • Support the mentorship and coaching of Junior assessors and consultants  
  • Support workforce development and assessment methodology improvements  
  • Assist practice leadership with service delivery planning and operational initiatives  
  • Promote assessment consistency, quality and professional excellence across engagement teams  

Skills, Knowledge and Expertise
Professional Experience 
  • Demonstrated expertise in information security, cybersecurity consulting, auditing, compliance, risk management, or related disciplines including management of IT organizations.  
  • Experience with FedRAMP Assessments and or Advisory Services.  
  • Must have extensive experience of auditing and/or assessment experience, 
  • Experience leading multi-disciplinary security assessment teams 
  • Experience delivering both assurance (assessment) and advisory consulting engagements 
  • Experience operating in highly regulated environments requiring exceptional attention to detail and documentation quality 
Government & Industry Experience 
  • U.S. Citizen authorized to work in the United States. 
  • Ability to successfully complete required background investigations. 
  • Strong understanding of U.S. Government cybersecurity programs and compliance requirements. 
  • Experience supporting Federal agencies, defense contractors, cloud service providers, or other government-regulated organizations. 
  • Familiarity with government acquisition and cybersecurity compliance environments. 
  • Understanding of software supply chain and cloud ecosystem security considerations. 
Cloud & Technical Experience 
  • Demonstrated experience assessing and securing cloud computing environments across SaaS, PaaS, IaaS, cloud-native, and hybrid architectures 
  • Strong understanding of security controls, risk assessment, and remediation within enterprise environments. 
Functional Expertise 
Candidates must demonstrate significant expertise in: 
  • FedRAMP authorization processes and assessment methodologies. 
  • NIST SP 800-53 security controls and control assessment practices. 
  • NIST 800-171 and NIST 800-171A 
  • Federal cybersecurity compliance programs. 
  • Security risk management and risk-based decision making. 
  • Security assessment report development and quality review. 
  • Executive briefing and stakeholder communications. 
Desirable: 
  • Experience advising on CMMC requirements and implementation. 
  • Experience working with DFARS cybersecurity requirements. 
  • Understanding of Federal Executive Orders impacting cybersecurity and software supply chain security. 
  • Experience supporting GovRAMP assessments. 
  • Familiarity with ISO/IEC 17020 requirements and accreditation standards. 
  • Experience supporting accredited conformity assessment organizations or testing laboratories. 
Required Certifications 
  • Certified Information Systems Security Professional (CISSP) 
  • Baltimore Cyber Range Technical Proficiency Certification 

Benefits
What do we offer in return?  
 
We have a high-performance culture which is balanced evenly with world-class well-being initiatives and benefits: 
  • Flexible Working: Balance your work and personal life with our flexible working options. 
  • Generous Holiday Allowance: Enjoy 25 days of holiday, plus bank holidays, with the option to buy up to 5 additional days of annual leave. 
  • Medicash & Critical Illness Scheme 
  • Financial & Investment Benefits: Enjoy peace of mind with our Pension, Life Assurance, and Share Save Scheme. 
  • Community & Volunteering Programmes: Make a difference in your community with our volunteering opportunities. 
  • Green Car Scheme: Drive green and save money with our eco-friendly car scheme. 
  • Cycle Scheme: Stay fit and healthy with our cycle-to-work scheme. 
  • Special Time Off: Take time off for those big moments in life, like getting married/entering into a civil partnership, becoming a grandparent, and welcoming home a new pet. 
  • Family Planning: Benefit from our generous maternity and paternity leave, as well as time off and support for those undergoing fertility treatments. 

About
We assess, develop and manage cyber threats across our increasingly connected society. We advise global technology, manufacturers, financial institutions, critical national infrastructure providers, retailers and governments on the best way to keep businesses, software and personal data safe.With our knowledge, experience and global footprint, we are best placed to help businesses identify, assess, mitigate & respond to the risks they face.We are passionate about making the Internet safer and revolutionising the way in which organisations think about cyber security.Headquartered in Manchester, UK, with over 35 offices across the world, NCC Group employs more than 2,000 people and is a trusted advisor to 15,000 clients worldwide.

Skills Required

  • Extensive experience in information security, cybersecurity consulting, auditing, compliance, risk management, or related disciplines
  • Experience with FedRAMP assessments or advisory services
  • Extensive auditing or security assessment experience
  • Experience leading multidisciplinary security assessment teams
  • Experience delivering assurance and advisory consulting engagements
  • Experience operating in highly regulated environments with strong documentation requirements
  • U.S. citizenship and authorization to work in the United States
  • Ability to successfully complete required background investigations
  • Understanding of U.S. Government cybersecurity programs and compliance requirements
  • Experience supporting federal agencies, defense contractors, cloud service providers, or government-regulated organizations
  • Experience assessing and securing SaaS, PaaS, IaaS, cloud-native, and hybrid cloud environments
  • Expertise with FedRAMP authorization processes and assessment methodologies
  • Expertise with NIST SP 800-53 security controls and control assessment practices
  • Expertise with NIST SP 800-171 and NIST SP 800-171A
  • Expertise in federal cybersecurity compliance, security risk management, and risk-based decision-making
  • Experience developing and quality-reviewing security assessment reports
  • Executive briefing and stakeholder communication experience
  • Certified Information Systems Security Professional certification
  • Baltimore Cyber Range Technical Proficiency Certification
  • Experience advising on CMMC requirements and implementation
  • Experience with DFARS cybersecurity requirements
  • Understanding of federal cybersecurity executive orders and software supply chain security
  • Experience supporting GovRAMP assessments
  • Familiarity with ISO/IEC 17020 requirements and accreditation standards
  • Experience supporting accredited conformity assessment organizations or testing laboratories
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Manchester
2,140 Employees
Year Founded: 1999

What We Do

NCC Group is a global cyber security and resilience company that helps organizations manage risk, strengthen resilience, and build trust. They provide services in cyber security consulting, managed services, technical assurance, and software escrow.

Similar Jobs

DraftKings Logo DraftKings

Salesforce Administrator

Digital Media • Gaming • Information Technology • Software • Sports • Esports • Big Data Analytics
Remote or Hybrid
United States
6400 Employees
71K-88K Annually

Apryse Logo Apryse

Enterprise Account Executive

Productivity • Software • App development • Automation
In-Office or Remote
15 Locations
665 Employees
150K-220K Annually

Apryse Logo Apryse

Commercial Account Executive

Productivity • Software • App development • Automation
In-Office or Remote
7 Locations
665 Employees
120K-200K Annually

AMP Logo AMP

Project Manager

Artificial Intelligence • Computer Vision • Greentech • Machine Learning • Robotics • Industrial • Automation
Easy Apply
Remote or Hybrid
United States
175 Employees

Similar Companies Hiring

Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Revel Thumbnail
Aerospace • Hardware • Robotics • Software
Marina Del Rey, California
60 Employees
Blee Thumbnail
Artificial Intelligence • Marketing Tech • Software
New York, New York
30 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account