Position Responsibilities:
- Manage projects (referred to as engagements): scope validation, client readiness, assessment performance, report preparation, findings remediation (for advisory engagements), certification recommendations, and quality assurance to meet USG standards.
- Serve as a point of contact for client stakeholders (Security or IT Manager, GRC POCs, program or product managers).
- Mentor staff assessors, consultants, and technical practitioners, ensuring accurate understanding of deliverable contribution expectations, quality of deliverables, and adherence to accreditation standards.
- Contribute to the standardization of team services by developing and implementing support for playbooks, templates, job aides, and tools for efficient assessment deployment across client sites and systems.
- Build content to support marketing and sales efforts, e.g., blog posts, thought leadership pieces, videos, etc.
- Maintain up-to-date awareness of regulatory standards and accreditation changes to the frameworks listed above, and integrate these changes into assessment/advisory thinking.
- Communicate complex technical findings and cybersecurity risks to non-technical leadership, providing actionable recommendations.
Qualifications:
- Bachelor’s degree in Computer Science, Information Systems, Cybersecurity or related field (Master’s a plus).
- Minimum of 3+ years of experience in cybersecurity, information assurance, third-party assessments, or compliance (experience with other C3PAOs, assessor organization or consulting firm strongly preferred).
- Demonstrated experience conducting assessment engagements under frameworks such as CMMC, NIST SP 800-171/800-53, FedRAMP, GovRAMP, NIST RMF, or similar.
- Strong technical understanding of cybersecurity controls, risk-based assessment methodologies, and audit criteria.
- Excellent communication skills, with experience translating technical cyber and compliance issues into business-focused insights for senior leadership.
- Ability to travel (domestic and possibly international) to client sites for assessments or audits (travel % to be determined).
- Candidate will already have successfully undergone and completed the required DoD CMMC Tier 3 background investigation for immediate placement on assessments.
- Recognized CCA (verifiable on CyberAB marketplace) OR recognized CCP with strong understanding and experience in RMF for DoD IT or FedRAMP/DISA’s FedRAMP+.
Preferred Qualifications
- Experience with cloud environments (SaaS, IaaS, PaaS), DevSecOps, identity & access management, penetration testing or GRC toolsets.
- Previous experience in business development or growth of an assurance services practice.
Top Skills
What We Do
Aprio is a premier CPA and business advisory firm that advises clients and associates on how to achieve what’s next. Aprio’s associates work as integrated teams across advisory, assurance, tax, outsourcing, staffing and private client services, bringing the best thinking and personal commitment to each client. Across practices, Aprio brings together proven expertise, deep understanding and strategic foresight for industries including Manufacturing and Distribution; Non-Profit and Education; Professional Services; Real Estate and Construction; Retail, Franchise and Hospitality; and Technology and Blockchain.
Headquartered in Atlanta, Georgia, Aprio has grown to over 1,000+ team members. To serve clients wherever life or business may take them, Aprio’s teams speak more than 30 languages and work with clients in over 50 countries.








