Assessment Lead
Paragon Technology Group, Inc. | |
United States, D.C., Washington | |
Aug 28, 2026 | |
|
Assessment Lead Paragon Technology Group is seeking an experienced Assessment Lead to support the Department of State Bureau of Diplomatic Technology, Enterprise Applications cybersecurity program under the Independent Security Control Assessment (ISCA) effort. The Assessment Lead is a Key Personnel position responsible for the overall planning, coordination, execution, quality, and delivery of Security Control Assessment activities. The position provides technical leadership and oversight of independent assessments supporting the Risk Management Framework (RMF), including RMF Step 4 - Assess, and ensures assessments provide objective, repeatable, evidence-based determinations of the effectiveness of implemented security and privacy controls. The ISCA effort supports ongoing security control assessments, risk determination and acceptance, continuous monitoring, remediation verification, and RMF documentation for information systems under Enterprise Applications authority. Monitor security controls, conduct ongoing assessments, support risk determination and acceptance, assist with issue resolution and remediation verification, maintain documentation and evidence, and support development of SAPs, SARs, and POA&Ms. Essential Duties and Responsibilities * Serve as the primary contractor lead and subject matter expert for Security Control Assessment activities. * Plan, coordinate, and oversee Security Control Assessments across assigned systems and environments. * Develop and manage assessment schedules, milestones, resource assignments, priorities, and stakeholder coordination. * Lead development, review, and execution of Security Assessment Plans (SAPs) and Rules of Engagement (ROEs), including assessment scope, control selection, assessment procedures, evidence requirements, testing methodologies, boundaries, timelines, and escalation procedures. * Ensure assessments comply with applicable Federal and Department cybersecurity requirements, including NIST SP 800-37, NIST SP 800-53, NIST SP 800-53A, FISMA requirements, and Government-approved assessment procedures. * Provide technical direction and oversight to Security Control Assessors and other personnel supporting assessment activities. * Review SSPs, policies, procedures, system configurations, architecture documentation, vulnerability scans, penetration-test results, prior findings, POA&Ms, and other assessment evidence. * Ensure assessors appropriately apply examination, interview, and testing methods and that assessment conclusions are supported by sufficient objective evidence. * Evaluate security and privacy control implementation and effectiveness and identify control deficiencies, vulnerabilities, weaknesses, and associated cybersecurity risks. * Conduct and lead assessment entrance meetings, status meetings, technical discussions, findings reviews, and exit briefings with Government and system stakeholders. * Coordinate activities with System Owners, ISSOs, ISSMs, system administrators, security engineers, technical teams, the Authorizing Official, and other Government-designated stakeholders. * Monitor assessment progress and proactively identify schedule risks, evidence deficiencies, technical issues, and other impediments to assessment completion. * Maintain assessment independence and ensure personnel do not assess controls they were directly responsible for implementing unless specifically authorized by the Government. * Perform quality assurance reviews to ensure assessment findings and deliverables are technically accurate, consistent, adequately supported, and compliant with Government standards. * Lead preparation and delivery of Security Assessment Reports (SARs), assessment findings, risk summaries, executive briefings, vulnerability matrices, and related assessment deliverables. * Support remediation and retesting activities to validate corrective actions and determine whether identified deficiencies have been successfully resolved. * Coordinate with System Owners and ISSOs to validate mitigation strategies, update POA&Ms, and support closure of findings. * Support evaluation of residual risk and provide technical assessment information needed for authorization and risk-based decisions by the Authorizing Official and other Government officials. * Track assessment findings, supporting evidence, and deliverables through closure and maintain records in Government-designated repositories and cybersecurity tools. * Identify recurring control deficiencies, systemic weaknesses, and assessment trends and recommend improvements to security posture, assessment consistency, and RMF execution. * Provide assessment status, performance metrics, risks, accomplishments, and issues to the COR and other Government-designated personnel. Required Qualifications * Bachelor's degree in Cybersecurity, Information Technology, Information Systems, Computer Science, Engineering, or a related technical discipline. * Minimum of eight (8) years of relevant professional experience in cybersecurity, information assurance, security assessment, RMF, or related disciplines. * CISSP, CISA, or equivalent certification. * CEH or equivalent penetration-testing certification. * Demonstrated experience leading or performing Security Control Assessments in Federal information-system environments. * Demonstrated experience with the Risk Management Framework, particularly RMF Step 4 - Assess. * Working knowledge and practical application of NIST SP 800-37, NIST SP 800-53, NIST SP 800-53A, and security testing methodologies. * Experience developing or reviewing SAPs, SARs, POA&Ms, Rules of Engagement, control test cases, assessment evidence, residual-risk documentation, and security authorization packages. * Experience assessing technical, management, and operational security controls using examination, interview, and testing techniques. * Experience interpreting vulnerability scanning and penetration-testing results and translating technical findings into documented cybersecurity risk. * Ability to lead multidisciplinary assessment teams and communicate effectively with technical personnel, system owners, ISSOs/ISSMs, senior Government stakeholders, and Authorizing Officials. * Strong technical writing, analytical, organizational, and quality-assurance skills. Security Requirements * Must be able to obtain and maintain the security clearance and/or Department of State personnel security eligibility required for the position. Work Location and Schedule The position is primarily contractor-site based; however, because the Assessment Lead is designated Key Personnel, the individual must reside within a reasonable commuting distance of State Annex 17, 600 19th Street NW, Washington, D.C., and must be available for onsite meetings, mission-critical activities, and other Government-directed support as required. | |
Aug 28, 2026