Security Assessor at Spry Methods

Washington, District of Columbia, United States

Spry Methods Logo
Not SpecifiedCompensation
Senior (5 to 8 years)Experience Level
Full TimeJob Type
UnknownVisa
Cybersecurity, GovernmentIndustries

Requirements

  • At least 5 years experience
  • Bachelor's Degree or 4 years of specialized experience
  • Strong security assessor background
  • Must understand the Risk Management Framework (RMF) process

Responsibilities

  • Apply strong working knowledge of IT Security requirements, technical security countermeasures, risk management processes, contingency planning, and secure data communications
  • Conduct full cycle Security Assessments & Authorizations (SA&A), including network, system, application, and NIST control testing from administrative and technical perspectives
  • Analyze vulnerability scans, interpret risks, and employ manual checks to validate vulnerability data
  • Assist the customer with understanding risk and providing risk mitigation
  • Create Security Assessment Plans, Reports, and POA&Ms
  • Conduct documentation reviews, inspections, and interviews with key personnel knowledgeable/responsible for various controls
  • Evaluate compliance based on responses to questions, analysis of supporting evidence, demonstrations of security features, configuration files, system logs, and tests

Skills

Key technologies and capabilities for this role

RMFNISTSA&AVulnerability ScanningRisk ManagementSecurity AssessmentsPOA&MCSAMContingency Planning

Questions & Answers

Common questions about this position

What experience level is required for the Security Assessor position?

At least 5 years of experience is required, along with a Bachelor's Degree or 4 years of specialized experience.

What are the key responsibilities of a Security Assessor at Spry Methods?

Responsibilities include conducting full cycle Security Assessments & Authorizations (SA&A), testing networks, systems, applications, and NIST controls, analyzing vulnerability scans, creating Security Assessment Plans, Reports, and POA&Ms, and assisting customers with risk understanding and mitigation.

Is this a remote position or does it require working in DC?

The position is to join the team in DC, suggesting an on-site requirement in the DC area.

What specific knowledge and skills are essential for this role?

Candidates need strong working knowledge of IT Security requirements, technical security countermeasures, risk management processes, contingency planning, secure data communications, and a strong understanding of the Risk Management Framework (RMF) process.

What makes a strong candidate for the Security Assessor role?

A strong candidate will have a strong security assessor background, experience with full cycle SA&A, vulnerability analysis, NIST control testing, and familiarity with RMF; knowledge of CSAM is a plus.

Spry Methods

Provides IT and cybersecurity solutions

About Spry Methods

Spry Methods delivers IT and cybersecurity solutions primarily to enterprise and government sectors. Their services include cybersecurity management, intelligence operations, data assurance, IT infrastructure support, software development, and program management. These services work by implementing streamlined security processes and integrated IT operations to protect clients' assets and improve efficiency. Unlike many competitors, Spry Methods emphasizes high-quality service delivery, certified by ISO 9001:2015 and CMMI Level 3, which enhances their reliability. The company's goal is to transform clients' operations in the digital world, making them more secure and efficient while maintaining a strong focus on recruiting top talent to ensure effective solutions.

McLean, VirginiaHeadquarters
2001Year Founded
VENTURE_UNKNOWNCompany Stage
Government & Public Sector, Enterprise Software, CybersecurityIndustries
51-200Employees

Risks

Emerging cybersecurity firms offer innovative solutions at lower costs, threatening Spry's market share.
Rapid AI-driven cyber threat evolution requires Spry to continuously invest in new technologies.
Potential changes in government contracting policies could impact Spry's future revenue streams.

Differentiation

Spry Methods holds ISO 9001:2015 and CMMI Level 3 certifications, ensuring quality service.
The company offers comprehensive IT and cybersecurity solutions for enterprise and government sectors.
Spry Methods secured the CIO SP3 Small Business Contract, highlighting its government service capability.

Upsides

Increased federal budget for cybersecurity offers more government contract opportunities for Spry.
Growing demand for AI-driven cybersecurity tools aligns with Spry's service offerings.
Hybrid work models require enhanced IT support, matching Spry's expertise.

Land your dream remote job 3x faster with AI