Summary
Senior Security Assessor
For over two decades, our expert team has successfully assisted organizations with the implementation and oversight of their information security, privacy, and regulatory compliance programs. Our reputation is our own, built upon our steadfast commitment over the years to do the right thing and go above and beyond for our clients. We pride ourselves on our ability to think outside-the-box, stay nimble and succeed as a team.
About the Senior Assessor Role
The Senior Security Assessor supports PCI Compliance, SOC 1, SOC 2, ISO, NIST, CMMC, Risk Assessment, HIPAA, CCPA, GDPR project initiatives by undertaking risk assessments, advising on implementation of security measures, recommending appropriate risk mitigations, interpreting security policy and standards in the context of projects and business scenarios to help the business operate securely. This role has a significant client consulting and management component in advising, defining client security requirements to industry best practice standards, and ensuring that all projects meet these requirements, or that exceptions and issues are noted and remediated as appropriate.
The ideal candidate combines the technical expertise commonly associated with PCI DSS and cybersecurity assessments with the audit, attestation, and internal control experience often found in SOC and assurance engagements. CPA and/or QSA credentials are highly valued.
As a Senior Assessor, You Will:
- Assess existing controls to determine level of compliance to the PCI DSS standard, SOC 2, ISO, HIPAA, GDPR, NIST, CMMC, etc. inclusive of: their maturity, state of compliance, and the risk associated with any findings.
- Support PCI-DSS, Risk, SOC 2, NIST, ISO, CMMC, FedRAMP, Cyber Security Compliance gap analyses and assessments.
- Conduct SOC 2 Type I and Type II readiness assessments and examinations, including control design review, testing of controls, evidence evaluation, gap analysis, and reporting.
- Support compliance privacy client engagements and familiarity with GDPR, CCPA, PIPEDA or similar privacy frameworks.
- Support sites in testing, documentation and issue resolution associated with cyber security programs.
- Perform comprehensive threat/risk assessments and business impact analysis of current system, data, application and technology environments to determine possible internal and external threats to information assets, and identify security measures required to counter such threats.
- Participate in the development and implementation of the enterprise security architecture and supporting security standards to ensure compliance with corporate policies, and relevant legislative and regulatory requirements.
- Perform technical security reviews or assessments to ensure targeted systems, networks, applications and/or data are in compliance with corporate policies and standards.
- Understand that, due to the rapidly evolving cybersecurity landscape, maintaining this role will require obtaining additional certifications to keep up with the cybersecurity threat landscape and industry acceptable certifications.
Required Education and Experience:
- A university degree in Computer Science, Engineering, or a field which relates to the role.
- Minimum of at least two security certifications from the following (ISC)2 CISSP, ISACA CISM, ISACA CISA, SANS GIAC/GSNA, ISO27001 Certified Lead Implementer/Lead Auditor/Internal Auditor
- Possession of a PCI QSA certification or the ability to obtain and maintain QSA status is strongly preferred.
- Five (5) + years of Information Security experience in Security Governance, Risk and Compliance practices and methodologies.
Preferred Experience That Drives Success In This Role:
- Additional certifications such as PCI QSA, CMMC CP, CMMC CCA, IRCA ISMS Auditor (or higher), IIA Certified Internal Auditor (CIA), HITRUST, or similar industry-recognized credentials.
- Certified Public Accountant (CPA) credential preferred.
- Demonstrated knowledge of the principles, best practices, architectures, and control frameworks applicable to PCI DSS, NIST, SOC 1, SOC 2, CMMC, and ISO standards.
- Experience conducting cybersecurity assessments and audits, including the use of industry-standard security and compliance tools.
- Experience with security hardening, policy development, and secure software development practices.
- Previous experience performing PCI DSS, NIST, CMMC, and ISO assessments, including readiness assessments, gap analyses, remediation validation, and formal audits.
- Experience leading or supporting SOC 1 and SOC 2 examinations, including scoping, control testing, evidence review, and report development.
- Experience evaluating internal controls, business processes, governance frameworks, and risk management practices in support of attestation and assurance engagements.
Job Description
Senior Security Assessor
For over two decades, our expert team has successfully assisted organizations with the implementation and oversight of their information security, privacy, and regulatory compliance programs. Our reputation is our own, built upon our steadfast commitment over the years to do the right thing and go above and beyond for our clients. We pride ourselves on our ability to think outside-the-box, stay nimble and succeed as a team.
About the Senior Assessor Role
The Senior Security Assessor supports PCI Compliance, SOC 1, SOC 2, ISO, NIST, CMMC, Risk Assessment, HIPAA, CCPA, GDPR project initiatives by undertaking risk assessments, advising on implementation of security measures, recommending appropriate risk mitigations, interpreting security policy and standards in the context of projects and business scenarios to help the business operate securely. This role has a significant client consulting and management component in advising, defining client security requirements to industry best practice standards, and ensuring that all projects meet these requirements, or that exceptions and issues are noted and remediated as appropriate.
The ideal candidate combines the technical expertise commonly associated with PCI DSS and cybersecurity assessments with the audit, attestation, and internal control experience often found in SOC and assurance engagements. CPA and/or QSA credentials are highly valued.
As a Senior Assessor, You Will:
- Assess existing controls to determine level of compliance to the PCI DSS standard, SOC 2, ISO, HIPAA, GDPR, NIST, CMMC, etc. inclusive of: their maturity, state of compliance, and the risk associated with any findings.
- Support PCI-DSS, Risk, SOC 2, NIST, ISO, CMMC, FedRAMP, Cyber Security Compliance gap analyses and assessments.
- Conduct SOC 2 Type I and Type II readiness assessments and examinations, including control design review, testing of controls, evidence evaluation, gap analysis, and reporting.
- Support compliance privacy client engagements and familiarity with GDPR, CCPA, PIPEDA or similar privacy frameworks.
- Support sites in testing, documentation and issue resolution associated with cyber security programs.
- Perform comprehensive threat/risk assessments and business impact analysis of current system, data, application and technology environments to determine possible internal and external threats to information assets, and identify security measures required to counter such threats.
- Participate in the development and implementation of the enterprise security architecture and supporting security standards to ensure compliance with corporate policies, and relevant legislative and regulatory requirements.
- Perform technical security reviews or assessments to ensure targeted systems, networks, applications and/or data are in compliance with corporate policies and standards.
- Understand that, due to the rapidly evolving cybersecurity landscape, maintaining this role will require obtaining additional certifications to keep up with the cybersecurity threat landscape and industry acceptable certifications.
Required Education and Experience:
- A university degree in Computer Science, Engineering, or a field which relates to the role.
- Minimum of at least two security certifications from the following (ISC)2 CISSP, ISACA CISM, ISACA CISA, SANS GIAC/GSNA, ISO27001 Certified Lead Implementer/Lead Auditor/Internal Auditor
- Possession of a PCI QSA certification or the ability to obtain and maintain QSA status is strongly preferred.
- Five (5) + years of Information Security experience in Security Governance, Risk and Compliance practices and methodologies.
Preferred Experience That Drives Success In This Role:
- Additional certifications such as PCI QSA, CMMC CP, CMMC CCA, IRCA ISMS Auditor (or higher), IIA Certified Internal Auditor (CIA), HITRUST, or similar industry-recognized credentials.
- Certified Public Accountant (CPA) credential preferred.
- Demonstrated knowledge of the principles, best practices, architectures, and control frameworks applicable to PCI DSS, NIST, SOC 1, SOC 2, CMMC, and ISO standards.
- Experience conducting cybersecurity assessments and audits, including the use of industry-standard security and compliance tools.
- Experience with security hardening, policy development, and secure software development practices.
- Previous experience performing PCI DSS, NIST, CMMC, and ISO assessments, including readiness assessments, gap analyses, remediation validation, and formal audits.
- Experience leading or supporting SOC 1 and SOC 2 examinations, including scoping, control testing, evidence review, and report development.
- Experience evaluating internal controls, business processes, governance frameworks, and risk management practices in support of attestation and assurance engagements.
Government Careers
Government jobs offer stability, competitive benefits, and the chance to make a meaningful impact on your community and country.
Whether you’re starting your career or seeking new opportunities, these roles provide pathways for growth, security, and service.
Explore positions across a wide range of fields and take the first step toward a rewarding future in public service.
MORE JOBS
-
Dispatcher
- Lancaster, California
- Transdev
- Aug 21, 2026
-
All-Source Intelligence Analyst Multi-Focus Missions
- Mc Lean, Virginia
- MissionOne
- Aug 21, 2026
-
Deputy Sheriff
- Brookings, South Dakota
- Minnehaha County
- Aug 21, 2026
-
Traffic Control Flagger II 2k Sign-On Bonus (17856)
- New Columbia, Pennsylvania
- RoadSafe Traffic Systems, Inc.
- Aug 21, 2026
-
Rentals Program Assistant- City of Raleigh Museum
- Fayetteville, North Carolina
- City of Raleigh NC
- Aug 21, 2026
-
Air Defense Artillery Recruit (97113)
- Cornelius, Oregon
- U.S. Army
- Aug 21, 2026