Apply Description Contingent Contract Award National Capital Region(Hybrid/Onsite/Telework if approval) Connected Logistics is seeking highly skilled and versatile Assessment Lead, to assist in providing the Department of State Directorate of Technology (DT), Enterprise Architecture (EA), Cyber Security Team (CST) comprehensive cybersecurity support services to protect critical consular systems and data. The CST Cyber portfolio ensures compliance with federal mandates including the Federal Information Security Modernization Act (FISMA) and the Risk Management Framework (RMF), encompassing security monitoring, incident response, threat detection, vulnerability management, and continuous authorization activities. The Assessment Lead (AL) shall serve as Key Personnel responsible for the overall planning, coordination, execution, quality, and delivery of Security Control Assessment activities performed under this PWS. The AL shall provide technical leadership and oversight of assessment activities in accordance with applicable cybersecurity requirements, Department policies and procedures, and government-approved assessment methodologies. The Assessment Lead (AL) shall lead and oversee Security Control Assessments in support of the Risk Management Framework (RMF), including RMF Step 4 – Assess, and shall ensure assessments provide the Government with an independent, objective, repeatable, and evidence-based determination of the effectiveness of implemented security and privacy controls. Key Responsibilities Serve as the primary contractor lead and subject matter expert for Security Control Assessment activities performed under this PWS. Plan, coordinate, and oversee the execution of Security Control Assessments across assigned information systems and environments. Develop and maintain assessment schedules, milestones, resource assignments, and assessment priorities in coordination with the Government. Lead the development, review, and execution of Security Assessment Plans (SAPs), including assessment scope, control selection, assessment procedures, evidence requirements, testing methodology, and Rules of Engagement (ROE), as applicable. Ensure assessment activities are performed in accordance with applicable versions of NIST Special Publication (SP) 800-37, NIST SP 800-53, NIST SP 800-53A, FISMA requirements, Department policies, and Government-established cybersecurity assessment procedures. Provide technical direction and oversight to Security Control Assessors and other contractor personnel supporting assessment activities. Review system security documentation, policies, procedures, technical configurations, architecture documentation, vulnerability scan results, penetration testing results, prior assessment findings, Plans of Action and Milestones (POA&Ms), and other supporting evidence necessary to determine control effectiveness. Ensure assessors appropriately apply examination, interview, and testing procedures and that assessment conclusions are supported by sufficient and appropriate objective evidence. Evaluate the implementation and effectiveness of security and privacy controls and identify control deficiencies, vulnerabilities, weaknesses, and associated cybersecurity risks. Ensure assessment findings clearly document the condition identified, supporting evidence, applicable control or requirement, risk, and assessment determination. Lead assessment entrance meetings, status meetings, technical discussions, findings reviews, and assessment exit briefings with Government and system stakeholders. Coordinate assessment activities with System Owners, Information System Security Officers (ISSOs), Information System Security Managers (ISSMs), system administrators, security engineers, technical teams, and other Government-designated stakeholders. Monitor assessment progress and proactively identify schedule risks, evidence deficiencies, technical issues, or other conditions that may affect successful completion of an assessment. Maintain assessment independence and ensure assessment personnel do not assess controls for which they were directly responsible for implementing, except where specifically authorized by the Government. Perform quality assurance reviews of assessment work products to ensure findings are technically accurate, consistent, adequately supported, and compliant with Government assessment standards. Review and approve contractor-developed assessment documentation prior to submission to the Government. Lead the preparation and delivery of Security Assessment Reports (SARs), assessment findings, risk summaries, executive-level briefings, and other required assessment deliverables. Support validation and retesting activities to determine whether identified deficiencies have been successfully remediated. Support the Government in evaluating residual risk and provide technical assessment information necessary to support authorization and risk-based decisions by the Authorizing Official (AO) and other designated Government officials. Track assessment findings and deliverables through closure and ensure assessment records and supporting evidence are maintained in Government-designated repositories and cybersecurity tools. Identify recurring control deficiencies, systemic weaknesses, and assessment trends and provide recommendations to the Government for improving security posture, assessment consistency, and RMF execution. Ensure assessment activities and sensitive security information are handled in accordance with applicable Federal and Department security, privacy, records management, and information-handling requirements. Provide assessment status, metrics, risks, accomplishments, and issues to the COR and other Government-designated personnel as required. Requirements Requirements Bachelor’s in computer science, IT, cybersecurity or related field +8 years’ conducting security control assessments. Demonstrated experience with NIST SP 800-53A assessment procedures. Additional demonstrated experience with NIST Special Publication (SP) 800-37, NIST SP 800-53, and FISMA requirements. Must have active CISSP, CISA or equivalent, and CEH or equivalent penetration testing certification. Current Secret clearance. Experience working with the DoS preferred. Total Rewards Statement We believe in fairness and clarity throughout our hiring process. The anticipated salary range for this position is $155,000.00-$165,000.00 USD . This is a good-faith range based on factors such as your experience, geographic location, and any applicable contractual requirements, and may vary slightly. Beyond salary, we provide a robust benefits package and encourage ongoing professional development, because your growth and well-being matter to us. We’re excited to support you in building a rewarding career with us! Connected Logistics respects the need for confidentiality for all applicants. Connected Logistics has been named a 2026 WTOP Top Workplace in the medium sized business category. Our mission is clear: we deliver mission-focused IT, cybersecurity, logistics, and enterprise modernization support to federal agencies. When we invest in our people and create an environment where they feel valued and empowered, we deliver stronger outcomes for our clients and the missions we support. Connected Logistics offers an excellent benefits package that includes health, dental, vision, life, and disability insurance, a great 401(k) package, and generous Paid Time Off. EOE/Disability/Veterans
K-12 Assessment Lead - Texas & Oklahoma
OpenEd
K-12 Assessment Lead - Indiana
OpenEd
Lead Security Risk Assessment Analyst
Lincolnfinancial
Vulnerability Assessment (VA) Team Lead (CBP)
Agile Defense
Assessment Design Lead
Speak
Needs Assessment Team Lead
Pyramid Healthcare