JOB TITLE: Principal Cybersecurity Assessment Methodologist
LOCATION: Florida (remote/hybrid acceptable) — limited travel for QA reviews and client briefings as needed
TRAVEL: Minimal; primary function is methodology oversight and quality review rather than field assessment
JOB TYPE: Contract / Engagement-Based (Government Consulting Services)
CONTRACT RATE BASIS: Principal Consultant tier
JOB SUMMARY
Judit Inc. is seeking a Principal Cybersecurity Assessment Methodologist to serve as the technical quality authority for a large-scale, multi-site government IT security risk assessment. This role owns the consistency, rigor, and defensibility of every assessment finding across more than 30 independent entities. This is a senior individual-contributor role for a late-career cybersecurity professional who prioritizes technical integrity over field management responsibilities.
KEY RESPONSIBILITIES
- Own and enforce a single, consistent set of risk-scoring criteria applied uniformly across all assessed entities, in conformance with NIST SP 800-30 risk assessment methodology
- Serve as quality assurance gate owner: review and approve every entity-level assessment package before it is included in the aggregate client-facing report
- Provide methodology authority on NIST alignment, cross-entity consistency, and overall defensibility of findings
- Own resolution protocols for any written client deficiency notices, including defined internal correction timelines and escalation procedures
- Define assessment approach for entities with limited or incomplete documentation, ensuring no risk category is left unscored
REQUIRED QUALIFICATIONS
- 20+ years in cybersecurity and IT security auditing across federal/DoD and enterprise environments
- Demonstrated end-to-end NIST Risk Management Framework (RMF) experience, including system categorization through Authorization to Operate (ATO), NIST SP 800-53/800-53A control assessment, POA&M management, and continuous monitoring
- Active professional certifications required (minimum of three): CISSP, CISA, CISM, ISSEP, CGEIT, CGRC, CDPSE
- FedRAMP and/or CMMC assessment experience
- Demonstrated prior experience owning assessment methodology (not solely executing it) on at least one multi-entity or multi-site engagement
- Willingness and ability to pass Level 2 background screening (Livescan/FBI) prior to accessing confidential information
- Enrollment in / compliance with E-Verify requirements
PREFERRED QUALIFICATIONS
- M.S. in Information Systems, Cybersecurity, or related field
- C|CISO or equivalent executive-level security credential
- Prior experience serving as an independent quality reviewer or methodology arbiter, distinct from field assessment execution