Principal Cybersecurity Assessment Methodologist

Judit Inc

Principal Cybersecurity Assessment Methodologist

Tallahassee, FL
Full Time
Paid
  • Responsibilities

    JOB TITLE: Principal Cybersecurity Assessment Methodologist

    LOCATION: Florida (remote/hybrid acceptable) — limited travel for QA reviews and client briefings as needed

    TRAVEL: Minimal; primary function is methodology oversight and quality review rather than field assessment

    JOB TYPE: Contract / Engagement-Based (Government Consulting Services)

    CONTRACT RATE BASIS: Principal Consultant tier

    JOB SUMMARY

    Judit Inc. is seeking a Principal Cybersecurity Assessment Methodologist to serve as the technical quality authority for a large-scale, multi-site government IT security risk assessment. This role owns the consistency, rigor, and defensibility of every assessment finding across more than 30 independent entities. This is a senior individual-contributor role for a late-career cybersecurity professional who prioritizes technical integrity over field management responsibilities.

    KEY RESPONSIBILITIES

    • Own and enforce a single, consistent set of risk-scoring criteria applied uniformly across all assessed entities, in conformance with NIST SP 800-30 risk assessment methodology
    • Serve as quality assurance gate owner: review and approve every entity-level assessment package before it is included in the aggregate client-facing report
    • Provide methodology authority on NIST alignment, cross-entity consistency, and overall defensibility of findings
    • Own resolution protocols for any written client deficiency notices, including defined internal correction timelines and escalation procedures
    • Define assessment approach for entities with limited or incomplete documentation, ensuring no risk category is left unscored

    REQUIRED QUALIFICATIONS

    • 20+ years in cybersecurity and IT security auditing across federal/DoD and enterprise environments
    • Demonstrated end-to-end NIST Risk Management Framework (RMF) experience, including system categorization through Authorization to Operate (ATO), NIST SP 800-53/800-53A control assessment, POA&M management, and continuous monitoring
    • Active professional certifications required (minimum of three): CISSP, CISA, CISM, ISSEP, CGEIT, CGRC, CDPSE
    • FedRAMP and/or CMMC assessment experience
    • Demonstrated prior experience owning assessment methodology (not solely executing it) on at least one multi-entity or multi-site engagement
    • Willingness and ability to pass Level 2 background screening (Livescan/FBI) prior to accessing confidential information
    • Enrollment in / compliance with E-Verify requirements

    PREFERRED QUALIFICATIONS

    • M.S. in Information Systems, Cybersecurity, or related field
    • C|CISO or equivalent executive-level security credential
    • Prior experience serving as an independent quality reviewer or methodology arbiter, distinct from field assessment execution