Level

NCC Group

Managing Security Consultant - Assessor

AI in this role

Location - New York, Chicago, Atlanta or Alpharetta 
 
NCC Group (US) is seeking an experienced and highly respected Managing Security Consultant / Senior Assessor to support and help lead the delivery of Federal cybersecurity assessment and advisory services within its accredited FedRAMP Third Party Assessment Organization (3PAO) practice. 

This position represents a senior technical and consulting role within the Government Services organization. The successful candidate will be recognized as a trusted subject matter expert in Federal cybersecurity compliance, cloud security assessments, and risk management. The individual will lead complex assessment engagements, provide strategic advisory services, mentor assessment teams, contribute to business development efforts, and support the continued growth and maturity of NCC Group's government security offerings. 

The role requires a deep understanding of FedRAMP assessment methodologies, Federal cybersecurity frameworks, cloud technologies, and independent auditing principles. The ideal candidate combines technical expertise with strong leadership, communication, and client relationship management capabilities. 

Key Responsibilities

Assessment Leadership 
  • Serve as a Lead Assessor for FedRAMP authorisation and continuous monitoring assessments  
  • Lead assessment teams responsible for evaluating cloud service providers against FedRAMP and NIST requirements  
  • Conduct independent evaluation of security controls, cloud architectures, operational processes and risk management programmes  
  • Review testing methodologies, assessment evidence and assessment reports for accuracy and quality 
  • Ensure assessment activities comply with FedRAMP, 3PAO and organisational quality requirements  
  • Identify deficiencies, risks and opportunities for improvements and communicate findings clearly to clients and stakeholders 
  • Support quality assurance activities and peer reviews across Government Services engagements  

Advisory Services
 
  • Provide advisory and readiness services related to:  
FedRAMP- Rev5 and FedRAMP20x CMMC / DFARS 7012 cybersecurity requirements  Secure cloud adoption and governance  NIST Risk Management Framework (RMF 
  • Assist organisations in developing compliance roadmaps and remediation strategies  
  • Advise clients on cybersecurity governance, risk management and control implementation  

Business Development and Client Engagement
 
  • Support pre-sales activities, including opportunities qualification, customer briefings, project scoping and proposal development  
  • Develop Statements of Work (SOWs), project plans, assumptions and costs. 
  • Participate in client workshops and executive-level discussions 
  • Act as a trust advisor to customers throughout engagement lifecycles  
  • Contribute thought leadership to support the growth of NCC Group’s Government Services practice 

Team Leadership:
 
  • Support the mentorship and coaching of Junior assessors and consultants  
  • Support workforce development and assessment methodology improvements  
  • Assist practice leadership with service delivery planning and operational initiatives  
  • Promote assessment consistency, quality and professional excellence across engagement teams  

Skills, Knowledge and Expertise

Professional Experience 
  • Demonstrated expertise in information security, cybersecurity consulting, auditing, compliance, risk management, or related disciplines including management of IT organizations.  
  • Experience with FedRAMP Assessments and or Advisory Services.  
  • Must have extensive experience of auditing and/or assessment experience, 
  • Experience leading multi-disciplinary security assessment teams 
  • Experience delivering both assurance (assessment) and advisory consulting engagements 
  • Experience operating in highly regulated environments requiring exceptional attention to detail and documentation quality 
Government & Industry Experience 
  • U.S. Citizen authorized to work in the United States. 
  • Ability to successfully complete required background investigations. 
  • Strong understanding of U.S. Government cybersecurity programs and compliance requirements. 
  • Experience supporting Federal agencies, defense contractors, cloud service providers, or other government-regulated organizations. 
  • Familiarity with government acquisition and cybersecurity compliance environments. 
  • Understanding of software supply chain and cloud ecosystem security considerations. 
Cloud & Technical Experience 
  • Demonstrated experience assessing and securing cloud computing environments across SaaS, PaaS, IaaS, cloud-native, and hybrid architectures 
  • Strong understanding of security controls, risk assessment, and remediation within enterprise environments. 
Functional Expertise 

Candidates must demonstrate significant expertise in: 
  • FedRAMP authorization processes and assessment methodologies. 
  • NIST SP 800-53 security controls and control assessment practices. 
  • NIST 800-171 and NIST 800-171A 
  • Federal cybersecurity compliance programs. 
  • Security risk management and risk-based decision making. 
  • Security assessment report development and quality review. 
  • Executive briefing and stakeholder communications. 
Desirable: 
  • Experience advising on CMMC requirements and implementation. 
  • Experience working with DFARS cybersecurity requirements. 
  • Understanding of Federal Executive Orders impacting cybersecurity and software supply chain security. 
  • Experience supporting GovRAMP assessments. 
  • Familiarity with ISO/IEC 17020 requirements and accreditation standards. 
  • Experience supporting accredited conformity assessment organizations or testing laboratories. 
Required Certifications 
  • Certified Information Systems Security Professional (CISSP) 
  • Baltimore Cyber Range Technical Proficiency Certification 

How we rate this

Managing Security Consultant - Assessor at NCC Group rates 39 out of 100 for how much of the daily work is AI. That makes it Little AI (AI Level 1 of 4). The level is about AI in the job, not seniority.

Classification

Little AI. AI is not part of the work.

  1. ●●●● Builds AI80 to 100
  2. ●●●○ Works on AI60 to 79
  3. ●●○○ Uses AI40 to 59
  4. ●○○○ Little AI0 to 39

Levels come from how often the tools, models and workflows of the role are named in the posting itself. Open the description and count.

Get new AI jobs by email

One email a week with the new AI jobs, each rated for how much AI is in the work. No recruiter spam, unsubscribe in one click.

Free. One email a week. Unsubscribe in one click.

Similar roles

Security roles that involve little AI, at other companies.

What kind of AI work fits you?

Answer 12 practical questions in about three minutes. Get a simple profile, the work it points to, and live roles to explore next.

Find my next step

More jobs at NCC Group

Related searches

Same AI level