CompQsoft

Cybersecurity Assessor

CompQsoft  •  $120k - $135k/yr  •  Brooklyn, NY (Onsite)  •  2 days ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

Job Type

Full-time

Description

Position: Cybersecurity Assessor

Location: Brooklyn, NY

Duration: Fulltime

Certification: CISA, CRISC, CGEIT, CISSP, CompTIA Security+, CCSK, CAP/ISC2 CGRC

The Cybersecurity Assessor evaluates enterprise systems, networks, and applications to identify vulnerabilities, assess risks, and

ensure compliance with security policies and regulatory standards. They provide actionable recommendations and collaborate with

technical and business teams to strengthen security controls and reduce organizational risk.

Requirements

Key Requirements

  • Expertise in GRC methodologies, security control auditing, and third-party risk assessments. Proven ability to interpret federal

compliance mandates (NIST SP 800-53, 800-37) and evaluate technical and administrative controls. Strong competency in

conducting "Security Impact Analyses" and managing Plan of Action and Milestones (POA&M) documentation. Compliance &

Assessment Support: Conduct security and compliance assessments across internal systems and third-party vendors,

supporting adherence to organizational and regulatory requirements.

  • Third-Party Risk Assessments: Evaluate the security practices of external service providers and assist with managing vendor[1]related risks throughout the assessment of lifecycle.
  • Findings & Remediation Tracking: Analyze assessment results, document findings, and support remediation efforts by tracking

issues and helping teams prioritize corrective actions.

  • Cross-Functional Coordination: Work with business and technical stakeholders to clarify compliance requirements and support

the resolution of identified risks within accepted thresholds.

  • Risk Documentation & Reporting: Use risk management tools and reporting dashboards to maintain assessment

documentation, track risk metrics, and contribute to security posture reporting.

  • Cross-Functional Synergy: Serve as a bridge between Business Analysts and Cybersecurity Engineers, translating compliance

requirements into actionable remediation tasks while maintaining organizational risk thresholds.

  • GRC Tool Proficiency: Use industry-standard GRC platforms (e.g., Archer, ServiceNow) and Third-Party Risk tools (e.g.,

OneTrust, Prevalent) to centralize documentation and streamline assessment workflows.

  • Data-Driven Risk Reporting: Convert complex assessment findings into actionable insights with Power BI and Excel, maintaining

dashboards that communicate enterprise security posture to stakeholders.

  • Security Control Execution & Validation: Perform daily RMF lifecycle control assessments, including evidence collection,

walkthroughs, testing of technical/administrative controls, and POA&M tracking to ensure risk remains within tolerance.

Experience: 5+ years

Certifications: CISA, CRISC, CGEIT, CISSP, CompTIA Security+, CCSK, CAP/ISC2 CGRC

Technologies: GRC Platforms (Archer/ServiceNow), Third-Party Risk Tools (OneTrust/Prevalent), MS Excel (Advanced), MS Power BI,

MS Visio, JIRA, and Microsoft Office Suite.

CompQsoft provides equal opportunity in all aspects of employment and in the working environment to all employees and applicants. CompQsoft does not take any non-merit factors like race, color, religion, sex (gender), mental/physical disability, and age into account for purposes of recruitment, hiring and development.

Salary Description

$120000 - $135000

CompQsoft

About CompQsoft

CompQsoft is a customer-centric digital platform and IT services company. We empower organizations across industries and technology verticals to leverage Software Development & Engineering, Unified Communication, Cloud, Data & Analytics, Application Modernization, Cybersecurity, Network Management, RPA and Automation, and next-gen technologies like generative AI to drive innovation and transform their businesses.

For 25 years, we have been dedicated to helping clients maximize their technology investments and achieve superior business outcomes.

Our expertise spans:

• Public Sector (Government) - Federal agencies, including the Department of Defense and state and local governments.

• Private (Commercial IT) - Startups, Small & Medium (SMBs) and Enterprises.

We help businesses integrate design, software engineering, and agile delivery capabilities to produce business outcomes and drive innovation.

Headquartered in Houston, Texas, CompQsoft operates engineering centers worldwide, extending the benefits of our true global presence to customers across industries.

We are ISO 9001:2008, 27001:2005, 20000:2005 & CMMI Level 3 certified company.

For more details, please visit: https://compqsoft.com/

Industry
IT & Software
Company Size
201-500 employees
Headquarters
Leesburg, Virginia
Year Founded
1997
Social Media