TestPros, Inc.

Security Controls Assessor / OSCAL (Remote)

TestPros, Inc.  •  United States (Remote)  •  2 months ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

TestPros is a successful and growing business, established in 1988 to provide Information Technology (IT) technical support services to a wide range of Commercial and U.S. Federal, State, and Local Government customers. Our capabilities include Program Management, Program Oversight, Process Audit, Intelligence Analysis, Cyber Security, NIST 800-53, NIST SP 800-171 / CMMC Consulting/Assessment/Compliance, PCI Compliance, HIPAA, SOC 2, GLBA, Zero Trust, Resiliency, Computer Forensics, Software Supply Chain Assurance, Software Testing, Test Automation, Section 508 and WCAG Accessibility Assessment and Remediation, Localization Testing, Independent Verification and Validation (IV&V), Quality Assurance (QA), Compliance, and Research and Development (R&D) services. TestPros is an Equal Opportunity Employer.

Position: Part time (as needed, 1099 or Corp. to Corp)

The ideal candidate will have strong hands-on experience conducting independent security control compliance assessments using guidelines from NIST (800-53, 800-171) and assessment automation via OSCAL (Open Security Controls Assessment Language). You must have security controls and OSCAL experience in both U.S. Government and Commercial environments. FedRAMP experience is a plus...

Required Qualifications

  • Proven OSCAL experience (at least two years)
  • 5+ years of hands-on security controls assessment and development of Security Assessment Plan (SAP), Security Assessment Report (SAR) and Plan of Actions and Milestones (POA&M).
  • Experience with RegScale, Paramify, or similar tools.
  • Experience with government, public sector, or municipal IT environments is highly preferred.
  • Ability to write clear, professional, and actionable technical reports.
  • Full U.S. Citizenship, and ability to pass an extensive background check.

Preferred Skills

  • Experience with NIST 800-53 based ATO assessment, NIST 800-171/CMMC assessment, and/or HIPAA assessment.
  • Ability to produce a set of interoperable, extensible, machine-readable formats that supports a broad range of control-based risk management processes (XML-, JSON-, and YAML-based formats that allow for lossless translations between XML, JSON, and YAML representations).
  • Familiarity with U.S. Government security policy requirements.
  • Experience coordinating with multi-agency or cross-organizational IT teams.
  • Expertise with common tools such as Kali Linux, Burp Suite, Nmap, Metasploit, Nessus/Tenable, and Wireshark.

Engagement Details

  • Estimated Start: April 2026

  • Estimated Duration: TBD

  • Work Location: Fully Remote

  • Clearances: Not required, but government experience is a plus

Benefits

TestPros offers a competitive salary, medical/dental/vision insurance, life insurance, paid time off, paid holidays, 401(k) retirement plan with company match, opportunities for professional growth, cell phone discounts, and much more! All benefits are per TestPros current policies and are subject to change without notice. Benefits are available to full-time employees.​

TestPros, Inc. is an Equal Opportunity Employer.

EEO Statement

All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, sexual orientation, gender identity, marital status, age, national origin, or protected veteran status.

TestPros, Inc.

About TestPros, Inc.

TestPros brings the latest relevant software life-cycle process methodologies, process improvement methods, test/QA methodologies, tools and industry best-practice knowledge to our customers. We continue to push the boundaries of technology by developing exciting and innovative IT services for the global market.

We have a culture of innovation where our employees can make a difference, and are always looking for the best and brightest talent to join our team and further their career. Like-minded, dynamic individuals are encouraged to apply.

Established in 1988, TestPros provides Independent Assessment and Security Services. Our range of services includes Cybersecurity, Testing, Independent Verification and Validation (IV&V), Quality Assurance, Software/Systems Testing, Automated Testing, Test Range/Test Lab operations, Section 508/WCAG Accessibility, Program Management, Oversight, Cyber Security, FedRAMP Cloud Security, 800-171, Information Assurance, Software Assurance, Configuration Management, Continuous Integration, Help Desk, and software lifecycle services.

TestPros supports both government and commercial clients. On the government side, we are a prime contractor on the DHS EAGLE II vehicle in Functional Category 3. We have many other contract vehicles, including a GSA MAS and GSA VETS2, which make us easy to engage. On the commercial side, we work with companies ranging from small start-ups looking to validate the functionality of their products under development, to Fortune 50 corporations augmenting their test operations or independently verifying the security (RMF, ISO/IEC 27000 series) and accessibility (WCAG / Section 508) compliance of their products.

Industry
IT & Software
Company Size
11-50 employees
Headquarters
Sterling, VA
Year Founded
1988
Social Media