Jobs · Accounting · Virginia

CSSP Auditor

CareersElite.com · Fort Belvoir, VA · 2 wk ago
Accounting$120k–$170k/yrFull-time

Provides independent oversight, compliance validation, and operational quality assurance across the Cybersecurity Service Provider (CSSP) environment. Establishes a continuous audit and inspection-ready posture by validating cybersecurity operations, telemetry quality, evidence traceability, regulatory compliance, and operational performance metrics. Works across the Protect, Detect, Respond, and Sustain functions to ensure cybersecurity operations align with DoD requirements, NIST guidance, CSSP Evaluator Scoring Metrics (ESM), and organizational quality standards.

Responsibilities

  • Data Quality Scoring (DQS) & Telemetry Auditing: Establish, govern, and audit the CSSP Data Quality Scoring (DQS) framework to evaluate the trustworthiness of ingested security telemetry. Perform continuous audits of telemetry sources against mandatory DQS metrics, including Parsing Success Rate (PSR), Field Completeness Score (FCS), Schema Adherence Score (SAS), and Timeliness Score (TS). Track, analyze, and manage the remediation of low-DQS sources and data-loss visibility gaps. Validate data collection, normalization, enrichment, and correlation processes to ensure critical security events are accurately represented throughout the detection lifecycle.
  • Evidence Object & Traceability Verification: Manage and validate CSSP Evidence Objects to ensure all defensive cyber actions are fully documented and package-proven. Ensure absolute traceability from ingested telemetry up to cybersecurity risk-reduction decisions. Verify complete traceability from source telemetry through analyst actions, incident response activities, and cybersecurity risk-reduction decisions. Conduct routine audits of evidence packages to ensure compliance with internal policies and external assessment requirements.
  • SOP Lifecycle Management & SharePoint Governance: Lead the full lifecycle of Standard Operating Procedures (SOPs), playbooks, and internal operational workflows. Develop, implement, and track an annual review plan for all CSSP documentation. Manage the SharePoint Master SOP Library, maintaining version control, access permissions, and formal archival processes. Verify that all published SOPs are synchronized with current DED requirements and operational capabilities.
  • NIST SP-800-53 Rev. 5 & 800-53A Compliance: Map CSSP operational controls and evidence logs directly to NIST SP-800-53 Rev. 5 control families, focusing heavily on Audit and Accountability, System and Information Integrity, and Incident Response. Embed NIST SP-800-53A assessment methods (Examine, Interview, and Test) into internal audit procedures to support continuous authorization and federal compliance mandates, including OMB M-26-14. Focus on Audit and Accountability (AU), System and Information Integrity (SI), Incident Response (IR), Configuration Management (CM), and Risk Assessment (RA) controls.
  • Audit Readiness: Lead activities supporting CSSP Evaluator Scoring Metrics (ESM) assessments, Cyber Operational Readiness Assessments (CORA), JFHQ-DODIN evaluations, and other government-directed inspections. Coordinate evidence collection, validation, scoring reviews, and corrective action tracking. Maintain a continuous inspection-ready posture and reduce organizational dependence on pre-audit preparation cycles. Define, monitor, and report on internal performance metrics, enforcing strict alignment with DTM 26-003.
  • Independent Quality Assurance: Conduct recurring audits across Protect, Detect, Respond, and Sustain teams. Assess procedural compliance, documentation quality, operational consistency, analyst performance evidence, and adherence to service delivery requirements. Validate execution against approved processes, operational standards, and organizational objectives.
  • Continuous Improvement and Lessons Learned: Identify recurring compliance deficiencies, operational trends, systemic weaknesses, and process inefficiencies. Develop lessons learned reports and corrective action recommendations. Facilitate continuous process improvement initiatives that strengthen cybersecurity effectiveness, audit readiness, and mission performance.

Requirements

  • Clearance: Active Top-Secret Clearance with SCI eligibility required.
  • Compliance & Certifications:
    • DoD 8140/8570 CSSP Auditor or equivalent certifications is required
    • Certified Information Systems Auditor (CISA) is required
  • Experience: Minimum of 7+ years of progressive experience in cybersecurity auditing, continuous monitoring, or compliance assessment (or 5+ years with a Master's degree), with a minimum of three (3) years supporting DoD or Federal cybersecurity programs. Experience supporting audit, inspection, or accreditation activities within a Security Operations Center (SOC), Cybersecurity Service Provider (CSSP), Cyber Defense Program, or related environment.
  • Education: BA/BS College degree required.
  • Technical Auditing Capabilities: Proven experience auditing database/SIEM logs, data ingestion schemas, and validating compliance data flows. Familiarity with data dictionaries, data validation rules, and automated log analysis is highly preferred.

Preferred Technical Experience/Knowledge

Three or more of the following areas desired:

  • DoD Cybersecurity Service Provider (CSSP) operations
  • Risk Management Framework (RMF)
  • NIST SP 800-53 Rev. 5 and NIST SP 800-53A
  • DoDI 8530.01 and applicable CSSP guidance
  • CNSSI 1253
  • Security Technical Implementation Guides (STIGs)
  • Continuous Monitoring programs
  • Incident Response processes
  • Vulnerability Management programs
  • Audit, compliance, and inspection readiness activities
  • MITRE ATT&CK Framework

Work Environment and Physical Demands

  • Location: Fort Belvoir, VA
  • Type of environment: Office
  • Noise level: Low
  • Work schedule: Schedule is Monday – Friday (0800 - 1600). May be requested to work evenings and weekends to meet program and contract needs.
  • Amount of Travel: Less than 10%

The physical demands include regular use of hands, reaching with hands and arms, talking, and hearing. The employee is regularly required to stand, walk, sit, climb or balance, and stoop, kneel, crouch, or crawl. The employee must regularly lift up to 10 pounds, frequently lift up to 25 pounds, and occasionally lift up to 50 pounds. Vision requirements include close vision, distance vision, peripheral vision, depth perception, and the ability to adjust focus.

Work Authorization/Security Clearance

  • U.S Citizenship Required
  • Top Secret Clearance with SCI Eligibility

Pay

Target salary range: $120,000.00 - $170,000.00. The salary range displayed is an estimate only and is not a guarantee of compensation or salary. It will be determined based on several factors including the individual’s education, knowledge, skills, competencies, experience, contract parameters, and organizational requirements.

Similar jobs

CSSP Auditor

TekSynapFort Belvoir, VA· 3 wk ago
Accounting$120k–$170k/yrapply on careers-teksynap.icims.com

Auditor (CSCA)

QIMANew York, NY· 1 mo ago
Accountingapply on jobs.smartrecruiters.com

Sr Corporate Auditor

Daikin Applied AmericasPlymouth, MN· 1 mo ago
$80k–$137k/yrapply on daikinapplied.wd1.myworkdayjobs.com

Corporate Auditor

Blue Cross Blue Shield of MichiganDetroit, MI· 1 mo ago
Financeapply on ejko.fa.us2.oraclecloud.com

RSPO SCC Auditor

QIMACharlotte, NC· 1 mo ago
RemoteConsultingapply on jobs.smartrecruiters.com