CSSP Auditor
$120,000–$170,000 year
On-siteFort Belvoir, Virginia, United States
Job Summary
Establish and audit the CSSP Data Quality Scoring framework to validate telemetry trustworthiness, track remediation for low-scoring sources, and ensure accurate security event representation. Manage Evidence Objects to verify absolute traceability from ingested telemetry through risk-reduction decisions and conduct routine audits of evidence packages. Lead the full lifecycle of Standard Operating Procedures, maintain the SharePoint Master SOP Library with version control, and map operational controls to NIST SP-800-53 Rev. 5 requirements. Support CSSP Evaluator Scoring Metrics assessments and government-directed inspections by coordinating evidence collection, validation, and corrective action tracking. Conduct recurring independent quality assurance across Protect, Detect, Respond, and Sustain teams to assess procedural compliance and operational consistency. Identify recurring deficiencies and develop lessons learned reports to facilitate continuous process improvement initiatives.
Required Qualifications
- Active Top-Secret Clearance with SCI eligibility
- DoD 8140/8570 CSSP Auditor or equivalent certifications
- Certified Information Systems Auditor (CISA)
- Minimum of 7+ years of progressive experience in cybersecurity auditing, continuous monitoring, or compliance assessment (or 5+ years with a Master's degree)
- Minimum of three (3) years supporting DoD or Federal cybersecurity programs
- Experience supporting audit, inspection, or accreditation activities within a Security Operations Center (SOC), Cybersecurity Service Provider (CSSP), Cyber Defense Program, or related environment
- BA/BS College degree
- Proven experience auditing database/SIEM logs, data ingestion schemas, and validating compliance data flows
- Familiarity with data dictionaries, data validation rules, and automated log analysis
- U.S. Citizenship
- Consent to receive text messages regarding interview and employment status
- Agreement that TekSynap Corporation may retain and use name, e-mail, and contact information for purposes related to employment consideration
- Compliance with any vaccination requirements mandated by contract, applicable law or regulation
- Schedule is Monday – Friday (0800 - 1600)
- May be requested to work evenings and weekends to meet program and contract needs
- Less than 10% travel
- Regularly required to use hands to handle, feel, touch; reach with hands and arms; talk and hear
- Regularly required to stand; walk; sit; climb or balance; and stoop, kneel, crouch, or crawl
- Regularly required to lift up to 10 pounds
- Frequently required to lift up to 25 pounds; and up to 50 pounds
- Close vision, distance vision, peripheral vision, depth perception, and ability to adjust focus
Desired Qualifications
- Familiarity with NIST SP 800-53 Rev. 5 control families, focusing heavily on Audit and Accountability, System and Information Integrity, and Incident Response
- Familiarity with NIST SP 800-53A assessment methods (Examine, Interview, and Test)
- Familiarity with OMB M-26-14
- Familiarity with DTM 26-003
- Familiarity with CSSP Evaluator Scoring Metrics (ESM)
- Familiarity with Cyber Operational Readiness Assessments (CORA)
- Familiarity with JFHQ-DODIN evaluations
- Familiarity with internal policies and external assessment requirements
- Familiarity with DED requirements
- Familiarity with operational capabilities
- Familiarity with approved processes, operational standards, and organizational objectives
- Familiarity with service delivery requirements
- Familiarity with analyst performance evidence
- Familiarity with cybersecurity effectiveness
- Familiarity with audit readiness
- Familiarity with mission performance
- Familiarity with recurring compliance deficiencies
- Familiarity with operational trends
- Familiarity with systemic weaknesses
- Familiarity with process inefficiencies
- Familiarity with lessons learned reports
- Familiarity with corrective action recommendations
- Familiarity with continuous process improvement initiatives
- Familiarity with DoD Cybersecurity Service Provider (CSSP) operations
- Familiarity with Risk Management Framework (RMF)
- Familiarity with DoDI 8530.01 and applicable CSSP guidance
- Familiarity with CNSSI 1253
- Familiarity with Security Technical Implementation Guides (STIGs)
- Familiarity with Continuous Monitoring programs
- Familiarity with Incident Response processes
- Familiarity with Vulnerability Management programs
- Familiarity with Audit, compliance, and inspection readiness activities
- Familiarity with MITRE ATT&CK Framework
- Familiarity with Parsing Success Rate (PSR)
- Familiarity with Field Completeness Score (FCS)
- Familiarity with Schema Adherence Score (SAS)
- Familiarity with Timeliness Score (TS)
- Familiarity with data collection, normalization, enrichment, and correlation processes
- Familiarity with detection lifecycle
- Familiarity with defensive cyber actions
- Familiarity with package-proven
- Familiarity with source telemetry
- Familiarity with analyst actions
- Familiarity with incident response activities
- Familiarity with cybersecurity risk-reduction decisions
- Familiarity with evidence packages
- Familiarity with internal policies
- Familiarity with external assessment requirements
- Familiarity with evidence collection
- Familiarity with validation scoring reviews
- Familiarity with corrective action tracking
- Familiarity with organizational dependence on pre-audit preparation cycles
- Familiarity with internal performance metrics
- Familiarity with procedural compliance
- Familiarity with documentation quality
- Familiarity with operational consistency
- Familiarity with adherence to service delivery requirements
- Familiarity with validation execution against approved processes
- Familiarity with operational standards
- Familiarity with organizational objectives
- Familiarity with recurring compliance deficiencies
- Familiarity with operational trends
- Familiarity with systemic weaknesses
- Familiarity with process inefficiencies
- Familiarity with lessons learned reports
- Familiarity with corrective action recommendations
- Familiarity with continuous process improvement initiatives
- Familiarity with cybersecurity effectiveness
- Familiarity with audit readiness
- Familiarity with mission performance
- Familiarity with Protect, Detect, Respond, and Sustain functions
- Familiarity with DoD requirements
- Familiarity with NIST guidance
- Familiarity with CSSP Evaluator Scoring Metrics (ESM)
- Familiarity with organizational quality standards
- Familiarity with independent oversight
- Familiarity with compliance validation
- Familiarity with operational quality assurance
- Familiarity with establishing a continuous audit and inspection-ready posture
- Familiarity with validating cybersecurity operations
- Familiarity with telemetry quality
- Familiarity with evidence traceability
- Familiarity with regulatory compliance
- Familiarity with operational performance metrics
- Familiarity with establishing, governing, and auditing the CSSP Data Quality Scoring (DQS) framework
- Familiarity with evaluating the trustworthiness of ingested security telemetry
- Familiarity with performing continuous audits of telemetry sources against mandatory DQS metrics
- Familiarity with tracking, analyzing, and managing the remediation of low-DQS sources
- Familiarity with managing data-loss visibility gaps
- Familiarity with validating data collection, normalization, enrichment, and correlation processes
- Familiarity with ensuring critical security events are accurately represented throughout the detection lifecycle
- Familiarity with managing and validating CSSP Evidence Objects
- Familiarity with ensuring all defensive cyber actions are fully documented and package-proven
- Familiarity with ensuring absolute traceability from ingested telemetry up to cybersecurity risk-reduction decisions
- Familiarity with verifying complete traceability from source telemetry through analyst actions, incident response activities, and cybersecurity risk-reduction decisions
- Familiarity with conducting routine audits of evidence packages
- Familiarity with ensuring compliance with internal policies and external assessment requirements
- Familiarity with leading the full lifecycle of Standard Operating Procedures (SOPs), playbooks, and internal operational workflows
- Familiarity with developing, implementing, and tracking an annual review plan for all CSSP documentation
- Familiarity with managing the SharePoint Master SOP Library
- Familiarity with maintaining version control, access permissions, and formal archival processes
- Familiarity with verifying that all published SOPs are synchronized with current DED requirements and operational capabilities
- Familiarity with mapping CSSP operational controls and evidence logs directly to NIST SP-800-53 Rev. 5 control families
- Familiarity with focusing heavily on Audit and Accountability, System and Information Integrity, and Incident Response
- Familiarity with embedding NIST SP-800-53A assessment methods (Examine, Interview, and Test) into internal audit procedures
- Familiarity with supporting continuous authorization and federal compliance mandates
- Familiarity with including OMB M-26-14
- Familiarity with focusing heavily on Audit and Accountability (AU), System and Information Integrity (SI), Incident Response (IR), Configuration Management (CM), and Risk Assessment (RA) controls
- Familiarity with leading activities supporting CSSP Evaluator Scoring Metrics (ESM) assessments
- Familiarity with coordinating Cyber Operational Readiness Assessments (CORA)
- Familiarity with coordinating JFHQ-DODIN evaluations
- Familiarity with other government-directed inspections
- Familiarity with coordinating evidence collection, validation scoring reviews, and corrective action tracking
- Familiarity with maintaining a continuous inspection-ready posture
- Familiarity with reducing organizational dependence on pre-audit preparation cycles
- Familiarity with defining, monitoring, and reporting on internal performance metrics
- Familiarity with enforcing strict alignment with DTM 26-003
- Familiarity with conducting recurring audits across Protect, Detect, Respond, and Sustain teams
- Familiarity with assessing procedural compliance, documentation quality, operational consistency, analyst performance evidence, and adherence to service delivery requirements
- Familiarity with validating execution against approved processes, operational standards, and organizational objectives
- Familiarity with identifying recurring compliance deficiencies, operational trends, systemic weaknesses, and process inefficiencies
- Familiarity with developing lessons learned reports and corrective action recommendations
- Familiarity with facilitating continuous process improvement initiatives that strengthen cybersecurity effectiveness, audit readiness, and mission performance
- Familiarity with high-tech company
- Familiarity with comprehensive well planned information management environment
- Familiarity with Technology moving at the speed of thought
- Familiarity with nimbly utilize the best that information technology offers to meet the business needs of our Federal Government customers
- Familiarity with competitive benefits package
- Familiarity with health, dental, vision, 401K, life insurance, short-term and long-term disability plans, vacation time and holidays
- Familiarity with TekSynap.com
- Familiarity with full-time employees
- Familiarity with the safety and health of our employees
- Familiarity with being of the utmost importance
- Familiarity with complying with any vaccination requirements mandated by contract, applicable law or regulation
- Familiarity with providing consent to receive text messages regarding your interview and employment status
- Familiarity with opting out of text messaging
- Familiarity with responding STOP
- Familiarity with TekSynap Corporation retaining and using your name, e-mail, and contact information for purposes related to employment consideration
- Familiarity with TekSynap is a fast growing high-tech company
- Familiarity with understanding both the pace of technology today and the need to have a comprehensive well planned information management environment
- Familiarity with the need to nimbly utilize the best that information technology offers to meet the business needs of our Federal Government customers
- Familiarity with offering our full-time employees a competitive benefits package
- Familiarity with including health, dental, vision, 401K, life insurance, short-term and long-term disability plans, vacation time and holidays
- Familiarity with Visit us at www.TekSynap.com
- Familiarity with Apply now to explore jobs with us
- Familiarity with The safety and health of our employees is of the utmost importance
- Familiarity with Employees are required to comply with any vaccination requirements mandated by contract, applicable law or regulation
- Familiarity with By applying to a role at TekSynap you are providing consent to receive text messages regarding your interview and employment status
- Familiarity with If at any time you would like to opt out of text messaging, respond STOP
- Familiarity with As part of the application process, you agree that TekSynap Corporation may retain and use your name, e-mail, and contact information for purposes related to employment consideration
- Familiarity with The CSSP Auditor provides independent oversight, compliance validation, and operational quality assurance across the Cybersecurity Service Provider (CSSP) environment
- Familiarity with The position is responsible for establishing a continuous audit and inspection-ready posture by validating cybersecurity operations, telemetry quality, evidence traceability, regulatory compliance, and operational performance metrics
- Familiarity with The CSSP Auditor works across the Protect, Detect, Respond, and Sustain functions to ensure cybersecurity operations align with DoD requirements, NIST guidance, CSSP Evaluator Scoring Metrics (ESM), and organizational quality standards
- Familiarity with Data Quality Scoring (DQS) & Telemetry Auditing
- Familiarity with Establish, govern, and audit the CSSP Data Quality Scoring (DQS) framework to evaluate the trustworthiness of ingested security telemetry
- Familiarity with Perform continuous audits of telemetry sources against mandatory DQS metrics, including Parsing Success Rate (PSR), Field Completeness Score (FCS), Schema Adherence Score (SAS), and Timeliness Score (TS)
- Familiarity with Track, analyze, and manage the remediation of low-DQS sources and data-loss visibility gaps
- Familiarity with Validate data collection, normalization, enrichment, and correlation processes to ensure critical security events are accurately represented throughout the detection lifecycle
- Familiarity with Evidence Object & Traceability Verification
- Familiarity with Manage and validate CSSP Evidence Objects to ensure all defensive cyber actions are fully documented and package-proven
- Familiarity with Ensure absolute traceability from ingested telemetry up to cybersecurity risk-reduction decisions
- Familiarity with Verify complete traceability from source telemetry through analyst actions, incident response activities, and cybersecurity risk-reduction decisions
- Familiarity with Conduct routine audits of evidence packages to ensure compliance with internal policies and external assessment requirements
- Familiarity with SOP Lifecycle Management & SharePoint Governance
- Familiarity with Lead the full lifecycle of Standard Operating Procedures (SOPs), playbooks, and internal operational workflows
- Familiarity with Develop, implement, and track an annual review plan for all CSSP documentation
- Familiarity with Manage the SharePoint Master SOP Library, maintaining version control, access permissions, and formal archival processes
- Familiarity with Verify that all published SOPs are synchronized with current DED requirements and operational capabilities
- Familiarity with NIST SP-800-53 Rev. 5 & 800-53A Compliance
- Familiarity with Map CSSP operational controls and evidence logs directly to NIST SP-800-53 Rev. 5 control families, focusing heavily on Audit and Accountability, System and Information Integrity, and Incident Response
- Familiarity with Embed NIST SP-800-53A assessment methods (Examine, Interview, and Test) into internal audit procedures to support continuous authorization and federal compliance mandates, including OMB M-26-14
- Familiarity with Focus heavily on Audit and Accountability (AU), System and Information Integrity (SI), Incident Response (IR), Configuration Management (CM), and Risk Assessment (RA) controls
- Familiarity with Audit Readiness
- Familiarity with Lead activities supporting CSSP Evaluator Scoring Metrics (ESM) assessments, Cyber Operational Readiness Assessments (CORA), JFHQ-DODIN evaluations, and other government-directed inspections
- Familiarity with Coordinate evidence collection, validation scoring reviews, and corrective action tracking
- Familiarity with Maintain a continuous inspection-ready posture and reduce organizational dependence on pre-audit preparation cycles
- Familiarity with Define, monitor, and report on internal performance metrics, enforcing strict alignment with DTM 26-003
- Familiarity with Independent Quality Assurance
- Familiarity with Conduct recurring audits across Protect, Detect, Respond, and Sustain teams
- Familiarity with Assess procedural compliance, documentation quality, operational consistency, analyst performance evidence, and adherence to service delivery requirements
- Familiarity with Validate execution against approved processes, operational standards, and organizational objectives
- Familiarity with Continuous Improvement and Lessons Learned
- Familiarity with Identify recurring compliance deficiencies, operational trends, systemic weaknesses, and process inefficiencies
- Familiarity with Develop lessons learned reports and corrective action recommendations
- Familiarity with Facilitate continuous process improvement initiatives that strengthen cybersecurity effectiveness, audit readiness, and mission performance
- Familiarity with WORK ENVIRONMENT AND PHYSICAL DEMANDS
- Familiarity with The work environment characteristics described here are representative of those an employee encounters while performing the essential functions of the job
- Familiarity with Reasonable accommodation may be made to enable individuals with disabilities to perform the essential functions
- Familiarity with Location: Fort Belvoir, VA
- Familiarity with Type of environment: Office
- Familiarity with Noise level: Low
- Familiarity with Work schedule: Schedule is Monday – Friday (0800 - 1600)
- Familiarity with May be requested to work evenings and weekends to meet program and contract needs
- Familiarity with Amount of Travel: Less than 10%
- Familiarity with PHYSICAL DEMANDS
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.