Remote job
Cyber Lead Auditor / Test Lead
Job details
About this role
Role overview A remote Cyber Lead Auditor and Test Lead role providing independent technical and assurance leadership for a state-level cybersecurity assurance program, including periodic travel to Tallahassee, Florida. The position translates oversight objectives into audit-defensible testing strategies, supervises evidence collection, and verifies that factual findings are traceable to applicable criteria across a multi-agency environment.
Responsibilities - Ingest and analyze agency documentation including risk assessments, remediation plans, prior findings, corrective actions, inventories, and strategic plans. - Direct development of the Agency Risk Understanding Memorandum, capturing environment summaries, agency-specific risks, assumptions, and documentation gaps. - Design ground-truth and ad hoc testing strategies, then approve detailed procedures covering objectives, systems, controls, access points, tools, sampling, evidence, thresholds, and escalation paths. - Map procedures and results to frameworks such as NIST CSF DE.AE, DE.DP, and PR.AC, along with applicable state rules and approved criteria. - Review evidence for relevance, reliability, sufficiency, attribution, timestamps, chain of custody, and reproducibility, and validate that reports distinguish factual results from advisory recommendations. - Lead technical briefings, workshops, job aids, and knowledge transfer sessions for oversight staff, and support urgent analysis of logs, timelines, after-action reports, and incident-specific control issues.
Requirements - Bachelor's degree in cybersecurity, information assurance, audit, information systems, or a closely related discipline. - Active CISSP certification. - Ten years of progressive cybersecurity experience spanning security operations, incident response, vulnerability management, intrusion analysis, adversary simulation, technical assessment, or audit support. - Five years supporting or conducting audits, compliance reviews, independent assessments, or assurance work in government or similarly regulated environments. - Demonstrated ability to design defensible test procedures, evaluate control performance, separate fact from opinion, and brief senior stakeholders. - Working knowledge of professional auditing or assurance standards and evidence requirements. - Willingness to undergo a government-issued background investigation.
Nice to have - Purple team or adversary-emulation leadership using MITRE ATT&CK and threat-informed kill chains. - Government incident-command experience. - Additional credentials such as CISA or CIA. - Hands-on experience with Active Directory, cloud platforms, APIs, web applications, databases, endpoints, SIEM and EDR tooling, vulnerability scanners, and evidence repositories.