{"schemaVersion":"jobsearcher.job.v1","id":"002a9719399df90f72a00a4e","url":"https://jobsearcher.com/jobs/002a9719399df90f72a00a4e","canonicalUrl":"https://jobsearcher.com/jobs/002a9719399df90f72a00a4e","title":"Cyber Security Controls Assessor","description":"Hi we are hiring a Cyber Security Controls Assessor III/ Remote (but need to be present in CA). Please view job description and reply with recent resume. Note: No visa sponsorship available. Candidates must have unrestricted U.S. work authorization and not require current or future employer sponsorshipCyber Security Controls Assessor IIILocation: California – RemoteExperience: 10+ years in Cybersecurity, Risk Management, Compliance, Audit, or Security Controls AssessmentRemote: candidate must be in the California regionDuration: Long TermTools: Cybersecurity Controls Assessment, Security Controls Validation, NIST CSF, NIST SP 800-53, CIS Controls, Risk Management, Security Risk Assessment, Regulatory Compliance, Cybersecurity Audit, Control Gap Analysis, Remediation Tracking, Security Documentation, Cloud Security, Azure, AWS, GRC, Critical Infrastructure SecurityJob DescriptionWe are seeking an experienced Cyber Security Controls Assessor III to support cybersecurity risk and compliance initiatives for critical energy infrastructure. The resource will conduct security control assessments across enterprise IT, cloud, and Operational Technology (OT) environments, evaluate control effectiveness, identify security risks and compliance gaps, and provide recommendations for remediation.The consultant will work closely with cybersecurity, engineering, IT, OT, compliance, and business stakeholders to assess and validate security controls and ensure alignment with organizational policies, regulatory requirements, and industry standards.Key ResponsibilitiesConduct cybersecurity control assessments across enterprise IT, cloud, and OT/industrial control system environments.Evaluate security controls against NIST CSF, NIST SP 800-53, NERC CIP, CIS Controls, and organizational security policies.Identify security risks, control deficiencies, compliance gaps, and areas requiring remediation.Develop detailed assessment reports documenting findings, risk ratings, control effectiveness, and remediation recommendations.Validate the implementation and effectiveness of security controls for new projects, system upgrades, applications, and technology deployments.Partner with cybersecurity, engineering, IT, OT, compliance, and business teams to identify and manage security risks.Support internal audits, regulatory reviews, and cybersecurity compliance initiatives.Track remediation activities and validate closure of cybersecurity findings.Review remediation evidence and determine whether identified control gaps have been adequately addressed.Maintain cybersecurity assessment methodologies, standards, procedures, and documentation.Support continuous improvement of cybersecurity risk and compliance processes.Mentor junior security assessors and provide guidance on assessment methodologies.Communicate cybersecurity risks and recommendations effectively to both technical and non-technical stakeholders.Required QualificationsBachelor's degree in Cybersecurity, Information Security, Computer Science, Engineering, Information Technology, or related field, or equivalent experience.5+ years of experience in cybersecurity, risk management, compliance, audit, or security controls assessment.Hands-on experience performing security assessments and evaluating cybersecurity controls.Strong understanding of NIST CSF, NIST SP 800-53, CIS Controls, and risk management methodologies.Experience supporting regulatory compliance programs and cybersecurity audits.Strong analytical, problem-solving, communication, and technical documentation skills.Ability to assess risks and clearly communicate findings and recommendations to technical and business stakeholders.Preferred QualificationsExperience in electric utilities, energy, critical infrastructure, or other regulated industries.Knowledge of NERC CIP standards and compliance requirements.Experience assessing OT, SCADA, ICS, Industrial Control Systems, or Energy Management Systems.Experience with Azure and AWS cloud security.Familiarity with GRC platforms.Experience with critical infrastructure, cybersecurity and regulatory compliance.Certifications such as CISSP, CISA, CRISC, GICSP, Security+, or equivalent.","company":"Kastech Software Solutions Group","rawCompany":"kastech software solutions group","city":"California","state":"MO","isRemote":false,"isActive":false,"createdAt":"2026-08-28T08:08:06.294Z","occupations":[{"code":"15-1212.00","title":"Information Security Analysts","slug":"information-security-analysts"},{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"},{"code":"13-1199.07","title":"Security Management Specialists","slug":"security-management-specialists"}],"industries":[{"code":"541690","title":"Other Scientific and Technical Consulting Services","slug":"other-scientific-and-technical-consulting-services"},{"code":"541618","title":"Other Management Consulting Services","slug":"other-management-consulting-services"},{"code":"541330","title":"Engineering Services","slug":"engineering-services"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Cyber Security Controls Assessor","description":"Hi we are hiring a Cyber Security Controls Assessor III/ Remote (but need to be present in CA). Please view job description and reply with recent resume. Note: No visa sponsorship available. Candidates must have unrestricted U.S. work authorization and not require current or future employer sponsorshipCyber Security Controls Assessor IIILocation: California – RemoteExperience: 10+ years in Cybersecurity, Risk Management, Compliance, Audit, or Security Controls AssessmentRemote: candidate must be in the California regionDuration: Long TermTools: Cybersecurity Controls Assessment, Security Controls Validation, NIST CSF, NIST SP 800-53, CIS Controls, Risk Management, Security Risk Assessment, Regulatory Compliance, Cybersecurity Audit, Control Gap Analysis, Remediation Tracking, Security Documentation, Cloud Security, Azure, AWS, GRC, Critical Infrastructure SecurityJob DescriptionWe are seeking an experienced Cyber Security Controls Assessor III to support cybersecurity risk and compliance initiatives for critical energy infrastructure. The resource will conduct security control assessments across enterprise IT, cloud, and Operational Technology (OT) environments, evaluate control effectiveness, identify security risks and compliance gaps, and provide recommendations for remediation.The consultant will work closely with cybersecurity, engineering, IT, OT, compliance, and business stakeholders to assess and validate security controls and ensure alignment with organizational policies, regulatory requirements, and industry standards.Key ResponsibilitiesConduct cybersecurity control assessments across enterprise IT, cloud, and OT/industrial control system environments.Evaluate security controls against NIST CSF, NIST SP 800-53, NERC CIP, CIS Controls, and organizational security policies.Identify security risks, control deficiencies, compliance gaps, and areas requiring remediation.Develop detailed assessment reports documenting findings, risk ratings, control effectiveness, and remediation recommendations.Validate the implementation and effectiveness of security controls for new projects, system upgrades, applications, and technology deployments.Partner with cybersecurity, engineering, IT, OT, compliance, and business teams to identify and manage security risks.Support internal audits, regulatory reviews, and cybersecurity compliance initiatives.Track remediation activities and validate closure of cybersecurity findings.Review remediation evidence and determine whether identified control gaps have been adequately addressed.Maintain cybersecurity assessment methodologies, standards, procedures, and documentation.Support continuous improvement of cybersecurity risk and compliance processes.Mentor junior security assessors and provide guidance on assessment methodologies.Communicate cybersecurity risks and recommendations effectively to both technical and non-technical stakeholders.Required QualificationsBachelor's degree in Cybersecurity, Information Security, Computer Science, Engineering, Information Technology, or related field, or equivalent experience.5+ years of experience in cybersecurity, risk management, compliance, audit, or security controls assessment.Hands-on experience performing security assessments and evaluating cybersecurity controls.Strong understanding of NIST CSF, NIST SP 800-53, CIS Controls, and risk management methodologies.Experience supporting regulatory compliance programs and cybersecurity audits.Strong analytical, problem-solving, communication, and technical documentation skills.Ability to assess risks and clearly communicate findings and recommendations to technical and business stakeholders.Preferred QualificationsExperience in electric utilities, energy, critical infrastructure, or other regulated industries.Knowledge of NERC CIP standards and compliance requirements.Experience assessing OT, SCADA, ICS, Industrial Control Systems, or Energy Management Systems.Experience with Azure and AWS cloud security.Familiarity with GRC platforms.Experience with critical infrastructure, cybersecurity and regulatory compliance.Certifications such as CISSP, CISA, CRISC, GICSP, Security+, or equivalent.","datePosted":"2026-08-28T08:08:06.294Z","dateModified":"2026-08-28T08:08:06.294Z","hiringOrganization":{"@type":"Organization","name":"Kastech Software Solutions Group","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"California","addressRegion":"MO","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"002a9719399df90f72a00a4e"},"url":"https://jobsearcher.com/jobs/002a9719399df90f72a00a4e"}}