FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in cybersecurity assurance, including the ability to design and implement audit-defensible testing strategies, validate findings, and lead technical briefings. Proficient in compliance with NIST CSF criteria and government regulations while managing multi-agency documentation and evidence analysis.
Highest-signal resume keywords
Certified Information Systems Security Professional (CISSP)Cybersecurity ExperienceAudit SupportDefensible Test Procedures DesignGovernment Compliance Experience
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
CybersecurityIncident ResponseVulnerability ManagementTechnical AssessmentAudit SupportEvidence CollectionRisk AssessmentControl EvaluationTesting Strategy DesignCompliance Review
Soft Skills
LeadershipCommunicationAnalytical ThinkingAttention to DetailProblem Solving
Tools & Technologies
Active DirectoryCloud PlatformsAPIsWeb ApplicationsDatabasesSIEM/EDRVulnerability ScannersEvidence Repositories
Certifications & Qualifications
CISSPGIAC GMONGCIHGCIAGSECCEHSSCPCompTIA Security+CISACIA
Industry Keywords
NIST CSFGovernment ComplianceAudit StandardsIncident CommandAdversary EmulationMITRE ATT&CKThreat-Informed Kill Chains
Tech Stack
Tools & technologiesCloudCyber Security
About the role
Key responsibilities & impact- Provide independent technical and assurance leadership for a cybersecurity assurance program for the state of Florida
- Convert OCIG objectives into audit-defensible testing strategies and step-by-step procedures
- Supervise evidence collection and analysis
- Verify factual findings are supported and traceable to applicable criteria across a multi-agency environment
- Lead ingestion and analysis of agency documentation, including risk assessments, remediation plans, prior findings, corrective actions, inventories, and strategic plans
- Direct development of the Agency Risk Understanding Memorandum
- Design Ground-Truth and Ad Hoc Testing Strategies and approve detailed testing procedures
- Map procedures and results to NIST CSF criteria, Rule 60GG-2, F.A.C., and applicable approved criteria
- Ensure testing remains within OCIG authorization, avoids duplication of operational testing, and complies with agency-specific Rules of Engagement
- Review evidence for relevance, reliability, sufficiency, attribution, timestamps, chain of custody, and reproducibility
- Validate reports and ensure advisory recommendations are distinctly labeled
- Conduct independent QA reviews of technical deliverables and document sign-off
- Lead technical briefings, workshops, job aids, and knowledge transfer
- Support urgent analysis of logs, timelines, after-action reports, remediation evidence, and incident-specific control issues
Requirements
What you’ll need- Bachelor’s degree in cybersecurity, information assurance, audit, information systems, or related discipline
- Active Certified Information Systems Security Professional (CISSP)
- At least two additional active certifications from: GIAC GMON, GCIH, GCIA, GSEC, CEH, SSCP, or CompTIA Security+
- At least 10 years of progressive cybersecurity experience, including security operations, incident response, vulnerability management, intrusion analysis, adversary simulation, technical assessment, or audit support
- At least 5 years supporting or conducting audits, compliance reviews, independent assessments, or assurance work in government or similarly regulated environments
- Ability to design defensible test procedures, evaluate control performance, distinguish fact from opinion, and communicate technical results to senior stakeholders
- Working knowledge of professional auditing or assurance standards and evidence requirements
- Willingness to undergo the government-issued background investigation process
- Preferred: CISSP plus one monitoring/intrusion credential (GMON or GCIA) and one incident-handling credential (GCIH)
- Preferred: Purple-team or adversary-emulation leadership using MITRE ATT&CK and threat-informed kill chains
- Preferred: Government incident-command experience
- Preferred: CISA, CIA, or other audit credential
- Preferred: Experience with Active Directory, cloud platforms, APIs, web applications, databases, endpoints, SIEM/EDR, vulnerability scanners, and evidence repositories
Benefits
Comp & perks- Equal opportunity employer and nondiscrimination protections
- Opportunity to work on a cybersecurity assurance program for the state of Florida
- Technical briefings, workshops, job aids, and knowledge transfer opportunities
