Security Compliance & Assessment Advisor at Abdul Farook | CazVid
Apply for this position
Review the job details below and click Apply Now to get started.
Security Compliance & Assessment Advisor
Abdul Farook
Remote in United States
$60 / hr
Position OverviewWe are seeking an experienced Security Compliance & Assessment Advisor to evaluate enterprise information systems for security risks, vulnerabilities, and compliance requirements.The ideal candidate will have strong hands-on experience conducting security control assessments across IT, Cloud, and AI environments, with particular expertise in NIST SP 800-37 and NIST SP 800-53/53A.This position will be responsible for security evidence review, control scoring, continuous monitoring, assessment automation, data-driven risk analysis, and communicating enterprise-level security findings to technical teams and leadership.Candidates with strong DevSecOps automation and/or AI security assessment experience are highly encouraged to apply. Additional rate flexibility may be available for candidates with this experience.Required Qualifications3–5+ years of relevant security assessment, security compliance, GRC, or information security experience.Proven experience conducting security control assessments within IT, Cloud, and/or AI environments.Strong working knowledge of NIST SP 800-37.Strong working knowledge of NIST SP 800-53 / 800-53A.Experience reviewing security control evidence, policies, standards, and procedures.Experience evaluating and maintaining consistency in security control scoring.Understanding of compliance, assurance, and continuous authorization processes.Experience with automated evidence pipelines.Experience with continuous monitoring tools.Knowledge of security assessment automation techniques.Strong data-analysis capabilities with the ability to analyze large and complex datasets.Ability to identify systemic security issues and enterprise-level risk patterns.Experience performing root-cause analysis.Experience developing security risk insights, executive summaries, and recommendations.Ability to translate complex technical security findings into concise information for leadership.Key ResponsibilitiesSecurity Control AssessmentsEvaluate information systems for security risks, vulnerabilities, and compliance with applicable SAFR and NIST requirements.Conduct and document detailed security control assessments.Review technical evidence and determine whether security controls are operating effectively.Maintain consistency and quality in security control scoring.Identify security gaps and recommend appropriate remediation.Evidence & Risk AnalysisReview security policies, procedures, control documentation, and supporting evidence.Analyze large and complex datasets to identify systemic risks and recurring security issues.Identify trends and enterprise-level risk themes.Conduct root-cause analysis and recommend process improvements.Automation & Continuous MonitoringUtilize automated evidence pipelines and continuous monitoring capabilities throughout the security assessment lifecycle.Support and improve security assessment automation.Identify opportunities to reduce manual assessment activities.Support modernization initiatives designed to improve assessment efficiency, consistency, and transparency.Risk ReportingDevelop concise and actionable security risk summaries.Translate technical assessment results into enterprise-level risk insights.Present data-driven security findings and recommendations to leadership.Identify recurring risk themes across systems and environments.Stakeholder AdvisoryProvide security and compliance guidance to system owners, architects, security teams, and organizational leadership.Serve as a trusted security advisor to cross-functional stakeholders.Support integration of new security processes with existing enterprise processes.Communicate security and compliance changes to impacted stakeholders.Cloud & AI SecurityCandidates should have experience or familiarity with:Security assessments within cloud environmentsAWS, Azure, and/or GCP security conceptsCloud security risks and controlsDevSecOps practices and automationAI-related security assessmentsAI security and governance frameworksAutomated security/compliance assessment processesCandidates with strong DevSecOps automation and/or AI assessment experience may be considered above the stated pay range.Required Soft SkillsExcellent written and verbal communicationAbility to communicate with both highly technical teams and executive leadershipStrong analytical and problem-solving skillsCross-functional collaborationStrong interpersonal and relationship-building abilitiesNegotiation and stakeholder-management skillsStrategic mindsetAttention to detailSound risk-management decision-makingAbility to operate as a trusted advisorEducationBachelor’s degree in Computer Science, Information Security, Cybersecurity, or a related discipline preferred.Equivalent professional experience may also be considered.Preferred CertificationsOne or more of the following certifications is preferred:CISSP – Certified Information Systems Security ProfessionalCISA – Certified Information Systems AuditorCISM – Certified Information Security ManagerAdditional Preferred ExperienceExperience working within policy and assurance environmentsExperience in quasi-governmental or similarly regulated organizationsSecurity compliance modernizationDevSecOps automationAI security assessmentsContinuous authorizationEnterprise security risk reporting30-60-90 Day ExpectationsFirst 30 Days:Onboard to SAFR frameworks, assessment tools, automated processes, and enterprise reporting standards. Shadow active security assessments, begin reviewing evidence, and build relationships with system owners and security stakeholders.First 60 Days:Independently lead security assessments using automation and continuous monitoring tools. Produce leadership-ready risk insights and contribute to security automation and process-improvement initiatives.First 90 Days:Take full ownership of end-to-end security assessments and compliance recommendations. Identify enterprise-level risk themes through data-driven analysis and propose improvements that increase assessment efficiency and transparency.Interview ProcessResume Review → 1–2 Panel Interviews → Final Selection → Background Check → OnboardingImportant: Interviews will be conducted via video. Candidates must be comfortable maintaining video presence and presenting valid identification when required.Work AuthorizationU.S. Citizenship is required for this position.ApplyQualified candidates are encouraged to apply with an updated resume highlighting experience with NIST 800-37, NIST 800-53/53A, security control assessments, Cloud/AI security, continuous monitoring, assessment automation, and DevSecOps.