What are the responsibilities and job description for the Cybersecurity Quality Assurance Analyst Independent Verification and Validation (IV&V) position at DataLock Consulting Group?
This is a remote position.
Independent Verification and Validation (IV&V)
- POSITION TITLE
Independent Verification and Validation (IV&V)
- SUMMARY
- RESPONSIBILITIES
- Review cybersecurity assessment documentation for accuracy, completeness, and compliance
- Conduct independent verification and validation of technical findings and risk statements
- Evaluate evidence against federal and industry standards
- Assess vendor cybersecurity risk and review third party risk documentation
- Validate compliance with ISO, SOC, and NIST standards
- Identify deficiencies or deviations from required quality and security standards
- Provide feedback and guidance to assessment teams to maintain quality consistency
- Maintain documentation, audit trails, and quality records
- Support internal audit activities and process improvement initiatives
- Prepare reports for management review and quality control oversight
- Recommend enhancements to assessment processes and methodologies
- MINIMUM EXPERIENCE AND SKILLS
- Senior level positions require seven or more years of relevant cybersecurity experience
- Advanced degree in a cybersecurity or technical field preferred, with experience or directly relevant certifications substituting for academic credentials
- At least five years of experience in Information Security Governance, Risk, and Compliance, demonstrating:
- Expertise in writing technical and risk management reports
- Strong analytical, problem solving, and organizational skills
- Experience assessing and mitigating risks associated with vendor relationships and vendor control evaluations
- Experience performing risk-based due diligence
- Technical understanding of cybersecurity concepts and working knowledge of ISO 27001, SOC 1 and SOC 2, NIST SP 800-53, and NIST SP 800-171
- At least three years of experience in third party cybersecurity risk management, demonstrating:
- Experience evaluating third party cyber risk
- Experience developing and implementing sustainable third party cyber risk processes
- Experience conducting assessments using NIST SP 800-53 within a federal agency
- Strong verbal and written communication skills
- Effective technical writing and documentation capabilities
- Experience in cybersecurity control assessment environments
- Ability to document cyber assessments and communicate results clearly
- Understanding of the Systems Development Life Cycle and its application to secure systems
- MINIMUM EDUCATION
- Advanced degree preferred
- Experience and certifications may be substituted for formal education on a case by case basis
- CERTIFICATIONS
- Certified Information Systems Security Professional (CISSP)
- Certified Information Systems Auditor (CISA)
- Certified Information Security Manager (CISM)
- Certified Third Party Risk Professional (CTPRP)
- Certified Third Party Risk Assessor (CTPRA)