Principal Assessor II, Cyber Security jobs in United States
cer-icon
Apply on Employer Site
company-logo

American Bureau of Shipping (ABS) · 7 hours ago

Principal Assessor II, Cyber Security

American Bureau of Shipping (ABS) is a leading ship classification society focused on digitalization and sustainability. The Principal Cyber Security Assessor II is responsible for implementing and delivering ABS cyber security products and services, primarily focusing on Risk Management Framework (RMF) activities for U.S. government maritime and OT cybersecurity projects.

EnergyMarine TransportationNon ProfitRenewable EnergyShipping
badNo H1BnoteU.S. Citizen Onlynote

Responsibilities

Function as a subject matter expert in IT/OT security and RMF-based cybersecurity for maritime and shipboard control systems, including Supervisor Control and Data Acquisition (SCADA) and Distributed Control Systems (DCS)
Serve as an independent Navy Qualified Validator (NQV) in accordance with U.S. Navy and client requirements, providing objective validation of cybersecurity assessments and evidence
Review, validate, and provide independent concurrence on:
OT/ICS cybersecurity assessments and system security documentation
Vulnerability scans and results produced by ABS teams (e.g., ISEE)
Plans of Action and Milestones (POA&Ms) and risk disposition recommendations
Support Risk Management Framework (RMF) activities for U.S. government clients, including assessment and authorization (A&A) activities for shipboard and shore-based systems and services
Confirm that vessels and systems meet applicable cybersecurity standards required to obtain and maintain Authority to Operate (ATO) from U.S. Navy and client stakeholders
Act as a primary technical liaison between ABS, clients, and U.S. Navy cybersecurity/accreditation organizations, helping to clarify technical issues, resolve findings, and support ATO decision-making
Contribute to the delivery and continuous improvement of ABS’s CS-RMF notation and related cybersecurity products and services
Develop and test various security features and controls to meet customer, U.S. government, and regulatory cybersecurity requirements
Support the development of proposals, provide ongoing technical and sales support for U.S. government and OT cybersecurity projects, and assist customers with maintaining compliance and cyber security
Conduct cyber vulnerability assessments and regulatory audits, including against applicable DoD/Navy standards and controls
Design and implement cyber security solutions for control systems in alignment with RMF and relevant DoD/Navy guidance
Develop project documentation, including security assessment reports (SARs), risk assessment artifacts, and RMF-aligned evidence packages
Successfully conduct onsite implementations and validations of security solutions and controls onboard vessels or at shore facilities as needed
Provide technical analysis and guidance on control systems security trends, DoD/Navy RMF practices, and emerging OT cybersecurity threats
Prepare and conduct technical presentations for internal and external stakeholders, including U.S. government and Navy audiences
Create technical reports and progress reports for projects, suitable for submission to the client, U.S. Navy ATO authorities, and other government stakeholders

Qualification

OT/ICS cybersecurityRisk Management Framework (RMF)Navy Qualified Validator (NQV)NIST SP 800-53CISSP certificationISO 27001Cyber vulnerability assessmentsOralTechnical analysisPresentation skillsWritten communication

Required

Degree in Engineering or Computer Science or demonstrated equivalent work-related experience
7-10+ years in OT/ICS cyber security, OT/ICS compliance, or OT/ICS audit
Experience supporting U.S. government, DoD, or U.S. Navy cybersecurity programs, preferably including RMF-based assessment and authorization activities
Broad experience in computer and network systems, including IT/OT security, cyber-related regulations, NIST requirements, and/or SANS security practices
Demonstrated knowledge of standards and frameworks such as NIST SP 800-53, NIST RMF, ISO 27001, ISA/IEC 62443, and DISA STIGs, and their application to OT and maritime environments
Familiarity with DoD and U.S. Navy RMF processes, ATO workflows, and associated cybersecurity documentation and artifacts
Hands-on technical configuration and implementation of cyber security standards and controls for OT/ICS environments
Ability to interpret and validate vulnerability scan outputs and other technical evidence supporting RMF assessments and ATO decisions
Excellent presentation skills, including presentation development, numeracy and analysis skills, and advanced skills in Microsoft Word, Excel, PowerPoint, Visio, and Outlook
Excellent oral and written English communication skills, with demonstrated capability to produce reports suitable for delivery to technical and non-technical audiences, including U.S. government reviewers
Willingness and ability to travel domestically and internationally, including travel to shipyards, vessels, or other operational sites
Ability to learn the ABS Health, Safety, Quality, and Environmental Management Systems

Preferred

Experience working with or in support of Navy Qualified Validator (NQV) functions, or direct experience in a formal NQV role, is strongly preferred
Managerial-level professional certification (i.e., CISSP, CISA, GICSP) preferred. Additional DoD 8570/8140-compliant certifications or Navy cybersecurity qualifications are a plus
Experience in offshore and maritime environments, especially in relation to shipboard control systems and OT cybersecurity
Prior experience writing technical reports and research papers in English, particularly for DoD, U.S. Navy, or other U.S. government cybersecurity programs
Experience developing and delivering training to clients or internal teams on RMF, Navy cybersecurity requirements, or OT cyber risk management

Benefits

Medical insurance (PPO and HD)
Dental and vision insurance
Health Savings Account (HSA)
Flexible Savings Account (FSA)
Life insurance
Accidental death and dismemberment insurance
Disability leave programs
Parental leave program
Paid holidays
Paid vacation time
Employee Assistance Plan (EAP)
401K plan with a generous company match

Company

American Bureau of Shipping (ABS)

company-logo
Since its founding in 1862, ABS has been committed to setting standards for safety and excellence as one of the world’s leading ship classification organizations.

Funding

Current Stage
Late Stage

Leadership Team

leader-logo
Patrick Ryan
Senior Vice President & Chief Technology Officer
linkedin
leader-logo
Stamatis Fradelos
VP of Regulatory Affairs
linkedin
Company data provided by crunchbase