1

Freelance Security Risk Assessment Jobs in Virginia

An information system security risk assessment should also be performed in compliance with SEC501.09 and SEC520.00 using the risk assessment template: ( 1.Appeals and Rulings 2.FACSYS 3.Fraud ...

An information system security risk assessment should also be performed in compliance with SEC501.09 and SEC520.00 using the risk assessment template: ( 1.Appeals and Rulings 2.FACSYS 3.Fraud ...

Conduct security risk assessments for third parties - including cloud service providers, SaaS platforms, technology partners, and infrastructure providers - across the third-party lifecycle (intake ...

next page

Showing results 1-20

Freelance Security Risk Assessment information

What is the difference between Freelance Security Risk Assessment vs Security Consultant?

AspectFreelance Security Risk AssessmentSecurity Consultant
CredentialsCertifications like CISSP, CISA, or CEH often requiredSimilar certifications, often with additional experience requirements
Work EnvironmentIndependent, project-based, often remote or on-site at client locationsTypically employed by firms or consulting agencies, may work on multiple projects
Industry UsageUsed by organizations seeking independent risk assessmentsEngaged for broader security strategy, policy development, and consulting

While both roles involve assessing security risks, Freelance Security Risk Assessments focus on independent, project-specific evaluations, whereas Security Consultants often provide ongoing security advice and strategy within organizations or consulting firms.

What are the most commonly searched types of Security Risk Assessment jobs in Virginia? The most popular types of Security Risk Assessment jobs in Virginia are:
What are popular job titles related to Freelance Security Risk Assessment jobs in Virginia? For Freelance Security Risk Assessment jobs in Virginia, the most frequently searched job titles are:
What job categories do people searching Freelance Security Risk Assessment jobs in Virginia look for? The top searched job categories for Freelance Security Risk Assessment jobs in Virginia are:
What cities in Virginia are hiring for Freelance Security Risk Assessment jobs? Cities in Virginia with the most Freelance Security Risk Assessment job openings:
Infographic showing various Freelance Security Risk Assessment job openings in Virginia as of July 2026, with employment types broken down into 2% As Needed, 79% Full Time, 16% Part Time, and 3% Contract. Highlights an 92% Physical, 2% Hybrid, and 6% Remote job distribution.

Information Security Risk Assessor

vTech Solution

Richmond, VA โ€ข On-site

Contractor

Posted 14 days ago


Job description

Job Summary:

The Senior Information Security Risk Assessor โ€“ PeopleSoft FSCM will lead comprehensive SEC530 risk assessments for PeopleSoft Financials and related business functions. This role involves identifying and evaluating risks, controls, and impacts to ensure the confidentiality, integrity, and availability of sensitive financial and operational data. The assessor will develop risk methodologies, risk registers, and corrective action plans while collaborating closely with IT security auditors and stakeholders.

Responsibilities:
  • Develop SEC530 risk-assessment methodology, scoring criteria, and risk-treatment categories.
  • Define system boundaries, critical business processes, sensitive data, technical dependencies, and third-party services.
  • Conduct interviews and risk workshops with technical, security, fiscal, system-owner, and executive stakeholders.
  • Identify and evaluate risks related to access control, segregation of duties, unauthorized changes, legacy customizations, and interface security.
  • Assess risks involving PeopleSoft roles, permissions, custom code, database privileges, and environment separation.
  • Review control-testing results and assign inherent and residual risk ratings.
  • Develop and maintain a detailed risk register documenting threats, vulnerabilities, controls, and treatment recommendations.
  • Prioritize corrective actions and support development of remediation plans and risk acceptance statements.
  • Prepare and present draft and final risk-assessment reports to leadership and system owners.
  • Participate in onsite kickoff, draft-review, and final wrap-up meetings.
Required Skills & Certifications:
  • Active CISSP or CISA certification.
  • Minimum three years of relevant cybersecurity or IT risk-assessment experience.
  • Experience leading formal application, system, or enterprise technology risk assessments.
  • Proficiency in identifying threats, vulnerabilities, business impacts, and risk levels.
  • Experience developing risk registers and formal risk-assessment reports.
  • Knowledge of systems handling sensitive financial, tax, payment, vendor, or personally identifiable information.
  • Ability to provide a reference from another state government agency.
  • Availability for onsite meetings in Richmond and ability to work from approved U.S.-based locations.
  • Understanding of SEC530 or comparable government risk-assessment standards.
Preferred Skills & Certifications:
  • Five or more years of cybersecurity risk-assessment experience.
  • Prior experience with SEC530, Commonwealth of Virginia, or VITA risk assessments.
  • Expertise in PeopleSoft FSCM, PeopleSoft Financials, Oracle ERP, and financial-system risk assessments.
  • Familiarity with Oracle 19c, PeopleTools, WebLogic, Windows, and Linux environments.
  • Experience assessing Active Directory/LDAP, SFTP, PowerShell, BizTalk, Integration Broker, and database links.
  • Knowledge of vendor, payment, tax, procurement, accounting, or billing system risks.
  • Experience evaluating shared and inherited controls in government-hosted environments.
  • Additional certifications such as CRISC, CISM, CCSP, CGEIT, or ISO 27001 Lead Auditor.
Special Considerations:
  • Mandatory background check and key-personnel status under the SOR.
  • Must be able to perform all work from approved U.S.-based locations.
  • Reference from another state government agency required.
  • Availability for required onsite meetings in Richmond, VA.
Scheduling:
  • Work schedule includes participation in onsite kickoff, draft-review, and final wrap-up meetings.
  • Typical work performed remotely with required onsite presence as specified.

vTech Solution Inc. is a Managed IT Services firm headquartered in Washington, DC. They specialize in a range of services includingย cloud computing,ย managed network security, andย cybersecurity. Their primary focus is on providing human-centered IT solutions for government and business sectors, including federal, state, local, and education (SLED) groups, as well as commercial organizations.

vTech Solution offers services such as:

  • Managed Security Services: Implementing zero-trust security frameworks to prevent cyber threats in real-time.
  • Multi-cloud Management Services: Helping businesses digitally transform with smart cloud technologies.
  • Infrastructure Managed Services: Creating resilient and secure infrastructure management.
  • Professional Services: Providing expertise for mission-critical programs.
  • Productivity and Communications: Ensuring secure and confident business connectivity from anywhere

vTech Solution logo

About vTech Solution

Sourced by ZipRecruiter

vTech is a Managed IT Services firm based out of Washington DC with a primary focus on Cloud Computing and Managed Network Security.

Industry

It services

Company size

51 - 200 Employees

Headquarters location

Washington, DC, US

Year founded

2006

Social media