Find Jobs
Find Jobs Near You – Available Work in Your Location
Skip to job details
T
TekSynap
CSSP Auditor
Career Insights for Auditor (General)
See where this job fits in the broader career landscape. Knowing your career path helps you see what's possible from here.
Scorecard
Based on Virginia data
Review key factors to help you decide if this role fits your goals. How is this calculated?
What they do
An Auditor examines records to determine the financial status of a company or organization. Inspects accounts and account books, prepares reports on the accuracy of internal financial records and accounting procedures.
$76,174 / year median in Virginia
-6% projected decline
Job Description
Responsibilities & Qualifications Position Summary The CSSP Auditor provides independent oversight, compliance validation, and operational quality assurance across the Cybersecurity Service Provider (CSSP) environment. The position is responsible for establishing a continuous audit and inspection-ready posture by validating cybersecurity operations, telemetry quality, evidence traceability, regulatory compliance, and operational performance metrics. The CSSP Auditor works across the Protect, Detect, Respond, and Sustain functions to ensure cybersecurity operations align with DoD requirements, NIST guidance, CSSP Evaluator Scoring Metrics (ESM), and organizational quality standards.
TekSynap.com. Apply now to explore jobs with us! The safety and health of our employees is of the utmost importance. Employees are required to comply with any vaccination requirements mandated by contract, applicable law or regulation. By applying to a role at TekSynap you are providing consent to receive text messages regarding your interview and employment status. If at any time you would like to opt out of text messaging, respond "STOP". As part of the application process, you agree that TekSynap Corporation may retain and use your name, e-mail, and contact information for purposes related to employment consideration. Additional Job Information
Key Responsibilities:
Data Quality Scoring (DQS) &Telemetry Auditing:
Establish, govern, and audit the CSSP Data Quality Scoring (DQS) framework to evaluate the trustworthiness of ingested security telemetry. Perform continuous audits of telemetry sources against mandatory DQS metrics, including Parsing Success Rate (PSR), Field Completeness Score (FCS), Schema Adherence Score (SAS), and Timeliness Score (TS). Track, analyze, and manage the remediation of low-DQS sources and data-loss visibility gaps. Validate data collection, normalization, enrichment, and correlation processes to ensure critical security events are accurately represented throughout the detection lifecycle.Evidence Object & Traceability Verification:
Manage and validate CSSP Evidence Objects to ensure all defensive cyber actions are fully documented and package-proven. Ensure absolute traceability from ingested telemetry up to cybersecurity risk-reduction decisions. Verify complete traceability from source telemetry through analyst actions, incident response activities, and cybersecurity risk-reduction decisions. Conduct routine audits of evidence packages to ensure compliance with internal policies and external assessment requirements.SOP Lifecycle Management & SharePoint Governance:
Lead the full lifecycle of Standard Operating Procedures (SOPs), playbooks, and internal operational workflows. Develop, implement, and track an annual review plan for all CSSP documentation. Manage the SharePoint Master SOP Library, maintaining version control, access permissions, and formal archival processes. Verify that all published SOPs are synchronized with current DED requirements and operational capabilities.NIST SP-800-53
Rev. 5 & 800-53A Compliance:
Map CSSP operational controls and evidence logs directly toNIST SP-800-53
Rev. 5 control families, focusing heavily on Audit and Accountability, System and Information Integrity, and Incident Response. EmbedNIST SP-800-53A
assessment methods (Examine, Interview, and Test) into internal audit procedures to support continuous authorization and federal compliance mandates, includingOMB M-26-14.
Focus heavily on Audit and Accountability (AU), System and Information Integrity (SI), Incident Response (IR), Configuration Management (CM), and Risk Assessment (RA) controls.Audit Readiness:
Lead activities supporting CSSP Evaluator Scoring Metrics (ESM) assessments, Cyber Operational Readiness Assessments (CORA), JFHQ-DODIN evaluations, and other government-directed inspections. Coordinate evidence collection, validation, scoring reviews, and corrective action tracking. Maintain a continuous inspection-ready posture and reduce organizational dependence on pre-audit preparation cycles. Define, monitor, and report on internal performance metrics, enforcing strict alignment withDTM 26-003.
Independent Quality Assurance:
Conduct recurring audits across Protect, Detect, Respond, and Sustain teams. Assess procedural compliance, documentation quality, operational consistency, analyst performance evidence, and adherence to service delivery requirements. Validate execution against approved processes, operational standards, and organizational objectives.Continuous Improvement and Lessons Learned:
Identify recurring compliance deficiencies, operational trends, systemic weaknesses, and process inefficiencies. Develop lessons learned reports and corrective action recommendations. Facilitate continuous process improvement initiatives that strengthen cybersecurity effectiveness, audit readiness, and mission performance.Required Qualifications:
Clearance:
Active Top-Secret Clearance with SCI eligibility required.Compliance & Certifications:
DoD 8140/8570 CSSP Auditor or equivalent certifications is required Certified Information Systems Auditor (CISA) is requiredExperience:
Minimum of 7+ years of progressive experience in cybersecurity auditing, continuous monitoring, or compliance assessment (or 5+ years with a Master's degree), with a minimum of three (3) years supporting DoD or Federal cybersecurity programs. Experience supporting audit, inspection, or accreditation activities within a Security Operations Center (SOC), Cybersecurity Service Provider (CSSP), Cyber Defense Program, or related environment.Education:
BA/BS College degree required.Technical Auditing Capabilities:
Proven experience auditing database/SIEM logs, data ingestion schemas, and validating compliance data flows. Familiarity with data dictionaries, data validation rules, and automated log analysis is highly preferred. Preferred Technical Experience/Knowledge (3 or more areas desired): DoD Cybersecurity Service Provider (CSSP) operations Risk Management Framework (RMF)NIST SP 800-53
Rev. 5 andNIST SP 800-53A
DoDI 8530.01 and applicable CSSP guidanceCNSSI 1253
Security Technical Implementation Guides (STIGs) Continuous Monitoring programs Incident Response processes Vulnerability Management programs Audit, compliance, and inspection readiness activitiesMITRE ATT&CK
Framework Overview We are seeking a CSSP Auditor to join our Prime Contract with the Defense Threat Reduction Agency. TekSynap is a fast growing high-tech company that understands both the pace of technology today and the need to have a comprehensive well planned information management environment. "Technology moving at the speed of thought" embodies these principles - the need to nimbly utilize the best that information technology offers to meet the business needs of our Federal Government customers. We offer our full-time employees a competitive benefits package to include health, dental, vision, 401K, life insurance, short-term and long-term disability plans, vacation time and holidays. Visit us at www.TekSynap.com. Apply now to explore jobs with us! The safety and health of our employees is of the utmost importance. Employees are required to comply with any vaccination requirements mandated by contract, applicable law or regulation. By applying to a role at TekSynap you are providing consent to receive text messages regarding your interview and employment status. If at any time you would like to opt out of text messaging, respond "STOP". As part of the application process, you agree that TekSynap Corporation may retain and use your name, e-mail, and contact information for purposes related to employment consideration. Additional Job Information