Nicholas Best
@nicholasbest
Results-driven Security Control Assessor with expertise in compliance.
What I'm looking for
I am a results-driven Security Control Assessor with over 5 years of experience supporting federal and commercial environments in achieving compliance through the full Risk Management Framework (RMF) lifecycle. My expertise lies in evaluating security controls per NIST SP 800-53 Rev 5, developing formal assessment documentation, and driving Authorization to Operate (ATO) processes.
Throughout my career, I have demonstrated proficiency in stakeholder engagement, technical evidence review, and vulnerability identification. I have successfully led full lifecycle RMF assessments, developed tailored Security Assessment Plans, and authored comprehensive Security Assessment Reports. My ability to work cross-functionally with ISSOs, system owners, and engineering teams has been instrumental in maintaining compliant, risk-informed security postures.
Experience
Work history, roles, and key accomplishments
Security Control Assessor
AetherForge
Aug 2023 - Present (1 year 11 months)
Led full lifecycle RMF assessments for FISMA-moderate and FedRAMP systems, developing and executing Security Assessment Plans (SAP). Conducted in-depth control testing against NIST 800-53 controls, authoring Security Assessment Reports (SAR) with severity ratings and mitigation strategies.
Associate Qualified Security Assessor
Viking Cloud
Feb 2021 - Present (4 years 5 months)
Performed assessments aligned with PCI-DSS, mapping controls to RMF equivalents and conducting gap analyses. Created and validated documentation including System Security Plans (SSP) and supported scanning operations with Tenable and Qualys.
Junior Security Control Assessor
Bincom Enterprises
Dec 2019 - Present (5 years 7 months)
Assisted senior SCAs in system categorization and tailoring baseline controls, reviewing and editing various security plans. Logged and tracked vulnerabilities from Nessus and OpenVAS scans, performing manual verification.
Education
Degrees, certifications, and relevant coursework
University of Maryland, College Park
Bachelor's Degree, Criminal Justice & Criminology
Studied Criminal Justice & Criminology at the University of Maryland, College Park. Gained foundational knowledge in legal frameworks and societal aspects relevant to security and compliance.
Tech stack
Software and tools used professionally
Availability
Location
Authorized to work in
Job categories
Interested in hiring Nicholas?
You can contact Nicholas and 90k+ other talented remote workers on Himalayas.
Message NicholasFind your dream job
Sign up now and join over 100,000 remote workers who receive personalized job alerts, curated job matches, and more for free!
