Schellman is a Top 50 CPA firm and a leading provider of attestation and compliance services. Our professional services focus on security and privacy audits, assessments, and certifications. Schellman has become one of the largest cybersecurity assessment firms in the United States without providing any traditional accounting services. We are an accredited multi-framework ISO Certification Body for security, privacy, business continuity, and quality; a globally licensed PCI Qualified Security Assessor and a top provider to clients serving the federal DoD space as a leading FedRAMP 3PAO and the first assessment firm authorized as a CMMC C3PAO. Our specialty and expertise remain in providing best in class Cybersecurity and IT Audits and Attestations. Our culture, approach with clients, and dedication to our values has led us to consistently be a Great Places to Work certified company and rated as a Best Firms to Work For by Accounting Today and a Glassdoor Best Places to Work. We deeply appreciate our employees, as shown by our first core value – People Come First. This is demonstrated in our culture, benefits, and how we handle business. Come see what makes Schellman special!
As a Seasonal Senior Associate, you’ll bring the best of your audit/assessor and attestation knowledgeto a flexible work environment where you can keep your skills sharp, your experience relevant andtogether achieve client and company goals. You’ll be primarily responsible for hands-on projectexecution and will be assigned to a specific service delivery management team and Principal that isresponsible for supervising the project. Additionally, senior associate’s daily activities are closelysupervised by the management teams of their assigned projects.
There is no typical day for our attestation and audit teams and the challenges abound to grow in skillsand experience. As a FedRAMP Seasonal Senior Associate specifically, you'll be able to work with thelatest cloud services and technology companies, all of which are looking to test their systems againstthe tried and true prescriptive controls provided by NIST 800-53. FedRAMP Senior Associates performa variety of responsibilities from start to finish during a project, including:
- Interviewing clouds service providers (CSP) Subject Matter Experts for different fields of theorganization such as Human Resources, SecDevOps, SOC/NOC, and Internal Compliance;Performing walkthroughs of various cloud infrastructure-as-a-service architectures (e.g., AWS,
- Reviewing system security configurations as they pertain to NIST 800-53 security controlbaselines; and
- Analyzing vulnerability reports, validating encryption configurations, and much more!
Working in Schellman’s Federal Practice will lead to the natural honing of your technical skills in a varietyof fields including cryptography, network structures, system security tools, and CI/CD.You’ll also improveyourunderstandingoforganizationalcontrolssuchassecuritytrainingprograms,configurationmanagement/ system development, and incident response processes. But more than that, a seasonalrole supporting our FedRAMP/CMMC practice at Schellman will add to your breadth of experience andexposure,supportingoutsideopportunitiesforfurthereducationthroughadditionaltrainingandthepursuit of industry-accepted certifications such as CISA, CISSP, and others.
THE ESSENTIALS
- Comply with Schellman’s code of ethics and professional conduct, methodologies, policies,
- Adhere to the professional and regulatory standards relevant to assigned service line
- Promote Schellman’s company culture and exemplifying Schellman's values
- Establish high quality relationships and rapport with client personnel
- Manage client expectations to ensure expectations are exceeded
- Complete assigned duties in a timely manner and with a high attention to detail
- Collaborate with fellow project team members in a productive and timely manner throughout
- the life cycle of each project
- Adhere to project schedules and keeping fellow project team members apprised of the
- progress of assigned tasks
- Escalate issues internally in a proper and timely manner
- Use discretion and decorum in the timing, form, and content of all client communications
- Book travel reservations in a timely manner and in accordance with Schellman's travel and
- expense policies and procedures
- Perform the essential functions of other service delivery positions when qualified and called
- Attend project kick-off and closing meetings
- Execute assigned testing procedures, performing detailed analysis, reaching conclusions,
- documenting results in accordance with company standards, and suggesting ideas for
- improvements, where applicable
- Draft project deliverables
- Serve as a contact for clients' basic questions regarding an engagement
- Develop an expert knowledge of professional and regulatory standards relevant to assigned
- service line specialization(s)
WHAT YOU’LL BRING
- Working knowledge of Schellman’s services, methodology, and relevant professional standardsRequisite knowledge of applicable technology and security domains
- High level of attention to detail and quality of work product
- Excellent time management, organizational, and verbal and written communication skills
- Ability to work on-site or remotely as a valuable contributor to a collaborative team
- Capable of simultaneously managing assigned tasks for multiple projects
- Proficient using Microsoft Word, Excel, and PowerPoint, as well as Schellman’s service deliveryapplications
- Full understanding and application of ethics, independence and Schellman’s values
YOUR BACKGROUND
- Bachelor's degree in accounting, finance, business management, technology, or other relevantsubject area, or equivalent years of experience directly related to the duties and responsibilitiesspecified
- 2+ years of related professional services experience in information security auditing,assessment, consulting or compliance, focused on Federal frameworks such as NIST,FedRAMP and the related
- Ability to work well independently, within a team and with clients as well as potential travelAbility to work seasonal part-time schedule
Maintains one or more of the following FedRAMP R311 certifications:
- Cisco Certified Network Associate Security (CCNA Security)
- Cisco Certified Network Associate Cyber Security Operations (CCNA Cyber Ops)Cybersecurity Analyst (CySA+)
- GIAC Certified Incident Handler (GCIH)
- GIAC Systems and Network Auditor (GSNA)
- GIAC Certified Intrusion Analyst (GCIA)
- Certified Information Systems Auditor (CISA)
- Certified Information System Security Professional or Associate (CISSP or Associate)Certified Secure Software Lifecycle Professional (CSSLP)
- Certified Information Systems Security Officer (CISSO)
- CyberSec First Responder (CFR)
- CompTIA Advanced Security Practitioner Continuing Education (CASP+) Continuing
- Global Industrial Cyber Security Professional (GICSP)
- Securing Cisco® Networks with Threat Detection Analysis (SCYBER)
Schellman is an equal opportunity employer (EOE) and strongly supports diversity in the workplace; therefore, providing equal employment opportunities to applicants and employees without regard to race, color, religion, age, sex, sexual orientation, gender identity/expression, national origin, protected veteran status, disability status, or any other legally protected basis, including arrest and conviction records, in accordance with applicable law. Schellman uses E-Verify in our hiring process.
At Schellman, we strive to provide a flexible and balanced environment and therefore offer the opportunity to work remotely, unless otherwise stated in the job requirements. Connecting, collaborating and continuous education are also highly valued and therefore we require some travel annually for our Internal Service Delivery roles, which can include in-person training, team meet-ups, and strategy meetings. Service Delivery team members will also be required to travel based on business and client needs.