Security Control Assessor, Lead
$99k - $225kBooz Allen Hamilton
Security Control Assessor, LeadThe Opportunity:The Lead Security Control Assessor directs the SCA workstream and provides independent cybersecurity assessment leadership for CDAO systems and environments to the ISSM. The Lead SCA owns assessment strategy, quality standards, stakeholder coordination, risk adjudication, and final review of Security Assessment Plans (SAPs) and Security Assessment Reports (SARs). The position advises technical leadership and Authorizing Official (AO) stakeholders on control effectiveness, authorization readiness, and residual cybersecurity risk. In this role you will be responsible for developing and governing the assessment approach, schedule, evidence standards, test procedures, and quality-control framework for the SCA team.What You'll Work On:Provide eMASS administration, analyze STIG, SCAP, ACAS findings, POA&Ms, architecture, inherited controls, compensating controls, and technical evidence.Work with the project ISSM to understand customer cybersecurity RMF requirements applicable to the systems in their respective environments.Lead independent security control assessments in accordance with DoD RMF, NIST guidance, applicable DoD cybersecurity policy, and organizational assessment procedures.Brief findings and risk recommendations to the ISSM, AO representative, and AO-level stakeholders.Develop all system applicable RMF Body of Evidence (BOE) documentation ensuring accuracy, relevance, and completion to meet requirements and input BOE documentation into AO approved databases such as eMASS or AO specific SharePoint site.Review and approve SAPs and SARs for technical accuracy, evidence sufficiency, traceability, consistency, and defensibility before stakeholder delivery.Coordinate with system owners, ISSMs and ISSOs, cybersecurity engineers, administrators, developers, program leadership, control providers, and AO representatives.Review system boundaries, data flows, external interfaces, interconnections, inherited controls, common-control dependencies, and significant changes.Oversee assessment execution for ATO, reauthorization, annual assessment, significant-change assessment, and continuous monitoring activities.Brief assessment status, systemic risks, unresolved findings, remediation priorities, and authorization recommendations to senior stakeholders.Mentor assessors, calibrate assessment judgments, and ensure independence and objectivity across the assessment lifecycle.Develop and maintain strong relationships with stakeholders across the organizationYou Have: 8+ years of experience with cybersecurity including substantial DoD or federal RMF, security assessment, security engineering, or authorizationExperience with eMASS, analyzing STIG, SCAP, ACAS findings, POA&Ms, architecture, inherited controls, compensating controls, and technical evidenceExperience leading security control assessments and producing or approving SSPs, SAPs, SARs, POA&Ms, risk assessments, and authorization packagesExperience with administration of Windows, Linux, AWS Cloud, and containerization systems and software configurationExperience with technical writing, facilitation, quality-assurance, team leadership, and stakeholder-management capabilitiesKnowledge of NIST SP 800-53, NIST SP 800-37, DoD RMF, STIGs, vulnerability management, and security-control assessment methodologyAbility to evaluate complex enterprises, cloud, hybrid, containerized, data, and AI-enabled architectures and communicate risks at the AO and executive levelsAbility to lead, organize, and complete various cybersecurity testing events including using applicable automated security scanning tools, system required manual STIGs and SRGs and compiling, reviewing, and analyzing results and providing to the ISSM for review and finalizationTS/SCI clearanceBachelor's degree in a technical field such as Engineering or CyberNice If You Have: Experience reviewing system connection requests for completion and ensure that requirements are met and make recommendations to the ISSM for approvalExperience performing dynamic security assessments triggered by system changes, threat changes, vulnerabilities, incidents, or mission conditionsAbility to communicate cybersecurity test result outcomes, risks, and suggest fixes to the project engineering team to fix or mitigate potential risks and document Plan of Action and Milestone (POA&M) development and tracking, driving remediation of vulnerabilities to a level acceptable to the Authorizing Official (AO)Ability to adjudicate complex findings, evaluate compensating controls and mitigations, validate risk determinations, and advise on residual mission riskAbility to lead quarterly Cyber Resilience and Continuous Monitoring reviewsClearance:Applicants selected will be subject to a security investigation and may need to meet eligibility requirements for access to classified information; TS/SCI clearance is required. CompensationAt Booz Allen, we celebrate your contributions, provide you with opportunities and choices, and support your total well-being. Our offerings include health, life, disability, financial, and retirement benefits, as well as paid leave, professional development, tuition assistance, work-life programs, and dependent care. Our recognition awards program acknowledges employees for exceptional performance and superior demonstration of our values. Full-time and part-time employees working at least 20 hours a week on a regular basis are eligible to participate in Booz Allen’s benefit programs. Individuals that do not meet the threshold are only eligible for select offerings, not inclusive of health benefits. We encourage you to learn more about our total benefits by visiting the Resource page on our Careers site and reviewing Our Employee Benefits page.Salary at Booz Allen is determined by various factors, including but not limited to location, the individual’s particular combination of education, knowledge, skills, competencies, and experience, as well as contract-specific affordability and organizational requirements. The projected compensation range for this position is $99,000.00 to $225,000.00 (annualized USD). The estimate displayed represents the typical salary range for this position and is just one component of Booz Allen’s total compensation package for employees. This posting will close within 90 days from the Posting Date.Identity StatementAs part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during interviews and assessments. We reserve the right to take your picture to verify your identity and prevent fraud.Candidate AI Usage PolicyAI is a part of our daily work at Booz Allen, and we are committed to the responsible and ethical use of AI tools. However, we want to ensure a fair candidate process based on your own skills and knowledge. As part of this commitment, the use of artificial intelligence (AI) or other tools to assist with responses during interviews (whether in-person or virtual) is prohibited unless permission is explicitly provided. Work ModelOur people-first culture prioritizes the benefits of collaboration, whether it occurs in person or virtually. To support engagement and effective communication, employees working virtually are generally expected to have their cameras on during meetings.Remote: If this position is listed as remote, there may still be occasions when you are required to work in person at a Booz Allen or customer facility.Hybrid: If this position is listed as hybrid, you will be expected to work from a Booz Allen facility frequently, in alignment with leadership expectations and the needs of the role. You may also be required to work from or visit a customer facility.Onsite: If this position is listed as onsite, work will primarily be performed at a Booz Allen office or customer facility, where employees will collaborate directly with colleagues and customers as required by the role.Commitment to Non-DiscriminationAll qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, local, or international law.SummaryLocation: Aberdeen Proving Ground, MD; Alexandria, VAType: Full time
- Chenega MIOS in Arlington, VA seeks a Lead Senior Security Control Assessor (SCA) to guide RMF-based assessments and continuous monitoring for DoD-related information systems. You will coordinate SAPs, SARs, and POA&Ms, and advise leadership on risk posture and mitigations...Suggested
$159.2k
Req ID: 42079 Summary Security Control Assessor (SCA) Arlington, VA Are you ready to enhance your skills and build your career in a rapidly evolving... ...look for new ways to maintain a culture where we excel and lead healthy, happy lives. Corporate citizenship Chenega MIOS...SuggestedWork at office- Northern Technologies Group (NTG) is seeking an experienced Security Control Accessor to provide expert-level support to the Department of Defense... ...SAP environments. Essential Duties and Responsibilities Lead Risk Management Framework (RMF) activities, including the...SuggestedContract workLocal areaMonday to FridayShift work
- ...Competitive salary About this Role We are looking for a SME Security Control Assessor that supports security control assessment activities for... ...assisting with vulnerability scanning and analysis. The assessor leads security control interviews, supports continuous monitoring...SuggestedWork at officeLocal areaWork from homeFlexible hours
- Amatriot Group, LLC is actively seeking a Security Control Assessor to perform comprehensive assessments of information system security controls, covering collateral, SCI, and SAP activities. The role emphasizes RMF-based evaluations, control effectiveness, and recommendations...Suggested
- Security Control Assessor (SCA), Level I Arlington, VA Role: Security Control Assessor (SCA), Level I Location: Arlington, VA Clearance Required: TS/SCI Polygraph: CI Position Description The SCA is responsible for conducting a comprehensive assessment of the management...Contract workLocal area
- Job Title: SecurityControl Assessor Location: On Site in Arlington, VA Department: CyberSecurity Services Reports To: Management FLSA... ...the ability to obtain SCI with CI Polygraph JobPurpose: The security control assessor (SCAs) supports a critical, objective role to...Full timeWork at office
- Apavo Corporation is seeking a Security Control Assessor to perform RMF-based security assessments for DoD/IC systems. You will use automated and manual testing, support RMF activities, and provide guidance to ensure controls are integrated into system designs. The role...
$169k - $171.5k
...as new positions become available. Location: Crystal City, VA Security Clearance: Active TS/SCI [Required] (Must be able to obtain a... ...which may impact salary Position Overview The Security Control Assessor (SCA) is responsible for conducting comprehensive assessments...Full time- CCI International Inc. seeks a Security Control Assessor / IA Specialist in the Alexandria, VA area to provide information assurance for digital systems and ensure compliance with security frameworks. You will plan and execute RMF-based assessments, validate control implementation...
- CACI International in Alexandria, VA is seeking a Security Control Assessor / IA Specialist with robust RMF and NIST controls expertise to assess and authorize complex information systems. You will plan and perform independent security control assessments, validate remediation...
$86.6k - $181.8k
Job Title: Security Control Assessor / IA SpecialistJob Category: SecurityTime Type: Full timeMinimum Clearance Required to Start: SecretEmployee... ...with minimal supervision.Desired:• Experience leading small technical teams or workgroups.• Practical knowledge of...Contract workWork experience placementLocal areaFlexible hours- General Dynamics - IT seeks a Security Control Assessor (SCA) II to conduct comprehensive assessments of management, operational, and technical security controls for IS and its environment. The role evaluates weaknesses, documents SARs, and recommends corrective actions...
- Chenega MIOS is seeking a Security Control Assessor in Arlington, VA to help manage RMF/DoD security authorizations. You will lead risk assessments, craft SAP/SAR/SAP documents, and guide continuous monitoring efforts while coordinating with A&A leadership. Ideal candidates...
- Security Control Assessor (SCA) LOCATION Tysons, VA 22182 CLEARANCE TS/SCI Full Poly (Please note this position requires full U.S. Citizenship) KEY SUMMARY We are seeking a meticulous and detail-oriented **Security Control Assessor (SCA)** to join our team and ensure that...Temporary workFor contractorsImmediate startFlexible hours
- ...Owned Small Business. SUBJECT MATTER EXPERTS specializing in security and risk management. We’re intimately familiar with DOD... ...plan. At Watermark, our people come first! Security Control Assessor (SCA) II The SCA is responsible for conducting a comprehensive...Hourly payFull timeContract workWork experience placementLocal area
$80k - $110k
Job Title: Security Control Assessor Location: Silver Spring, MD Clearance Required: None Salary Range: $80K - $110K Application Deadline: June 30, 2026 To apply, please follow these steps: Visit Select the position you are interested in Review the job details,...- General Dynamics Information Technology is seeking a Security Control Assessor to own security assessments, write final reports, defend findings, and drive mitigation strategies on customer sites in Bethesda, MD. The role requires 6+ years in cybersecurity, SCA experience...
$150k - $168k
...is seeking a Please Note: This position is contingent upon contract award. ECS seeks a Job Description ECS is seeking a Security Controls Assessor to work in our Washington, DC (hybrid) office. Please Note: This position is contingent upon contract award. ECS seeks a...Long term contractFull timeContract workWork at officeLocal areaImmediate start- ...value to clients through tailored solutions based on industry-leading practices. ProSidian provides enterprise services/... ...To the ProSidian website at DescriptionProSidian Seeks a Security Controls Assessor / ISSO | Human Capital Programmatic Evaluation & Compliance...Full timeContract workTemporary workFor contractorsH1bWork at officeFlexible hours
$140k - $210k
Overview VTG is looking for multiple levels (Level 2, 3 & 4) of a Security Control Assessor (SCA) in multiple locations. (Note: position is contingent upon program award and the postions are located in Chantilly VA, Aurora CO, Springfield VA, Las Cruces NM, & LAAFB.) What...For contractorsWork experience placement$160k - $180k
...delivers high-impact, technical solutions to complex national security issues. With over 50 years of business expertise and... ...Force Assessments. SPA has an immediate need for a Security Controls Assessor (SCA). #FC #Dice Responsibilities The Security Controls Assessor...Immediate startFlexible hours- ...to support our nation's defense. Make an impact by connecting and securing critical operations across the globe, keeping our country safe and secure. Job Description The Security Control Assessor (SCA) II is responsible for conducting a comprehensive assessment...
$102.83k - $150k
...Exempt Anticipated Salary Range: $102,831.00 - $150,000.00 Security Clearance: TS/SCI Level of Experience: Mid The selected... ...clearance will be required. What you will do The Security Controls Assessor plays a critical role in evaluating, validating, and strengthening...Full timeWork experience placementLocal area$95k - $105k
...addressing intricate issues and ensuring a more secure future. AGE Solutions is looking for Senior Security Control Assessors to join our team in support of a cybersecurity... ..., test plans, and scope with the SCA Team Lead. Perform vulnerability assessments, capture...Contract workImmediate start- ...rockITdata is a unique SDVOSB services company that partners with leading commercial healthcare/life sciences organizations on... ...the American taxpayer and consumer. Join rockITdata as a Security Control Assessor / ISSE Support supporting one of the nation's largest...Full time
- ...401K, an Employee Stock Purchase Plan (ESPP) through Tetra Tech, and more! Responsibilities:Execute all phases of cyber security and privacy control assessment supportRequired Qualifications:Masters Degree in a Technical or Cyber-related Field7+ years of Relevant Cybersecurity...
- ...SECRET/SCI The SCA is responsible for conducting a comprehensive assessment of the management, operational, and technical security controls employed within or inherited by an IS to determine the overall effectiveness of the controls (i.e., the extent to which the controls...
$149.6k - $254.32k
...and systems. Intelligence & Security provides services and products... ...camaraderie and a shared ambition to lead the world in defense... ...analytics, firewalls, network access controls and bandwidth service... ...actively seeking Security Controls Assessor (SCA) with a minimum of 11...Full timePart timeFor contractorsLocal areaRemote workWorldwideFlexible hours$130k - $170k
...Title: Security Control Assessor Representative (SCAR) KBR is seeking a Security Control Assessor Representative (SCAR) to join our team. Why... ...network systems. Alongside the TRMC Cybersecurity Team Lead develop and implement cybersecurity independent audit processes...Full timeTemporary workWork experience placementLocal areaRelocation packageFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security Control Assessor, Lead. Be the first to apply!

