Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Security Control Assessor

Crest Security Assurance

Job Description

Job Description

Support the Defense Contract Management Agency (DCMA) Cybersecurity Support Services (CSS) contract by independently assessing security controls for classified and unclassified information systems. Plan and execute security control assessments in accordance with DoDI 8510.01, the DoD Risk Management Framework (RMF), NIST SP 800-53, and NIST SP 800-53A, and provide objective evidence and risk-based recommendations to support authorization decisions and continuous monitoring.

Responsibilities:

• Develop and execute Security Assessment Plans (SAPs), including assessment scope, methodology, procedures, schedules, and evidence requirements, in coordination with system owners, Information System Security Officers (ISSOs), Information System Security Managers (ISSMs), and Authorizing Official staff.

• Assess implemented technical, operational, and management security controls through documentation review, interviews, observation, testing, and analysis of artifacts such as vulnerability scan results, Security Technical Implementation Guide (STIG) checklists, configuration baselines, and continuous monitoring records.

• Document assessment results, findings, and residual risk in Security Assessment Reports (SARs), Security Control Assessment Reports (SCARs), Risk Assessment Reports (RARs), and related RMF artifacts; validate that findings are accurate, traceable, and supported by sufficient evidence.

• Review Plans of Action and Milestones (POA&Ms) and remediation evidence, evaluate proposed mitigations, and perform closure validation or follow-up testing to confirm that identified weaknesses have been effectively addressed.

• Maintain assessment results, control status, evidence, and authorization documentation in the Enterprise Mission Assurance Support Service (eMASS); track assessment activities and provide status, risk, and performance metrics to DCMA leadership.

Requirements:

• Active Secret security clearance

• At least 5-7 years of related cybersecurity, RMF, security control assessment, or information assurance experience

• DoD IAM III required certification(s) (one of the following):

  • CISM
  • CISSP (or Associate)
  • GSLC
  • CCISO

Vacancy posted 25 days ago
Similar jobs that could be interesting for youBased on the Security Control Assessor in Fort Lee, VA vacancy
  • A leading claims adjustment firm in Virginia is seeking Independent Insurance Claims Adjusters. This opportunity offers valuable career growth and training programs designed to enhance your skills. While prior experience is beneficial, all licenses are welcomed, and the...
    Suggested
    Flexible hours

    MileHigh Adjusters Houston

    Hopewell, VA
    4 days ago
  • Description Demonstrates independent judgement, and an advanced knowledge of appraisal techniques and mass appraisal methodology necessary to evaluate and conclude value on unique and difficult property for assessment purposes. Works under general supervision, independently...
    Suggested
    For contractors
    Work at office

    Hopewell Bureau of Fire

    Hopewell, VA
    17 hours ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Security Control Assessor. Be the first to apply!