Security Control Assessor, Lead
$99k - $225kBooz Allen Hamilton
The Opportunity:
The Lead Security Control Assessor directs the SCA workstream and provides independent cybersecurity assessment leadership for CDAO systems and environments to the ISSM. The Lead SCA owns assessment strategy, quality standards, stakeholder coordination, risk adjudication, and final review of Security Assessment Plans (SAPs) and Security Assessment Reports (SARs). The position advises technical leadership and Authorizing Official (AO) stakeholders on control effectiveness, authorization readiness, and residual cybersecurity risk. In this role you will be responsible for developing and governing the assessment approach, schedule, evidence standards, test procedures, and quality-control framework for the SCA team.
What You'll Work On:
Provide eMASS administration, analyze STIG, SCAP, ACAS findings, POA&Ms, architecture, inherited controls, compensating controls, and technical evidence.
Work with the project ISSM to understand customer cybersecurity RMF requirements applicable to the systems in their respective environments.
Lead independent security control assessments in accordance with DoD RMF, NIST guidance, applicable DoD cybersecurity policy, and organizational assessment procedures.
Brief findings and risk recommendations to the ISSM, AO representative, and AO-level stakeholders.
Develop all system applicable RMF Body of Evidence (BOE) documentation ensuring accuracy, relevance, and completion to meet requirements and input BOE documentation into AO approved databases such as eMASS or AO specific SharePoint site.
Review and approve SAPs and SARs for technical accuracy, evidence sufficiency, traceability, consistency, and defensibility before stakeholder delivery.
Coordinate with system owners, ISSMs and ISSOs, cybersecurity engineers, administrators, developers, program leadership, control providers, and AO representatives.
Review system boundaries, data flows, external interfaces, interconnections, inherited controls, common-control dependencies, and significant changes.
Oversee assessment execution for ATO, reauthorization, annual assessment, significant-change assessment, and continuous monitoring activities.
Brief assessment status, systemic risks, unresolved findings, remediation priorities, and authorization recommendations to senior stakeholders.
Mentor assessors, calibrate assessment judgments, and ensure independence and objectivity across the assessment lifecycle.
Develop and maintain strong relationships with stakeholders across the organization
You Have:
8+ years of experience with cybersecurity including substantial DoD or federal RMF, security assessment, security engineering, or authorization
Experience with eMASS, analyzing STIG, SCAP, ACAS findings, POA&Ms, architecture, inherited controls, compensating controls, and technical evidence
Experience leading security control assessments and producing or approving SSPs, SAPs, SARs, POA&Ms, risk assessments, and authorization packages
Experience with administration of Windows, Linux, AWS Cloud, and containerization systems and software configuration
Experience with technical writing, facilitation, quality-assurance, team leadership, and stakeholder-management capabilities
Knowledge of NIST SP 800-53, NIST SP 800-37, DoD RMF, STIGs, vulnerability management, and security-control assessment methodology
Ability to evaluate complex enterprises, cloud, hybrid, containerized, data, and AI-enabled architectures and communicate risks at the AO and executive levels
Ability to lead, organize, and complete various cybersecurity testing events including using applicable automated security scanning tools, system required manual STIGs and SRGs and compiling, reviewing, and analyzing results and providing to the ISSM for review and finalization
TS/SCI clearance
Bachelor's degree in a technical field such as Engineering or Cyber
Nice If You Have:
Experience reviewing system connection requests for completion and ensure that requirements are met and make recommendations to the ISSM for approval
Experience performing dynamic security assessments triggered by system changes, threat changes, vulnerabilities, incidents, or mission conditions
Ability to communicate cybersecurity test result outcomes, risks, and suggest fixes to the project engineering team to fix or mitigate potential risks and document Plan of Action and Milestone (POA&M) development and tracking, driving remediation of vulnerabilities to a level acceptable to the Authorizing Official (AO)
Ability to adjudicate complex findings, evaluate compensating controls and mitigations, validate risk determinations, and advise on residual mission risk
Ability to lead quarterly Cyber Resilience and Continuous Monitoring reviews
Clearance:
Applicants selected will be subject to a security investigation and may need to meet eligibility requirements for access to classified information; TS/SCI clearance is required.
Compensation
At Booz Allen, we celebrate your contributions, provide you with opportunities and choices, and support your total well-being. Our offerings include health, life, disability, financial, and retirement benefits, as well as paid leave, professional development, tuition assistance, work-life programs, and dependent care. Our recognition awards program acknowledges employees for exceptional performance and superior demonstration of our values. Full-time and part-time employees working at least 20 hours a week on a regular basis are eligible to participate in Booz Allen’s benefit programs. Individuals that do not meet the threshold are only eligible for select offerings, not inclusive of health benefits. We encourage you to learn more about our total benefits by visiting the Resource page on our Careers site and reviewing Our Employee Benefits page.
Salary at Booz Allen is determined by various factors, including but not limited to location, the individual’s particular combination of education, knowledge, skills, competencies, and experience, as well as contract-specific affordability and organizational requirements. The projected compensation range for this position is $99,000.00 to $225,000.00 (annualized USD). The estimate displayed represents the typical salary range for this position and is just one component of Booz Allen’s total compensation package for employees. This posting will close within 90 days from the Posting Date.Identity Statement
As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during interviews and assessments. We reserve the right to take your picture to verify your identity and prevent fraud.
Candidate AI Usage Policy
AI is a part of our daily work at Booz Allen, and we are committed to the responsible and ethical use of AI tools. However, we want to ensure a fair candidate process based on your own skills and knowledge. As part of this commitment, the use of artificial intelligence (AI) or other tools to assist with responses during interviews (whether in-person or virtual) is prohibited unless permission is explicitly provided .
Work Model
Our people-first culture prioritizes the benefits of collaboration, whether it occurs in person or virtually. To support engagement and effective communication, employees working virtually are generally expected to have their cameras on during meetings.
Remote : If this position is listed as remote, there may still be occasions when you are required to work in person at a Booz Allen or customer facility.
Hybrid : If this position is listed as hybrid, you will be expected to work from a Booz Allen facility frequently, in alignment with leadership expectations and the needs of the role. You may also be required to work from or visit a customer facility.
Onsite : If this position is listed as onsite, work will primarily be performed at a Booz Allen office or customer facility, where employees will collaborate directly with colleagues and customers as required by the role.
Commitment to Non-Discrimination
All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, local, or international law.
- ...401K, an Employee Stock Purchase Plan (ESPP) through Tetra Tech, and more! Responsibilities:Execute all phases of cyber security and privacy control assessment supportRequired Qualifications:Masters Degree in a Technical or Cyber-related Field7+ years of Relevant Cybersecurity...Suggested
- ...value to clients through tailored solutions based on industry-leading practices. ProSidian provides enterprise services/... ...To the ProSidian website at DescriptionProSidian Seeks a Security Controls Assessor / ISSO | Human Capital Programmatic Evaluation & Compliance...SuggestedFull timeContract workTemporary workFor contractorsH1bWork at officeFlexible hours
- ...Position Overview The Security Control Assessor must fulfill a variety of cybersecurity functions, to include: System Administrator, Enterprise Oversight, certification and accreditation, SAP and SCI assessment and authorization (A&A), Platform Information Technology (...SuggestedLocal area
$112.5k
...Security Control Assessor Leidos is seeking mid- to senior-level Security Control Assessors to join our SCA team. This position requires significant... ...logistics, test plans, and scope with the SCA Team Lead. Perform vulnerability assessments, capture results using...SuggestedDaily paidLocal areaWork from home- ...Position Overview We are seeking an experienced Security Control Assessor to support cybersecurity assessment and authorization activities... ...and alignment with applicable cybersecurity requirements. Lead the review, preparation, and quality assurance of...SuggestedImmediate startFlexible hours
$86.6k - $181.8k
Job Title: Security Control Assessor / IA SpecialistJob Category: SecurityTime Type: Full timeMinimum Clearance Required to Start: SecretEmployee... ...with minimal supervision. Desired: • Experience leading small technical teams or workgroups. • Practical knowledge...Full timeContract workWork experience placementLocal areaFlexible hours$150k - $168k
Job DescriptionECS is seeking a Security Controls Assessor to work in our Washington, DC (hybrid) office. Please Note: This position is contingent upon contract award.ECS seeks a Security Controls Assessor to support a full range of cybersecurity services on a long-term...Long term contractFull timeContract workWork at officeImmediate start$180k - $220k
Modern Technology Solutions, Inc. (MTSI) is seeking a Security Control Assessor (SCA) to support an MTSI contract with the Assistant Secretary of the Air Force, Acquisition, Technology and Logistics. The SCA is responsible for conducting a comprehensive assessment of the...Contract work$160k - $180k
...Security Controls Assessor (SCA) Systems Planning and Analysis, Inc. (SPA) delivers high-impact, technical solutions to complex national security issues. With over 50 years of business expertise and consistent growth, we are known for continuous innovation for our...Immediate startFlexible hours$180k
...Senior Security Control Assessor Quantico, VA, United States Up to $180,000/ year Information Security Leader Cyber Security Engineer Security Analyst Compliance Officer Compliance Analyst Cyber Consultant Security Engineer Security clearance: Currently holds...Work at office- ...Security Control Assessor (SCA) LOCATION Reston, VA 20190 CLEARANCE TS/SCI Full Poly (Please note this position requires full U.S. Citizenship) KEY SUMMARY We are seeking a meticulous and detail-oriented **Security Control Assessor (SCA)** to join our team and ensure that...Temporary workFor contractorsImmediate startFlexible hours
$85.19k - $135k
...Number: 29043 Employment Type: Full Time/Salaried/Exempt | Required Travel: 0‑10% | Security Clearance: TS/SCI | Level of Experience: Mid Summary This position is a Security Controls Assessor (SCA) within HII Mission Technologies’ Cyber and Intelligence division. The role...Full timeLocal area- ...Security Control Assessor (SCA) LOCATION Tysons, VA 22182 CLEARANCE TS/SCI Full Poly (Please note this position requires full U.S. Citizenship) KEY SUMMARY We are seeking a meticulous and detail-oriented **Security Control Assessor (SCA)** to join...Temporary workFor contractorsImmediate startFlexible hours
$140k - $210k
...Overview VTG is looking for multiple levels (Level 2, 3 & 4) of a Security Control Assessor (SCA) in multiple locations. (Note: position is contingent upon program award and the postions are located in Chantilly VA, Auroro CO, Springfield VA, Las Cruces NM, & LAAFB...For contractorsWork experience placement$95k - $105k
...addressing intricate issues and ensuring a more secure future. AGE Solutions is looking for Senior Security Control Assessors to join our team in support of a cybersecurity... ..., test plans, and scope with the SCA Team Lead. Perform vulnerability assessments, capture...Contract workImmediate start- ...Job Description Job Description Security Control Accessor II REQ-26-J-0055 The SCA is responsible for conducting a comprehensive assessment of the management, operational, and technical security controls employed within or inherited by an IS to determine the...Immediate startFlexible hours
- ...to support our nation's defense. Make an impact by connecting and securing critical operations across the globe, keeping our country safe and secure. Job Description The Security Control Assessor (SCA) II is responsible for conducting a comprehensive assessment...
- ...Job Description Job Description Description: Job Title: Security Control Assessor Location: On Site in Arlington, VA Department: Cyber Security Services Reports To: Management FLSA Status: Full Time/Non-exempt Job Purpose: The security control assessor...Full timeWork at office
$169k - $171.5k
...Description Job Description Location: Crystal City, VA Security Clearance: Active TS/SCI [Required] (Must be able to obtain... ...which may impact salary Position Overview The Security Control Assessor (SCA) is responsible for conducting comprehensive assessments...Full time- ...rockITdata is a unique SDVOSB services company that partners with leading commercial healthcare/life sciences organizations on... ...the American taxpayer and consumer. Join rockITdata as a Security Control Assessor / ISSE Support supporting one of the nation's largest...Full time
$140k - $145k
...Dark Wolf Solutions is seeking a Senior Security Control Assessor Representative (SCAR) to conduct independent comprehensive assessments of the management, operation, and technical security controls and control enhancements employed within, or inherited by, an Information...Hourly payWork at office$87k - $198k
...Security Control Assessor and System Certification Specialist, Senior The Opportunity: Function as a Senior System Certification Specialist or Security Control Assessor as part of a team in the performance of Assessment and Authorization (A&A) activities ensuring...Full timeContract workPart timeLocal areaRemote work$130k - $170k
...Title: Security Control Assessor Representative (SCAR) KBR is seeking a Security Control Assessor Representative (SCAR) to join our team. Why... ...network systems. Alongside the TRMC Cybersecurity Team Lead develop and implement cybersecurity independent audit processes...Full timeTemporary workWork experience placementLocal areaRelocation packageFlexible hours$135k - $150k
...Job Description Job Description Dark Wolf Solutions is seeking Security Control Assessor/Representatives (SCA/Rs) to lead security control assessments across high-priority projects. Working at the intersection of cybersecurity engineering, cloud architecture,...Full timeFor contractors- ...Job Description Job Description The Security Control Assessor (SCA) ? Level II serves as a senior technical authority responsible for leading Assessment and Authorization (A&A) activities across the Department of Homeland Security (DHS) Intelligence Enterprise...Interim roleWork at office
$148.75k - $201.25k
...Citizenship Required: Yes Job Description: A career as a Security Control Assessor at GDIT means owning every opportunity to help support and... ...policies and guidance Actively participate in or lead Technical Exchange Meetings (TEMS) and application review boards...Full timeTemporary workPart timeImmediate startRemote workWorldwideFlexible hours$135k - $140k
...Job Description Job Description RiVidium Inc. is seeking a Security Control Assessor who conducts independent comprehensive assessments of the management, operational, and technical security controls and control enhancements employed within or inherited by an information...- ...Job Description Job Description Position Overview RiVidium Inc. is seeking an experienced Security Control Assessor (SCA) ? Level II / Journeyman to support federal cybersecurity assessment, authorization, compliance, and risk management activities. The Security...Contract work
- ...referral program, and educational assistance. Additional details can be found on our website at: Position Title : DHS Security Control Assessor III Location : NCR Clearance : TS/SCI OneZero Solutions is on contract to provide division-wide support for Federal...Full timeContract workWork at office
$123k - $136k
...Job Description Job Description SMS is seeking a Senior Security Controls Assessor and Validator to join our team supporting the United... ...the Risk Management Framework (RMF) and have experience in leading a team of Assessors. Since 1976, SMS has specialized in...Work experience placement
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security Control Assessor, Lead. Be the first to apply!

