Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Security Control Assessor (SCA)

System High Corporation

Position OverviewThe Security Control Assessor must fulfill a variety of cybersecurity functions, to include: System Administrator, Enterprise Oversight, certification and accreditation, SAP and SCI assessment and authorization (A&A), Platform Information Technology (PIT) assessment and authorization, Information Assurance and Technical Security for AIS, Information Technology (IT) Network Administration & Support, and Information System Security Officer support. Will perform the IA tasks necessary to ensure that the existing DARPA IA program meets National, DoD, and DARPA IA standards, and continues to protect and defend DARPA information and Information Systems (IS) by ensuring the confidentiality integrity, availability, authentication, and non-repudiation of the systems.The Senior Cybersecurity Specialist possesses experience in successfully participating in DoD Special Access Program Joint Certification and Accreditation, Assessment, and Approval events for DoD Joint cyber ranges and/or jointly accredited SAP information systems. The DARPA systems to be protected include systems that process and store information from controlled unclassified (CUI) up to Top Secret, including SAP and SCI caveats/compartments.Duties shall include, but are not limited to the following:Must possess experience in successfully meeting and participating in Defense Information System Agency (DISA), National Security Agency, and USCBYERCOM Computer Network Defense Program (CNDSP) and CBYERCOM Computer Readiness Inspections (CCRI)Experience with network security devices, classified Local Area Networks, Wide Area Networks, public key infrastructure (PKI), virtual machines, and end-point security solutions.Must be thoroughly familiar with, understand, and be able to apply the standards and requirements contained in the following:DoD Instruction 5220.22 National Industrial Security Program (NISPOM) Operating Manual, Chapter 8Defense Security Service Manual for the Certification and Accreditation of Classified Systems under the NISPOM Version 3.2DoD Directive 5205.16 The DoD Insider Threat ProgramNIST SP 800-53 Rev. 4, Security and Privacy Controls for Federal Information Systems and OrganizationsDoD Joint Special Access Program Implementation Guide (JSIG)Committee for National Security System Policy (CNSSP) Policy (CNSSP) No. 22 on Information Assurance Risk Management for National Security SystemsCNSSP No. 26 National Policy on Reducing the Risk of Removable MediaCommitted for National Security Systems Directive (CNSSD) No. 504 Directive on Protecting National Security Systems From Insider ThreatCommittee for National Security System Instruction (CNSSI) No. 1253 Security categorization and Control Selection for National Security SystemsDoDD 8000.1, Management of DoD Information Resources and Information TechnologyDoD Directive 8100.2, Use of Commercial Wireless Devices, Services, and Technologies in the DoD Global Information Grid (GIG)DoDD 8140.01 Cyberspace Workforce ManagementDoDI 8500.01 CybersecurityDoD Instruction 8510.01 Risk Management Framework (RMF) for DoD Information TechnologyDoD Directive 8530.1, Computer Network Defense (CND)DoD Instruction 8530.2, Support to CNDDoD Instruction 8551.1, Ports, Protocols, and Services Management (PPSM)DoD Manual 8570.01-M Information Assurance Workforce Improvement ProgramDCID 6/3, Protecting SCI within Information SystemsIntelligence Community Directive (ICD) 503Chairman of the Joint Chiefs of Staff Manual (CJCSM) 6510.01B Cyber Incident Handling ProgramDefense Federal Acquisition Regulation Supplement (DFARS)Clause View phone number on click.appcast.io: Safeguarding Unclassified Controlled Technical InformationDoDI 8581.01 Information Assurance Policy for Space Systems Used by the Department of DefenseNote: The legacy cybersecurity/information security accreditation governance documents are listed due to the state of transition of network accreditation guidance and the fact that networks may be operating under legacy certification and accreditation guidance.Ensure system security requirements are addressed during all phases of DARPA program life cycles (concept development, Request for Information (RFI), Request for Proposal (RFP) or BAA, Proposal, Selection, Award, Closeout, Transition, etc.).Planning, preparing, and executing inspections, authorization and approval (A&A) events IAW with the respective policies detailed in paragraph 3.12.c. for all classifications of networks; to include the development and review of Automated Information System Authorization and Approval Packages.Develop, review, endorse, and recommend action by the authorizing official (AO), delegated authorizing official (DAO), or designated approval authority (DAA) for system certification documentationConduct quality control of system accreditation packages for completeness of accreditation artifacts within 3 business days of receipt from the technology office security staffs or their cleared defense industry contractors and/or participating government agencies.Process authorization and approval or denial documentation to the respective DAPRA AO/DAO/or DAA within 10 business days of receipt of a complete packageConduct security control assessments for the evaluation of security controls to determine the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for an AISProvide an assessment of the severity of weaknesses or deficiencies discovered in the information system and its environment of operation and recommend corrective actions to address identified vulnerabilitiesAnalyze and make recommendations in support of DARPA accredited network Configuration Control Board cases within 10 calendar days of case validation by the respective network’s Information System ownerMonitor activities of DARPA accredited networks and DARPA DAO Accredited performer networksProvide advice, assistance, and analysis of threats and vulnerabilities and risk mitigation and acceptance recommendations, as required. Conduct certification tests that include verification that the features and assurances are functional and support accreditationWork collaboratively with the MSO/Information Technology Directorate (ITD) in the authorization and approval and continuous monitoring of DARPA unclassified and classified networks; including but not limited to:DARPA Management Security System (DMSS) – UnclassifiedDARPA Public Network (DPN) - UnclassifiedDARPA Secret Network (DSN)/Secret Internet Protocol Router Network (SIPRNet) Connection – up to SECRET CollateralDARPA Joint Worldwide Intelligence Communications System (JWICS) Network (DJN)/JWICS Connections – up to TOP SECRET SCIDARPA Secure Wide Area Network (DSWAN) – up to SECRET CollateralMulti-Level Security System (SAVANNAH) – up to TOP SECRET SAP and SCIReview and recommend changes or amplification of policy, procedures, and strategy developmentEvaluate Information Assurance (IA) products and provide written recommendations as to their risk and usefulness and/or adoption for the DARPA IA missionEvaluate information technology (IT) vulnerabilities to assess whether additional safeguards are prudent and ensure certification is accomplished for each information systemDevelop and maintain a formal, written Information Systems Security Program SOPEnsure all Information System Security Officers (ISSO), network administrators, and other Automated Information Security (AIS) personnel, to include DARPA performers performing these functions, receive the necessary and required technical and security training to carry out their dutiesEnsure development and implementation of an information security education, training, and awareness program, to include attending, monitoring, and presenting local AIS security training.Maintain a repository for all system certification/accreditation documentation and modificationsCoordinate AIS security inspections, tests, and reviewsPrepare policies and procedures for responding to security incidents and for investigating and reporting security violations and incidentsEnsure proper protection or corrective measures have been taken when an incident or vulnerability has been discoveredAssess changes in a system, its environment, or operational needs that could affect the accreditationEnsure configuration management (CM) for security-relevant AIS software, hardware, and firmware is maintained and documentedPerform system audits on multiple systems; work closely with system administrators and ensure current security measures are sufficient and in compliance with approved policies and processesPerform, and conduct training as required, for the execution of secure file transfers/trusted downloads between local systems to storage devices, this includes secure down writing of data between systems of different security levelsProvide technical advice and assistance, as required, and perform technical oversight on telecommunications requirements for Collateral, SAP, and SCI systems and networksIn coordination with SID Emergency Management, review and provide AIS security relevant input to DARPA Emergency/Disaster plans and procedures.Required Skills (Knowledge, Skills, Abilities)Relevant work experience as specified for an Information Assurance Technical (IAT) Level III or Information Assurance Management (IAM) Level II in DoD Manual 8570.1-MExtensive knowledge of RMF (Risk Management Framework)Experience assessing and authorizing various PIT systems (of all classification levels) including but not limited to; space systems, manned and unmanned aircraft systems, manned and unmanned underwater vessels, cyber operation platforms, cyber capabilities, directed energy systems, and hand-held battle field orientation electronic devicesProfessional Business FunctionsAttend meetings (either locally or out-of-area) and create meeting summaries or trip reportsPrepare and submit meeting minutes on an as-required basisPrepare/present briefings, incorporating graphics (if appropriate) for/to SID/ DARPA leadersPrepare various security forms associated with their dutiesAssist in entry control and perform escort duties for visitorsAnswer telephones and other modes of administrative communications in the performance of dutiesPerform self-inspections, identify security discrepancies, and report security incidentsPerform, or support, security inspections, identify security discrepancies and prepare reportsPerform courier duties within the continental United States (CONUS)Perform user-level security administrator and information security responsibilities are required and in compliance with US Codes, Executive Orders, and DoD and DARPA policyPerform objective reviews on all documentation encountered during performance of dutiesClearanceMinimum of active Top Secret (TS)TS/SCI strongly desiredSubject to a random counter-intelligence scope polygraphs as a condition of access eligibility.Years of Experience/Education RequirementsThe Senior Cybersecurity positions require a Bachelor’s degree in Computer Science or Information Systems with at least 12 years of specific, demonstrable, and successful experience fulfilling a Cybersecurity role for a DoD or IC customer on similar size and scale.A Master’s degree in Computer Science or Information Systems may substitute for 4 years of relevant experience.Certification RequirementsDoD Approved Baseline Certification as a CISSP IAW DoD 8570.1-MTravel RequirementsSome travel is required for this position.Ability to travel to CONUS and/or OCONUS locationsMust have active US passport for OCONUS travel requirementsAdditional InformationThis job description is not designed to cover or contain all job duties required of the employee. There may be additional activities, duties and/or responsibilities that are required for this position that are not listed in this job description.In compliance with federal law, all persons hired will be required to verify identity and eligibility to work in the United States and to complete the required employment eligibility verification document form upon hire.System High is a Military friendly employer. Our extensive work on behalf of the U.S. government offers those who have served in uniform an opportunity to continue to serve their country in a new and exciting way while enjoying a successful civilian career.System High values the power and strength of diverse backgrounds on the culture and performance of our company. We strive to maintain an inclusive culture to encourage each employee to bring their whole self to the mission.System High Corporation is committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender, gender identity or expression, veteran status, or any other characteristic protected by law. We are proud to be an equal opportunity workplace.If you require a reasonable accommodation to apply for a position with us, please email View email address on click.appcast.io notices can be viewed on the following PDFs: Know Your Rights: Workplace Discrimination is Illegal; EPPA Notice; FMLA NoticeWarning: Beware of recruitment scams: System High will never request money or personal purchases during the hiring process. Verify all communications come from a systemhigh.com or msg.paycomonline.com email address. #J-18808-Ljbffr System High Corporation

Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the Security Control Assessor (SCA) in Arlington, VA vacancy
  • The Security Control Assessor (SCA) II is responsible for conducting a comprehensive assessment of the management, operational, and technical security controls employed within or inherited by an IS to determine the overall effectiveness of the controls (i.e., the extent... 
    Suggested

    General Dynamics - IT

    Arlington, VA
    2 days ago
  • Security Control Assessor (SCA), Level I Arlington, VA Role: Security Control Assessor (SCA), Level I Location: Arlington, VA Clearance Required: TS/SCI Polygraph: CI Position Description The SCA is responsible for conducting a comprehensive assessment of the management... 
    Suggested
    Contract work
    Local area

    TAC Integrated Solutions

    Arlington, VA
    2 days ago
  • $102.83k - $150k

     ...Range: $102,831.00 - $150,000.00 Security Clearance: TS/SCI Level of...  ...the salary ranges: Security Controls Accessor: $85,185 - $135,000Sr...  ...will doThe Security Controls Assessor plays a critical role in...  ...across the organization.The SCA is responsible for:-Reviewing... 
    Suggested
    Full time
    Work experience placement
    Local area
    Worldwide

    HII Mission Technologies Division

    Springfield, VA
    13 hours ago
  • $131.6k

     ...Summary Security Control Assessor (SCA) Oakton, VA Are you ready to enhance your skills and build your career in a rapidly evolving business climate? Are you looking for a career where professional development is embedded in your employer’s core culture? If so, Chenega... 
    Suggested

    Chenega Agile Real Time Solutions, LLC

    Oakton, VA
    1 day ago
  •  ...Position OverviewThe Security Control Assessor must fulfill a variety of cybersecurity functions, to include: System Administrator, Enterprise Oversight, certification and accreditation, SAP and SCI assessment and authorization (A&A), Platform Information Technology (PIT... 
    Suggested
    For contractors
    Work experience placement
    Work at office
    Local area
    Worldwide

    System High Corp

    Arlington, VA
    1 day ago
  •  ...Security Control Assessor (SCA) LOCATION Reston, VA 20190 CLEARANCE TS/SCI Full Poly (Please note this position requires full U.S. Citizenship) KEY SUMMARY We are seeking a meticulous and detail-oriented **Security Control Assessor (SCA)** to join our team and ensure... 
    Temporary work
    For contractors
    Immediate start
    Flexible hours

    Cymertek

    Reston, VA
    1 day ago
  • $160k - $172k

     ...Title: Security Control Assessor (SCA) Belong. Connect. Grow. with KBR! KBR's National Security Solutions team provides high-end engineering and advanced technology solutions to our customers in the intelligence and national security communities. In this position... 
    Full time
    Contract work
    Temporary work
    Local area
    Relocation package
    Flexible hours

    KBR

    Washington DC
    10 days ago
  • $150k - $168k

     ...contract award. ECS seeks a Job Description ECS is seeking a Security Controls Assessor to work in our Washington, DC (hybrid) office. Please Note:...  ..., Security Plans, Security Controls Assessments (SCA), and related documentation Current industry practices for... 
    Long term contract
    Full time
    Contract work
    Work at office
    Local area
    Immediate start

    ECS Limited

    Washington DC
    1 day ago
  • $160k - $180k

     ...delivers high-impact, technical solutions to complex national security issues. With over 50 years of business expertise and...  ...Force Assessments. SPA has an immediate need for a Security Controls Assessor (SCA). #FC #Dice Responsibilities The Security Controls Assessor... 
    Immediate start
    Flexible hours

    Systems Planning & Analysis

    Washington DC
    3 days ago
  • $107.9k - $195.05k

    SCI Security Controls Assessor Representative A&A SpecialistLocation: Suitland, MDClearance: Active TS/SCILeidos is seeking a SCI Security Controls Assessor Representative A&A Specialist to join our team in Suitland, MD. In this role, you will support the assessment and... 
    Full time
    Interim role
    Work at office
    Worldwide

    Leidos

    Suitland, MD
    2 days ago
  • General Dynamics - IT seeks a Security Control Assessor (SCA) II to conduct comprehensive assessments of management, operational, and technical security controls for IS and its environment. The role evaluates weaknesses, documents SARs, and recommends corrective actions... 

    General Dynamics - IT

    Arlington, VA
    2 days ago
  • 38North Security is the world’s most experienced, technically expert, cloud advisory team...  ...environments against NIST SP 800-53 rev 5 security control requirements. Systems assessed could...  ...to obtain a Public Trust Clearance Assessor must be able to conduct assessment... 
    Local area
    Remote work
    Flexible hours

    38North Security

    Washington DC
    3 days ago
  •  ...401K, an Employee Stock Purchase Plan (ESPP) through Tetra Tech, and more! Responsibilities:Execute all phases of cyber security and privacy control assessment supportRequired Qualifications:Masters Degree in a Technical or Cyber-related Field7+ years of Relevant Cybersecurity... 

    EGlobalTech

    Arlington, VA
    1 day ago
  • General Dynamics Information Technology (GDIT) is seeking a Security Control Assessor II to conduct comprehensive assessments of security controls for information systems, including SAP/SCI environments, to determine effectiveness and identify weaknesses. The role requires... 

    General Dynamics Information Technology

    Arlington, VA
    2 days ago
  • $146k - $234k

    ResponsibilitiesPeraton seeks a Cloud Security Control Assessor to support the Army Cyber Command (ARCYBER). Location: Alexandria, VA/Metro Park near Fort Belvoir, VA.Tasks include:Conduct assessments and facilitate risk mitigation planningProvide Assessment and Authorization... 
    Contract work
    Local area
    Shift work

    Peraton Corporation

    Alexandria, VA
    3 days ago
  •  ...assets, processes, policies, and people delivering value. See Link To the ProSidian website at DescriptionProSidian Seeks a Security Controls Assessor / ISSO | Human Capital Programmatic Evaluation & Compliance - Cybersecurity & Compliance [NSF0083083] for Program Support... 
    Full time
    Contract work
    Temporary work
    For contractors
    H1b
    Work at office
    Flexible hours

    Prosidian Consultng

    Alexandria, VA
    3 days ago
  • Chenega MIOS in Oakton, VA seeks a Security Control Assessor (SCA) to evaluate security controls for information systems. You will serve as the primary liaison between system owners and security stakeholders, guiding RMF and A&A processes while ensuring policy alignment... 

    Chenega Agile Real Time Solutions, LLC

    Oakton, VA
    1 day ago
  • $87k - $198k

     ...Security Control Assessor and System Certification Specialist, Senior The Opportunity: Function as a Senior System Certification Specialist...  ...in NIST security guidance and security control assessment (SCA) processes using the NIST Risk Management Framework (RMF). Guide... 
    Full time
    Contract work
    Part time
    Local area
    Remote work

    Booz Allen Hamilton

    Arlington, VA
    more than 2 months ago
  •  ...Job#: 3044387 Job Description: Security Control Assessor Location: Alexandria, Virginia (Onsite) Role Overview We are seeking a skilled and detail-oriented Security Control Assessor to join our team. The successful candidate will be responsible for evaluating, testing,... 

    Apex Systems

    Alexandria, VA
    3 days ago
  • Chenega MIOS in Oakton, VA seeks a Security Control Assessor (SCA) to evaluate and validate security controls for information systems and coordinate with system owners and security teams to expedite agency approvals. The ideal candidate understands governance, policy,... 

    Chenega MIOS SBU

    Oakton, VA
    4 days ago
  • Everforth Apex is seeking a Security Control Assessor in Alexandria, VA to evaluate, test, and validate security controls within information systems, with RMF emphasis. You will develop A&A artifacts, SARs, SSPs, and POA&Ms, and guide remediation actions through authorization... 

    Apex Systems

    Alexandria, VA
    4 days ago
  • $146k - $234k

    About Peraton Peraton is a next-generation national security company that drives missions of consequence spanning the globe and extending...  ...and secure. About The Role Peraton seeks a Cloud Security Control Assessor to support the Army Cyber Command (ARCYBER). Location:... 
    Contract work
    Temporary work
    Local area
    Shift work

    Peraton

    Alexandria, VA
    3 days ago
  •  ...government entities to deliver predictable, measurable impact for the American taxpayer and consumer. Join rockITdata as a Security Control Assessor / ISSE Support supporting one of the nation's largest federal healthcare modernization initiatives. In this role, you'll... 
    Full time
    Local area

    rockITdata

    Arlington, VA
    a month ago
  • $87.1k - $157.45k

    SCI Security Controls Assessor Liaison SpecialistLocation: Suitland, MDClearance: Active TS/SCILeidos is seeking a Security Controls Assessor Liaison to support the Assessment & Validation Division within the Office of Naval Intelligence at the Hopper Global Communications... 
    Full time
    Interim role
    Work at office

    Leidos

    Suitland, MD
    2 days ago
  •  ...Cybersecurity Specialist to perform a broad range of DoD/IC cybersecurity duties, including A&A for complex systems, RMF implementation, and security assessments. The role involves collaboration with DARPA program teams to protect highly sensitive information and ensure... 

    System High Corporation

    Arlington, VA
    2 days ago
  • Peraton seeks a Cloud Security Control Assessor to support Army Cyber Command (ARCYBER). Location: Alexandria, VA/near Fort Belvoir. Responsibilities include risk mitigation planning, A&A for ARCYBER cloud infrastructure, and maintaining the System Security Plan under NIST... 

    Peraton

    Alexandria, VA
    3 days ago
  • Security Assessor (RMF / GRC) Location: Bethesda, MD (Hybrid; On-site as Required) Clearance: Tier 2 Public Trust (Required) Employment Type...  ..., documenting, and reporting comprehensive security control assessments that evaluate the effectiveness of administrative... 
    Full time
    Work at office

    Digital Global Connectors

    Mc Lean, VA
    2 days ago
  • Digital Global Connectors (DGC) is seeking an experienced Security Assessor (RMF / GRC) to support a Federal information security program. The...  ..., documenting, and reporting comprehensive security control assessments that evaluate the effectiveness of administrative... 

    Digital Global Connectors

    Mc Lean, VA
    2 days ago
  • $140k

     ...Job Title: Mid-Level Security Control Assessor Location: Bethesda, Maryland Type: Direct Hire Salary: $140,000 range annually, plus benefits Work Model: Hybrid – onsite and remote Hours: 40.0/week Security Clearance: Public Trust Work expected to begin... 
    Local area
    Remote work

    System One

    Bethesda, MD
    a month ago
  • $100k - $115k

     ...026 Clearance / Public Trust: Public Trust eligibility (Tier 2/3) required About the role We’re hiring a Junior Security Control Assessor to support independent security control assessments across the system authorization lifecycle. You’ll work under a senior... 
    Local area
    Remote work

    System One

    Bethesda, MD
    a month ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Security Control Assessor (SCA). Be the first to apply!