Security Control Assessor (SCA) — Level II
Rividium Inc
The Security Control Assessor (SCA) - Level II serves as a senior technical authority responsible for leading Assessment and Authorization (A&A) activities across the Department of Homeland Security (DHS) Intelligence Enterprise (DHS IE). This position conducts comprehensive security control assessments for classified and unclassified information systems, cloud environments, Cross Domain Solutions (CDS), and C-LAN extension sites in support of the NIST Risk Management Framework (RMF) and DHS/Intelligence Community (IC) cybersecurity requirements. The Security Control Assessor provides expert guidance on security control implementation, risk management, continuous monitoring, and authorization package development while working closely with System Owners, Information System Security Officers (ISSOs), Information System Security Managers (ISSMs), Security Engineers, Government Authorizing Officials (AOs), Security Control Assessor Representatives (SCARs), Branch Chiefs, and the DHS I&A Chief Information Security Officer (CISO). The successful candidate will possess extensive experience leading complex A&A efforts for enterprise systems operating in classified, hybrid, cloud, and Cross Domain Solution environments. Key Responsibilities Lead comprehensive Assessment and Authorization (A&A) activities for DHS Intelligence Enterprise information systems operating in Top Secret/Sensitive Compartmented Information (TS/SCI), Secret, and Unclassified environments. Conduct security assessments for enterprise systems hosted in: On-premises data centers
DHS DICE
Commercial Cloud Enterprise (C2E) Intelligence Community (IC) Cloud AWS GovCloud Hybrid cloud environments Cross Domain Solution (CDS) environments CONUS and OCONUS C-LAN extension sites Lead project discovery sessions, kickoff meetings, and stakeholder engagements for new system authorizations, reauthorizations, and major system changes. Assess the implementation and effectiveness of NIST security controls and document findings within the Security Assessment Report (SAR) and Governance, Risk, and Compliance (GRC) platform. Identify security control deficiencies, vulnerabilities, and compliance gaps; provide technical recommendations to reduce organizational risk. Validate the accuracy and completeness of Plans of Action and Milestones (POA&Ms), ensuring corrective actions align with identified assessment findings. Monitor remediation activities and verify completion of corrective actions before recommending authorization decisions. Develop and prepare complete Authorization and Assessment packages, including: Authorization to Operate (ATO) Authorization to Connect (ATC) Interim Authorization to Test (IATT) Security Assessment Reports (SARs) Risk Recommendation Memoranda Risk Management Matrices Security Assessment Plans (SAPs) Project kickoff memoranda System Owner acknowledgment letters Conduct technical reviews of System Security Plans (SSPs), Contingency Plans, Configuration Management Plans, and supporting RMF documentation. Maintain and update Assessment and Authorization Standard Operating Procedures (SOPs) for all DHS I&A enclaves, ensuring annual review and compliance with evolving Federal and Intelligence Community requirements. Participate in Office of Inspector General (OIG), Federal Information Security Modernization Act (FISMA), and Intelligence Community Oversight Program (ICOP) audits, inspections, and cybersecurity assessments. Represent the program during DHS and Intelligence Community cybersecurity working groups and technical review boards. Maintain enterprise A&A Project Portfolio Listing Reports and Quarterly A&A Assignment Reports. Research emerging technologies, cybersecurity standards, and automation opportunities to improve A&A efficiency and support ongoing authorization initiatives. Prepare executive briefings, risk summaries, technical presentations, and decision support materials for the DHS I&A CISO, Government leadership, and Authorizing Officials. Mentor junior cybersecurity personnel and provide technical guidance on RMF implementation, security control assessments, and authorization processes. Minimum Qualifications Active Top Secret/Sensitive Compartmented Information (TS/SCI) clearance with SAP eligibility. Minimum 10 years of experience in information security, cybersecurity risk management, or Assessment and Authorization (A&A), including demonstrated experience in: Assessment and Authorization (A&A) Federal Information Security Modernization Act (FISMA) compliance Intelligence Community cybersecurity policy Continuous Monitoring (ConMon) Cross Domain Solutions (CDS) Secure cloud and hybrid cloud environments Current Certified Information Security Manager (CISM), Certified Authorization Professional (CAP), or comparable Governance, Risk, and Compliance (GRC) certification. Certified Information Systems Security Professional (CISSP) certification is highly desirable. Expert knowledge of: NIST Risk Management Framework (RMF)NIST SP 800-37
NIST SP 800-53
NIST SP 800-53A
CNSSI 1253
ICD 503
DHS Sensitive Systems Policy Directive 4300C Intelligence Community security overlays and authorization requirements Experience using Governance, Risk, and Compliance (GRC) platforms such as RSA Archer. Experience using security assessment and vulnerability management tools, including: Nessus SCAP Nmap WebInspect SonarQube Comparable security assessment tools Demonstrated experience leading A&A activities for Cross Domain Solutions (CDS), classified information systems, and cloud-based environments. Bachelor's degree in Cybersecurity, Computer Science, Information Systems, Information Assurance, or a related technical discipline. Preferred Qualifications AWS Certified Security - Specialty, Microsoft Certified: Azure Security Engineer Associate, Google Professional Cloud Security Engineer, or equivalent cloud security certification. Experience supporting DHS Intelligence & Analysis (I&A) or other Intelligence Community cybersecurity organizations. Experience conducting Assessment and Authorization activities for OCONUS locations and C-LAN authorization extension sites. Experience supporting National Cross Domain Strategy and Management Office (NCDSMO) accreditation requirements and Raise the Bar (RTB) initiatives. Experience implementing Continuous Authorization (cATO), Agile RMF, or automated security assessment processes. Knowledge of DevSecOps security controls, Infrastructure as Code (IaC), and cloud-native security assessment methodologies. Required Certifications One of the following current certifications is required: Certified Information Security Manager (CISM) Certified Authorization Professional (CAP) Governance, Risk, and Compliance (GRC) Certification Preferred Certifications Include Certified Information Systems Security Professional (CISSP) AWS Certified Security - Specialty Microsoft Certified: Azure Security Engineer Associate Google Professional Cloud Security Engineer Clearance Requirement SAP Eligibility Required Active Top Secret/Sensitive Compartmented Information (TS/SCI) Clearance Required About the Organization Established in 2008, RiVidium, Inc. (dba TripleCyber) is a VA-Verified SDVOSB and an SBA-Certified 8(a) company. To prepare our clients for the future, RiVidium has balanced all parts of our organization to attract the finest employees in order to 'Strive to be the missing element defining tomorrow's technology'. RiVidium keeps pace and surpasses its competitors by meeting challenges of advancements in Logistics, Human Capital, Cyber, Intelligence & Technology. EOE Statement We are an equal employment opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veteran status or any other characteristic protected by law. If you need a reasonable accommodation for any part of the employment process, please contact Human Resources (HR) at View email address on click.appcast.io. #J-18808-Ljbffr Rividium Inc- The Security Control Assessor (SCA) II is responsible for conducting a comprehensive assessment of the management, operational, and technical security... ...are required Advise the Government concerning the impact levels for Confidentiality, Integrity, and Availability for the...Suggested
- Security Control Assessor (SCA), Level I Arlington, VA Role: Security Control Assessor (SCA), Level I Location: Arlington, VA Clearance Required: TS/SCI Polygraph: CI Position Description The SCA is responsible for conducting a comprehensive assessment of the management...SuggestedContract workLocal area
$160k - $172k
...Title: Security Control Assessor (SCA) Belong. Connect. Grow. with KBR! KBR's National Security Solutions... ...the Government concerning the impact levels for confidentiality, integrity, and... ...8570/8140 IAT Level III or IAM Level II/III certification (e.g., CISSP...SuggestedContract workTemporary workLocal areaRelocation packageFlexible hours$140k - $210k
...Overview VTG is looking for multiple levels (Level 2, 3 & 4) of a Security Control Assessor (SCA) in multiple locations. (Note: position is contingent upon... ...and Level 2 qualifications, a compliant IAM Level II certification, and the additional desired qualifications...SuggestedFor contractorsWork experience placement$107.9k - $195.05k
SCI Security Controls Assessor Representative A&A SpecialistLocation: Suitland, MDClearance: Active TS/SCILeidos... ...ranging in years of experience. Level of opportunity, including compensation,... ...Required CertificationsActive IAM Level II or higher certification, such as...SuggestedFull timeInterim roleWork at officeWorldwide$102.83k - $150k
...$102,831.00 - $150,000.00 Security Clearance: TS/SCI Level of Experience: Mid This opportunity... ...salary ranges: Security Controls Accessor: $85,185 - $135,0... ...doThe Security Controls Assessor plays a critical role in... ...the organization.The SCA is responsible for:-Reviewing...Full timeWork experience placementLocal areaWorldwide- ...Title: SecurityControl Assessor Location:On Site inArlington... ...exempt JobPurpose: The security control assessor (SCAs)... ...mitigating security risks.The SCA will support a critical... ...concerning the impact levels for Confidentiality,... ...polygraph. DOD 8140 IAM Level II (CAP, CASP, CISM, CISSP...Full timeWork at office
- ...Security Control Assessor (SCA) LOCATION Tysons, VA 22182 CLEARANCE TS/SCI Full Poly (Please note this position requires full U.S. Citizenship) KEY... ...Security Risk Assessor, Compliance Manager, ect. DEGREE (Level Desired) Bachelor's Degree DEGREE (Focus) Cybersecurity, Information...Temporary workFor contractorsImmediate startFlexible hours
- ...Security Control Assessor (SCA) HII's Mission Technologies division is dedicated to delivering cutting-edge solutions that advance national security... ..., which plays a critical role in supporting Enterprise-Level Security and Modernization efforts across IT...Work experience placement
$160k - $180k
...Security Controls Assessor (SCA) Systems Planning and Analysis, Inc. (SPA) delivers high-impact, technical solutions to... ...570.01-M for Information Assurance Technician Level III or Information Assurance Manager Level II ~ Active TS/SCI and the ability to maintain...Immediate startFlexible hours$112.5k
...Security Control Assessor Leidos is seeking mid- to senior-level Security Control Assessors to join our SCA team. This position requires significant travel—please review the position overview... ...Secret clearance and current IAT/IAM II certification (eg Security+ or...Daily paidLocal areaWork from home- Dark Wolf Solutions is seeking Security Control Assessors/Representatives (SCA/Rs) to lead security control assessments... ...at multiple classification levels. The position is based in Arlington... ...active TS clearance, DoD 8570 IAM Level II/III, and 5-7+ years of security assessment...Remote work
$135k - $160k
Dark Wolf Solutions is seeking Security Control Assessor/Representatives (SCA/Rs) to lead security control assessments... ...across multiple classification levels. This position is ideal for a pragmatic... ...Current DoD 8570/8140 IAM Level II or Level III certification (e.g., Security+...Full timeFor contractorsRemote work- RiVidium is seeking a Security Control Assessor (SCA) Level II to lead complex A&A activities for DHS Intelligence Enterprise across TS/SCI environments. You will assess security controls, prepare SARs, and guide remediation efforts while collaborating with ISSOs, AOs,...
- RiVidium, Inc. is seeking a senior Security Control Assessor (SCA) - Level II to lead A&A activities across the DHS Intelligence Enterprise. You will assess classified and unclassified systems, cloud environments, CDS, and C-LAN sites, guiding RMF compliance and security...
$180k - $220k
...Modern Technology Solutions, Inc. (MTSI) is seeking a Security Control Assessor (SCA) to support an MTSI contract with the Assistant Secretary of... ...required. Advise the Government concerning the impact levels for confidentiality, integrity, and availability for the information...Contract work- ...Position Overview The Security Control Assessor must fulfill a variety of cybersecurity functions,... ...DSWAN) up to SECRET Collateral # Multi-Level Security System (SAVANNAH) up to TOP... ...Information Assurance Management (IAM) Level II in DoD Manual 8570.1-M Extensive...For contractorsWork experience placementWork at officeLocal areaWorldwide
$150k - $168k
...seeks a Job Description ECS is seeking a Security Controls Assessor to work in our Washington, DC (hybrid)... ...and maintain test cases for control-level security testing across system... ...Plans, Security Controls Assessments (SCA), and related documentation Current industry...Long term contractFull timeContract workWork at officeLocal areaImmediate start- ...Position Overview The Security Control Assessor must fulfill a variety of cybersecurity functions, to include: System Administrator, Enterprise Oversight, certification and accreditation, SAP and SCI assessment and authorization (A&A), Platform Information Technology (...Local area
$128.8k - $214.5k
...Senior Security Control Assessor (SCA) Unlock the secrets of intelligence with MANTECH! Join a dynamic team at the forefront of national security... ...with the system owner, regarding systems' impact levels and ISs' authorization boundary Initiate, coordinate, and...Hourly payContract workTemporary workWork experience placementWork at officeLocal areaRemote work- ...Serco has the right opportunity for you! As a Senior Security Control Assessor, you will provide senior-level security control assessment support to a Department... .... Desired Skills Security Control Assessment (SCA) experience within the Department of Defense Environments...Full timeContract workPart timeFor contractorsWork at officeLocal areaMonday to FridayFlexible hours
$87.1k - $157.45k
SCI Security Controls Assessor Liaison SpecialistLocation: Suitland, MDClearance: Active TS/SCILeidos is... ..., Intelligence Community, and national level system security initiatives and secure... ...certification, such as CGRC, CISM, or Security+ II, or the ability to obtain a...Full timeInterim roleWork at office$146k - $234k
ResponsibilitiesPeraton seeks a Cloud Security Control Assessor to support the Army Cyber Command (ARCYBER). Location: Alexandria, VA/Metro Park... ...Will consider HS+16 or Associates +14.Must have current IAM level III certification (such as CISM)Must have knowledge of...Contract workLocal areaShift work- ...To the ProSidian website at DescriptionProSidian Seeks a Security Controls Assessor / ISSO | Human Capital Programmatic Evaluation & Compliance... ...a Systems Engineer Labor Category as a Engagement Team Mid Level Professional aligned under services related to NAICS: 54161...Full timeContract workTemporary workFor contractorsH1bWork at officeFlexible hours
- General Dynamics - IT seeks a Security Control Assessor (SCA) II to conduct comprehensive assessments of management, operational, and technical security controls for IS and its environment. The role evaluates weaknesses, documents SARs, and recommends corrective actions...
$146k - $234k
...Peraton is a next-generation national security company that drives missions of consequence... ...Role Peraton seeks a Cloud Security Control Assessor to support the Army Cyber Command (ARCYBER... ...Associates +14. Must have current IAM level III certification (such as CISM) Must...Contract workTemporary workLocal areaShift work$137k - $152k
...mobilizing the right people, skills, clearance levels, and technologies to help organizations... ..., Data Delivery & Analytics, Cyber Security, Cloud Migration, Applications and... ...Accounting. M9 Solutions is seeking a Security Control Assessor to work on-site in support of a...Full timeContract workFor subcontractor- ...Security Control Assessor (Authorizing Official) Position Summary: As Security Control Assessor... ...assurance documents to confirm that the level of risk is within acceptable limits for... ...Certification Requirements: ~ lAM Level II certification (CAP, CASP+, CISM, CISSP...Full timeWork at officeImmediate startFlexible hours
- ...Security Control Assessor The Security Control Assessor conducts comprehensive assessments of security... ...applicable security requirements. The SCA develops and submits the complete Body... ..., integrity, and availability impact levels in accordance with Risk Management...
- ...Job Description We are seeking a highly skilled Security Control Assessor (SCA) to support independent cybersecurity assessments of systems in accordance with the Risk Management Framework (RMF). This role is responsible for evaluating the implementation and effectiveness...2 days per week
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security Control Assessor (SCA) — Level II. Be the first to apply!

