Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Security Control Assessor (SCA) — Level II

Rividium Inc

The Security Control Assessor (SCA) - Level II serves as a senior technical authority responsible for leading Assessment and Authorization (A&A) activities across the Department of Homeland Security (DHS) Intelligence Enterprise (DHS IE). This position conducts comprehensive security control assessments for classified and unclassified information systems, cloud environments, Cross Domain Solutions (CDS), and C-LAN extension sites in support of the NIST Risk Management Framework (RMF) and DHS/Intelligence Community (IC) cybersecurity requirements. The Security Control Assessor provides expert guidance on security control implementation, risk management, continuous monitoring, and authorization package development while working closely with System Owners, Information System Security Officers (ISSOs), Information System Security Managers (ISSMs), Security Engineers, Government Authorizing Officials (AOs), Security Control Assessor Representatives (SCARs), Branch Chiefs, and the DHS I&A Chief Information Security Officer (CISO). The successful candidate will possess extensive experience leading complex A&A efforts for enterprise systems operating in classified, hybrid, cloud, and Cross Domain Solution environments. Key Responsibilities Lead comprehensive Assessment and Authorization (A&A) activities for DHS Intelligence Enterprise information systems operating in Top Secret/Sensitive Compartmented Information (TS/SCI), Secret, and Unclassified environments. Conduct security assessments for enterprise systems hosted in: On-premises data centers

DHS DICE

Commercial Cloud Enterprise (C2E) Intelligence Community (IC) Cloud AWS GovCloud Hybrid cloud environments Cross Domain Solution (CDS) environments CONUS and OCONUS C-LAN extension sites Lead project discovery sessions, kickoff meetings, and stakeholder engagements for new system authorizations, reauthorizations, and major system changes. Assess the implementation and effectiveness of NIST security controls and document findings within the Security Assessment Report (SAR) and Governance, Risk, and Compliance (GRC) platform. Identify security control deficiencies, vulnerabilities, and compliance gaps; provide technical recommendations to reduce organizational risk. Validate the accuracy and completeness of Plans of Action and Milestones (POA&Ms), ensuring corrective actions align with identified assessment findings. Monitor remediation activities and verify completion of corrective actions before recommending authorization decisions. Develop and prepare complete Authorization and Assessment packages, including: Authorization to Operate (ATO) Authorization to Connect (ATC) Interim Authorization to Test (IATT) Security Assessment Reports (SARs) Risk Recommendation Memoranda Risk Management Matrices Security Assessment Plans (SAPs) Project kickoff memoranda System Owner acknowledgment letters Conduct technical reviews of System Security Plans (SSPs), Contingency Plans, Configuration Management Plans, and supporting RMF documentation. Maintain and update Assessment and Authorization Standard Operating Procedures (SOPs) for all DHS I&A enclaves, ensuring annual review and compliance with evolving Federal and Intelligence Community requirements. Participate in Office of Inspector General (OIG), Federal Information Security Modernization Act (FISMA), and Intelligence Community Oversight Program (ICOP) audits, inspections, and cybersecurity assessments. Represent the program during DHS and Intelligence Community cybersecurity working groups and technical review boards. Maintain enterprise A&A Project Portfolio Listing Reports and Quarterly A&A Assignment Reports. Research emerging technologies, cybersecurity standards, and automation opportunities to improve A&A efficiency and support ongoing authorization initiatives. Prepare executive briefings, risk summaries, technical presentations, and decision support materials for the DHS I&A CISO, Government leadership, and Authorizing Officials. Mentor junior cybersecurity personnel and provide technical guidance on RMF implementation, security control assessments, and authorization processes. Minimum Qualifications Active Top Secret/Sensitive Compartmented Information (TS/SCI) clearance with SAP eligibility. Minimum 10 years of experience in information security, cybersecurity risk management, or Assessment and Authorization (A&A), including demonstrated experience in: Assessment and Authorization (A&A) Federal Information Security Modernization Act (FISMA) compliance Intelligence Community cybersecurity policy Continuous Monitoring (ConMon) Cross Domain Solutions (CDS) Secure cloud and hybrid cloud environments Current Certified Information Security Manager (CISM), Certified Authorization Professional (CAP), or comparable Governance, Risk, and Compliance (GRC) certification. Certified Information Systems Security Professional (CISSP) certification is highly desirable. Expert knowledge of: NIST Risk Management Framework (RMF)

NIST SP 800-37

NIST SP 800-53

NIST SP 800-53A

CNSSI 1253

ICD 503

DHS Sensitive Systems Policy Directive 4300C Intelligence Community security overlays and authorization requirements Experience using Governance, Risk, and Compliance (GRC) platforms such as RSA Archer. Experience using security assessment and vulnerability management tools, including: Nessus SCAP Nmap WebInspect SonarQube Comparable security assessment tools Demonstrated experience leading A&A activities for Cross Domain Solutions (CDS), classified information systems, and cloud-based environments. Bachelor's degree in Cybersecurity, Computer Science, Information Systems, Information Assurance, or a related technical discipline. Preferred Qualifications AWS Certified Security - Specialty, Microsoft Certified: Azure Security Engineer Associate, Google Professional Cloud Security Engineer, or equivalent cloud security certification. Experience supporting DHS Intelligence & Analysis (I&A) or other Intelligence Community cybersecurity organizations. Experience conducting Assessment and Authorization activities for OCONUS locations and C-LAN authorization extension sites. Experience supporting National Cross Domain Strategy and Management Office (NCDSMO) accreditation requirements and Raise the Bar (RTB) initiatives. Experience implementing Continuous Authorization (cATO), Agile RMF, or automated security assessment processes. Knowledge of DevSecOps security controls, Infrastructure as Code (IaC), and cloud-native security assessment methodologies. Required Certifications One of the following current certifications is required: Certified Information Security Manager (CISM) Certified Authorization Professional (CAP) Governance, Risk, and Compliance (GRC) Certification Preferred Certifications Include Certified Information Systems Security Professional (CISSP) AWS Certified Security - Specialty Microsoft Certified: Azure Security Engineer Associate Google Professional Cloud Security Engineer Clearance Requirement SAP Eligibility Required Active Top Secret/Sensitive Compartmented Information (TS/SCI) Clearance Required About the Organization Established in 2008, RiVidium, Inc. (dba TripleCyber) is a VA-Verified SDVOSB and an SBA-Certified 8(a) company. To prepare our clients for the future, RiVidium has balanced all parts of our organization to attract the finest employees in order to 'Strive to be the missing element defining tomorrow's technology'. RiVidium keeps pace and surpasses its competitors by meeting challenges of advancements in Logistics, Human Capital, Cyber, Intelligence & Technology. EOE Statement We are an equal employment opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veteran status or any other characteristic protected by law. If you need a reasonable accommodation for any part of the employment process, please contact Human Resources (HR) at View email address on click.appcast.io. #J-18808-Ljbffr Rividium Inc

Vacancy posted 4 days ago
Similar jobs that could be interesting for youBased on the Security Control Assessor (SCA) — Level II in Washington DC vacancy
  • The Security Control Assessor (SCA) II is responsible for conducting a comprehensive assessment of the management, operational, and technical security...  ...are required Advise the Government concerning the impact levels for Confidentiality, Integrity, and Availability for the... 
    Suggested

    General Dynamics - IT

    Arlington, VA
    1 day ago
  • Security Control Assessor (SCA), Level I Arlington, VA Role: Security Control Assessor (SCA), Level I Location: Arlington, VA Clearance Required: TS/SCI Polygraph: CI Position Description The SCA is responsible for conducting a comprehensive assessment of the management... 
    Suggested
    Contract work
    Local area

    TAC Integrated Solutions

    Arlington, VA
    1 day ago
  • $160k - $172k

     ...Title: Security Control Assessor (SCA) Belong. Connect. Grow. with KBR! KBR's National Security Solutions...  ...the Government concerning the impact levels for confidentiality, integrity, and...  ...8570/8140 IAT Level III or IAM Level II/III certification (e.g., CISSP... 
    Suggested
    Contract work
    Temporary work
    Local area
    Relocation package
    Flexible hours

    KBR

    Washington DC
    5 days ago
  • $140k - $210k

     ...Overview VTG is looking for multiple levels (Level 2, 3 & 4) of a Security Control Assessor (SCA) in multiple locations. (Note: position is contingent upon...  ...and Level 2 qualifications, a compliant IAM Level II certification, and the additional desired qualifications... 
    Suggested
    For contractors
    Work experience placement

    VTG Defense

    Springfield, VA
    3 days ago
  • $107.9k - $195.05k

    SCI Security Controls Assessor Representative A&A SpecialistLocation: Suitland, MDClearance: Active TS/SCILeidos...  ...ranging in years of experience. Level of opportunity, including compensation,...  ...Required CertificationsActive IAM Level II or higher certification, such as... 
    Suggested
    Full time
    Interim role
    Work at office
    Worldwide

    Leidos

    Suitland, MD
    1 day ago
  • $102.83k - $150k

     ...$102,831.00 - $150,000.00 Security Clearance: TS/SCI Level of Experience: Mid This opportunity...  ...salary ranges: Security Controls Accessor: $85,185 - $135,0...  ...doThe Security Controls Assessor plays a critical role in...  ...the organization.The SCA is responsible for:-Reviewing... 
    Full time
    Work experience placement
    Local area
    Worldwide

    HII Mission Technologies Division

    Springfield, VA
    4 days ago
  •  ...Title: SecurityControl Assessor Location:On Site inArlington...  ...exempt JobPurpose: The security control assessor (SCAs)...  ...mitigating security risks.The SCA will support a critical...  ...concerning the impact levels for Confidentiality,...  ...polygraph. DOD 8140 IAM Level II (CAP, CASP, CISM, CISSP... 
    Full time
    Work at office

    Apavo Corporation

    Arlington, VA
    3 days ago
  •  ...Security Control Assessor (SCA) LOCATION Tysons, VA 22182 CLEARANCE TS/SCI Full Poly (Please note this position requires full U.S. Citizenship) KEY...  ...Security Risk Assessor, Compliance Manager, ect. DEGREE (Level Desired) Bachelor's Degree DEGREE (Focus) Cybersecurity, Information... 
    Temporary work
    For contractors
    Immediate start
    Flexible hours

    Cymertek

    Falls Church, VA
    5 days ago
  •  ...Security Control Assessor (SCA) HII's Mission Technologies division is dedicated to delivering cutting-edge solutions that advance national security...  ..., which plays a critical role in supporting Enterprise-Level Security and Modernization efforts across IT... 
    Work experience placement

    HII Mission Technologies Division

    Springfield, VA
    1 day ago
  • $160k - $180k

     ...Security Controls Assessor (SCA) Systems Planning and Analysis, Inc. (SPA) delivers high-impact, technical solutions to...  ...570.01-M for Information Assurance Technician Level III or Information Assurance Manager Level II ~ Active TS/SCI and the ability to maintain... 
    Immediate start
    Flexible hours

    Systems Planning and Analysis, Inc

    Washington DC
    5 days ago
  • $112.5k

     ...Security Control Assessor Leidos is seeking mid- to senior-level Security Control Assessors to join our SCA team. This position requires significant travel—please review the position overview...  ...Secret clearance and current IAT/IAM II certification (eg Security+ or... 
    Daily paid
    Local area
    Work from home

    Leidos

    Alexandria, VA
    5 days ago
  • Dark Wolf Solutions is seeking Security Control Assessors/Representatives (SCA/Rs) to lead security control assessments...  ...at multiple classification levels. The position is based in Arlington...  ...active TS clearance, DoD 8570 IAM Level II/III, and 5-7+ years of security assessment... 
    Remote work

    Darkwolfsolutions

    Washington DC
    5 days ago
  • $135k - $160k

    Dark Wolf Solutions is seeking Security Control Assessor/Representatives (SCA/Rs) to lead security control assessments...  ...across multiple classification levels. This position is ideal for a pragmatic...  ...Current DoD 8570/8140 IAM Level II or Level III certification (e.g., Security+... 
    Full time
    For contractors
    Remote work

    BuddoBot Inc.

    Washington DC
    5 days ago
  • RiVidium is seeking a Security Control Assessor (SCA) Level II to lead complex A&A activities for DHS Intelligence Enterprise across TS/SCI environments. You will assess security controls, prepare SARs, and guide remediation efforts while collaborating with ISSOs, AOs,... 

    Rividium

    Washington DC
    5 days ago
  • RiVidium, Inc. is seeking a senior Security Control Assessor (SCA) - Level II to lead A&A activities across the DHS Intelligence Enterprise. You will assess classified and unclassified systems, cloud environments, CDS, and C-LAN sites, guiding RMF compliance and security... 

    Rividium Inc

    Washington DC
    4 days ago
  • $180k - $220k

     ...Modern Technology Solutions, Inc. (MTSI) is seeking a Security Control Assessor (SCA) to support an MTSI contract with the Assistant Secretary of...  ...required. Advise the Government concerning the impact levels for confidentiality, integrity, and availability for the information... 
    Contract work

    Modern Technology Solutions Inc

    Washington DC
    4 days ago
  •  ...Position Overview The Security Control Assessor must fulfill a variety of cybersecurity functions,...  ...DSWAN) up to SECRET Collateral # Multi-Level Security System (SAVANNAH) up to TOP...  ...Information Assurance Management (IAM) Level II in DoD Manual 8570.1-M Extensive... 
    For contractors
    Work experience placement
    Work at office
    Local area
    Worldwide

    G-Force Solutions

    Arlington, VA
    1 day ago
  • $150k - $168k

     ...seeks a Job Description ECS is seeking a Security Controls Assessor to work in our Washington, DC (hybrid)...  ...and maintain test cases for control-level security testing across system...  ...Plans, Security Controls Assessments (SCA), and related documentation Current industry... 
    Long term contract
    Full time
    Contract work
    Work at office
    Local area
    Immediate start

    ECS Limited

    Washington DC
    1 day ago
  •  ...Position Overview The Security Control Assessor must fulfill a variety of cybersecurity functions, to include: System Administrator, Enterprise Oversight, certification and accreditation, SAP and SCI assessment and authorization (A&A), Platform Information Technology (... 
    Local area

    System High Corp

    Arlington, VA
    19 hours ago
  • $128.8k - $214.5k

     ...Senior Security Control Assessor (SCA) Unlock the secrets of intelligence with MANTECH! Join a dynamic team at the forefront of national security...  ...with the system owner, regarding systems' impact levels and ISs' authorization boundary Initiate, coordinate, and... 
    Hourly pay
    Contract work
    Temporary work
    Work experience placement
    Work at office
    Local area
    Remote work

    ManTech

    Washington DC
    2 days ago
  •  ...Serco has the right opportunity for you! As a Senior Security Control Assessor, you will provide senior-level security control assessment support to a Department...  .... Desired Skills Security Control Assessment (SCA) experience within the Department of Defense Environments... 
    Full time
    Contract work
    Part time
    For contractors
    Work at office
    Local area
    Monday to Friday
    Flexible hours

    Serco

    Arlington, VA
    3 days ago
  • $87.1k - $157.45k

    SCI Security Controls Assessor Liaison SpecialistLocation: Suitland, MDClearance: Active TS/SCILeidos is...  ..., Intelligence Community, and national level system security initiatives and secure...  ...certification, such as CGRC, CISM, or Security+ II, or the ability to obtain a... 
    Full time
    Interim role
    Work at office

    Leidos

    Suitland, MD
    1 day ago
  • $146k - $234k

    ResponsibilitiesPeraton seeks a Cloud Security Control Assessor to support the Army Cyber Command (ARCYBER). Location: Alexandria, VA/Metro Park...  ...Will consider HS+16 or Associates +14.Must have current IAM level III certification (such as CISM)Must have knowledge of... 
    Contract work
    Local area
    Shift work

    Peraton Corporation

    Alexandria, VA
    2 days ago
  •  ...To the ProSidian website at DescriptionProSidian Seeks a Security Controls Assessor / ISSO | Human Capital Programmatic Evaluation & Compliance...  ...a Systems Engineer Labor Category as a Engagement Team Mid Level Professional aligned under services related to NAICS: 54161... 
    Full time
    Contract work
    Temporary work
    For contractors
    H1b
    Work at office
    Flexible hours

    Prosidian Consultng

    Alexandria, VA
    2 days ago
  • General Dynamics - IT seeks a Security Control Assessor (SCA) II to conduct comprehensive assessments of management, operational, and technical security controls for IS and its environment. The role evaluates weaknesses, documents SARs, and recommends corrective actions... 

    General Dynamics - IT

    Arlington, VA
    1 day ago
  • $146k - $234k

     ...Peraton is a next-generation national security company that drives missions of consequence...  ...Role Peraton seeks a Cloud Security Control Assessor to support the Army Cyber Command (ARCYBER...  ...Associates +14. Must have current IAM level III certification (such as CISM) Must... 
    Contract work
    Temporary work
    Local area
    Shift work

    Peraton

    Alexandria, VA
    1 day ago
  • $137k - $152k

     ...mobilizing the right people, skills, clearance levels, and technologies to help organizations...  ..., Data Delivery & Analytics, Cyber Security, Cloud Migration, Applications and...  ...Accounting. M9 Solutions is seeking a Security Control Assessor to work on-site in support of a... 
    Full time
    Contract work
    For subcontractor

    M9 Solutions

    Alexandria, VA
    1 day ago
  •  ...Security Control Assessor (Authorizing Official) Position Summary: As Security Control Assessor...  ...assurance documents to confirm that the level of risk is within acceptable limits for...  ...Certification Requirements: ~ lAM Level II certification (CAP, CASP+, CISM, CISSP... 
    Full time
    Work at office
    Immediate start
    Flexible hours

    Life Cycle Engineering

    Springfield, VA
    1 day ago
  •  ...Security Control Assessor The Security Control Assessor conducts comprehensive assessments of security...  ...applicable security requirements. The SCA develops and submits the complete Body...  ..., integrity, and availability impact levels in accordance with Risk Management... 

    Pueo Business Solutions LLC

    McLean, VA
    18 hours ago
  •  ...Job Description We are seeking a highly skilled Security Control Assessor (SCA) to support independent cybersecurity assessments of systems in accordance with the Risk Management Framework (RMF). This role is responsible for evaluating the implementation and effectiveness... 
    2 days per week

    Centurion Consulting Group, LLC

    Andrews Air Force Base, MD
    1 day ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Security Control Assessor (SCA) — Level II. Be the first to apply!