Security Control Assessor ? Level II / Journeyman
RIVIDIUM
Job Description
Job Description
Position Overview
RiVidium Inc. is seeking an experienced Security Control Assessor (SCA) ? Level II / Journeyman to support federal cybersecurity assessment, authorization, compliance, and risk management activities.
The Security Control Assessor will evaluate the effectiveness of security controls implemented within information systems and enterprise environments. This position will conduct security control assessments, review technical and procedural evidence, identify deficiencies, document findings, and provide recommendations to reduce cybersecurity risk.
The ideal candidate will have hands-on experience with the Risk Management Framework (RMF) , security control assessments, cybersecurity compliance, and federal security requirements. The candidate should be comfortable working with ISSOs, system owners, engineers, cybersecurity teams, and government stakeholders.
Key Responsibilities
- Conduct security control assessments for information systems and applications in accordance with federal cybersecurity requirements.
- Assess the design, implementation, and operating effectiveness of security controls.
- Review system security documentation, policies, procedures, configurations, and assessment evidence.
- Develop and execute security assessment plans, procedures, and testing activities.
- Perform interviews, technical reviews, documentation analysis, and other assessment activities to validate control implementation.
- Identify security control deficiencies, weaknesses, and potential risks.
- Document assessment findings and provide clear, actionable remediation recommendations.
- Develop and maintain Security Assessment Reports (SARs) and supporting assessment documentation.
- Support Plan of Action and Milestones (POA&M) development and remediation tracking.
- Validate corrective actions and determine whether identified findings have been adequately addressed.
- Support Risk Management Framework (RMF) activities throughout the system lifecycle.
- Assist with Authorization to Operate (ATO), authorization package development, and continuous authorization activities.
- Evaluate security controls against applicable federal standards and organizational requirements.
- Assess technical and management controls across applications, infrastructure, networks, cloud environments, and enterprise systems.
- Review vulnerability assessment results and determine their impact on security control effectiveness and overall system risk.
- Coordinate with Information System Security Officers (ISSOs), Information System Security Managers (ISSMs), system owners, system administrators, engineers, and other stakeholders.
- Support continuous monitoring activities and periodic security control reassessments.
- Assist with security audits, compliance reviews, and customer assessments.
- Track assessment milestones, findings, risks, and remediation activities.
- Prepare technical reports, briefings, presentations, and cybersecurity metrics for government leadership.
- Maintain awareness of changes to federal cybersecurity policies, standards, and assessment requirements.
- Provide guidance and mentoring to junior cybersecurity assessment personnel.
Required Qualifications
- Bachelor?s degree in Cybersecurity, Information Systems, Information Technology, Computer Science, or a related field .
- Demonstrated experience performing security control assessments, cybersecurity assessments, compliance assessments, or information assurance activities.
- Experience with the NIST Risk Management Framework (RMF) .
- Working knowledge of security controls and control assessment methodologies.
- Experience reviewing security documentation, policies, procedures, technical configurations, and assessment evidence.
- Ability to identify, document, and evaluate security control weaknesses.
- Experience developing assessment reports, findings, and remediation recommendations.
- Knowledge of federal cybersecurity requirements and information security best practices.
- Understanding of NIST SP 800-53 security controls.
- Experience supporting ATO and authorization activities.
- Strong analytical, organizational, technical writing, and communication skills.
- Ability to work independently and collaborate with technical teams and government stakeholders.
Preferred Certifications
One or more of the following certifications is highly desirable:
- Certified Authorization Professional (CAP)
- CompTIA Security+
- GRC-related certification
- CISSP
- CISM
- CRISC
- GIAC certification
Preferred Qualifications
- Experience supporting federal civilian or Department of Defense (DoD) cybersecurity programs.
- Experience with NIST SP 800-37, NIST SP 800-53, FISMA , and related federal cybersecurity requirements.
- Experience supporting enterprise-level security authorization programs.
- Familiarity with RSA Archer, ServiceNow GRC, eMASS , or similar GRC platforms.
- Experience with continuous monitoring and ongoing authorization.
- Experience assessing cloud environments, including AWS, Azure, Google Cloud, or Microsoft 365 .
- Knowledge of vulnerability management and security assessment tools.
- Experience reviewing vulnerability scans and technical security assessment results.
- Experience working with system security plans (SSPs), security assessment reports (SARs), and POA&Ms.
- Experience with cybersecurity policies, procedures, standards, and control implementation documentation.
- Ability to translate technical findings into business and mission risk.
Technical Skills
The successful candidate should have knowledge of:
- Security Control Assessments
- NIST RMF
- NIST SP 800-53
- NIST SP 800-37
- FISMA
- ATO / Authorization
- Continuous Monitoring
- Security Assessment Plans
- Security Assessment Reports
- System Security Plans
- POA&M Management
- Cybersecurity Risk Management
- Security Control Testing
- Compliance Assessments
- Vulnerability Management
- GRC Platforms
- RSA Archer
- eMASS
- ServiceNow GRC
- Cloud Security
- Security Documentation
- Risk Analysis
- Audit and Compliance
RiVidium Inc is seeking a ? Security Control Assessor (SCA) ? Level II / Journeyman ? to support a federal client. This position is contingent upon contract award and funding approval. As such, this job posting is intended to identify qualified candidates for a potential future opportunity and does not represent a currently available position. Compensation has not yet been determined and will be established based on contract requirements, candidate qualifications, experience, and applicable market conditions.
- ...Job Description Job Description The Security Control Assessor (SCA) ? Level II serves as a senior technical authority responsible for leading Assessment and Authorization (A&A) activities across the Department of Homeland Security (DHS) Intelligence Enterprise...SuggestedInterim roleWork at office
- Security Control Assessor (SCA), Level I Arlington, VA Role: Security Control Assessor (SCA), Level I Location: Arlington, VA Clearance Required: TS/SCI Polygraph: CI Position Description The SCA is responsible for conducting a comprehensive assessment of the management...SuggestedContract workLocal area
- ...SUBJECT MATTER EXPERTS specializing in security and risk management. We’re intimately... ...people come first! Security Control Assessor (SCA) II The SCA is responsible for... ...the Government concerning the impact levels for Confidentiality, Integrity, and Availability...SuggestedHourly payFull timeContract workWork experience placementLocal area
- ...defense. Make an impact by connecting and securing critical operations across the globe,... ...Job Description The Security Control Assessor (SCA) II is responsible for conducting a comprehensive... ...the Government concerning the impact levels for Confidentiality, Integrity, and...Suggested
$160k - $180k
...Security Controls Assessor (SCA) Systems Planning and Analysis, Inc. (SPA) delivers high-impact, technical solutions... ...8570.01-M for Information Assurance Technician Level III or Information Assurance Manager Level II ~ Active TS/SCI and the ability to maintain it...SuggestedImmediate startFlexible hours$112.5k
...Security Control Assessor Leidos is seeking mid- to senior-level Security Control Assessors to join our SCA team. This position requires significant travel—please... ...,500. A Top Secret clearance and current IAT/IAM II certification (eg Security+ or equivalent) is required...Daily paidLocal areaWork from home- Job Title: SecurityControl Assessor Location: On Site in Arlington,... ...CI Polygraph JobPurpose: The security control assessor (SCAs) supports a... ...(ISO) concerning the impact levels for Confidentiality, Integrity... ...Polygraph. DOD 8140 IAM Level II (CAP, CASP, CISM, CISSP, GSLC...Full timeWork at office
$175.2k
Summary Lead Senior Security Control Assessor (SCA) Arlington, VA Are you ready to enhance your skills... ...technology and take your career to the next level! SecuriGence delivers essential... ...experience requiredDOD 8140 IAM Level II (CAP, CASP, CISM, CISSP, GSLC, CCISO) required...Work at office$135k - $150k
Security Control Assessor/Representatives Dark Wolf Solutions is seeking Security Control Assessor/Representatives... ...across multiple classification levels. Thisposition is ideal for a pragmatic... ...Current DoD 8570/8140 IAM Level II or Level III certification (e.g., Security+...Full timeFor contractorsRemote work$180k - $220k
Modern Technology Solutions, Inc. (MTSI) is seeking a Security Control Assessor (SCA) to support an MTSI contract with the Assistant Secretary of... ...are required.Advise the Government concerning the impact levels for confidentiality, integrity, and availability for the information...Contract work- ...To the ProSidian website at DescriptionProSidian Seeks a Security Controls Assessor / ISSO | Human Capital Programmatic Evaluation & Compliance... ...a Systems Engineer Labor Category as a Engagement Team Mid Level Professional aligned under services related to NAICS: 54161...Full timeContract workTemporary workFor contractorsH1bWork at officeFlexible hours
$150k - $168k
Job DescriptionECS is seeking a Security Controls Assessor to work in our Washington, DC (hybrid) office. Please Note: This position is contingent... ...implementationDevelop and maintain test cases for control-level security testing across system components (applications, servers...Long term contractFull timeContract workWork at officeImmediate start$180k
...Senior Security Control Assessor Quantico, VA, United States Up to $180,000/ year Information Security Leader Cyber Security Engineer... ...consultation with the system owner, regarding systems' impact levels and ISs' authorization boundary Initiate, coordinate,...Work at office$140k - $210k
...Overview VTG is looking for multiple levels (Level 2, 3 & 4) of a Security Control Assessor (SCA) in multiple locations. (Note: position is contingent upon... ...1 and Level 2 qualifications, a compliant IAM Level II certification, and the additional desired qualifications...For contractorsWork experience placement- ...Position Overview We are seeking an experienced Security Control Assessor to support cybersecurity assessment and authorization activities... ...availability when evaluating system categorization and impact levels, including High, Moderate, and Low classifications....Immediate startFlexible hours
- A career as a Security Control Assessor at GDIT means owning every opportunity to help support and advance our clients’ missions. At GDIT, cyber... ...Program requirement for Information Assurance Manger (IAM) Level III (CISM, CISSP or Associate GSLC or CCISO). Knowledge of...
$146k - $234k
...Peraton is a next-generation national security company that drives missions of consequence... ...Role Peraton seeks a Cloud Security Control Assessor to support the Army Cyber Command (ARCYBER... ...Associates +14. Must have current IAM level III certification (such as CISM) Must...Contract workTemporary workLocal areaShift work$99k - $225k
Security Control Assessor, Lead The Opportunity: The Lead Security Control Assessor directs the SCA workstream and provides independent cybersecurity... ...recommendations to the ISSM, AO representative, and AO-level stakeholders. Develop all system applicable RMF Body of...Full timeContract workPart timeWork at officeLocal areaRemote work- Peraton seeks a Cloud Security Control Assessor to support Army Cyber Command (ARCYBER). Location: Alexandria, VA/near Fort Belvoir. Responsibilities... ...guidelines. The role requires deep RMF/NIST knowledge, IAM level III certification, and experience with eMASS, ACAS, CCSP/...
- ...401K, an Employee Stock Purchase Plan (ESPP) through Tetra Tech, and more! Responsibilities:Execute all phases of cyber security and privacy control assessment supportRequired Qualifications:Masters Degree in a Technical or Cyber-related Field7+ years of Relevant Cybersecurity...
- ...motivated and qualified Journeyman Heating, Ventilation,... ...• Facilities Condition Assessor qualified in building HVAC... ...mandatory DoW Secret Security clearance, if not already... ...• Understand UNIFORMAT II building component data structure down to Level 4. • Additional...JourneymanFor contractorsRemote work
$85.19k - $135k
...Number: 29043 Employment Type: Full Time/Salaried/Exempt | Required Travel: 0‑10% | Security Clearance: TS/SCI | Level of Experience: Mid Summary This position is a Security Controls Assessor (SCA) within HII Mission Technologies’ Cyber and Intelligence division. The role...Full timeLocal area- ...Security Control Assessor The Security Control Assessor conducts comprehensive assessments of security controls employed by, or inherited within... ...confidentiality, integrity, and availability impact levels in accordance with Risk Management Framework (RMF) requirements...
- ...Position Overview The Security Control Assessor must fulfill a variety of cybersecurity functions, to include: System Administrator, Enterprise Oversight, certification and accreditation, SAP and SCI assessment and authorization (A&A), Platform Information Technology (...Local area
- Omniscius Consulting is seeking a SecurityControl Assessor in Arlington, VA, on site, to evaluate security controls and support RMF implementation for a critical IC mission. You will perform assessments using automated tools, authoring SARs, SAPs, and plans of action &...
- Arlo Solutions in Arlington, VA, seeks a Security Control Assessor (SCA) to evaluate and enhance the security posture of DSCA information systems. Active Secret Clearance is required, with a Bachelor's degree in a related field and 5+ years in information security. The...
- General Dynamics Information Technology is seeking a Security Control Assessor to own security assessments, write final reports, defend findings, and drive mitigation strategies on customer sites in Bethesda, MD. The role requires 6+ years in cybersecurity, SCA experience...
- Tetra Tech in Arlington, Virginia, is seeking a cybersecurity professional to execute all phases of security and privacy control assessments. The ideal candidate will have at least 7 years of relevant experience, specifically in federal cybersecurity, as well as strong...
- ...improve services to end-users, and give our customers a competitive edge, now and into the future. Position Description The Security Control Assessor (SCA) will be responsible for evaluating and assessing the security controls of Defense Security Cooperation Agency’s (...
- Apavo Corporation is seeking a Security Control Assessor to perform RMF-based security assessments for DoD/IC systems. You will use automated and manual testing, support RMF activities, and provide guidance to ensure controls are integrated into system designs. The role...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security Control Assessor ? Level II / Journeyman. Be the first to apply!
- assessor Washington DC
- security control assessor Washington DC
- journeyman apprentice Washington DC
- journeyman hvac Washington DC
- licensed electrician journeyman Washington DC
- journeyman Washington DC
- maintenance journeyman Washington DC
- journeyman maintenance mechanic Washington DC
- electrical journeyman Washington DC
- mds assessor


