Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Security Control Accessor

VIATEQ Corporation

Job Description

Job Description:\n\nVIATEQ Corporation is looking for a Security Control Assessor (SCA) to support a comprehensive enterprise cybersecurity services program for a federal government client.\n\nThis position requires the ability to obtain and maintain a Minimum Background Investigation (MBI) or higher, PIV credentials, and all requisite IT access authorizations prior to performing work. Primary work will be performed at the client site in Washington, DC and approved remote/telework locations. \n\nThis role serves as a key technical contributor responsible for the independent assessment and evaluation of security and privacy controls across the client's enterprise IT portfolio, spanning on-premises, cloud-hosted, and hybrid systems, in support of the agency's Federal Information Security Modernization Act (FISMA) compliance program, Risk Management Framework (RMF) activities, and Ongoing Authorization (OA) initiatives.\n\nThe ideal candidate is a detail-oriented and technically proficient security assessment professional with demonstrated experience conducting NIST SP 800-53 security and privacy controls assessments, developing Security Assessment Reports (SARs), supporting Authority to Operate (ATO) activities, and executing continuous monitoring assessments across a diverse federal enterprise IT environment. This individual must possess the ability to work independently across complex, multi-technology system boundaries and deliver thorough, accurate, and well-written assessment artifacts that meet rigorous federal documentation standards.\n\nThe Security Control Assessor will serve as an independent technical evaluator responsible for planning, executing, and reporting on security and privacy controls assessments for assigned systems and services across the client's enterprise IT portfolio. This individual is responsible for assessing the implementation and effectiveness of NIST SP 800-53 security and privacy controls, documenting assessment findings in accordance with NIST SP 800-53A methodologies, producing high-quality assessment artifacts, and supporting the full RMF assessment lifecycle from initial planning through final report delivery and POA&M development. The SCA works closely with ISSOs, system owners, security engineers, and Government stakeholders to ensure assessments are thorough, accurate, and completed within required timelines.\nResponsibilities:\nSecurity & Privacy Controls Assessment\n\n \n Plan, execute, and report on comprehensive security and privacy controls assessments for assigned federal information systems and services, including on-premises, IaaS, PaaS, and SaaS implementations, in accordance with NIST SP 800-53 Rev 5, NIST SP 800-53A Rev 5, and applicable agency implementation procedures.\n Conduct point-in-time full controls assessments, annual controls assessments, multi-year one-third assessments, and Ongoing Authorization (OA) evaluation assessments in accordance with the agency's assessment schedule and applicable implementation procedures.\n Develop and deliver draft Security Assessment Plans (SAPs) no less than ten (10) business days prior to beginning each assessment, clearly documenting the assessment scope, boundaries, sampling strategies, test methods, and schedule.\n Execute NIST SP 800-53A Determine If Statements (DISs) for all in-scope controls, documenting assessment findings to a level of detail sufficient to demonstrate that the implementation of each control objective is validated or not validated, avoiding high-level summary statements and ensuring technical depth across all technology types within the system boundary.\n Conduct technical controls assessments across all technology types within each system boundary, including Windows and UNIX servers, network devices (routers, switches, Cisco, F5 load balancers), web applications, databases, cloud platforms, and endpoint systems, applying appropriate sampling strategies approved by the Government prior to implementation.\n Develop Government-approved sampling strategies encompassing all asset types within each system boundary, typically between ten (10) and twenty (20) percent of applicable assets where appropriate, ensuring sampling covers all relevant device types, users, and services.\n Map identified vulnerabilities and assessment findings to applicable NIST SP 800-53 Rev 5 controls and control families, ensuring accurate and complete linkage between technical findings and corresponding control deficiencies.\n Produce comprehensive draft and final Security Assessment Reports (SARs) within required timelines, ensuring reports are comprehensive to the scope identified in the SAP, fully aligned to the agency's Governance, Risk, and Compliance (GRC) tool, include visual representation against the NIST Cybersecurity Framework (CSF), and are peer-reviewed for accuracy and grammar prior to submission.\n Develop draft Plans of Action and Milestones (POA&M) entries for identified control deficiencies, typically using the agency's GRC tool, delivering draft POA&Ms within thirty (30) calendar days from point-in-time assessment kickoff.\n Develop draft Annual Assessment Reports (AARs) per in-scope system within one-hundred-twenty (120) business days from point-in-time annual assessment kickoff, and deliver draft summary reports for multi-year assessment efforts no later than sixty (60) business days prior to the end of each Fiscal Year.\n Incorporate all Government feedback into assessment artifacts within five (5) business days of receipt of comments, delivering finalized deliverables that accurately reflect all Government-provided corrections, questions, and recommendations.\n \n\nOngoing Authorization (OA) Evaluation Support\n\n \n Conduct Ongoing Authorization (OA) controls assessments for systems approved for OA, applying agency-specific OA test procedures that replace traditional NIST SP 800-53A test procedures for OA-approved systems.\n Execute OA Positive Testing monthly for OA-approved systems, using automated or semi-automated techniques to determine whether controls are operating effectively under normal circumstances, documenting results in the agency GRC tool in accordance with OA implementation procedures.\n Execute OA Negative Testing annually for OA-approved systems, using automated or semi-automated techniques to determine whether controls respond as expected under abnormal circumstances where misuse is injected to attempt to circumvent the control, coordinating as necessary with penetration testing purple team resources.\n Assist in the development and submission of OA Playbooks for Government approval, documenting the testing methodology for each OA core control including Test Strategy, Test Design, Test Execution, Results Evaluation, and Visualization components.\n Conduct OA testing comprehensively across all technology types within each target system's boundary, including sampling across in-scope devices, users, and services, documenting all test results in detail within the agency GRC tool in accordance with applicable OA implementation procedures.\n Ensure all OA Positive and Negative Testing documentation is peer-reviewed for accuracy and grammar prior to submission to the Government.\n \n\nISSO Support & Collaboration\n\n \n Collaborate closely with assigned ISSOs to support their development of in-depth technical and operational knowledge about assigned systems, providing assessment expertise, technical guidance, and documentation support as needed.\n Provide technical support and expertise to ISSOs in the development and maintenance of all security documentation in the ATO package, including System Security Plans (SSPs), Configuration Management Plans (CMPs), Information System Contingency Plans (ISCPs), and other RMF artifacts, ensuring documentation aligns with applicable agency implementation procedures and template requirements.\n Support ISSOs in reviewing and validating system security documentation for technical accuracy, completeness, and alignment with the system boundary and technology stack, providing specific and actionable feedback to improve documentation quality.\n Assist ISSOs in ensuring control implementation descriptions within SSPs are written to the required level of technical detail, clearly explaining how each control is implemented across all technologies within the system boundary using specific naming conventions, configurations, and operational procedures rather than high-level general statements.\n Participate in Enterprise Change Control Board (ECCB) activities as needed, providing security assessment expertise to support the evaluation of proposed system changes and their potential impact on the system's security posture and ATO status.\n \n\nAudit & Compliance Support\n\n \n Support internal and external audit activities for assigned FISMA systems, facilitating meetings and walkthroughs of key cybersecurity capabilities, coordinating with system support personnel, and supplying auditors with requested artifacts and evidence within required timeframes.\n Ensure audit artifacts are complete, accurate, and delivered on time to avoid repeated requests from auditors, communicating any issues or problems to the Government immediately upon discovery.\n Support FISMA continuous monitoring activities, including the collection, validation, and submission of system-level FISMA metrics for assigned systems in alignment with federal CIO metrics requirements and agency reporting schedules.\n Assist in the development and maintenance of automated visualizations and dashboards that reflect the status and effectiveness of security controls for assigned systems, providing continuous visibility into the security posture and compliance status of assigned systems.\n Support High Value Asset (HVA) assessment activities for designated HVA systems, including vulnerability scanning and remediation validation, monitoring and analysis of relevant audit logs, and identification of connections between HVAs and other systems.\n Assist in FedRAMP Continuous Monitoring (CONMON) management activities for applicable cloud service provider systems, including review of vulnerability, penetration testing, and ad hoc reporting to ensure vendor actions pose no security risk to the enterprise environment.\n \n\nDocumentation & Reporting\n\n \n Develop and maintain all assigned security and privacy assessment documentation in alignment with applicable agency implementation procedures, ensuring all documents are complete, well-written, aligned to agency templates, and meet the level of detail specified in agency procedures.\n Ensure all assigned documents are updated in the agency's GRC tool and relevant SharePoint repositories in accordance with required timelines and agency standards.\n Prepare and submit all assigned deliverables peer-reviewed for accuracy, punctuation, and grammar prior to submission, ensuring deliverables are delivered on or before agency-defined completion dates.\n Address all Government-provided comments, edits, errors, and questions within ten (10) business days of receipt, and escalate stakeholder unresponsiveness to the Government POC after ten (10) business days without receiving a required response.\n Ensure all documentation created under the contract is Government-owned, properly marked, accessible via Section 508 compliant formats as required, and not marked with any proprietary or company-restrictive language.\n \n\nRequired Education and Experience:\n\n \n Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Information Systems, or a related field from an accredited college or university. \n Minimum of 5 years of experience in federal information security, with demonstrated hands-on experience conducting NIST SP 800-53 security and privacy controls assessments for federal information systems. \n Demonstrated experience developing Security Assessment Plans (SAPs), Security Assessment Reports (SARs), Annual Assessment Reports (AARs), and Plans of Action and Milestones (POA&Ms) in accordance with NIST SP 800-53A methodologies and federal RMF requirements. \n Experience conducting technical controls assessments across diverse technology stacks, including Windows and UNIX servers, network devices, web applications, databases, and cloud platforms (IaaS, PaaS, SaaS). \n Experience working with federal agency Governance, Risk, and Compliance (GRC) tools for documentation management, POA&M tracking, and continuous monitoring activities. \n Ability to obtain and maintain a Minimum Background Investigation (MBI) or higher, PIV credentials, and all requisite IT access authorizations; must be eligible for Top Secret clearance access should such a requirement arise during the period of performance.\n \n\nPreferred Education and Experience:\n\n \n CISSP certification or demonstrated equivalent experience and commitment to obtain within 12 months of award.\n Prior experience supporting federal civilian agency FISMA compliance programs in a Security Control Assessor or ISSO capacity.\n Experience working on GSA Multiple Award Schedule (MAS) HACS SIN contracts or comparable federal IT cybersecurity contract vehicles.\n Experience conducting Ongoing Authorization (OA) assessments using agency-specific positive and negative testing methodologies.\n \n\nRequired Skills and Competencies:\n\n \n Exceptional written communication skills in English with demonstrated ability to produce clear, concise, technically thorough, and professionally written security assessment artifacts that meet rigorous federal documentation standards, including SSPs, SAPs, SARs, AARs, and POA&Ms.\n Deep knowledge of NIST SP 800-53 Rev 5 security and privacy control families, including the ability to assess all control families across diverse federal information systems and accurately document implementation status at the required level of technical detail.\n Strong proficiency with NIST SP 800-53A Rev 5 assessment methodologies, including development and execution of Determine If Statements (DISs), examination, interview, and testing assessment methods, and objective-based evidence collection and validation techniques.\n Demonstrated ability to conduct technical controls assessments across heterogeneous technology stacks, including the ability to assess controls across Windows and UNIX operating systems, Cisco and other network devices, F5 load balancers, web applications, SQL and NoSQL databases, and cloud service environments.\n Experience developing and applying Government-approved sampling strategies for large-scale system assessments, ensuring sampling encompasses all asset types and is representative of the full system boundary.\n Proficiency with federal GRC tools for documentation development, POA&M management, continuous monitoring tracking, and assessment results documentation.\n Familiarity with the NIST Risk Management Framework (RMF) lifecycle, including all six RMF steps—Categorize, Select, Implement, Assess, Authorize, and Mon

Vacancy posted 5 days ago
Similar jobs that could be interesting for youBased on the Security Control Accessor in Washington DC vacancy
  • $45 - $50 per hour

     ...Control Room OperatorThe Control Room Operator ensures safe, reliable, and efficient operation of the 761MW natural gas-fired, combined-cycle Keys Energy Center. Following plant procedures and Senior Operations Supervisor directives, the operator exercises judgment in... 
    Suggested
    Full time
    Shift work
    Rotating shift

    Consolidated Asset Management Services, LLC

    Brandywine, MD
    3 days ago
  •  ...Northern Technologies Group (NTG) is seeking an experienced Security Control Accessor to provide expert-level support to the Department of Defense (DoD) Chief Information Officer’s SAP IT Cybersecurity program. This role delivers technical and managerial leadership across... 
    Suggested
    Contract work
    Local area
    Monday to Friday
    Shift work

    NTG

    Alexandria, VA
    1 day ago
  •  ...Full Time/Non-exempt Clearance: Top Secret clearance with the ability to obtain SCI with CI Polygraph JobPurpose: The security control assessor (SCAs) supports a critical, objective role to evaluate the effectiveness of implemented controls in mitigating... 
    Suggested
    Full time
    Work at office

    Omniscius Consulting

    Arlington, VA
    5 days ago
  • $54k - $75k

     ...dynamic newsroom settings and are passionate about live production, journalism, and broadcast technology. Job Title: Master Control Room and Ingest Operator Summary Reach Media is looking for a technically sharp and solution driven Master Control Room and... 
    Suggested
    Full time
    Flexible hours

    Volant Media UK Ltd

    Washington DC
    1 day ago
  •  ...and believe customer satisfaction comes first. JOB SUMMARY: Business Operational Concepts (BOC) is currently seeking a Security Control Assessor to work with our government client. The selected candidate will conduct independent comprehensive assessments of the... 
    Suggested
    Full time

    Jobs via Dice

    Washington DC
    1 day ago
  • CCI International Inc. seeks a Security Control Assessor / IA Specialist in the Alexandria, VA area to provide information assurance for digital systems and ensure compliance with security frameworks. You will plan and execute RMF-based assessments, validate control implementation... 

    CACI International Inc.

    Alexandria, VA
    5 days ago
  • $86.8k - $198k

    Technology Transfer and Export Control Specialist, SeniorThe Opportunity:This position offers the opportunity to directly support the...  ...advancing its mission by managing and implementing international security cooperation programs, technology transfer processes, and export... 
    Full time
    Contract work
    Part time
    Local area
    Remote work

    Booz Allen Hamilton

    Arlington, VA
    3 days ago
  •  ...Security Control Assessor / IA Specialist Provide information assurance for digital systems, ensuring adherence to security and compliance standards. Develop and maintain assessment procedures and methodologies aligned with NIST guidelines and other relevant frameworks... 

    National Guard Employment Network

    Alexandria, VA
    4 days ago
  • Camstex operates the Keys Energy Center (761MW) as a control room operator, ensuring safe, reliable, and efficient plant operation. You will follow procedures and directives, monitor turbines, log data, and communicate conditions clearly. Requires 3+ years in Aeroderivative... 
    Full time
    Rotating shift

    Camstex

    Brandywine, MD
    3 days ago
  • $86.6k - $181.8k

     ...Security Control Assessor / IA Specialist Provide information assurance for digital systems, ensuring adherence to security and compliance standards. Develop and maintain assessment procedures and methodologies aligned with NIST guidelines and other relevant frameworks... 
    Contract work
    Work experience placement
    Flexible hours

    CACI International

    Alexandria, VA
    6 days ago
  • $102.83k - $150k

     ...Salaried/ExemptAnticipated Salary Range: $102,831.00 - $150,000.00 Security Clearance: TS/SCI Level of Experience: Mid This opportunity...  ...experience. Below are the salary ranges: Security Controls Accessor: $85,185 - $135,000Sr. Security Controls Accessor: $104,738... 
    Full time
    Work experience placement
    Local area
    Worldwide

    HII Mission Technologies Division

    Springfield, VA
    4 days ago
  •  ...401K, an Employee Stock Purchase Plan (ESPP) through Tetra Tech, and more! Responsibilities:Execute all phases of cyber security and privacy control assessment supportRequired Qualifications:Masters Degree in a Technical or Cyber-related Field7+ years of Relevant Cybersecurity... 

    EGlobalTech

    Arlington, VA
    3 days ago
  •  ...delivers high-impact, technical solutions to complex national security issues. With over 50 years of business expertise and consistent...  ...Responsive. Trusted. SPA seeks an experienced export and trade control professional to work within the SPA Legal Department. This role... 
    Full time
    For contractors
    Work at office
    Flexible hours

    Systems Planning and Analysis

    Alexandria, VA
    2 days ago
  • $131k - $218.3k

     ...with resilience, grow with confidence, and proactively manage to secure success.Work you'll doAs a Senior Consultant on the Cyber...  ...responsible for helping deliver Oracle Cloud Applications Security & Controls implementations and Risk Management Cloud modules, with a focus... 
    Local area

    Deloitte

    Rosslyn, VA
    4 days ago
  • $160k - $230k

     ...Owned Small Business specializing in mission-critical engineering, secure infrastructure, and advanced technical solutions for federal...  ...Summary Fusion is seeking a highly qualified Senior Controls Engineer to join an IT/OT hybrid Industrial Control Systems (... 
    Contract work
    Immediate start

    Rippling

    Washington DC
    2 days ago
  •  ...Planned Companies is seeking friendly, professional Private Security Guards for part-time night shifts in Arlington, VA. The role covers routine patrols, gate house security, and monitoring CCTV to ensure property safety. Requirements include a valid Security Officer... 
    Part time
    Night shift

    Jobleads-US

    Arlington, VA
    3 days ago
  • $100k - $130k

     ...Controls Engineer FusionICS, LLC Washington, District of Columbia, United States About this position About Fusion Fusion...  ...Owned Small Business specializing in mission-critical engineering, secure infrastructure, and advanced technical solutions for federal... 
    Contract work
    Immediate start
    Remote work

    FusionICS, LLC

    Washington DC
    3 days ago
  • $29 per hour

     ...Security SupervisorThe Security Supervisor is responsible for assisting the Director of Security in the daily operations of the Safety...  ...work tasks are performed indoors. Temperature is moderate and controlled by hotel environmental systems. There is a requirement to work... 
    Hourly pay
    Weekend work

    Montage International

    Washington DC
    2 days ago
  • $168.93k

    11-009 – Security Control Assessor (SCA) II Location: Crystal City, VA Salary: $168,932.71 Billet Number: JUSTIFIED-0055 Skill Level: 2 Current Vacancy-Specific Requirements MANDATORY: 7-9 years related experience; 4+ years experience in SAP, SCI, or Collateral Information... 

    Sandy Mac Evolution

    Arlington, VA
    5 days ago
  • $140k - $200k

    Modern Technology Solutions Inc. (MTSI) is seeking a Senior Security Controls Assessor Representative (SCAR) to join our team in support of a high profile Air Force program at Joint Base Anacostia‑Bolling (DC) or Wright‑Patterson AFB (OH). The candidate will be responsible... 
    Contract work

    Modern Technology Solutions

    Washington DC
    3 days ago
  •  ...Security Control AssessorVMD Corp, now part of Xcelerate Solutions, seeks a Security Control Assessor to be responsible for the cybersecurity of a program, organization, system, or enclave. The Security Control Assessor ensures that the security and privacy posture is... 
    Local area

    VMD Corp

    Arlington, VA
    2 days ago
  •  ...Position Overview We are seeking an experienced Security Control Assessor to support cybersecurity assessment and authorization activities for Department of Defense information systems. This role is responsible for conducting in-depth security control assessments, validating... 
    Immediate start
    Flexible hours

    novulsolutions

    Arlington, VA
    1 day ago
  • $29 per hour

     ...considered. Please Click Here to apply internally. Security Supervisor SUMMARY The Security Supervisor is...  ...work tasks are performed indoors. Temperature is moderate and controlled by hotel environmental systems. There is a requirement to work... 
    Hourly pay
    Weekend work

    Montage International

    Washington DC
    4 days ago
  •  ...delivers high-impact, technical solutions to complex national security issues. With over 50 years of business expertise and consistent...  ...Future Force Assessments. SPA has an immediate need for a Security Controls Assessor (SCA).#FC #DiceResponsibilitiesThe Security Controls... 
    Immediate start
    Flexible hours

    MCR

    Washington DC
    7 hours ago
  •  ...defense missions, playing a crucial role in ensuring the safety and security of the United States and its allies. Join JRC's Missiles and...  ...s Missiles and Space Team is actively searching for an Access Control Specialist and play a vital role in supporting one of the Navy... 
    Flexible hours

    JRC

    Washington DC
    3 days ago
  •  ...Admiral Security Services Job Opportunity Admiral Security Services was established in 1976 and has consistently grown for over four...  ...site specific post orders. These duties may include: Access control for guests, tenants and vendors. Enforcement of Client and... 
    Contract work
    Work experience placement
    Work at office

    Admiral Security

    Washington DC
    1 day ago
  •  ...delivers high-impact, technical solutions to complex national security issues. With over 50 years of business expertise and consistent...  ...superiority in the future. We have a future need for a Sr. ISR and Space Control Analyst to support the C4ISR and Space directorates within the... 
    Flexible hours
    Shift work

    MCR

    Arlington, VA
    3 days ago
  • Job Description Access Control Specialist Department: Operations Reports To: Access Control Supervisor / Director of Safety & Security Schedule: Varied shifts, including nights, weekends, and holidays Status: On-site, essential position (24/7 operations) Position Summary... 
    For contractors
    Work at office
    Shift work
    Night shift

    The Westchester Corporation

    Washington DC
    2 days ago
  • $131.6k

     ...Summary Security Control Assessor Franconia, VA Are you ready to enhance your skills and build your career in a rapidly evolving business climate? Are you looking for a career where professional development is embedded in your employer’s core culture? If so,... 

    Chenega Professional Services Strategic Business Unit

    Alexandria, VA
    3 days ago
  • $159.2k

     ...Req ID: 42079 Summary Security Control Assessor (SCA) Arlington, VA Are you ready to enhance your skills and build your career in a rapidly evolving business climate? Are you looking for a career where professional development is embedded in your employers... 
    Work at office

    NJVC

    Arlington, VA
    5 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Security Control Accessor. Be the first to apply!