Security Control Assessor
Apavo Corporation
Security Control Assessor
Location: On Site in Arlington, VA
Department: Cyber Security Services
Reports To: Management
FLSA Status: Full Time/Non-exempt
Job Purpose:
The security control assessor (SCAs) supports a critical, objective role to evaluate the effectiveness of implemented controls in mitigating security risks. The SCA will support a critical mission within the intelligence community. In the role as a SCA, you are expected to use automated scanning tools, manual techniques, and specialized testing methodologies to identify weaknesses and vulnerabilities. The SCA is expected to be a collaborative member of the RMF program of the organization, to provide intelligent input to system security architectures in order to align with RMF principles and guidelines. This includes ensuring to guide the RMF process so that security controls are integrated seamlessly into system designs to provide comprehensive protection against threats and vulnerabilities.
Duties & Responsibilities:
The SCA's specific duties include:
- Advise the Information System Owner (ISO) concerning the impact levels for Confidentiality, Integrity, and Availability for the information on systems.
- Ensure security assessments are completed for each IS.
- Initiate a POA&M with identified weaknesses and suspense dates for each IS based on findings and recommendations from the SAR.
- Evaluate security assessment documentation and provide written recommendations for security authorization to the CISO and AO.
- Assess proposed changes to Information Systems, their environment of operation, and mission needs that could affect system authorization.
- Serve as a cybersecurity technical advisor to the CISO and AO under their purview.
- Be integral to the development of the monitoring strategy. The system-level continuous monitoring strategy must conform to all applicable published DoD enterprise-level or DoD Component-level continuous monitoring strategies.
- Determine and document in the SAR a risk level for every noncompliant security control in the system baseline.
- Determine and document in the SAR an aggregate level of risk to the system and identify the key drivers for the assessment. The SCA's risk assessment considers threats, vulnerabilities, and potential impacts as well as existing and planned risk mitigation.
- Develop the continuous monitoring plan specific to the information system.
The SCA is responsible for the RMF deliverables associated with Step 4 of DOD and IC RMF Policies for assigned systems. This includes, but is not limited to:
- Security Assessment Plans tailored to specific systems control requirements
- Security control assessment input, which includes narratives for the review of controls and artifacts
- Security Assessment Reports
- ATO recommendations or ATO with Condition Memorandums
- Conduct initial remediation actions once a security assessment has been completed to ensure proper hand off to the ISSM and ISSOs.
- Assessment of selected controls IAW continuous monitoring strategy
The SCA is expected to have additional duties as assigned in support of corporate cyber security services. Additional details are reviewed in accordance with company policies.
Required Skills & Experience:
- Strong knowledge of Risk Management Framework (RMF) 800-37 and continuous monitoring 800-137
- Expert knowledge and hands-on experience with FISMA Systems, NIST 800-series guidelines, FIPS, Security Assessment & Authorization (SA&A) requirements and processes, Continuous Monitoring Framework experience and its tools, Plan of Action & Milestones (POA&M) policies, and vulnerability/patch management, risk management, project management, proficient with Microsoft products - Word, Excel, PowerPoint.
- Proficient with vulnerability and scanning tools and well-versed in interpreting risk posture resulting from assessment reports. Experience in project management and tracking, and the Microsoft suite of office products
- Experience of assessing cloud-based security authorizations (FedRamp, AWS & Azure) as well as the NIST control responsibilities
- Experience with SAP/JSIG
- Expert with documenting and or reviewing of security materials such as; system security plans (SSP), Security Assessment Report (SAR), and Security Assessment Plan (SAP), and other documents per NIST 800 guidelines.
- Experience supporting cloud-based security authorizations (FedRamp, AWS, & Azure)
- Experience creating Security Assessment Plans, Security Assessment Reports, and Executive-level briefings
Qualifications:
- Bachelor's Degree in Computer Science or a related technical discipline
- Master's Degree preferred.
- Minimum 6-10 years of experience.
- Must currently possess an active TS/SCI with the ability to obtain and maintain a CI polygraph.
- DOD 8140 IAM Level II (CAP, CASP, CISM, CISSP, GSLC, CCISO) is required
- Systems Security Engineering background preferred.
- Effective communication skills to collaborate with cross-functional teams and stakeholders on implementing security measures organization-wide.
- Strong analytical skills for identifying system vulnerabilities and documenting control remediation recommendations through collaboration on System Impact Analysis and Documented Risk Acceptance.
- Detail-oriented with the ability to manage multiple tasks and prioritize effectively.
- Comprehensive knowledge of RMF activities at a senior level (ability to articulate to Executive audiences preferred).
- Familiarity with federal regulatory requirements, contractual obligations, and industry standards related to information security. Evaluate adherence to standards such as Privacy, GDPR, and HIPAA
Other:
This is typical office or administrative work, and there is no exposure to adverse environmental conditions.
This position requires sedentary work. Sedentary work is defined as: Exerting up to 10 pounds of force occasionally and/or a negligible amount of force frequently or constantly to lift, carry, push, pull or otherwise move objects, including the human body. Sedentary work involves sitting most of the time. Jobs are sedentary if walking and standing are required only occasionally, and all other sedentary criteria are met.
$150k - $168k
Job DescriptionECS is seeking a Security Controls Assessor to work in our Washington, DC (hybrid) office. Please Note: This position is contingent upon contract award.ECS seeks a Security Controls Assessor to support a full range of cybersecurity services on a long-term...SuggestedLong term contractFull timeContract workWork at officeImmediate start- ...Position OverviewThe Security Control Assessor must fulfill a variety of cybersecurity functions, to include: System Administrator, Enterprise Oversight, certification and accreditation, SAP and SCI assessment and authorization (A&A), Platform Information Technology (PIT...SuggestedFor contractorsWork experience placementWork at officeLocal areaWorldwide
- ...Digital Global Connectors (DGC) is seeking an experienced Security Assessor (RMF / GRC) to support a Federal information security program.... ...conducting, documenting, and reporting comprehensive security control assessments that evaluate the effectiveness of administrative...Suggested
- ...Cymertek Tysons, VA–based System Security Auditor position seeks a meticulous professional to audit security controls, assess vulnerabilities, and ensure regulatory compliance. You will produce detailed reports, craft audit plans, and recommend improvements to safeguard...Suggested
- 38North Security is the world’s most experienced, technically expert, cloud advisory team... ...environments against NIST SP 800-53 rev 5 security control requirements. Systems assessed could... ...to obtain a Public Trust Clearance Assessor must be able to conduct assessment...SuggestedLocal areaRemote workFlexible hours
$160k - $180k
...delivers high-impact, technical solutions to complex national security issues. With over 50 years of business expertise and... ...Force Assessments. SPA has an immediate need for a Security Controls Assessor (SCA). #FC #Dice Responsibilities The Security Controls Assessor...Immediate startFlexible hours- ...401K, an Employee Stock Purchase Plan (ESPP) through Tetra Tech, and more! Responsibilities:Execute all phases of cyber security and privacy control assessment supportRequired Qualifications:Masters Degree in a Technical or Cyber-related Field7+ years of Relevant Cybersecurity...
- Security Control Assessor (SCA), Level I Arlington, VA Role: Security Control Assessor (SCA), Level I Location: Arlington, VA Clearance Required: TS/SCI Polygraph: CI Position Description The SCA is responsible for conducting a comprehensive assessment of the management...Contract workLocal area
- The Security Control Assessor (SCA) II is responsible for conducting a comprehensive assessment of the management, operational, and technical security controls employed within or inherited by an IS to determine the overall effectiveness of the controls (i.e., the extent...
$128.8k - $214.5k
...Senior Security Control Assessor (SCA) Unlock the secrets of intelligence with MANTECH! Join a dynamic team at the forefront of national security, providing advanced solutions to government intelligence agencies. Since 1968, we've been solving the toughest challenges...Hourly payContract workTemporary workWork experience placementWork at officeLocal areaRemote work$120k - $135k
...Senior Security Control Assessor Remote Blu Omega is seeking a Senior Security Control Assessor to support a federal program focused on security and privacy control assessment support. This role operates within a remote environment and is responsible for conducting...Temporary workRemote work- Apavo Corporation is seeking a Security Control Assessor to perform RMF-based security assessments for DoD/IC systems. You will use automated and manual testing, support RMF activities, and provide guidance to ensure controls are integrated into system designs. The role...
- General Dynamics Information Technology (GDIT) is seeking a Security Control Assessor II to conduct comprehensive assessments of security controls for information systems, including SAP/SCI environments, to determine effectiveness and identify weaknesses. The role requires...
$102.83k - $150k
...Salary Range: $102,831.00 - $150,000.00 Security Clearance: TS/SCI Level of Experience: Mid... .... Below are the salary ranges: Security Controls Accessor: $85,185 - $135,000Sr. Security... ...00What you will doThe Security Controls Assessor plays a critical role in evaluating,...Full timeWork experience placementLocal areaWorldwide$146k - $234k
ResponsibilitiesPeraton seeks a Cloud Security Control Assessor to support the Army Cyber Command (ARCYBER). Location: Alexandria, VA/Metro Park near Fort Belvoir, VA.Tasks include:Conduct assessments and facilitate risk mitigation planningProvide Assessment and Authorization...Contract workLocal areaShift work- ...assets, processes, policies, and people delivering value. See Link To the ProSidian website at DescriptionProSidian Seeks a Security Controls Assessor / ISSO | Human Capital Programmatic Evaluation & Compliance - Cybersecurity & Compliance [NSF0083083] for Program Support...Full timeContract workTemporary workFor contractorsH1bWork at officeFlexible hours
- General Dynamics - IT seeks a Security Control Assessor (SCA) II to conduct comprehensive assessments of management, operational, and technical security controls for IS and its environment. The role evaluates weaknesses, documents SARs, and recommends corrective actions...
- ...Security Control Assessor (SCA) LOCATION Reston, VA 20190 CLEARANCE TS/SCI Full Poly (Please note this position requires full U.S. Citizenship) KEY SUMMARY We are seeking a meticulous and detail-oriented **Security Control Assessor (SCA)** to join our team and ensure that...Temporary workFor contractorsImmediate startFlexible hours
- ...Security Control Assessor (Authorizing Official) Position Summary: As Security Control Assessor (Authorizing Official/AO) you will provide cybersecurity support to the National Geospatial-Intelligence Agency (NGA) in Springfield, VA. You will award authorization...Full timeWork at officeImmediate startFlexible hours
$131.6k
...Summary Security Control Assessor (SCA) Oakton, VA Are you ready to enhance your skills and build your career in a rapidly evolving business climate? Are you looking for a career where professional development is embedded in your employer’s core culture? If so, Chenega...$137k - $152k
...include IT Talent Solutions, Data Delivery & Analytics, Cyber Security, Cloud Migration, Applications and Infrastructure, Software... ...and Finance & Accounting. M9 Solutions is seeking a Security Control Assessor to work on-site in support of a government contract for a...Full timeContract workFor subcontractor- ...Security Control Assessor (SCA) HII's Mission Technologies division is dedicated to delivering cutting-edge solutions that advance national security and defense objectives. This position is part of our Cyber and Intelligence division, which plays a critical role in...Work experience placement
- ...Job#: 3044387 Job Description: Security Control Assessor Location: Alexandria, Virginia (Onsite) Role Overview We are seeking a skilled and detail-oriented Security Control Assessor to join our team. The successful candidate will be responsible for evaluating, testing,...
$146k - $234k
...About Peraton Peraton is a next-generation national security company that drives missions of consequence spanning the globe and extending... ...and secure. About The Role Peraton seeks a Cloud Security Control Assessor to support the Army Cyber Command (ARCYBER). Location:...Contract workTemporary workLocal areaShift work- Everforth Apex is seeking a Security Control Assessor in Alexandria, VA to evaluate, test, and validate security controls within information systems, with RMF emphasis. You will develop A&A artifacts, SARs, SSPs, and POA&Ms, and guide remediation actions through authorization...
$160k - $172k
...Title: Security Control Assessor (SCA) Belong. Connect. Grow. with KBR! KBR's National Security Solutions team provides high-end engineering and advanced technology solutions to our customers in the intelligence and national security communities. In this position...Full timeContract workTemporary workLocal areaRelocation packageFlexible hours- ...opportunity at a place where you can have an influence every day? Then Serco has the right opportunity for you! As a Senior Security Control Assessor, you will provide senior-level security control assessment support to a Department of Defense (DoD) customer supporting...Full timeContract workPart timeFor contractorsWork at officeLocal areaMonday to FridayFlexible hours
$107.9k - $195.05k
SCI Security Controls Assessor Representative A&A SpecialistLocation: Suitland, MDClearance: Active TS/SCILeidos is seeking a SCI Security Controls Assessor Representative A&A Specialist to join our team in Suitland, MD. In this role, you will support the assessment and...Full timeInterim roleWork at officeWorldwide- ...government entities to deliver predictable, measurable impact for the American taxpayer and consumer. Join rockITdata as a Security Control Assessor / ISSE Support supporting one of the nation's largest federal healthcare modernization initiatives. In this role, you'll...Full timeLocal area
$87.1k - $157.45k
SCI Security Controls Assessor Liaison SpecialistLocation: Suitland, MDClearance: Active TS/SCILeidos is seeking a Security Controls Assessor Liaison to support the Assessment & Validation Division within the Office of Naval Intelligence at the Hopper Global Communications...Full timeInterim roleWork at office
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security Control Assessor. Be the first to apply!

