Security Control Assessor
Apavo Corporation
Job Title: SecurityControl Assessor Location:On Site inArlington, VA Department: CyberSecurity Services Reports To: Management FLSA Status:Full Time/Non-exempt JobPurpose: The security control assessor (SCAs) supports a critical, objective role to evaluate the effectiveness of implemented controls in mitigating security risks.The SCA will support a critical mission within the intelligence community. In the role as a SCA, you are expected to use automated scanning tools, manual techniques, and specialized testing methodologies toidentifyweaknesses and vulnerabilities.The SCA is expected to be a collaborative member of the RMF program of the organization, to provide intelligent input to system security architecturesin order toalign with RMF principles and guidelines. This includes ensuring to guide the RMF process so that security controls are integrated seamlessly into system designs to provide comprehensive protection against threats and vulnerabilities. Duties&Responsibilities: The SCA's specific duties include: Advisethe Information System Owner (ISO) concerning the impact levels for Confidentiality, Integrity, and Availability for the information on systems. Ensure security assessments are completed for each IS. Initiate a POA&M with identified weaknesses and suspense dates for each IS based on findings and recommendations from the SAR. Evaluate security assessment documentation and provide written recommendations for security authorization tothe CISOand AO. Assess proposed changes to Information Systems, their environment of operation, and mission needs that could affect system authorization. Serve as a cybersecurity technical advisor to the CISO and AO under their purview. Be integral to the development of the monitoring strategy. The system-level continuous monitoring strategy must conform to all applicable published DoD enterprise-level or DoD Component-level continuous monitoring strategies. Determineand document in the SAR a risk level for every noncompliant security control in the system baseline. Determineand document in the SAR an aggregate level of risk to the system andidentifythe key drivers for the assessment. The SCA's risk assessment considers threats, vulnerabilities, and potential impacts as well as existing and planned risk mitigation. Develop the continuous monitoring plan specific to the information system. The SCAis responsible forthe RMF deliverables associated with Step 4 of DOD and IC RMF Policies for assigned systems. This includes, but is not limited to: Security Assessment Plans tailored to specific systems control requirements Security control assessment input, which includes narratives for the review of controls and artifacts Security Assessment Reports ATO recommendations or ATO with Condition Memorandums Conduct initial remediation actions once a security assessment has been completed to ensure properhand offto the ISSM and ISSOs. Assessment of selected controls IAW continuous monitoring strategy The SCA is expected to haveadditionalduties as assigned in support of corporate cyber security services.Additionaldetails are reviewedin accordance withcompany policies. Requirements Required Skills & Experience: Strong knowledge of Risk Management Framework (RMF) 800-37 and continuous monitoring 800-137 Expert knowledge and hands-on experience with FISMA Systems, NIST 800-series guidelines, FIPS, Security Assessment & Authorization (SA&A) requirements and processes, Continuous Monitoring Framework experience and its tools, Plan of Action & Milestones (POA&M) policies, and vulnerability/patch management, risk management, project management, proficient with Microsoft products - Word, Excel, PowerPoint. Proficient with vulnerability and scanning tools and well-versed in interpreting risk posture resulting from assessment reports. Experience in project management and tracking, and the Microsoft suite of office products Experience of assessing cloud-based security authorizations (FedRamp, AWS & Azure) as well as the NIST control responsibilities Experience with SAP/JSIG Expert with documenting and or reviewing of security materials suchas;system security plans (SSP), Security Assessment Report (SAR), and Security Assessment Plan (SAP), and other documents per NIST 800 guidelines. Experience supporting cloud-based security authorizations (FedRamp, AWS, & Azure) Experiencecreating Security Assessment Plans, Security Assessment Reports, and Executive-level briefings Qualifications: Bachelor'sDegree in Computer Scienceor a related technical discipline Master'sDegree preferred. Minimum6-10 years of experience. Must currentlypossessan active TS/SCI with the ability to obtain andmaintaina CI polygraph. DOD 8140 IAM Level II (CAP, CASP, CISM, CISSP, GSLC, CCISO) isrequired Systems Security Engineering background preferred. Effective communication skills to collaborate with cross-functional teams and stakeholders on implementing security measures organization-wide. Strong analytical skills foridentifyingsystem vulnerabilities anddocumenting control remediation recommendations through collaboration on System Impact Analysis and Documented Risk Acceptance. Detail-oriented with the ability to manage multiple tasks and prioritize effectively. Comprehensive knowledge of RMF activities at a senior level (ability to articulate to Executive audiences preferred). Familiarity with federalregulatory requirements, contractual obligations, and industry standards related to information security. Evaluate adherence to standards such as Privacy, GDPR, and HIPAA Other: This is typical office or administrative work, and there is no exposure toadverse environmental conditions. This position requires sedentary work. Sedentary work is defined as: Exerting up to 10 pounds of force occasionally and/or a negligible amount of forcefrequentlyor constantly to lift, carry, push, pull or otherwise move objects, including the human body. Sedentary work involves sitting most of the time. Jobs are sedentary if walking and standing arerequiredonlyoccasionally,and all other sedentary criteria are met. #J-18808-Ljbffr Apavo Corporation
- ...RMF and A&A documentation including SSPs, control implementation matrices, SARs, POA&Ms,... ...Components and customer agencies implement security controls, maintain accurate... ...System Owners, ISSOs, IAMs, and third-party assessors, reducing manual burden for ISSOs and system...SuggestedTemporary workWork at officeFlexible hours
$150k - $168k
...is seeking a Please Note: This position is contingent upon contract award. ECS seeks a Job Description ECS is seeking a Security Controls Assessor to work in our Washington, DC (hybrid) office. Please Note: This position is contingent upon contract award. ECS seeks a...SuggestedLong term contractFull timeContract workWork at officeLocal areaImmediate start$160k - $180k
...delivers high-impact, technical solutions to complex national security issues. With over 50 years of business expertise and... ...Force Assessments. SPA has an immediate need for a Security Controls Assessor (SCA). #FC #Dice Responsibilities The Security Controls Assessor...SuggestedImmediate startFlexible hours- Security Control Assessor (SCA), Level I Arlington, VA Role: Security Control Assessor (SCA), Level I Location: Arlington, VA Clearance Required: TS/SCI Polygraph: CI Position Description The SCA is responsible for conducting a comprehensive assessment of the management...SuggestedContract workLocal area
- Position Overview The Security Control Assessor must fulfill a variety of cybersecurity functions, to include: System Administrator, Enterprise Oversight, certification and accreditation, SAP and SCI assessment and authorization (A&A), Platform Information Technology (PIT...SuggestedLocal area
- Benefits Competitive salary About this Role We are looking for a SME Security Control Assessor that supports security control assessment activities for HHS-ACF information systems by applying NIST security controls and frameworks to evaluate control implementation and...Work at officeLocal areaWork from homeFlexible hours
- Tetra Tech in Arlington, Virginia, is seeking a cybersecurity professional to execute all phases of security and privacy control assessments. The ideal candidate will have at least 7 years of relevant experience, specifically in federal cybersecurity, as well as strong...
- Omniscius Consulting is seeking a SecurityControl Assessor in Arlington, VA, on site, to evaluate security controls and support RMF implementation for a critical IC mission. You will perform assessments using automated tools, authoring SARs, SAPs, and plans of action &...
- Dark Wolf Solutions in Arlington, VA is seeking Security Control Assessors/Representatives to lead security assessments across high-priority projects. You will evaluate controls for AI/LLM technologies, work within DoD-aligned frameworks, and deliver risk briefings for...Remote job
- Apavo Corporation is seeking a Security Control Assessor to perform RMF-based security assessments for DoD/IC systems. You will use automated and manual testing, support RMF activities, and provide guidance to ensure controls are integrated into system designs. The role...
$175.2k
Req ID: 42078 Summary Lead Senior Security Control Assessor (SCA) Arlington, VA Are you ready to enhance your skills and build your career in a rapidly evolving business climate? Are you looking for a career where professional development is embedded in your employers...Work at office- Chenega MIOS is seeking a Security Control Assessor in Arlington, VA to help manage RMF/DoD security authorizations. You will lead risk assessments, craft SAP/SAR/SAP documents, and guide continuous monitoring efforts while coordinating with A&A leadership. Ideal candidates...
- Chenega MIOS in Arlington, VA seeks a Lead Senior Security Control Assessor (SCA) to guide RMF-based assessments and continuous monitoring for DoD-related information systems. You will coordinate SAPs, SARs, and POA&Ms, and advise leadership on risk posture and mitigations...
$140k - $210k
Overview VTG is looking for multiple levels (Level 2, 3 & 4) of a Security Control Assessor (SCA) in multiple locations. (Note: position is contingent upon program award and the postions are located in Chantilly VA, Aurora CO, Springfield VA, Las Cruces NM, & LAAFB.) What...For contractorsWork experience placement- Security Control Assessor (SCA) LOCATION Tysons, VA 22182 CLEARANCE TS/SCI Full Poly (Please note this position requires full U.S. Citizenship) KEY SUMMARY We are seeking a meticulous and detail-oriented **Security Control Assessor (SCA)** to join our team and ensure that...Temporary workFor contractorsImmediate startFlexible hours
$102.83k - $150k
...Exempt Anticipated Salary Range: $102,831.00 - $150,000.00 Security Clearance: TS/SCI Level of Experience: Mid The selected... ...clearance will be required. What you will do The Security Controls Assessor plays a critical role in evaluating, validating, and strengthening...Full timeWork experience placementLocal area$169k - $171.5k
...Description Job Description Location: Crystal City, VA Security Clearance: Active TS/SCI [Required] (Must be able to obtain... ...which may impact salary Position Overview The Security Control Assessor (SCA) is responsible for conducting comprehensive assessments...Full time- ...Job Description Job Description Description: P-11 Security is seeking a SCA who is responsible for conducting a comprehensive assessment of the management, operational, and technical security controls employed within or inherited by an IS to determine the overall...
- ...to support our nation's defense. Make an impact by connecting and securing critical operations across the globe, keeping our country safe and secure. Job Description The Security Control Assessor (SCA) II is responsible for conducting a comprehensive assessment...
$180k - $220k
Modern Technology Solutions, Inc. (MTSI) is seeking a Security Control Assessor (SCA) to support an MTSI contract with the Assistant Secretary of the Air Force, Acquisition, Technology and Logistics. The SCA is responsible for conducting a comprehensive assessment of the...Contract work- ...referral program, and educational assistance. Additional details can be found on our website at: Position Title : DHS Security Control Assessor III Location : NCR Clearance : TS/SCI OneZero Solutions is on contract to provide division-wide support for Federal...Full timeContract workWork at office
- ...government entities to deliver predictable, measurable impact for the American taxpayer and consumer. Join rockITdata as a Security Control Assessor / ISSE Support supporting one of the nation's largest federal healthcare modernization initiatives. In this role, you'll...Full time
- ...Job Description Job Description Position Overview RiVidium Inc. is seeking an experienced Security Control Assessor (SCA) ? Level II / Journeyman to support federal cybersecurity assessment, authorization, compliance, and risk management activities. The Security...Contract work
- ...401K, an Employee Stock Purchase Plan (ESPP) through Tetra Tech, and more! Responsibilities:Execute all phases of cyber security and privacy control assessment supportRequired Qualifications:Masters Degree in a Technical or Cyber-related Field7+ years of Relevant Cybersecurity...
- CCI International Inc. seeks a Security Control Assessor / IA Specialist in the Alexandria, VA area to provide information assurance for digital systems and ensure compliance with security frameworks. You will plan and execute RMF-based assessments, validate control implementation...
$87k - $198k
...Security Control Assessor and System Certification Specialist, Senior The Opportunity: Function as a Senior System Certification Specialist or Security Control Assessor as part of a team in the performance of Assessment and Authorization (A&A) activities ensuring...Full timeContract workPart timeLocal areaRemote work$135k - $150k
...Job Description Job Description Dark Wolf Solutions is seeking Security Control Assessor/Representatives (SCA/Rs) to lead security control assessments across high-priority projects. Working at the intersection of cybersecurity engineering, cloud architecture,...Full timeFor contractors- Job Family:Technology ConsultingTravel Required:Up to 10%Clearance Required:NoneWhat You Will Do:The Security Assessor supports security and privacy control assessments for public‑sector systems by evaluating control effectiveness, validating evidence, and contributing...Work experience placementFlexible hours
- ...assets, processes, policies, and people delivering value. See Link To the ProSidian website at DescriptionProSidian Seeks a Security Controls Assessor / ISSO | Human Capital Programmatic Evaluation & Compliance - Cybersecurity & Compliance [NSF0083083] for Program Support...Full timeContract workTemporary workFor contractorsH1bWork at officeFlexible hours
$135k - $140k
...Job Description Job Description RiVidium Inc. is seeking a Security Control Assessor who conducts independent comprehensive assessments of the management, operational, and technical security controls and control enhancements employed within or inherited by an information...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security Control Assessor. Be the first to apply!
