it job board logo
  • Home
  • Find IT Jobs
  • Register CV
  • Register as Employer
  • Contact us
  • Career Advice
  • Recruiting? Post a job
  • Sign in
  • Sign up
  • Home
  • Find IT Jobs
  • Register CV
  • Register as Employer
  • Contact us
  • Career Advice
Sorry, that job is no longer available. Here are some results that may be similar to the job you were looking for.

16 jobs found

Email me jobs like this
Refine Search
Current Search
security control assessor sca ii
SCA II - Security Control Assessor
Watermark Risk Management International Arlington, Virginia
Job Description Job Description Come make your mark with Watermark! FOUNDED BY USAF VETERANS in 2007, we are proud to be a Service-Disabled Veteran Owned Small Business. SUBJECT MATTER EXPERTS specializing in security and risk management. We're intimately familiar with DOD security programs and mission requirements. OUR CORE VALUES drive every action we take as a company. We strive to exhibit PERSPECTIVE, PASSION, COMMUNICATION, INTEGRITY AND ETHICS, and BALANCE in all we do. COMPETITIVE BENEFITS PACKAGE to address our employees' physical, mental, emotional, and financial well-being. This includes 100% employer- paid medical insurance, ample paid leave, a free employee assistance program, and a competitive 401k savings plan. At Watermark, our people come first! Security Control Assessor (SCA) II The SCA is responsible for conducting a comprehensive assessment of the management, operational, and technical security controls employed within or inherited by an IS to determine the overall effectiveness of the controls (i.e., the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for the system). SCAs also provide an assessment of the severity of weaknesses or deficiencies discovered in the IS and its environment of operation and recommend corrective actions to address identified vulnerabilities. Responsibilities will cover Collateral, Sensitive Compartmented Information (SCI) and Special Access Program (SAP) activities within the customer's area of responsibility. In this role you will . Perform oversight of the development, implementation and evaluation of IS security program policy; special emphasis placed upon integration of existing SAP network infrastructure Perform assessment of ISs, based upon the Risk Management Framework (RMF) methodology in accordance with the Joint Special Access Program (SAP) Implementation Guide (JSIG) Advise the Information System Owner (ISO), Information Data Owner (IDO), Program Security Officer (PSO), and the Delegated and/or Authorizing Official (DAO/AO) on any assessment and authorization issues Evaluate Authorization packages and make recommendation to the AO and/or DAO for authorization Evaluate IS threats and vulnerabilities to determine whether additional safeguards are required Advise the Government concerning the impact levels for Confidentiality, Integrity, and Availability for the information on a system Ensure security assessments are completed and results documented and prepare the Security Assessment Report (SAR) for the Authorization boundary Initiate a Plan of Action and Milestones (POA&M) with identified weaknesses for each Authorization Boundaries assessed, based on findings and recommendations from the SAR Evaluate security assessment documentation and provide written recommendations for security authorization to the Government Discuss recommendation for authorization and submit the security authorization package to the AO/DAO Assess proposed changes to Authorization boundaries operating environment and mission needs to determine the continuation to operate. Review and concur with all sanitization and clearing procedures in accordance with Government guidance and/or policy Assist the Government compliance inspections Assist the Government with security incidents that relate to cybersecurity and ensure that the proper and corrective measures have been taken Ensure organization are addressing and conducting all phases of the system development life cycle (SDLC) Evaluate Hardware and Software to determine security impact that it might have on Authorization boundaries Evaluate the effectiveness and implementation of Continuous Monitoring Plans Represent the customer on inspection teams Additional duties as assigned Experience Requirements: 7-9 years related experience Minimum of four (4) years' experience in SAP, SCI or Collateral Information Systems (IS) Security and the implementation of regulations identified in the description of duties. Prior performance in the role of ISSO and ISSM or SCA Education Requirements: Bachelor's degree in a related area OR Associate's degree in a related area + 2 years' experience OR equivalent experience (4 years) Certification Requirements: Must meet position and certification requirements outlined in DoD Directive 8570.01-M for Information Assurance Technician Level III or Information Assurance Manager Level II within 6 months of the date of hire Security Clearance Requirements: Active TS/SCI clearance Eligibility for access to Special Access Program Information Willingness to submit to a Counterintelligence polygraph Other Requirements: Must be able to regularly lift up to 50 lbs. May require sedentary work at least 50% of the time Reports to a physical location which occasionally requires the ability to traverse between buildings Ability to manage stress with a high degree of maturity/professionalism Demonstrated critical thinking and leadership skills and the ability to work well with others Effective verbal and written communication skills All Level I & Level II positions - candidate should possess some Special Access Program (SAP) experience All Level III positions -candidate should possess 2+ years of Special Access Program (SAP) experience Watermark provides salary ranges with job postings in states where it is legally required; any other salary ranges associated with our postings are third party estimates and may not be an accurate reflection of Watermark's total compensation package. Multiple considerations are taken into account when determining the final salary/hourly rate, including but not limited to, Contract Wage Determination, education and certifications, relevant work experience, related skills and competencies, as well as Federal Government Contract Labor Categories. Central to Watermark's employment philosophy is the wellbeing of our employees which is why we offer a robust benefits package and wellness program alongside of annual base compensation. Watermark is an equal opportunity employer. All terms and conditions of employment are established without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, pregnancy, genetic information, disability, veteran status, or any other protected category under applicable federal, state, and local laws. Powered by JazzHR Ulb7SEozj9
09/16/2026
Full time
Job Description Job Description Come make your mark with Watermark! FOUNDED BY USAF VETERANS in 2007, we are proud to be a Service-Disabled Veteran Owned Small Business. SUBJECT MATTER EXPERTS specializing in security and risk management. We're intimately familiar with DOD security programs and mission requirements. OUR CORE VALUES drive every action we take as a company. We strive to exhibit PERSPECTIVE, PASSION, COMMUNICATION, INTEGRITY AND ETHICS, and BALANCE in all we do. COMPETITIVE BENEFITS PACKAGE to address our employees' physical, mental, emotional, and financial well-being. This includes 100% employer- paid medical insurance, ample paid leave, a free employee assistance program, and a competitive 401k savings plan. At Watermark, our people come first! Security Control Assessor (SCA) II The SCA is responsible for conducting a comprehensive assessment of the management, operational, and technical security controls employed within or inherited by an IS to determine the overall effectiveness of the controls (i.e., the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for the system). SCAs also provide an assessment of the severity of weaknesses or deficiencies discovered in the IS and its environment of operation and recommend corrective actions to address identified vulnerabilities. Responsibilities will cover Collateral, Sensitive Compartmented Information (SCI) and Special Access Program (SAP) activities within the customer's area of responsibility. In this role you will . Perform oversight of the development, implementation and evaluation of IS security program policy; special emphasis placed upon integration of existing SAP network infrastructure Perform assessment of ISs, based upon the Risk Management Framework (RMF) methodology in accordance with the Joint Special Access Program (SAP) Implementation Guide (JSIG) Advise the Information System Owner (ISO), Information Data Owner (IDO), Program Security Officer (PSO), and the Delegated and/or Authorizing Official (DAO/AO) on any assessment and authorization issues Evaluate Authorization packages and make recommendation to the AO and/or DAO for authorization Evaluate IS threats and vulnerabilities to determine whether additional safeguards are required Advise the Government concerning the impact levels for Confidentiality, Integrity, and Availability for the information on a system Ensure security assessments are completed and results documented and prepare the Security Assessment Report (SAR) for the Authorization boundary Initiate a Plan of Action and Milestones (POA&M) with identified weaknesses for each Authorization Boundaries assessed, based on findings and recommendations from the SAR Evaluate security assessment documentation and provide written recommendations for security authorization to the Government Discuss recommendation for authorization and submit the security authorization package to the AO/DAO Assess proposed changes to Authorization boundaries operating environment and mission needs to determine the continuation to operate. Review and concur with all sanitization and clearing procedures in accordance with Government guidance and/or policy Assist the Government compliance inspections Assist the Government with security incidents that relate to cybersecurity and ensure that the proper and corrective measures have been taken Ensure organization are addressing and conducting all phases of the system development life cycle (SDLC) Evaluate Hardware and Software to determine security impact that it might have on Authorization boundaries Evaluate the effectiveness and implementation of Continuous Monitoring Plans Represent the customer on inspection teams Additional duties as assigned Experience Requirements: 7-9 years related experience Minimum of four (4) years' experience in SAP, SCI or Collateral Information Systems (IS) Security and the implementation of regulations identified in the description of duties. Prior performance in the role of ISSO and ISSM or SCA Education Requirements: Bachelor's degree in a related area OR Associate's degree in a related area + 2 years' experience OR equivalent experience (4 years) Certification Requirements: Must meet position and certification requirements outlined in DoD Directive 8570.01-M for Information Assurance Technician Level III or Information Assurance Manager Level II within 6 months of the date of hire Security Clearance Requirements: Active TS/SCI clearance Eligibility for access to Special Access Program Information Willingness to submit to a Counterintelligence polygraph Other Requirements: Must be able to regularly lift up to 50 lbs. May require sedentary work at least 50% of the time Reports to a physical location which occasionally requires the ability to traverse between buildings Ability to manage stress with a high degree of maturity/professionalism Demonstrated critical thinking and leadership skills and the ability to work well with others Effective verbal and written communication skills All Level I & Level II positions - candidate should possess some Special Access Program (SAP) experience All Level III positions -candidate should possess 2+ years of Special Access Program (SAP) experience Watermark provides salary ranges with job postings in states where it is legally required; any other salary ranges associated with our postings are third party estimates and may not be an accurate reflection of Watermark's total compensation package. Multiple considerations are taken into account when determining the final salary/hourly rate, including but not limited to, Contract Wage Determination, education and certifications, relevant work experience, related skills and competencies, as well as Federal Government Contract Labor Categories. Central to Watermark's employment philosophy is the wellbeing of our employees which is why we offer a robust benefits package and wellness program alongside of annual base compensation. Watermark is an equal opportunity employer. All terms and conditions of employment are established without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, pregnancy, genetic information, disability, veteran status, or any other protected category under applicable federal, state, and local laws. Powered by JazzHR Ulb7SEozj9
Security Control Assessor
Apavo Corporation Arlington, Virginia
Job Description Job Description Description: Job Title: Security Control Assessor Location: On Site in Arlington, VA Department: Cyber Security Services Reports To: Management FLSA Status: Full Time/Non-exempt Job Purpose: The security control assessor (SCAs) supports a critical, objective role to evaluate the effectiveness of implemented controls in mitigating security risks. The SCA will support a critical mission within the intelligence community. In the role as a SCA, you are expected to use automated scanning tools, manual techniques, and specialized testing methodologies to identify weaknesses and vulnerabilities. The SCA is expected to be a collaborative member of the RMF program of the organization, to provide intelligent input to system security architectures in order to align with RMF principles and guidelines. This includes ensuring to guide the RMF process so that security controls are integrated seamlessly into system designs to provide comprehensive protection against threats and vulnerabilities. Duties & Responsibilities: The SCA's specific duties include: Advise the Information System Owner (ISO) concerning the impact levels for Confidentiality, Integrity, and Availability for the information on systems. Ensure security assessments are completed for each IS. Initiate a POA&M with identified weaknesses and suspense dates for each IS based on findings and recommendations from the SAR. Evaluate security assessment documentation and provide written recommendations for security authorization to the CISO and AO. Assess proposed changes to Information Systems, their environment of operation, and mission needs that could affect system authorization. Serve as a cybersecurity technical advisor to the CISO and AO under their purview. Be integral to the development of the monitoring strategy. The system-level continuous monitoring strategy must conform to all applicable published DoD enterprise-level or DoD Component-level continuous monitoring strategies. Determine and document in the SAR a risk level for every noncompliant security control in the system baseline. Determine and document in the SAR an aggregate level of risk to the system and identify the key drivers for the assessment. The SCA's risk assessment considers threats, vulnerabilities, and potential impacts as well as existing and planned risk mitigation. Develop the continuous monitoring plan specific to the information system. The SCA is responsible for the RMF deliverables associated with Step 4 of DOD and IC RMF Policies for assigned systems. This includes, but is not limited to: Security Assessment Plans tailored to specific systems control requirements Security control assessment input, which includes narratives for the review of controls and artifacts Security Assessment Reports ATO recommendations or ATO with Condition Memorandums Conduct initial remediation actions once a security assessment has been completed to ensure proper hand off to the ISSM and ISSOs. Assessment of selected controls IAW continuous monitoring strategy The SCA is expected to have additional duties as assigned in support of corporate cyber security services. Additional details are reviewed in accordance with company policies. Requirements: Required Skills & Experience: Strong knowledge of Risk Management Framework (RMF) 800-37 and continuous monitoring 800-137 Expert knowledge and hands-on experience with FISMA Systems, NIST 800-series guidelines, FIPS, Security Assessment & Authorization (SA&A) requirements and processes, Continuous Monitoring Framework experience and its tools, Plan of Action & Milestones (POA&M) policies, and vulnerability/patch management, risk management, project management, proficient with Microsoft products - Word, Excel, PowerPoint. Proficient with vulnerability and scanning tools and well-versed in interpreting risk posture resulting from assessment reports. Experience in project management and tracking, and the Microsoft suite of office products Experience of assessing cloud-based security authorizations (FedRamp, AWS & Azure) as well as the NIST control responsibilities Experience with SAP/JSIG Expert with documenting and or reviewing of security materials such as; system security plans (SSP), Security Assessment Report (SAR), and Security Assessment Plan (SAP), and other documents per NIST 800 guidelines. Experience supporting cloud-based security authorizations (FedRamp, AWS, & Azure) Experience creating Security Assessment Plans, Security Assessment Reports, and Executive-level briefings Qualifications: Bachelor's Degree in Computer Science or a related technical discipline Master's Degree preferred. Minimum 6-10 years of experience. Must currently possess an active TS/SCI with the ability to obtain and maintain a CI polygraph. DOD 8140 IAM Level II (CAP, CASP, CISM, CISSP, GSLC, CCISO) is required Systems Security Engineering background preferred. Effective communication skills to collaborate with cross-functional teams and stakeholders on implementing security measures organization-wide. Strong analytical skills for identifying system vulnerabilities and documenting control remediation recommendations through collaboration on System Impact Analysis and Documented Risk Acceptance. Detail-oriented with the ability to manage multiple tasks and prioritize effectively. Comprehensive knowledge of RMF activities at a senior level (ability to articulate to Executive audiences preferred). Familiarity with federal regulatory requirements, contractual obligations, and industry standards related to information security. Evaluate adherence to standards such as Privacy, GDPR, and HIPAA Other: This is typical office or administrative work, and there is no exposure to adverse environmental conditions. This position requires sedentary work. Sedentary work is defined as: Exerting up to 10 pounds of force occasionally and/or a negligible amount of force frequently or constantly to lift, carry, push, pull or otherwise move objects, including the human body. Sedentary work involves sitting most of the time. Jobs are sedentary if walking and standing are required only occasionally, and all other sedentary criteria are met.
09/15/2026
Full time
Job Description Job Description Description: Job Title: Security Control Assessor Location: On Site in Arlington, VA Department: Cyber Security Services Reports To: Management FLSA Status: Full Time/Non-exempt Job Purpose: The security control assessor (SCAs) supports a critical, objective role to evaluate the effectiveness of implemented controls in mitigating security risks. The SCA will support a critical mission within the intelligence community. In the role as a SCA, you are expected to use automated scanning tools, manual techniques, and specialized testing methodologies to identify weaknesses and vulnerabilities. The SCA is expected to be a collaborative member of the RMF program of the organization, to provide intelligent input to system security architectures in order to align with RMF principles and guidelines. This includes ensuring to guide the RMF process so that security controls are integrated seamlessly into system designs to provide comprehensive protection against threats and vulnerabilities. Duties & Responsibilities: The SCA's specific duties include: Advise the Information System Owner (ISO) concerning the impact levels for Confidentiality, Integrity, and Availability for the information on systems. Ensure security assessments are completed for each IS. Initiate a POA&M with identified weaknesses and suspense dates for each IS based on findings and recommendations from the SAR. Evaluate security assessment documentation and provide written recommendations for security authorization to the CISO and AO. Assess proposed changes to Information Systems, their environment of operation, and mission needs that could affect system authorization. Serve as a cybersecurity technical advisor to the CISO and AO under their purview. Be integral to the development of the monitoring strategy. The system-level continuous monitoring strategy must conform to all applicable published DoD enterprise-level or DoD Component-level continuous monitoring strategies. Determine and document in the SAR a risk level for every noncompliant security control in the system baseline. Determine and document in the SAR an aggregate level of risk to the system and identify the key drivers for the assessment. The SCA's risk assessment considers threats, vulnerabilities, and potential impacts as well as existing and planned risk mitigation. Develop the continuous monitoring plan specific to the information system. The SCA is responsible for the RMF deliverables associated with Step 4 of DOD and IC RMF Policies for assigned systems. This includes, but is not limited to: Security Assessment Plans tailored to specific systems control requirements Security control assessment input, which includes narratives for the review of controls and artifacts Security Assessment Reports ATO recommendations or ATO with Condition Memorandums Conduct initial remediation actions once a security assessment has been completed to ensure proper hand off to the ISSM and ISSOs. Assessment of selected controls IAW continuous monitoring strategy The SCA is expected to have additional duties as assigned in support of corporate cyber security services. Additional details are reviewed in accordance with company policies. Requirements: Required Skills & Experience: Strong knowledge of Risk Management Framework (RMF) 800-37 and continuous monitoring 800-137 Expert knowledge and hands-on experience with FISMA Systems, NIST 800-series guidelines, FIPS, Security Assessment & Authorization (SA&A) requirements and processes, Continuous Monitoring Framework experience and its tools, Plan of Action & Milestones (POA&M) policies, and vulnerability/patch management, risk management, project management, proficient with Microsoft products - Word, Excel, PowerPoint. Proficient with vulnerability and scanning tools and well-versed in interpreting risk posture resulting from assessment reports. Experience in project management and tracking, and the Microsoft suite of office products Experience of assessing cloud-based security authorizations (FedRamp, AWS & Azure) as well as the NIST control responsibilities Experience with SAP/JSIG Expert with documenting and or reviewing of security materials such as; system security plans (SSP), Security Assessment Report (SAR), and Security Assessment Plan (SAP), and other documents per NIST 800 guidelines. Experience supporting cloud-based security authorizations (FedRamp, AWS, & Azure) Experience creating Security Assessment Plans, Security Assessment Reports, and Executive-level briefings Qualifications: Bachelor's Degree in Computer Science or a related technical discipline Master's Degree preferred. Minimum 6-10 years of experience. Must currently possess an active TS/SCI with the ability to obtain and maintain a CI polygraph. DOD 8140 IAM Level II (CAP, CASP, CISM, CISSP, GSLC, CCISO) is required Systems Security Engineering background preferred. Effective communication skills to collaborate with cross-functional teams and stakeholders on implementing security measures organization-wide. Strong analytical skills for identifying system vulnerabilities and documenting control remediation recommendations through collaboration on System Impact Analysis and Documented Risk Acceptance. Detail-oriented with the ability to manage multiple tasks and prioritize effectively. Comprehensive knowledge of RMF activities at a senior level (ability to articulate to Executive audiences preferred). Familiarity with federal regulatory requirements, contractual obligations, and industry standards related to information security. Evaluate adherence to standards such as Privacy, GDPR, and HIPAA Other: This is typical office or administrative work, and there is no exposure to adverse environmental conditions. This position requires sedentary work. Sedentary work is defined as: Exerting up to 10 pounds of force occasionally and/or a negligible amount of force frequently or constantly to lift, carry, push, pull or otherwise move objects, including the human body. Sedentary work involves sitting most of the time. Jobs are sedentary if walking and standing are required only occasionally, and all other sedentary criteria are met.
Security Control Assessor
Omniscius Consulting Arlington, Virginia
Job Description Job Description Job Title: Security Control Assessor Location: On Site in Arlington, VA Department: Cyber Security Services Reports To: Management FLSA Status: Full Time/Non-exempt Clearance: Top Secret clearance with the ability to obtain SCI with CI Polygraph Job Purpose: The security control assessor (SCAs) supports a critical, objective role to evaluate the effectiveness of implemented controls in mitigating security risks. The SCA will support a critical mission within the intelligence community. In the role as a SCA, you are expected to use automated scanning tools, manual techniques, and specialized testing methodologies to identify weaknesses and vulnerabilities. The SCA is expected to be a collaborative member of the RMF program of the organization, to provide intelligent input to system security architectures in order to align with RMF principles and guidelines. This includes ensuring to guide the RMF process so that security controls are integrated seamlessly into system designs to provide comprehensive protection against threats and vulnerabilities. Duties & Responsibilities: The SCA's specific duties include: Advise the Information System Owner (ISO) concerning the impact levels for Confidentiality, Integrity, and Availability for the information on systems. Ensure security assessments are completed for each IS. Initiate a POA&M with identified weaknesses and suspense dates for each IS based on findings and recommendations from the SAR. Evaluate security assessment documentation and provide written recommendations for security authorization to the CISO and AO. Assess proposed changes to Information Systems, their environment of operation, and mission needs that could affect system authorization. Serve as a cybersecurity technical advisor to the CISO and AO under their purview. Be integral to the development of the monitoring strategy. The system-level continuous monitoring strategy must conform to all applicable published DoD enterprise-level or DoD Component-level continuous monitoring strategies. Determine and document in the SAR a risk level for every noncompliant security control in the system baseline. Determine and document in the SAR an aggregate level of risk to the system and identify the key drivers for the assessment. The SCA's risk assessment considers threats, vulnerabilities, and potential impacts as well as existing and planned risk mitigation. Develop the continuous monitoring plan specific to the information system. The SCA is responsible for the RMF deliverables associated with Step 4 of DOD and IC RMF Policies for assigned systems. This includes, but is not limited to: Security Assessment Plans tailored to specific systems control requirements Security control assessment input, which includes narratives for the review of controls and artifacts Security Assessment Reports ATO recommendations or ATO with Condition Memorandums Conduct initial remediation actions once a security assessment has been completed to ensure proper hand off to the ISSM and ISSOs. Assessment of selected controls IAW continuous monitoring strategy The SCA is expected to have additional duties as assigned in support of corporate cyber security services. Additional details are reviewed in accordance with company policies. Requirements Required Skills & Experience: Strong knowledge of Risk Management Framework (RMF) 800-37 and continuous monitoring 800-137 Expert knowledge and hands-on experience with FISMA Systems, NIST 800-series guidelines, FIPS, Security Assessment & Authorization (SA&A) requirements and processes, Continuous Monitoring Framework experience and its tools, Plan of Action & Milestones (POA&M) policies, and vulnerability/patch management, risk management, project management, proficient with Microsoft products - Word, Excel, PowerPoint. Proficient with vulnerability and scanning tools and well-versed in interpreting risk posture resulting from assessment reports. Experience in project management and tracking, and the Microsoft suite of office products Experience of assessing cloud-based security authorizations (FedRamp, AWS & Azure) as well as the NIST control responsibilities Experience with SAP/JSIG Expert with documenting and or reviewing of security materials such as; system security plans (SSP), Security Assessment Report (SAR), and Security Assessment Plan (SAP), and other documents per NIST 800 guidelines. Experience supporting cloud-based security authorizations (FedRamp, AWS, & Azure) Experience creating Security Assessment Plans, Security Assessment Reports, and Executive-level briefings Qualifications: Bachelor's Degree in Computer Science or a related technical discipline Master's Degree preferred. Minimum 6-10 years of experience. Must currently possess an active Top Secret clearance with the ability to obtain SCI with CI Polygraph. DOD 8140 IAM Level II (CAP, CASP, CISM, CISSP, GSLC, CCISO) is required Systems Security Engineering background preferred. Effective communication skills to collaborate with cross-functional teams and stakeholders on implementing security measures organization-wide. Strong analytical skills for identifying system vulnerabilities and documenting control remediation recommendations through collaboration on System Impact Analysis and Documented Risk Acceptance. Detail-oriented with the ability to manage multiple tasks and prioritize effectively. Comprehensive knowledge of RMF activities at a senior level (ability to articulate to Executive audiences preferred). Familiarity with federal regulatory requirements, contractual obligations, and industry standards related to information security. Evaluate adherence to standards such as Privacy, GDPR, and HIPAA Powered by JazzHR I48iVzr4Ds
09/15/2026
Full time
Job Description Job Description Job Title: Security Control Assessor Location: On Site in Arlington, VA Department: Cyber Security Services Reports To: Management FLSA Status: Full Time/Non-exempt Clearance: Top Secret clearance with the ability to obtain SCI with CI Polygraph Job Purpose: The security control assessor (SCAs) supports a critical, objective role to evaluate the effectiveness of implemented controls in mitigating security risks. The SCA will support a critical mission within the intelligence community. In the role as a SCA, you are expected to use automated scanning tools, manual techniques, and specialized testing methodologies to identify weaknesses and vulnerabilities. The SCA is expected to be a collaborative member of the RMF program of the organization, to provide intelligent input to system security architectures in order to align with RMF principles and guidelines. This includes ensuring to guide the RMF process so that security controls are integrated seamlessly into system designs to provide comprehensive protection against threats and vulnerabilities. Duties & Responsibilities: The SCA's specific duties include: Advise the Information System Owner (ISO) concerning the impact levels for Confidentiality, Integrity, and Availability for the information on systems. Ensure security assessments are completed for each IS. Initiate a POA&M with identified weaknesses and suspense dates for each IS based on findings and recommendations from the SAR. Evaluate security assessment documentation and provide written recommendations for security authorization to the CISO and AO. Assess proposed changes to Information Systems, their environment of operation, and mission needs that could affect system authorization. Serve as a cybersecurity technical advisor to the CISO and AO under their purview. Be integral to the development of the monitoring strategy. The system-level continuous monitoring strategy must conform to all applicable published DoD enterprise-level or DoD Component-level continuous monitoring strategies. Determine and document in the SAR a risk level for every noncompliant security control in the system baseline. Determine and document in the SAR an aggregate level of risk to the system and identify the key drivers for the assessment. The SCA's risk assessment considers threats, vulnerabilities, and potential impacts as well as existing and planned risk mitigation. Develop the continuous monitoring plan specific to the information system. The SCA is responsible for the RMF deliverables associated with Step 4 of DOD and IC RMF Policies for assigned systems. This includes, but is not limited to: Security Assessment Plans tailored to specific systems control requirements Security control assessment input, which includes narratives for the review of controls and artifacts Security Assessment Reports ATO recommendations or ATO with Condition Memorandums Conduct initial remediation actions once a security assessment has been completed to ensure proper hand off to the ISSM and ISSOs. Assessment of selected controls IAW continuous monitoring strategy The SCA is expected to have additional duties as assigned in support of corporate cyber security services. Additional details are reviewed in accordance with company policies. Requirements Required Skills & Experience: Strong knowledge of Risk Management Framework (RMF) 800-37 and continuous monitoring 800-137 Expert knowledge and hands-on experience with FISMA Systems, NIST 800-series guidelines, FIPS, Security Assessment & Authorization (SA&A) requirements and processes, Continuous Monitoring Framework experience and its tools, Plan of Action & Milestones (POA&M) policies, and vulnerability/patch management, risk management, project management, proficient with Microsoft products - Word, Excel, PowerPoint. Proficient with vulnerability and scanning tools and well-versed in interpreting risk posture resulting from assessment reports. Experience in project management and tracking, and the Microsoft suite of office products Experience of assessing cloud-based security authorizations (FedRamp, AWS & Azure) as well as the NIST control responsibilities Experience with SAP/JSIG Expert with documenting and or reviewing of security materials such as; system security plans (SSP), Security Assessment Report (SAR), and Security Assessment Plan (SAP), and other documents per NIST 800 guidelines. Experience supporting cloud-based security authorizations (FedRamp, AWS, & Azure) Experience creating Security Assessment Plans, Security Assessment Reports, and Executive-level briefings Qualifications: Bachelor's Degree in Computer Science or a related technical discipline Master's Degree preferred. Minimum 6-10 years of experience. Must currently possess an active Top Secret clearance with the ability to obtain SCI with CI Polygraph. DOD 8140 IAM Level II (CAP, CASP, CISM, CISSP, GSLC, CCISO) is required Systems Security Engineering background preferred. Effective communication skills to collaborate with cross-functional teams and stakeholders on implementing security measures organization-wide. Strong analytical skills for identifying system vulnerabilities and documenting control remediation recommendations through collaboration on System Impact Analysis and Documented Risk Acceptance. Detail-oriented with the ability to manage multiple tasks and prioritize effectively. Comprehensive knowledge of RMF activities at a senior level (ability to articulate to Executive audiences preferred). Familiarity with federal regulatory requirements, contractual obligations, and industry standards related to information security. Evaluate adherence to standards such as Privacy, GDPR, and HIPAA Powered by JazzHR I48iVzr4Ds
TASS (Current Contract) - Security Control Assessor, Senior
AGE solutions Alexandria, Virginia
Job Description Job Description About Us AGE Solutions is a premier technology and professional services company, providing in-depth consulting, advanced technology solutions, and essential services throughout the U.S. government, defense, and intelligence sectors. Prioritizing innovation and client-focused solutions, we assist major agencies in addressing intricate issues and ensuring a more secure future. AGE Solutions is looking for Senior Security Control Assessors to join our team in support of a cybersecurity risk management and assessment program with our DoD customer. Responsibilities: Conduct cybersecurity assessments, audits, and inspections for DoD organizations and partners handling DoD information or connecting to the DoDIN. Evaluate systems and Defensive Cyberspace Operations using cyber threat emulation and performance-based testing. Adhere to policies and processes for each assessment type. Support assessment development and execution to ensure security expertise is properly applied. Coordinate logistics, test plans, and scope with the SCA Team Lead. Perform vulnerability assessments, capture results using STIG Viewer or designated tools, and document findings in eMASS. Analyze security gaps and provide mitigation recommendations. Validate cybersecurity controls, TTPs, STIGs, RMF controls, and compliance with DoD policies and guidelines. Provide risk analysis and assessment results for authorization recommendations. Participate in daily assessment reviews, in-briefs, and out-briefs, sharing findings with the SCA-R. Mentor and guide personnel by providing technical expertise, best practices, and professional development support to enhance team capabilities and knowledge. Requirements: Bachelor's degree (IT-related field preferred) Eight (8) years of overall experience in cybersecurity or network security position Five (5) years of experience in a Certification and Accreditation/A&A role Must have and maintain an active DoD Top Secret clearance with SCI eligibility Must be able and willing to travel up to approximately 85% of the time, inside and outside the continental United States and internationally (CONUS / OCONUS) DoD 8570 IA Technical (IAT) Level III certification Demonstrated experience with STIGs (Security Technical Implementation Guides), Security Requirement Guides (SRGs), Plan of Action and Milestones (POA&Ms) and cybersecurity best practices Advanced understanding of the RMF process, NIST SP 800- 37, NIST SP 800-53, CNSSI 1253 Demonstrated experience with relevant tools such as eMASS, STIG Viewer, Nessus, ACAS, SCAP, or HBSS Advanced understanding of key technologies areas/domain such as: Network, Mobility, Windows, UNIX, Cloud Environments and Cloud Native Tools/Services, Host Based Security System (HBSS)/Endpoint Security Solutions (ESS), Databases, Applications Strong written and verbal communication skills for reporting assessment findings. Compensation: $95,000 - $105,000 This posting is part of a pipeline for future opportunities supporting the current TASS contract. Employment is contingent upon position availability and government customer approval. AGE Solutions is actively engaging talent and encourages incumbents and new candidates to express interest to be considered if/when opportunities may become available. At AGE Solutions, we reward performance, invest in growth, and share success. Our benefits support the whole person, professionally, financially, and personally. 26 Days Paid Leave: Includes vacation, sick, personal time, and holidays. You choose how to use it. Performance Bonuses: Performance bonuses are awarded based on individual contributions and company-wide results, aligning recognition with impact. 401(k) with Match: We match 3% of your contributions with immediate vesting. Financial Protection: Company-paid life insurance up to $300K and options for additional coverage for you and your dependents. Health Benefits: Multiple medical plans, dental, vision, FSA and HSA options to fit your needs. Parental Leave: 15 days of fully paid leave for new parents, because family matters. Military Differential Pay: We bridge the gap for employees on active duty, so they don't take a financial hit while serving. Professional Growth: Paid training and certifications, tuition reimbursement, and the tools and tech to get the job done right. Shared Success: In the event of a company sale, our CEO has committed to returning 80% of net proceeds to employees. This ensures our team shares in the long term value they help create. At AGE, you'll do work that matters, supported by a company that delivers for its people.
09/15/2026
Full time
Job Description Job Description About Us AGE Solutions is a premier technology and professional services company, providing in-depth consulting, advanced technology solutions, and essential services throughout the U.S. government, defense, and intelligence sectors. Prioritizing innovation and client-focused solutions, we assist major agencies in addressing intricate issues and ensuring a more secure future. AGE Solutions is looking for Senior Security Control Assessors to join our team in support of a cybersecurity risk management and assessment program with our DoD customer. Responsibilities: Conduct cybersecurity assessments, audits, and inspections for DoD organizations and partners handling DoD information or connecting to the DoDIN. Evaluate systems and Defensive Cyberspace Operations using cyber threat emulation and performance-based testing. Adhere to policies and processes for each assessment type. Support assessment development and execution to ensure security expertise is properly applied. Coordinate logistics, test plans, and scope with the SCA Team Lead. Perform vulnerability assessments, capture results using STIG Viewer or designated tools, and document findings in eMASS. Analyze security gaps and provide mitigation recommendations. Validate cybersecurity controls, TTPs, STIGs, RMF controls, and compliance with DoD policies and guidelines. Provide risk analysis and assessment results for authorization recommendations. Participate in daily assessment reviews, in-briefs, and out-briefs, sharing findings with the SCA-R. Mentor and guide personnel by providing technical expertise, best practices, and professional development support to enhance team capabilities and knowledge. Requirements: Bachelor's degree (IT-related field preferred) Eight (8) years of overall experience in cybersecurity or network security position Five (5) years of experience in a Certification and Accreditation/A&A role Must have and maintain an active DoD Top Secret clearance with SCI eligibility Must be able and willing to travel up to approximately 85% of the time, inside and outside the continental United States and internationally (CONUS / OCONUS) DoD 8570 IA Technical (IAT) Level III certification Demonstrated experience with STIGs (Security Technical Implementation Guides), Security Requirement Guides (SRGs), Plan of Action and Milestones (POA&Ms) and cybersecurity best practices Advanced understanding of the RMF process, NIST SP 800- 37, NIST SP 800-53, CNSSI 1253 Demonstrated experience with relevant tools such as eMASS, STIG Viewer, Nessus, ACAS, SCAP, or HBSS Advanced understanding of key technologies areas/domain such as: Network, Mobility, Windows, UNIX, Cloud Environments and Cloud Native Tools/Services, Host Based Security System (HBSS)/Endpoint Security Solutions (ESS), Databases, Applications Strong written and verbal communication skills for reporting assessment findings. Compensation: $95,000 - $105,000 This posting is part of a pipeline for future opportunities supporting the current TASS contract. Employment is contingent upon position availability and government customer approval. AGE Solutions is actively engaging talent and encourages incumbents and new candidates to express interest to be considered if/when opportunities may become available. At AGE Solutions, we reward performance, invest in growth, and share success. Our benefits support the whole person, professionally, financially, and personally. 26 Days Paid Leave: Includes vacation, sick, personal time, and holidays. You choose how to use it. Performance Bonuses: Performance bonuses are awarded based on individual contributions and company-wide results, aligning recognition with impact. 401(k) with Match: We match 3% of your contributions with immediate vesting. Financial Protection: Company-paid life insurance up to $300K and options for additional coverage for you and your dependents. Health Benefits: Multiple medical plans, dental, vision, FSA and HSA options to fit your needs. Parental Leave: 15 days of fully paid leave for new parents, because family matters. Military Differential Pay: We bridge the gap for employees on active duty, so they don't take a financial hit while serving. Professional Growth: Paid training and certifications, tuition reimbursement, and the tools and tech to get the job done right. Shared Success: In the event of a company sale, our CEO has committed to returning 80% of net proceeds to employees. This ensures our team shares in the long term value they help create. At AGE, you'll do work that matters, supported by a company that delivers for its people.
Junior Security Control Assessor
The Newberry Group Annapolis Junction, Maryland
Job Description Job Description Job Summary Newberry Group seeks a Jr. Security Control Assessor to support its Government Client. This role requires 85% travel to various government locations both domestically and internationally. Location Hybrid position - approx. 25% remote support with up to 75% CONUS and OCONUS travel. Clearance Active Secret Clearance (will sponsor). DoD Top Secret/SCI Clearance required or Interim Top Secret preferred. Certifications DoD 8570 IAT II (active or will obtain within 90 days of hire) Contingencies If an opening is not currently available, candidates applying to this role will be placed in our pipeline for future openings within this contract's program. Compensation $50,000 - $60,000 Primary Responsibilities: Conduct cybersecurity assessments, audits, and inspections for DoD organizations and partners handling DoD information or connecting to the DoDIN. Evaluate systems and Defensive Cyberspace Operations using cyber threat emulation and performance-based testing. Adhere to policies and processes for each assessment type. Support assessment development and execution to ensure security expertise is properly applied. Coordinate logistics, test plans, and scope with the SCA Team Lead. Perform vulnerability assessments, capture results using STIG Viewer or designated tools, and document findings in eMASS. Analyze security gaps and provide mitigation recommendations. Validate cybersecurity controls, TTPs, STIGs, RMF controls, and compliance with DoD policies and guidelines. Provide risk analysis and assessment results for authorization recommendations. Participate in daily assessment reviews, in-briefs, and out-briefs, sharing findings with the SCA-R. For each RMF Review, the assessors shall perform the following: The candidate will be required to review applicable controls to determine compliance status and enter all test results into the designated repository (Enterprise Mission Assurance Support Service (eMASS) Providing key assessment results to the team lead to include the number of controls reviewed and risk/residual information for inclusion in the authorization recommendation. The candidate will be required to be certified via the ACP IAW the ACP CONOPS before conducting any assessments. The candidate must be certified in a minimum of two (2) technologies and RMF Control Validation before conducting any assessments. Training through the DISA program will be provided after hire and consist of at least 3 months. The contractor shall maintain active accounts to the tools and systems required to perform risk assessments. The candidate will be required to participate in the in-brief and out-brief of each assessment. Qualifications: Bachelor's degree in a related area of study (i.e. Security, Information Technology). 0-1 year of experience required. Willing to train on both technologies and RMF. Active DoD Top Secret clearance with SCI eligibility is preferred but can begin with a secret clearance. IAT Level II certification active or will obtain within 90 days of hire. CompTIA Cybersecurity Analyst (CySA+) CompTIA Security. EC-Council Certified Network Defense (CND) v3. Red Hat Certified System Administrator (RHCSA) CCNA Security. Global Industrial Cyber Security Professional (GICSP) GIAC Security Essentials (GSEC) Systems Security Certified Practitioner (SSCP) Familiarity with STIGs (Security Technical Implementation Guides), Security Requirement Guides (SRGs), Plan of Action and Milestones (POA&Ms) and cybersecurity best practices desired. Understanding of the RMF process, NIST SP 800- 37, NIST SP 800-53, CNSSI 1253 desired Familiarity with relevant tools such as eMASS, STIG Viewer, Nessus, ACAS, SCAP, or HBSS desired Strong written and verbal communication skills for reporting assessment findings. Who We Are Today's leading government agencies are putting their trust in Newberry Group, and for good reason. Newberry brings strength to our clients, from the inside out, through: • client intimacy and superior quality, • presence and accountability in our relationships, and • Public sector best practices. Newberry Group is a professional services firm, providing information security compliance, governance, program/project management, and mission-critical project-based consulting to public sector clients nationwide. The strength of our company is a direct reflection of our highly skilled and talented workforce. Benefits and Perks In addition to competitive wages, Newberry Group offers an outstanding benefit package. This includes medical coverage with three plan options, dental and vision coverage, personal time off, paid holidays, paid parental leave, telecommuting if available, retirement savings accounts (Pre-Tax and Roth), flexible and dependent care savings accounts, life insurance, long and short-term disability coverage, tuition and training reimbursement, employee assistance program, and more. The Newberry Group, Inc. is an Equal Opportunity Employer - EEO/AA/Disability/Veterans. Powered by JazzHR 5whc8Lvtfu
09/15/2026
Full time
Job Description Job Description Job Summary Newberry Group seeks a Jr. Security Control Assessor to support its Government Client. This role requires 85% travel to various government locations both domestically and internationally. Location Hybrid position - approx. 25% remote support with up to 75% CONUS and OCONUS travel. Clearance Active Secret Clearance (will sponsor). DoD Top Secret/SCI Clearance required or Interim Top Secret preferred. Certifications DoD 8570 IAT II (active or will obtain within 90 days of hire) Contingencies If an opening is not currently available, candidates applying to this role will be placed in our pipeline for future openings within this contract's program. Compensation $50,000 - $60,000 Primary Responsibilities: Conduct cybersecurity assessments, audits, and inspections for DoD organizations and partners handling DoD information or connecting to the DoDIN. Evaluate systems and Defensive Cyberspace Operations using cyber threat emulation and performance-based testing. Adhere to policies and processes for each assessment type. Support assessment development and execution to ensure security expertise is properly applied. Coordinate logistics, test plans, and scope with the SCA Team Lead. Perform vulnerability assessments, capture results using STIG Viewer or designated tools, and document findings in eMASS. Analyze security gaps and provide mitigation recommendations. Validate cybersecurity controls, TTPs, STIGs, RMF controls, and compliance with DoD policies and guidelines. Provide risk analysis and assessment results for authorization recommendations. Participate in daily assessment reviews, in-briefs, and out-briefs, sharing findings with the SCA-R. For each RMF Review, the assessors shall perform the following: The candidate will be required to review applicable controls to determine compliance status and enter all test results into the designated repository (Enterprise Mission Assurance Support Service (eMASS) Providing key assessment results to the team lead to include the number of controls reviewed and risk/residual information for inclusion in the authorization recommendation. The candidate will be required to be certified via the ACP IAW the ACP CONOPS before conducting any assessments. The candidate must be certified in a minimum of two (2) technologies and RMF Control Validation before conducting any assessments. Training through the DISA program will be provided after hire and consist of at least 3 months. The contractor shall maintain active accounts to the tools and systems required to perform risk assessments. The candidate will be required to participate in the in-brief and out-brief of each assessment. Qualifications: Bachelor's degree in a related area of study (i.e. Security, Information Technology). 0-1 year of experience required. Willing to train on both technologies and RMF. Active DoD Top Secret clearance with SCI eligibility is preferred but can begin with a secret clearance. IAT Level II certification active or will obtain within 90 days of hire. CompTIA Cybersecurity Analyst (CySA+) CompTIA Security. EC-Council Certified Network Defense (CND) v3. Red Hat Certified System Administrator (RHCSA) CCNA Security. Global Industrial Cyber Security Professional (GICSP) GIAC Security Essentials (GSEC) Systems Security Certified Practitioner (SSCP) Familiarity with STIGs (Security Technical Implementation Guides), Security Requirement Guides (SRGs), Plan of Action and Milestones (POA&Ms) and cybersecurity best practices desired. Understanding of the RMF process, NIST SP 800- 37, NIST SP 800-53, CNSSI 1253 desired Familiarity with relevant tools such as eMASS, STIG Viewer, Nessus, ACAS, SCAP, or HBSS desired Strong written and verbal communication skills for reporting assessment findings. Who We Are Today's leading government agencies are putting their trust in Newberry Group, and for good reason. Newberry brings strength to our clients, from the inside out, through: • client intimacy and superior quality, • presence and accountability in our relationships, and • Public sector best practices. Newberry Group is a professional services firm, providing information security compliance, governance, program/project management, and mission-critical project-based consulting to public sector clients nationwide. The strength of our company is a direct reflection of our highly skilled and talented workforce. Benefits and Perks In addition to competitive wages, Newberry Group offers an outstanding benefit package. This includes medical coverage with three plan options, dental and vision coverage, personal time off, paid holidays, paid parental leave, telecommuting if available, retirement savings accounts (Pre-Tax and Roth), flexible and dependent care savings accounts, life insurance, long and short-term disability coverage, tuition and training reimbursement, employee assistance program, and more. The Newberry Group, Inc. is an Equal Opportunity Employer - EEO/AA/Disability/Veterans. Powered by JazzHR 5whc8Lvtfu
Security Control Assessor II
P-11 Security Inc Arlington, Virginia
Job Description Job Description Description: P-11 Security is seeking a SCA who is responsible for conducting a comprehensive assessment of the management, operational, and technical security controls employed within or inherited by an IS to determine the overall effectiveness of the controls (i.e., the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for the system). SCAs also provide an assessment of the severity of weaknesses or deficiencies discovered in the IS and its environment of operation and recommend corrective actions to address identified vulnerabilities. Responsibilities will cover Collateral, Sensitive Compartmented Information (SCI) and Special Access Program (SAP) activities within the customer's area of responsibility. Performance shall include: Perform oversight of the development, implementation and evaluation of IS security program policy; special emphasis placed upon integration of existing SAP network infrastructure Perform assessment of ISs, based upon the Risk Management Framework (RMF) methodology in accordance with the Joint Special Access Program (SAP) Implementation Guide (JSIG) Advise the Information System Owner (ISO), Information Data Owner (IDO), Program Security Officer (PSO), and the Delegated and/or Authorizing Official (DAO/AO) on any assessment and authorization issues Evaluate Authorization packages and make recommendation to the AO and/or DAO for authorization Evaluate IS threats and vulnerabilities to determine whether additional safeguards are required Advise the Government concerning the impact levels for Confidentiality, Integrity, and Availability for the information on a system Ensure security assessments are completed and results documented and prepare the Security Assessment Report (SAR) for the Authorization boundary Initiate a Plan of Action and Milestones (POA&M) with identified weaknesses for each Authorization Boundaries assessed, based on findings and recommendations from the SAR Evaluate security assessment documentation and provide written recommendations for security authorization to the Government Discuss recommendation for authorization and submit the security authorization package to the AO/DAO Assess proposed changes to Authorization boundaries operating environment and mission needs to determine the continuation to operate. Review and concur with all sanitization and clearing procedures in accordance with Government guidance and/or policy Assist the Government compliance inspections Assist the Government with security incidents that relate to cybersecurity and ensure that the proper and corrective measures have been taken Ensure organization are addressing and conducting all phases of the system development life cycle (SDLC) Evaluate Hardware and Software to determine security impact that it might have on Authorization boundaries Evaluate the effectiveness and implementation of Continuous Monitoring Plans Represent the customer on inspection teams Requirements: Experience: 7 - 9 years related experience Minimum of four (4) years' experience in SAP, SCI or Collateral Information Systems (IS) Security and the implementation of regulations identified in the description of duties. Prior performance in the role of ISSO and ISSM or SCA Education : Bachelor's degree in a related discipline or equivalent experience (4 years) Certifications: Must meet position and certification requirements outlined in DoD Directive 8570.01-M for Information Assurance Technician Level III or Information Assurance Manager Level II within 6 months of the date of hire Security Clearance: Current Top Secret Clearance with SCI Eligibility Eligibility for access to Special Access Program Information Willingness to submit to a Counterintelligence polygraph Other Requirements: Must be able to regularly lift 50lbs
09/15/2026
Full time
Job Description Job Description Description: P-11 Security is seeking a SCA who is responsible for conducting a comprehensive assessment of the management, operational, and technical security controls employed within or inherited by an IS to determine the overall effectiveness of the controls (i.e., the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for the system). SCAs also provide an assessment of the severity of weaknesses or deficiencies discovered in the IS and its environment of operation and recommend corrective actions to address identified vulnerabilities. Responsibilities will cover Collateral, Sensitive Compartmented Information (SCI) and Special Access Program (SAP) activities within the customer's area of responsibility. Performance shall include: Perform oversight of the development, implementation and evaluation of IS security program policy; special emphasis placed upon integration of existing SAP network infrastructure Perform assessment of ISs, based upon the Risk Management Framework (RMF) methodology in accordance with the Joint Special Access Program (SAP) Implementation Guide (JSIG) Advise the Information System Owner (ISO), Information Data Owner (IDO), Program Security Officer (PSO), and the Delegated and/or Authorizing Official (DAO/AO) on any assessment and authorization issues Evaluate Authorization packages and make recommendation to the AO and/or DAO for authorization Evaluate IS threats and vulnerabilities to determine whether additional safeguards are required Advise the Government concerning the impact levels for Confidentiality, Integrity, and Availability for the information on a system Ensure security assessments are completed and results documented and prepare the Security Assessment Report (SAR) for the Authorization boundary Initiate a Plan of Action and Milestones (POA&M) with identified weaknesses for each Authorization Boundaries assessed, based on findings and recommendations from the SAR Evaluate security assessment documentation and provide written recommendations for security authorization to the Government Discuss recommendation for authorization and submit the security authorization package to the AO/DAO Assess proposed changes to Authorization boundaries operating environment and mission needs to determine the continuation to operate. Review and concur with all sanitization and clearing procedures in accordance with Government guidance and/or policy Assist the Government compliance inspections Assist the Government with security incidents that relate to cybersecurity and ensure that the proper and corrective measures have been taken Ensure organization are addressing and conducting all phases of the system development life cycle (SDLC) Evaluate Hardware and Software to determine security impact that it might have on Authorization boundaries Evaluate the effectiveness and implementation of Continuous Monitoring Plans Represent the customer on inspection teams Requirements: Experience: 7 - 9 years related experience Minimum of four (4) years' experience in SAP, SCI or Collateral Information Systems (IS) Security and the implementation of regulations identified in the description of duties. Prior performance in the role of ISSO and ISSM or SCA Education : Bachelor's degree in a related discipline or equivalent experience (4 years) Certifications: Must meet position and certification requirements outlined in DoD Directive 8570.01-M for Information Assurance Technician Level III or Information Assurance Manager Level II within 6 months of the date of hire Security Clearance: Current Top Secret Clearance with SCI Eligibility Eligibility for access to Special Access Program Information Willingness to submit to a Counterintelligence polygraph Other Requirements: Must be able to regularly lift 50lbs
Security Control Assessor/Representatives
Dark Wolf Solutions Arlington, Virginia
Job Description Job Description Dark Wolf Solutions is seeking Security Control Assessor/Representatives (SCA/Rs) to lead security control assessments across high-priority projects. Working at the intersection of cybersecurity engineering, cloud architecture, and DevSecOps prototyping, you will evaluate security controls for cutting-edge AI/LLM technologies across multiple classification levels. This position is ideal for a pragmatic cloud assessor or SCAR who excels in fast-paced DevSecOps environments, understands AWS cloud security, and is eager to shape the cybersecurity posture of next-generation DoD AI capabilities.This position will be based out of Arlington, VA. Additional responsibilities include: Key Responsibilities Execute formal SCA/R duties. Lead security assessment efforts, establishing reusable security playbooks and assessment frameworks for rapid AI deployment into enterprise workflows. Evaluate technical control effectiveness across AWS cloud infrastructure, DevSecOps pipelines, microservices, containerized workloads, and GenAI/LLM application stacks. Partner directly with cybersecurity engineering and DevSecOps prototyping teams to integrate security controls early in the development lifecycle. Review, author, and maintain assessment packages-including System Security Plans (SSPs), Security Assessment Plans (SAPs), Security Assessment Reports (SARs), and POA&Ms-tailored to rapid prototyping and AI systems. Assess technical security risks specific to AI/LLM implementations, such as API exposure, vector database access controls, model integration surface area, and software supply chain dependencies. Support continuous monitoring (ConMon), technical risk evaluations, and cloud architecture reviews across multi-tenant, multi-classification environments. Coordinate with Authorizing Officials (AOs), program managers, and engineering leads to deliver decision-ready risk briefings and ATO recommendations. Provide technical input and oversight for cybersecurity engineering and penetration testing activities across prototype projects. Required Qualifications Active Top Secret security clearance Current DoD 8570/8140 IAM Level II or Level III certification (e.g., Security+, CySA+, CISM, CISSP, CCISO, CAP/CISC) 3-5+ years of experience conducting security control assessments, compliance testing, or A&A/RMF activities for DoD or federal information systems Solid operational understanding of core AWS cloud services (EC2, S3, IAM, VPCs, Security Groups, Security Hub) and how security controls function within cloud-native and CI/CD pipeline environments. Strong working knowledge of NIST SP 800-53 (Rev. 4/5), NIST SP 800-37 (RMF), DoD Cloud Computing SRG, and FedRAMP baselines. Demonstrated experience writing and evaluating core RMF artifacts (SSPs, SAPs, SARs, POA&Ms) Exceptional written and verbal communication skills, with the ability to articulate technical risk clearly to executive stakeholders, Authorizing Officials, and engineering teams. Hands-on experience navigating government GRC repositories, such as eMASS or XACTA. Desired Qualifications Hands-on experience mapping security controls to the NIST AI Risk Management Framework (AI RMF), the OWASP Top 10 for LLM Applications, or the DoD Responsible AI (RAI) Guidelines. Familiarity evaluating secure design patterns for autonomous AI Agents (e.g., tool-calling permissions, sandboxing agent execution environments, prompt boundaries, and ReAct/LangGraph architectures). Experience assessing cloud-managed AI ecosystems and foundation model platforms (e.g., AWS Bedrock, AWS SageMaker, Hugging Face Enterprise, or self-hosted open-source models). Understanding of data protection, access controls, and boundary security for RAG pipelines and vector databases (e.g., OpenSearch Vector Engine, Pinecone, Milvus, or PostgreSQL pgvector). Familiarity evaluating risks unique to LLMs-including prompt injection, data poisoning, model inversion, insecure output handling, and open-source supply chain vulnerabilities in AI libraries (PyTorch, LangChain, LlamaIndex). Exposure to LLM guardrail platforms, evaluation frameworks, or AI security tools (e.g., Promptfoo, Garak, Giskard, NeMo Guardrails) used to test model robustness and output safety. Experience with cATO methodologies, Infrastructure as Code (IaC) templates (Terraform, CloudFormation), and container security (AWS EKS/ECS, Docker). Active AWS Certifications (e.g., AWS Certified Security - Specialty or AWS Certified Solutions Architect). Background or familiarity with offensive security, penetration testing The salary range for this position is estimated to be between $135,000.00 - $150,000.00, commensurate on experience and technical skillset. We are proud to be an EEO/AA employer Minorities/Women/Veterans/Disabled and other protected categories. In compliance with federal law, all persons hired will be required to verify identity, confirm US Citizenship, and complete the required employment eligibility verification upon hire. We are strictly looking for direct, full-time W2 employees. We do not engage with third-party staffing agencies, C2C, or 1099 independent contractors for this role.
09/15/2026
Full time
Job Description Job Description Dark Wolf Solutions is seeking Security Control Assessor/Representatives (SCA/Rs) to lead security control assessments across high-priority projects. Working at the intersection of cybersecurity engineering, cloud architecture, and DevSecOps prototyping, you will evaluate security controls for cutting-edge AI/LLM technologies across multiple classification levels. This position is ideal for a pragmatic cloud assessor or SCAR who excels in fast-paced DevSecOps environments, understands AWS cloud security, and is eager to shape the cybersecurity posture of next-generation DoD AI capabilities.This position will be based out of Arlington, VA. Additional responsibilities include: Key Responsibilities Execute formal SCA/R duties. Lead security assessment efforts, establishing reusable security playbooks and assessment frameworks for rapid AI deployment into enterprise workflows. Evaluate technical control effectiveness across AWS cloud infrastructure, DevSecOps pipelines, microservices, containerized workloads, and GenAI/LLM application stacks. Partner directly with cybersecurity engineering and DevSecOps prototyping teams to integrate security controls early in the development lifecycle. Review, author, and maintain assessment packages-including System Security Plans (SSPs), Security Assessment Plans (SAPs), Security Assessment Reports (SARs), and POA&Ms-tailored to rapid prototyping and AI systems. Assess technical security risks specific to AI/LLM implementations, such as API exposure, vector database access controls, model integration surface area, and software supply chain dependencies. Support continuous monitoring (ConMon), technical risk evaluations, and cloud architecture reviews across multi-tenant, multi-classification environments. Coordinate with Authorizing Officials (AOs), program managers, and engineering leads to deliver decision-ready risk briefings and ATO recommendations. Provide technical input and oversight for cybersecurity engineering and penetration testing activities across prototype projects. Required Qualifications Active Top Secret security clearance Current DoD 8570/8140 IAM Level II or Level III certification (e.g., Security+, CySA+, CISM, CISSP, CCISO, CAP/CISC) 3-5+ years of experience conducting security control assessments, compliance testing, or A&A/RMF activities for DoD or federal information systems Solid operational understanding of core AWS cloud services (EC2, S3, IAM, VPCs, Security Groups, Security Hub) and how security controls function within cloud-native and CI/CD pipeline environments. Strong working knowledge of NIST SP 800-53 (Rev. 4/5), NIST SP 800-37 (RMF), DoD Cloud Computing SRG, and FedRAMP baselines. Demonstrated experience writing and evaluating core RMF artifacts (SSPs, SAPs, SARs, POA&Ms) Exceptional written and verbal communication skills, with the ability to articulate technical risk clearly to executive stakeholders, Authorizing Officials, and engineering teams. Hands-on experience navigating government GRC repositories, such as eMASS or XACTA. Desired Qualifications Hands-on experience mapping security controls to the NIST AI Risk Management Framework (AI RMF), the OWASP Top 10 for LLM Applications, or the DoD Responsible AI (RAI) Guidelines. Familiarity evaluating secure design patterns for autonomous AI Agents (e.g., tool-calling permissions, sandboxing agent execution environments, prompt boundaries, and ReAct/LangGraph architectures). Experience assessing cloud-managed AI ecosystems and foundation model platforms (e.g., AWS Bedrock, AWS SageMaker, Hugging Face Enterprise, or self-hosted open-source models). Understanding of data protection, access controls, and boundary security for RAG pipelines and vector databases (e.g., OpenSearch Vector Engine, Pinecone, Milvus, or PostgreSQL pgvector). Familiarity evaluating risks unique to LLMs-including prompt injection, data poisoning, model inversion, insecure output handling, and open-source supply chain vulnerabilities in AI libraries (PyTorch, LangChain, LlamaIndex). Exposure to LLM guardrail platforms, evaluation frameworks, or AI security tools (e.g., Promptfoo, Garak, Giskard, NeMo Guardrails) used to test model robustness and output safety. Experience with cATO methodologies, Infrastructure as Code (IaC) templates (Terraform, CloudFormation), and container security (AWS EKS/ECS, Docker). Active AWS Certifications (e.g., AWS Certified Security - Specialty or AWS Certified Solutions Architect). Background or familiarity with offensive security, penetration testing The salary range for this position is estimated to be between $135,000.00 - $150,000.00, commensurate on experience and technical skillset. We are proud to be an EEO/AA employer Minorities/Women/Veterans/Disabled and other protected categories. In compliance with federal law, all persons hired will be required to verify identity, confirm US Citizenship, and complete the required employment eligibility verification upon hire. We are strictly looking for direct, full-time W2 employees. We do not engage with third-party staffing agencies, C2C, or 1099 independent contractors for this role.
Security Control Assessor (SME), Level III
OneZero Solutions Curtis Bay, Maryland
Job Description Job Description We are an employee-centric company that truly values our team members and the contributions they make to our customers and the missions they support. We pride ourselves on being forward-leaning thinkers and on building teams that are, and continue to be, technically proficient across a broad range of cyber mission areas. OneZero full-time employees receive a highly competitive benefits package, including health, dental, vision, and life insurance, a 401(k) with company matching, paid time off and holidays, an employee referral program, and educational assistance. Additional details are available on our website: Position Title : Security Control Assessor (SME), Level IIILocation: USCG Surface Forces Logistics Center, 2401 Hawkins Point Road, Baltimore, MD 21226. Work may also be performed at the SFLC satellite offices at 707 East Ordnance Road, approximately one mile from the primary site, and at other sites as determined necessary by the Contracting Officer's Representative (COR).Clearance:No security clearance required. This position does not involve access to classified information or classified IT systems.S. citizenship is required in accordance with HSAR 3052.204-71 Alternate I.Position SummaryThe Security Control Assessor (SCA) provides independent security control assessment and authorization support to the USCG SFLC Business Operations Division in support of Surface Domain Operational Technology (OT) and Platform IT systems. The role is the assessment authority on the team: it evaluates whether security and privacy controls are implemented correctly, operating as intended, and producing the intended outcome, and it provides the evidence the Authorizing Official relies on to make risk decisions.This is the senior assessment position on the task order and is distinct from the ISSO roles, which own and maintain the authorization packages. The SCA assesses; the ISSOs prepare and sustain. The position is expected to operate with a high degree of independence and to advise the OT Security Manager (ISSM) directly.Key ResponsibilitiesSupport the OT Security Manager (ISSM) and staff in establishing and maintaining the programs, procedures, and policies that protect Government Sensitive But Unclassified (SBU) information.Perform independent assessments of SFLC Operational Technology to verify that applicable security and privacy controls are implemented correctly, operating as intended, and producing the desired outcome.Provide security assessment and authorization consultation services to the ISSM, on site.Review existing policies, procedures, and guidelines for compliance with DHS, USCG, and DoD cybersecurity policy; draft or revise SFLC policy documentation for ISSM review, approval, and organizational implementation.Assist in preparing RMF security authorization documentation for submission to the Authorizing Official (AO).Maintain security assessment information and supporting documentation within Government-designated systems and repositories.Create and validate SFLC security assessment and authorization accounts within Government-designated systems and tools.Update and maintain assessment and authorization status within Government-designated tracking systems and databases.Upload, track, and update Plans of Action and Milestones (POA recommend POA&M updates based on assessment results and maintain traceability from identified vulnerabilities through to the applicable POA&M.Conduct vulnerability scans of SFLC OT, networks, devices, and associated components using Government-approved tools.Provide assistance to system administrators in remediating vulnerabilities identified through scanning.Provide vulnerability and risk management support in conjunction with assessment and authorization activities.Maintain the enterprise tracking log for electronic spillage activities in accordance with Government policy.Support the destruction of removable media generated during assessment activities in accordance with Government procedures.Support cybersecurity strategic planning and continuous monitoring activities, evaluating enterprise services through assessment of priorities and risk.Provide bi-weekly status reports to the SFLC OT Security Manager (ISSM).Conduct a monthly project status update briefing to the ISSM at SFLC Baltimore.Required QualificationsExperienceTen (10) or more years of progressive cybersecurity experience, including at least five (5) years performing security control assessments or independent A&A validation in a federal environment.Demonstrated experience executing NIST SP 800-37 RMF end to end, including control assessment against NIST SP 800-53A.Experience assessing systems to a formal authorization decision and producing assessment artifacts relied upon by an Authorizing Official.Experience conducting and interpreting vulnerability scans and translating findings into risk-based recommendations and POA&M entries.Experience drafting and revising organizational cybersecurity policy for Government review and adoption.CertificationMust hold and maintain at least one active certification approved for Information Assurance Management (IAM) Level II or Level III. Any one of the following satisfies the requirement:CISSP - Certified Information Systems Security Professional (or CISSP Associate)CISM - Certified Information Security ManagerCGRC - Governance, Risk and Compliance Certification (formerly CAP)CASP+ - CompTIA Advanced Security PractitionerGSLC - GIAC Security Leadership CertificationCCISO - EC-Council Certified Chief Information Security Officer (Level III only)Certification requirements are subject to confirmation against COMDTINST M2620.2 (series) Appendix D, the controlling USCG certification matrix. Verify the accepted certification list with the Program Manager before extending an offer.Evidence of active certification in good standing is required prior to onboarding. Waivers and exceptions to certification requirements will not be granted.Certifications must remain current, active, and in good standing throughout performance. Loss, lapse, or revocation of a required certification is grounds for removal from the contract. Continuing education required to maintain certification is at the employee's and company's expense.Ability to work independently and advise a Government security manager at the senior level.Strong written communication: the role produces bi-weekly written reporting and briefs the ISSM monthly.Ability to read, write, speak, and understand English fluently.Preferred QualificationsPrior USCG, DHS, or DoD assessment experience, particularly with Surface Domain OT or Platform IT systems.Familiarity with COMDTINST M2620.2 (series) and COMDTINST 5500.13 (series).Experience assessing OT/ICS or PIT systems where conventional endpoint tooling cannot be deployed.CGRC (formerly CAP), CISA, or GSNA in addition to the required baseline certification.Experience supporting DHS SELC-aligned programs.Master's degree in cybersecurity, information systems, or a related field.Technical SkillsNIST SP 800-37 (RMF), 800-53 / 53A / 53B, 800-137 (ISCM), FIPS 199 and FIPS 200DHS 4300A Sensitive Systems Handbook and the DHS Systems Engineering Life Cycle (SELC)Government-designated A&A repositories and tracking tools (e.g., eMASS or successor)DISA Security Technical Implementation Guides (STIGs) and Security Requirements Guides (SRGs)Government-approved vulnerability scanning and compliance tooling (e.g., ACAS/Nessus, SCAP-validated scanners)POA&M development, tracking, and closure, including waiver and risk acceptance packagesOperational Technology (OT), Platform IT (PIT), and industrial control system environments, including constraints on agent-based toolingNIST SP 800-30 risk assessment methodology and NIST SP 800-115 technical assessment techniquesElectronic spillage handling and removable media sanitization proceduresSecurity ClearanceNo security clearance required. This position does not involve access to classified information or classified IT systems.S. citizenship is required in accordance with HSAR 3052.204-71 Alternate I.A favorably adjudicated Tier 1 background investigation (or higher) is required. Candidates without an existing investigation on file must complete an Electronic Application (eApp) for investigation processing.Note to recruiting: per the task order, the position is not billable until the selected candidate is fully cleared, has a CAC in hand, and has reported to the work site. Fill timelines should assume 30-90 days for investigation and CAC issuance.EducationBachelor 's degree in cybersecurity, computer science, information systems, engineering, or a related field.Work EnvironmentPrimarily on-site at SFLC Baltimore. On-site presence is required for the monthly status briefing to the ISSM and for participation in change management boards, technical exchange meetings, and Government working groups.The Government furnishes workspace, telephone, a Standard Workstation, and copy/fax access.Remote work may be authorized at the sole discretion of the Government. If authorized, compliant hardware, software, and internet service are contractor- furnished.Occasional travel outside the local commuting area may be required for training and associated off-site meetings, subject to advance COR approval and reimbursed per the Federal Travel Regulations. The 707 East Ordnance Road satellite office is within the local commuting area.OneZero Solutions, LLC is an Equal Opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, pregnancy, genetic information, disability, status as a protected veteran, or any other protected category under applicable federal, state, and local laws.To request an accommodation . click apply for full job details
09/15/2026
Full time
Job Description Job Description We are an employee-centric company that truly values our team members and the contributions they make to our customers and the missions they support. We pride ourselves on being forward-leaning thinkers and on building teams that are, and continue to be, technically proficient across a broad range of cyber mission areas. OneZero full-time employees receive a highly competitive benefits package, including health, dental, vision, and life insurance, a 401(k) with company matching, paid time off and holidays, an employee referral program, and educational assistance. Additional details are available on our website: Position Title : Security Control Assessor (SME), Level IIILocation: USCG Surface Forces Logistics Center, 2401 Hawkins Point Road, Baltimore, MD 21226. Work may also be performed at the SFLC satellite offices at 707 East Ordnance Road, approximately one mile from the primary site, and at other sites as determined necessary by the Contracting Officer's Representative (COR).Clearance:No security clearance required. This position does not involve access to classified information or classified IT systems.S. citizenship is required in accordance with HSAR 3052.204-71 Alternate I.Position SummaryThe Security Control Assessor (SCA) provides independent security control assessment and authorization support to the USCG SFLC Business Operations Division in support of Surface Domain Operational Technology (OT) and Platform IT systems. The role is the assessment authority on the team: it evaluates whether security and privacy controls are implemented correctly, operating as intended, and producing the intended outcome, and it provides the evidence the Authorizing Official relies on to make risk decisions.This is the senior assessment position on the task order and is distinct from the ISSO roles, which own and maintain the authorization packages. The SCA assesses; the ISSOs prepare and sustain. The position is expected to operate with a high degree of independence and to advise the OT Security Manager (ISSM) directly.Key ResponsibilitiesSupport the OT Security Manager (ISSM) and staff in establishing and maintaining the programs, procedures, and policies that protect Government Sensitive But Unclassified (SBU) information.Perform independent assessments of SFLC Operational Technology to verify that applicable security and privacy controls are implemented correctly, operating as intended, and producing the desired outcome.Provide security assessment and authorization consultation services to the ISSM, on site.Review existing policies, procedures, and guidelines for compliance with DHS, USCG, and DoD cybersecurity policy; draft or revise SFLC policy documentation for ISSM review, approval, and organizational implementation.Assist in preparing RMF security authorization documentation for submission to the Authorizing Official (AO).Maintain security assessment information and supporting documentation within Government-designated systems and repositories.Create and validate SFLC security assessment and authorization accounts within Government-designated systems and tools.Update and maintain assessment and authorization status within Government-designated tracking systems and databases.Upload, track, and update Plans of Action and Milestones (POA recommend POA&M updates based on assessment results and maintain traceability from identified vulnerabilities through to the applicable POA&M.Conduct vulnerability scans of SFLC OT, networks, devices, and associated components using Government-approved tools.Provide assistance to system administrators in remediating vulnerabilities identified through scanning.Provide vulnerability and risk management support in conjunction with assessment and authorization activities.Maintain the enterprise tracking log for electronic spillage activities in accordance with Government policy.Support the destruction of removable media generated during assessment activities in accordance with Government procedures.Support cybersecurity strategic planning and continuous monitoring activities, evaluating enterprise services through assessment of priorities and risk.Provide bi-weekly status reports to the SFLC OT Security Manager (ISSM).Conduct a monthly project status update briefing to the ISSM at SFLC Baltimore.Required QualificationsExperienceTen (10) or more years of progressive cybersecurity experience, including at least five (5) years performing security control assessments or independent A&A validation in a federal environment.Demonstrated experience executing NIST SP 800-37 RMF end to end, including control assessment against NIST SP 800-53A.Experience assessing systems to a formal authorization decision and producing assessment artifacts relied upon by an Authorizing Official.Experience conducting and interpreting vulnerability scans and translating findings into risk-based recommendations and POA&M entries.Experience drafting and revising organizational cybersecurity policy for Government review and adoption.CertificationMust hold and maintain at least one active certification approved for Information Assurance Management (IAM) Level II or Level III. Any one of the following satisfies the requirement:CISSP - Certified Information Systems Security Professional (or CISSP Associate)CISM - Certified Information Security ManagerCGRC - Governance, Risk and Compliance Certification (formerly CAP)CASP+ - CompTIA Advanced Security PractitionerGSLC - GIAC Security Leadership CertificationCCISO - EC-Council Certified Chief Information Security Officer (Level III only)Certification requirements are subject to confirmation against COMDTINST M2620.2 (series) Appendix D, the controlling USCG certification matrix. Verify the accepted certification list with the Program Manager before extending an offer.Evidence of active certification in good standing is required prior to onboarding. Waivers and exceptions to certification requirements will not be granted.Certifications must remain current, active, and in good standing throughout performance. Loss, lapse, or revocation of a required certification is grounds for removal from the contract. Continuing education required to maintain certification is at the employee's and company's expense.Ability to work independently and advise a Government security manager at the senior level.Strong written communication: the role produces bi-weekly written reporting and briefs the ISSM monthly.Ability to read, write, speak, and understand English fluently.Preferred QualificationsPrior USCG, DHS, or DoD assessment experience, particularly with Surface Domain OT or Platform IT systems.Familiarity with COMDTINST M2620.2 (series) and COMDTINST 5500.13 (series).Experience assessing OT/ICS or PIT systems where conventional endpoint tooling cannot be deployed.CGRC (formerly CAP), CISA, or GSNA in addition to the required baseline certification.Experience supporting DHS SELC-aligned programs.Master's degree in cybersecurity, information systems, or a related field.Technical SkillsNIST SP 800-37 (RMF), 800-53 / 53A / 53B, 800-137 (ISCM), FIPS 199 and FIPS 200DHS 4300A Sensitive Systems Handbook and the DHS Systems Engineering Life Cycle (SELC)Government-designated A&A repositories and tracking tools (e.g., eMASS or successor)DISA Security Technical Implementation Guides (STIGs) and Security Requirements Guides (SRGs)Government-approved vulnerability scanning and compliance tooling (e.g., ACAS/Nessus, SCAP-validated scanners)POA&M development, tracking, and closure, including waiver and risk acceptance packagesOperational Technology (OT), Platform IT (PIT), and industrial control system environments, including constraints on agent-based toolingNIST SP 800-30 risk assessment methodology and NIST SP 800-115 technical assessment techniquesElectronic spillage handling and removable media sanitization proceduresSecurity ClearanceNo security clearance required. This position does not involve access to classified information or classified IT systems.S. citizenship is required in accordance with HSAR 3052.204-71 Alternate I.A favorably adjudicated Tier 1 background investigation (or higher) is required. Candidates without an existing investigation on file must complete an Electronic Application (eApp) for investigation processing.Note to recruiting: per the task order, the position is not billable until the selected candidate is fully cleared, has a CAC in hand, and has reported to the work site. Fill timelines should assume 30-90 days for investigation and CAC issuance.EducationBachelor 's degree in cybersecurity, computer science, information systems, engineering, or a related field.Work EnvironmentPrimarily on-site at SFLC Baltimore. On-site presence is required for the monthly status briefing to the ISSM and for participation in change management boards, technical exchange meetings, and Government working groups.The Government furnishes workspace, telephone, a Standard Workstation, and copy/fax access.Remote work may be authorized at the sole discretion of the Government. If authorized, compliant hardware, software, and internet service are contractor- furnished.Occasional travel outside the local commuting area may be required for training and associated off-site meetings, subject to advance COR approval and reimbursed per the Federal Travel Regulations. The 707 East Ordnance Road satellite office is within the local commuting area.OneZero Solutions, LLC is an Equal Opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, pregnancy, genetic information, disability, status as a protected veteran, or any other protected category under applicable federal, state, and local laws.To request an accommodation . click apply for full job details
Offensive Security Control Assessor Security Control Assessor Representative
Dark Wolf Solutions Herndon, Virginia
Job Description Job Description Dark Wolf Solutions is seeking Security Control Assessor/Representatives (SCA/Rs) to lead security control assessments across high-priority projects. Working at the intersection of cybersecurity engineering, cloud architecture, and DevSecOps prototyping, you will evaluate security controls for cutting-edge AI/LLM technologies across multiple classification levels. This position is ideal for a pragmatic cloud assessor or SCAR who excels in fast-paced DevSecOps environments, understands AWS cloud security, and is eager to shape the cybersecurity posture of next-generation DoD AI capabilities.This position will be based out of Arlington, VA with hybrid/remote opportunities. Additional responsibilities include: Key Responsibilities Execute formal SCA/R duties. Lead security assessment efforts, establishing reusable security playbooks and assessment frameworks for rapid AI deployment into enterprise workflows. Evaluate technical control effectiveness across AWS cloud infrastructure, DevSecOps pipelines, microservices, containerized workloads, and GenAI/LLM application stacks. Bridge the gap between OffSec and development by applying software design best practices. Lead technical exchange meetings (TEMs), participate in Discovery & Framing workshops, and maintain effective communication with cross-functional teams and stakeholders. Act as the primary subject matter expert and lead developer for custom offensive tooling, integrating disparate capabilities into a cohesive, mission-ready platform. Review, author, and maintain assessment packages-including System Security Plans (SSPs), Security Assessment Plans (SAPs), Security Assessment Reports (SARs), and POA&Ms-tailored to rapid prototyping and AI systems. Assess technical security risks specific to AI/LLM implementations, such as API exposure, vector database access controls, model integration surface area, and software supply chain dependencies. Support continuous monitoring (ConMon), technical risk evaluations, and cloud architecture reviews across multi-tenant, multi-classification environments. Coordinate with Authorizing Officials (AOs), program managers, and engineering leads to deliver decision-ready risk briefings and ATO recommendations. Provide technical input and oversight for cybersecurity engineering and penetration testing activities across prototype projects. Required Qualifications Active Top Secret security clearance Current DoD 8570/8140 IAM Level II or Level III certification (e.g., Security+, CySA+, CISM, CISSP, CCISO, CAP/CISC) 5-7+ years of experience conducting security control assessments, compliance testing, or A&A/RMF activities for DoD or federal information systems Solid operational understanding of core AWS cloud services (EC2, S3, IAM, VPCs, Security Groups, Security Hub) and how security controls function within cloud-native and CI/CD pipeline environments. Experience with GitLab CI/CD (pipeline design, runners, artifact management) and AWS Cloud services (EC2, VPC, IAM, S3). Strong working knowledge of NIST SP 800-53 (Rev. 4/5), NIST SP 800-37 (RMF), DoD Cloud Computing SRG, and FedRAMP baselines. Demonstrated experience writing and evaluating core RMF artifacts (SSPs, SAPs, SARs, POA&Ms) Exceptional written and verbal communication skills, with the ability to articulate technical risk clearly to executive stakeholders, Authorizing Officials, and engineering teams. Hands-on experience navigating government GRC repositories, such as eMASS or XACTA. Desired Qualifications Hands-on experience mapping security controls to the NIST AI Risk Management Framework (AI RMF), the OWASP Top 10 for LLM Applications, or the DoD Responsible AI (RAI) Guidelines. Familiarity evaluating secure design patterns for autonomous AI Agents (e.g., tool-calling permissions, sandboxing agent execution environments, prompt boundaries, and ReAct/LangGraph architectures). Experience assessing cloud-managed AI ecosystems and foundation model platforms (e.g., AWS Bedrock, AWS SageMaker, Hugging Face Enterprise, or self-hosted open-source models). Understanding of data protection, access controls, and boundary security for RAG pipelines and vector databases (e.g., OpenSearch Vector Engine, Pinecone, Milvus, or PostgreSQL pgvector). Familiarity evaluating risks unique to LLMs-including prompt injection, data poisoning, model inversion, insecure output handling, and open-source supply chain vulnerabilities in AI libraries (PyTorch, LangChain, LlamaIndex). Exposure to LLM guardrail platforms, evaluation frameworks, or AI security tools (e.g., Promptfoo, Garak, Giskard, NeMo Guardrails) used to test model robustness and output safety. Experience with cATO methodologies, Infrastructure as Code (IaC) templates (Terraform, CloudFormation), and container security (AWS EKS/ECS, Docker). Active AWS Certifications (e.g., AWS Certified Security - Specialty or AWS Certified Solutions Architect). Background or familiarity with offensive security, penetration testing The salary range for this position is estimated to be between $135,000.00 - $160,000.00, commensurate on experience and technical skillset. We are proud to be an EEO/AA employer Minorities/Women/Veterans/Disabled and other protected categories. In compliance with federal law, all persons hired will be required to verify identity, confirm US Citizenship, and complete the required employment eligibility verification upon hire. We are strictly looking for direct, full-time W2 employees. We do not engage with third-party staffing agencies, C2C, or 1099 independent contractors for this role.
09/15/2026
Full time
Job Description Job Description Dark Wolf Solutions is seeking Security Control Assessor/Representatives (SCA/Rs) to lead security control assessments across high-priority projects. Working at the intersection of cybersecurity engineering, cloud architecture, and DevSecOps prototyping, you will evaluate security controls for cutting-edge AI/LLM technologies across multiple classification levels. This position is ideal for a pragmatic cloud assessor or SCAR who excels in fast-paced DevSecOps environments, understands AWS cloud security, and is eager to shape the cybersecurity posture of next-generation DoD AI capabilities.This position will be based out of Arlington, VA with hybrid/remote opportunities. Additional responsibilities include: Key Responsibilities Execute formal SCA/R duties. Lead security assessment efforts, establishing reusable security playbooks and assessment frameworks for rapid AI deployment into enterprise workflows. Evaluate technical control effectiveness across AWS cloud infrastructure, DevSecOps pipelines, microservices, containerized workloads, and GenAI/LLM application stacks. Bridge the gap between OffSec and development by applying software design best practices. Lead technical exchange meetings (TEMs), participate in Discovery & Framing workshops, and maintain effective communication with cross-functional teams and stakeholders. Act as the primary subject matter expert and lead developer for custom offensive tooling, integrating disparate capabilities into a cohesive, mission-ready platform. Review, author, and maintain assessment packages-including System Security Plans (SSPs), Security Assessment Plans (SAPs), Security Assessment Reports (SARs), and POA&Ms-tailored to rapid prototyping and AI systems. Assess technical security risks specific to AI/LLM implementations, such as API exposure, vector database access controls, model integration surface area, and software supply chain dependencies. Support continuous monitoring (ConMon), technical risk evaluations, and cloud architecture reviews across multi-tenant, multi-classification environments. Coordinate with Authorizing Officials (AOs), program managers, and engineering leads to deliver decision-ready risk briefings and ATO recommendations. Provide technical input and oversight for cybersecurity engineering and penetration testing activities across prototype projects. Required Qualifications Active Top Secret security clearance Current DoD 8570/8140 IAM Level II or Level III certification (e.g., Security+, CySA+, CISM, CISSP, CCISO, CAP/CISC) 5-7+ years of experience conducting security control assessments, compliance testing, or A&A/RMF activities for DoD or federal information systems Solid operational understanding of core AWS cloud services (EC2, S3, IAM, VPCs, Security Groups, Security Hub) and how security controls function within cloud-native and CI/CD pipeline environments. Experience with GitLab CI/CD (pipeline design, runners, artifact management) and AWS Cloud services (EC2, VPC, IAM, S3). Strong working knowledge of NIST SP 800-53 (Rev. 4/5), NIST SP 800-37 (RMF), DoD Cloud Computing SRG, and FedRAMP baselines. Demonstrated experience writing and evaluating core RMF artifacts (SSPs, SAPs, SARs, POA&Ms) Exceptional written and verbal communication skills, with the ability to articulate technical risk clearly to executive stakeholders, Authorizing Officials, and engineering teams. Hands-on experience navigating government GRC repositories, such as eMASS or XACTA. Desired Qualifications Hands-on experience mapping security controls to the NIST AI Risk Management Framework (AI RMF), the OWASP Top 10 for LLM Applications, or the DoD Responsible AI (RAI) Guidelines. Familiarity evaluating secure design patterns for autonomous AI Agents (e.g., tool-calling permissions, sandboxing agent execution environments, prompt boundaries, and ReAct/LangGraph architectures). Experience assessing cloud-managed AI ecosystems and foundation model platforms (e.g., AWS Bedrock, AWS SageMaker, Hugging Face Enterprise, or self-hosted open-source models). Understanding of data protection, access controls, and boundary security for RAG pipelines and vector databases (e.g., OpenSearch Vector Engine, Pinecone, Milvus, or PostgreSQL pgvector). Familiarity evaluating risks unique to LLMs-including prompt injection, data poisoning, model inversion, insecure output handling, and open-source supply chain vulnerabilities in AI libraries (PyTorch, LangChain, LlamaIndex). Exposure to LLM guardrail platforms, evaluation frameworks, or AI security tools (e.g., Promptfoo, Garak, Giskard, NeMo Guardrails) used to test model robustness and output safety. Experience with cATO methodologies, Infrastructure as Code (IaC) templates (Terraform, CloudFormation), and container security (AWS EKS/ECS, Docker). Active AWS Certifications (e.g., AWS Certified Security - Specialty or AWS Certified Solutions Architect). Background or familiarity with offensive security, penetration testing The salary range for this position is estimated to be between $135,000.00 - $160,000.00, commensurate on experience and technical skillset. We are proud to be an EEO/AA employer Minorities/Women/Veterans/Disabled and other protected categories. In compliance with federal law, all persons hired will be required to verify identity, confirm US Citizenship, and complete the required employment eligibility verification upon hire. We are strictly looking for direct, full-time W2 employees. We do not engage with third-party staffing agencies, C2C, or 1099 independent contractors for this role.
Security Control Assessor ? Level II / Journeyman
RIVIDIUM Washington, Washington DC
Job Description Job Description Position Overview RiVidium Inc. is seeking an experienced Security Control Assessor (SCA) ? Level II / Journeyman to support federal cybersecurity assessment, authorization, compliance, and risk management activities. The Security Control Assessor will evaluate the effectiveness of security controls implemented within information systems and enterprise environments. This position will conduct security control assessments, review technical and procedural evidence, identify deficiencies, document findings, and provide recommendations to reduce cybersecurity risk. The ideal candidate will have hands-on experience with the Risk Management Framework (RMF) , security control assessments, cybersecurity compliance, and federal security requirements. The candidate should be comfortable working with ISSOs, system owners, engineers, cybersecurity teams, and government stakeholders. Key Responsibilities Conduct security control assessments for information systems and applications in accordance with federal cybersecurity requirements. Assess the design, implementation, and operating effectiveness of security controls. Review system security documentation, policies, procedures, configurations, and assessment evidence. Develop and execute security assessment plans, procedures, and testing activities. Perform interviews, technical reviews, documentation analysis, and other assessment activities to validate control implementation. Identify security control deficiencies, weaknesses, and potential risks. Document assessment findings and provide clear, actionable remediation recommendations. Develop and maintain Security Assessment Reports (SARs) and supporting assessment documentation. Support Plan of Action and Milestones (POA&M) development and remediation tracking. Validate corrective actions and determine whether identified findings have been adequately addressed. Support Risk Management Framework (RMF) activities throughout the system lifecycle. Assist with Authorization to Operate (ATO), authorization package development, and continuous authorization activities. Evaluate security controls against applicable federal standards and organizational requirements. Assess technical and management controls across applications, infrastructure, networks, cloud environments, and enterprise systems. Review vulnerability assessment results and determine their impact on security control effectiveness and overall system risk. Coordinate with Information System Security Officers (ISSOs), Information System Security Managers (ISSMs), system owners, system administrators, engineers, and other stakeholders. Support continuous monitoring activities and periodic security control reassessments. Assist with security audits, compliance reviews, and customer assessments. Track assessment milestones, findings, risks, and remediation activities. Prepare technical reports, briefings, presentations, and cybersecurity metrics for government leadership. Maintain awareness of changes to federal cybersecurity policies, standards, and assessment requirements. Provide guidance and mentoring to junior cybersecurity assessment personnel. Required Qualifications Bachelor?s degree in Cybersecurity, Information Systems, Information Technology, Computer Science, or a related field . Demonstrated experience performing security control assessments, cybersecurity assessments, compliance assessments, or information assurance activities. Experience with the NIST Risk Management Framework (RMF) . Working knowledge of security controls and control assessment methodologies. Experience reviewing security documentation, policies, procedures, technical configurations, and assessment evidence. Ability to identify, document, and evaluate security control weaknesses. Experience developing assessment reports, findings, and remediation recommendations. Knowledge of federal cybersecurity requirements and information security best practices. Understanding of NIST SP 800-53 security controls. Experience supporting ATO and authorization activities. Strong analytical, organizational, technical writing, and communication skills. Ability to work independently and collaborate with technical teams and government stakeholders. Preferred Certifications One or more of the following certifications is highly desirable: Certified Authorization Professional (CAP) CompTIA Security+ GRC-related certification CISSP CISM CRISC GIAC certification Preferred Qualifications Experience supporting federal civilian or Department of Defense (DoD) cybersecurity programs. Experience with NIST SP 800-37, NIST SP 800-53, FISMA , and related federal cybersecurity requirements. Experience supporting enterprise-level security authorization programs. Familiarity with RSA Archer, ServiceNow GRC, eMASS , or similar GRC platforms. Experience with continuous monitoring and ongoing authorization. Experience assessing cloud environments, including AWS, Azure, Google Cloud, or Microsoft 365 . Knowledge of vulnerability management and security assessment tools. Experience reviewing vulnerability scans and technical security assessment results. Experience working with system security plans (SSPs), security assessment reports (SARs), and POA&Ms. Experience with cybersecurity policies, procedures, standards, and control implementation documentation. Ability to translate technical findings into business and mission risk. Technical Skills The successful candidate should have knowledge of: Security Control Assessments NIST RMF NIST SP 800-53 NIST SP 800-37 FISMA ATO / Authorization Continuous Monitoring Security Assessment Plans Security Assessment Reports System Security Plans POA&M Management Cybersecurity Risk Management Security Control Testing Compliance Assessments Vulnerability Management GRC Platforms RSA Archer eMASS ServiceNow GRC Cloud Security Security Documentation Risk Analysis Audit and Compliance RiVidium Inc is seeking a ? Security Control Assessor (SCA) ? Level II / Journeyman ? to support a federal client. This position is contingent upon contract award and funding approval. As such, this job posting is intended to identify qualified candidates for a potential future opportunity and does not represent a currently available position. Compensation has not yet been determined and will be established based on contract requirements, candidate qualifications, experience, and applicable market conditions.
09/15/2026
Full time
Job Description Job Description Position Overview RiVidium Inc. is seeking an experienced Security Control Assessor (SCA) ? Level II / Journeyman to support federal cybersecurity assessment, authorization, compliance, and risk management activities. The Security Control Assessor will evaluate the effectiveness of security controls implemented within information systems and enterprise environments. This position will conduct security control assessments, review technical and procedural evidence, identify deficiencies, document findings, and provide recommendations to reduce cybersecurity risk. The ideal candidate will have hands-on experience with the Risk Management Framework (RMF) , security control assessments, cybersecurity compliance, and federal security requirements. The candidate should be comfortable working with ISSOs, system owners, engineers, cybersecurity teams, and government stakeholders. Key Responsibilities Conduct security control assessments for information systems and applications in accordance with federal cybersecurity requirements. Assess the design, implementation, and operating effectiveness of security controls. Review system security documentation, policies, procedures, configurations, and assessment evidence. Develop and execute security assessment plans, procedures, and testing activities. Perform interviews, technical reviews, documentation analysis, and other assessment activities to validate control implementation. Identify security control deficiencies, weaknesses, and potential risks. Document assessment findings and provide clear, actionable remediation recommendations. Develop and maintain Security Assessment Reports (SARs) and supporting assessment documentation. Support Plan of Action and Milestones (POA&M) development and remediation tracking. Validate corrective actions and determine whether identified findings have been adequately addressed. Support Risk Management Framework (RMF) activities throughout the system lifecycle. Assist with Authorization to Operate (ATO), authorization package development, and continuous authorization activities. Evaluate security controls against applicable federal standards and organizational requirements. Assess technical and management controls across applications, infrastructure, networks, cloud environments, and enterprise systems. Review vulnerability assessment results and determine their impact on security control effectiveness and overall system risk. Coordinate with Information System Security Officers (ISSOs), Information System Security Managers (ISSMs), system owners, system administrators, engineers, and other stakeholders. Support continuous monitoring activities and periodic security control reassessments. Assist with security audits, compliance reviews, and customer assessments. Track assessment milestones, findings, risks, and remediation activities. Prepare technical reports, briefings, presentations, and cybersecurity metrics for government leadership. Maintain awareness of changes to federal cybersecurity policies, standards, and assessment requirements. Provide guidance and mentoring to junior cybersecurity assessment personnel. Required Qualifications Bachelor?s degree in Cybersecurity, Information Systems, Information Technology, Computer Science, or a related field . Demonstrated experience performing security control assessments, cybersecurity assessments, compliance assessments, or information assurance activities. Experience with the NIST Risk Management Framework (RMF) . Working knowledge of security controls and control assessment methodologies. Experience reviewing security documentation, policies, procedures, technical configurations, and assessment evidence. Ability to identify, document, and evaluate security control weaknesses. Experience developing assessment reports, findings, and remediation recommendations. Knowledge of federal cybersecurity requirements and information security best practices. Understanding of NIST SP 800-53 security controls. Experience supporting ATO and authorization activities. Strong analytical, organizational, technical writing, and communication skills. Ability to work independently and collaborate with technical teams and government stakeholders. Preferred Certifications One or more of the following certifications is highly desirable: Certified Authorization Professional (CAP) CompTIA Security+ GRC-related certification CISSP CISM CRISC GIAC certification Preferred Qualifications Experience supporting federal civilian or Department of Defense (DoD) cybersecurity programs. Experience with NIST SP 800-37, NIST SP 800-53, FISMA , and related federal cybersecurity requirements. Experience supporting enterprise-level security authorization programs. Familiarity with RSA Archer, ServiceNow GRC, eMASS , or similar GRC platforms. Experience with continuous monitoring and ongoing authorization. Experience assessing cloud environments, including AWS, Azure, Google Cloud, or Microsoft 365 . Knowledge of vulnerability management and security assessment tools. Experience reviewing vulnerability scans and technical security assessment results. Experience working with system security plans (SSPs), security assessment reports (SARs), and POA&Ms. Experience with cybersecurity policies, procedures, standards, and control implementation documentation. Ability to translate technical findings into business and mission risk. Technical Skills The successful candidate should have knowledge of: Security Control Assessments NIST RMF NIST SP 800-53 NIST SP 800-37 FISMA ATO / Authorization Continuous Monitoring Security Assessment Plans Security Assessment Reports System Security Plans POA&M Management Cybersecurity Risk Management Security Control Testing Compliance Assessments Vulnerability Management GRC Platforms RSA Archer eMASS ServiceNow GRC Cloud Security Security Documentation Risk Analysis Audit and Compliance RiVidium Inc is seeking a ? Security Control Assessor (SCA) ? Level II / Journeyman ? to support a federal client. This position is contingent upon contract award and funding approval. As such, this job posting is intended to identify qualified candidates for a potential future opportunity and does not represent a currently available position. Compensation has not yet been determined and will be established based on contract requirements, candidate qualifications, experience, and applicable market conditions.
Security Control Assessor II (SCA II)
Targeted Solutions, LLC Arlington, Virginia
Job Description Job Description Security Control Accessor II REQ-26-J-0055 The SCA is responsible for conducting a comprehensive assessment of the management, operational, and technical security controls employed within or inherited by an IS to determine the overall effectiveness of the controls (i.e., the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for the system). SCAs also provide an assessment of the severity of weaknesses or deficiencies discovered in the IS and its environment of operation and recommend corrective actions to address identified vulnerabilities. Responsibilities will cover Collateral, Sensitive Compartmented Information (SCI) and Special Access Program (SAP) activities within the customer's area of responsibility. Performance shall include: Perform oversight of the development, implementation and evaluation of IS security program policy; special emphasis placed upon integration of existing SAP network infrastructure. Perform assessment of ISs, based upon the Risk Management Framework (RMF) methodology in accordance with the Joint Special Access Program (SAP) Implementation Guide (JSIG). Advise the Information System Owner (ISO), Information Data Owner (IDO), Program Security. Officer (PSO), and the Delegated and/or Authorizing Official (DAO/AO) on any assessment and authorization issues. Evaluate Authorization packages and make recommendation to the AO and/or DAO for authorization. Evaluate IS threats and vulnerabilities to determine whether additional safeguards are required. Advise the Government concerning the impact levels for Confidentiality, Integrity, and Availability for the information on a system. Ensure security assessments are completed and results documented and prepare the Security Assessment Report (SAR) for the Authorization boundary. Initiate a Plan of Action and Milestones (POA&M) with identified weaknesses for each Authorization Boundaries assessed, based on findings and recommendations from the SAR. Evaluate security assessment documentation and provide written recommendations for security authorization to the Government. Discuss recommendation for authorization and submit the security authorization package to the AO/DAO Assess proposed changes to Authorization boundaries operating environment and mission needs to determine the continuation to operate. Review and concur with all sanitizations and clearing procedures in accordance with Government guidance and/or policy. Assist the Government compliance inspections. Assist the Government with security incidents that relate to cybersecurity and ensure that the proper and corrective measures have been taken. Ensure organization are addressing and conducting all phases of the system development life cycle (SDLC). Evaluate Hardware and Software to determine security impact that it might have on Authorization boundaries. Evaluate the effectiveness and implementation of Continuous Monitoring Plans. Represent the customer on inspection teams. EDUCATION: Bachelor's degree or equivalent experience (4 years) CLEARANCE: Top-Secret w/SCI Eligibility MANDATORY: 7-9 years related experience; 4+ years' experience in SAP, SCI, or Collateral Information Systems (S) security and implantation of regulations identified in the description of duties; Prior performance in the role of ISSO and ISSM or SCA; TRAINING: IAM Level II (in lieu of IAT Level III) BENEFITS: We offer a competitive compensation package including a generous PTO and Flexible holiday package, tax-free healthcare cost reimbursement, and an immediate vesting 401K with 4% matching.
09/15/2026
Full time
Job Description Job Description Security Control Accessor II REQ-26-J-0055 The SCA is responsible for conducting a comprehensive assessment of the management, operational, and technical security controls employed within or inherited by an IS to determine the overall effectiveness of the controls (i.e., the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for the system). SCAs also provide an assessment of the severity of weaknesses or deficiencies discovered in the IS and its environment of operation and recommend corrective actions to address identified vulnerabilities. Responsibilities will cover Collateral, Sensitive Compartmented Information (SCI) and Special Access Program (SAP) activities within the customer's area of responsibility. Performance shall include: Perform oversight of the development, implementation and evaluation of IS security program policy; special emphasis placed upon integration of existing SAP network infrastructure. Perform assessment of ISs, based upon the Risk Management Framework (RMF) methodology in accordance with the Joint Special Access Program (SAP) Implementation Guide (JSIG). Advise the Information System Owner (ISO), Information Data Owner (IDO), Program Security. Officer (PSO), and the Delegated and/or Authorizing Official (DAO/AO) on any assessment and authorization issues. Evaluate Authorization packages and make recommendation to the AO and/or DAO for authorization. Evaluate IS threats and vulnerabilities to determine whether additional safeguards are required. Advise the Government concerning the impact levels for Confidentiality, Integrity, and Availability for the information on a system. Ensure security assessments are completed and results documented and prepare the Security Assessment Report (SAR) for the Authorization boundary. Initiate a Plan of Action and Milestones (POA&M) with identified weaknesses for each Authorization Boundaries assessed, based on findings and recommendations from the SAR. Evaluate security assessment documentation and provide written recommendations for security authorization to the Government. Discuss recommendation for authorization and submit the security authorization package to the AO/DAO Assess proposed changes to Authorization boundaries operating environment and mission needs to determine the continuation to operate. Review and concur with all sanitizations and clearing procedures in accordance with Government guidance and/or policy. Assist the Government compliance inspections. Assist the Government with security incidents that relate to cybersecurity and ensure that the proper and corrective measures have been taken. Ensure organization are addressing and conducting all phases of the system development life cycle (SDLC). Evaluate Hardware and Software to determine security impact that it might have on Authorization boundaries. Evaluate the effectiveness and implementation of Continuous Monitoring Plans. Represent the customer on inspection teams. EDUCATION: Bachelor's degree or equivalent experience (4 years) CLEARANCE: Top-Secret w/SCI Eligibility MANDATORY: 7-9 years related experience; 4+ years' experience in SAP, SCI, or Collateral Information Systems (S) security and implantation of regulations identified in the description of duties; Prior performance in the role of ISSO and ISSM or SCA; TRAINING: IAM Level II (in lieu of IAT Level III) BENEFITS: We offer a competitive compensation package including a generous PTO and Flexible holiday package, tax-free healthcare cost reimbursement, and an immediate vesting 401K with 4% matching.
DHS Security Control Assessor III
OneZero Solutions Washington, Washington DC
Job Description Job Description We are an employee-centric company that truly appreciates our team members and their value to our customers and the missions they support. We pride ourselves on being forward-leaning thinkers and fostering teams that are and continue to be technically proficient and technically capable across a comprehensive range of cyber mission areas. OneZero full-time employees receive an extremely competitive benefits package that includes health/dental/vision/life insurance plans, 401K with company matching, PTO & paid holidays, employee referral program, and educational assistance. Additional details can be found on our website at: Title: DHS Security Control Assessor IIILocation: NCRClearance: TS/SCIOneZero Solutions is on contract to provide division-wide support for Federal Information Security Modernization Act (FISMA) compliance, execution of the Risk Management Framework (RMF) process to achieve and maintain Authority to Operate (ATO) security authorizations, and deliver cyber security compliance for DHS operational mission systems. We are looking for personnel to support our DHS customer in achieving its mission of providing division-wide cyber security support for operational mission systems and assisting programs as they navigate the ATO process. The result of these efforts will be that the systems meet all the requirements for ATO approval before they are officially submitted to the Office of Chief Information Officer (OCIO).Qualified Parking Allowance: Employer may provide a monthly stipend or cover the cost of parking for employees who commute to government site by car.Job SummaryConduct independent assessments of the management, operational, and technical security controls employed within various DHS systems and networks.Evaluate the effectiveness of implemented controls in mitigating identified risks and protecting sensitive data and systems.Identify and document control deficiencies, vulnerabilities, and non-compliance with security policies, regulations, and prescribed hardening guidelines.Develop and present clear and concise findings and recommendations to stakeholders and decision-makers.Support the implementation of corrective actions to address identified deficiencies and improve overall security posture.Stay current with emerging security threats, vulnerabilities, and federal and industry best practices, standards, and policies for employed IT and its continued compliance within DHS.Contribute to the development and continual refinement of internal security assessment methodologies and procedures.Qualifications:10+ years of direct experience serving as a Security Control Assessor (SCA) within the DoD/Federal Government. Experience within the Intelligence Community and Law Enforcement is a strong plus.Demonstrated expertise in various security control frameworks and methodologies, including NIST SP 800-53, FISMA, RMF, DISA STIGs, and DHS supplemental IA controls.Proficiency in conducting security assessments, utilizing tools and techniques for vulnerability scanning, penetration testing, and configuration review.Strong understanding of information security principles and best practices, including network security, system security, encryption, and incident response.Experience with OpenRMF is a strong plus.Excellent analytical and problem-solving skills.Exceptional written and verbal communication skills.Ability to work independently and as part of a team.EducationBachelor 's degree and/or CRISC, GISP, CASP, CISSP, or other advanced security-related certificationsAdditional relevant experience may be considered in lieu of a degree. OneZero Solutions, LLC is an Equal Opportunity/Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, or protected veteran status and will not be discriminated against on the basis of disability.If you are a qualified individual with a disability or a disabled veteran, you have the right to request an accommodation if you are unable or limited in your ability to use or access as a result of your disability.To request an accommodation, please contact us at or call . Job Posted by ApplicantPro
09/15/2026
Full time
Job Description Job Description We are an employee-centric company that truly appreciates our team members and their value to our customers and the missions they support. We pride ourselves on being forward-leaning thinkers and fostering teams that are and continue to be technically proficient and technically capable across a comprehensive range of cyber mission areas. OneZero full-time employees receive an extremely competitive benefits package that includes health/dental/vision/life insurance plans, 401K with company matching, PTO & paid holidays, employee referral program, and educational assistance. Additional details can be found on our website at: Title: DHS Security Control Assessor IIILocation: NCRClearance: TS/SCIOneZero Solutions is on contract to provide division-wide support for Federal Information Security Modernization Act (FISMA) compliance, execution of the Risk Management Framework (RMF) process to achieve and maintain Authority to Operate (ATO) security authorizations, and deliver cyber security compliance for DHS operational mission systems. We are looking for personnel to support our DHS customer in achieving its mission of providing division-wide cyber security support for operational mission systems and assisting programs as they navigate the ATO process. The result of these efforts will be that the systems meet all the requirements for ATO approval before they are officially submitted to the Office of Chief Information Officer (OCIO).Qualified Parking Allowance: Employer may provide a monthly stipend or cover the cost of parking for employees who commute to government site by car.Job SummaryConduct independent assessments of the management, operational, and technical security controls employed within various DHS systems and networks.Evaluate the effectiveness of implemented controls in mitigating identified risks and protecting sensitive data and systems.Identify and document control deficiencies, vulnerabilities, and non-compliance with security policies, regulations, and prescribed hardening guidelines.Develop and present clear and concise findings and recommendations to stakeholders and decision-makers.Support the implementation of corrective actions to address identified deficiencies and improve overall security posture.Stay current with emerging security threats, vulnerabilities, and federal and industry best practices, standards, and policies for employed IT and its continued compliance within DHS.Contribute to the development and continual refinement of internal security assessment methodologies and procedures.Qualifications:10+ years of direct experience serving as a Security Control Assessor (SCA) within the DoD/Federal Government. Experience within the Intelligence Community and Law Enforcement is a strong plus.Demonstrated expertise in various security control frameworks and methodologies, including NIST SP 800-53, FISMA, RMF, DISA STIGs, and DHS supplemental IA controls.Proficiency in conducting security assessments, utilizing tools and techniques for vulnerability scanning, penetration testing, and configuration review.Strong understanding of information security principles and best practices, including network security, system security, encryption, and incident response.Experience with OpenRMF is a strong plus.Excellent analytical and problem-solving skills.Exceptional written and verbal communication skills.Ability to work independently and as part of a team.EducationBachelor 's degree and/or CRISC, GISP, CASP, CISSP, or other advanced security-related certificationsAdditional relevant experience may be considered in lieu of a degree. OneZero Solutions, LLC is an Equal Opportunity/Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, or protected veteran status and will not be discriminated against on the basis of disability.If you are a qualified individual with a disability or a disabled veteran, you have the right to request an accommodation if you are unable or limited in your ability to use or access as a result of your disability.To request an accommodation, please contact us at or call . Job Posted by ApplicantPro
Security Control Assessor II (SCA II) (TS, w/ SCI Eligibility) -
RedTrace Technologies Inc Colorado Springs, Colorado
Job Description Job Description SECURITY CLEARANCE REQUIREMENT: TS, WITH SCI ELIGIBILITY POSITION REQUIRES US CITIZENSHIP Position Title: Security Control Assessor (SCA) II Location: Peterson SFB, CO Position Description: The SCA is responsible for conducting a comprehensive assessment of the management, operational, and technical security controls employed within or inherited by an IS to determine the overall effectiveness of the controls (i.e., the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for the system). SCAs also provide an assessment of the severity of weaknesses or deficiencies discovered in the IS and its environment of operation and recommend corrective actions to address identified vulnerabilities. Responsibilities will cover Collateral, Sensitive Compartmented Information (SCI) and Special Access Program (SAP) activities within the customer's area of responsibility. We are seeking an Security Control Assessor (SCA) II to carry out the following duties and responsibilities: Perform oversight of the development, implementation and evaluation of IS security program policy; special emphasis placed upon integration of existing SAP network infrastructure Perform assessment of ISs, based upon the Risk Management Framework (RMF) methodology in accordance with the Joint Special Access Program (SAP) Implementation Guide (JSIG) Advise the Information System Owner (ISO), Information Data Owner (IDO), Program Security Officer (PSO), and the Delegated and/or Authorizing Official (DAO/AO) on any assessment and authorization issues Evaluate Authorization packages and make recommendation to the AO and/or DAO for authorization Evaluate IS threats and vulnerabilities to determine whether additional safeguards are required Advise the Government concerning the impact levels for Confidentiality, Integrity, and Availability for the information on a system Ensure security assessments are completed and results documented and prepare the Security Assessment Report (SAR) for the Authorization boundary Initiate a Plan of Action and Milestones (POA&M) with identified weaknesses for each Authorization Boundaries assessed, based on findings and recommendations from the SAR Evaluate security assessment documentation and provide written recommendations for security authorization to the Government Discuss recommendation for authorization and submit the security authorization package to the AO/DAO Assess proposed changes to Authorization boundaries operating environment and mission needs to determine the continuation to operate. Review and concur with all sanitization and clearing procedures in accordance with Government guidance and/or policy Assist the Government compliance inspections Assist the Government with security incidents that relate to cybersecurity and ensure that the proper and corrective measures have been taken Ensure organization are addressing and conducting all phases of the system development life cycle (SDLC) Evaluate Hardware and Software to determine security impact that it might have on Authorization boundaries Evaluate the effectiveness and implementation of Continuous Monitoring Plans Represent the customer on inspection teams Qualifications: Required: 7 - 9 years related experience Bachelor's degree in a related discipline or equivalent experience (4 years) Minimum of four (4) years' experience in SAP, SCI or Collateral Information Systems (IS) Security and the implementation of regulations identified in the description of duties Prior performance in the role of ISSO, ISSM, SCA Must meet position and certification requirements outlined in DoD Directive 8570.01-M for Information Assurance Manager Level II Must be able to regularly lift 50lbs Security Clearance: TS, with SCI eligibility Eligibility for access to Special Access Program Information Willingness to submit to a Counterintelligence polygraph Employee Benefits: Competitive salary for well qualified applicants 401(k) plan Annual performance bonus Certification and advanced degree attainment bonuses Student Loan / Tuition reimbursement Health Care Insurance (medical, dental, vision) Up to four weeks of paid vacation 11 Federal Holidays, and 3 Floating Holidays Team bonding events RedTrace Technologies is an EOE employer Powered by JazzHR 9XbYYqgKb5
09/15/2026
Full time
Job Description Job Description SECURITY CLEARANCE REQUIREMENT: TS, WITH SCI ELIGIBILITY POSITION REQUIRES US CITIZENSHIP Position Title: Security Control Assessor (SCA) II Location: Peterson SFB, CO Position Description: The SCA is responsible for conducting a comprehensive assessment of the management, operational, and technical security controls employed within or inherited by an IS to determine the overall effectiveness of the controls (i.e., the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for the system). SCAs also provide an assessment of the severity of weaknesses or deficiencies discovered in the IS and its environment of operation and recommend corrective actions to address identified vulnerabilities. Responsibilities will cover Collateral, Sensitive Compartmented Information (SCI) and Special Access Program (SAP) activities within the customer's area of responsibility. We are seeking an Security Control Assessor (SCA) II to carry out the following duties and responsibilities: Perform oversight of the development, implementation and evaluation of IS security program policy; special emphasis placed upon integration of existing SAP network infrastructure Perform assessment of ISs, based upon the Risk Management Framework (RMF) methodology in accordance with the Joint Special Access Program (SAP) Implementation Guide (JSIG) Advise the Information System Owner (ISO), Information Data Owner (IDO), Program Security Officer (PSO), and the Delegated and/or Authorizing Official (DAO/AO) on any assessment and authorization issues Evaluate Authorization packages and make recommendation to the AO and/or DAO for authorization Evaluate IS threats and vulnerabilities to determine whether additional safeguards are required Advise the Government concerning the impact levels for Confidentiality, Integrity, and Availability for the information on a system Ensure security assessments are completed and results documented and prepare the Security Assessment Report (SAR) for the Authorization boundary Initiate a Plan of Action and Milestones (POA&M) with identified weaknesses for each Authorization Boundaries assessed, based on findings and recommendations from the SAR Evaluate security assessment documentation and provide written recommendations for security authorization to the Government Discuss recommendation for authorization and submit the security authorization package to the AO/DAO Assess proposed changes to Authorization boundaries operating environment and mission needs to determine the continuation to operate. Review and concur with all sanitization and clearing procedures in accordance with Government guidance and/or policy Assist the Government compliance inspections Assist the Government with security incidents that relate to cybersecurity and ensure that the proper and corrective measures have been taken Ensure organization are addressing and conducting all phases of the system development life cycle (SDLC) Evaluate Hardware and Software to determine security impact that it might have on Authorization boundaries Evaluate the effectiveness and implementation of Continuous Monitoring Plans Represent the customer on inspection teams Qualifications: Required: 7 - 9 years related experience Bachelor's degree in a related discipline or equivalent experience (4 years) Minimum of four (4) years' experience in SAP, SCI or Collateral Information Systems (IS) Security and the implementation of regulations identified in the description of duties Prior performance in the role of ISSO, ISSM, SCA Must meet position and certification requirements outlined in DoD Directive 8570.01-M for Information Assurance Manager Level II Must be able to regularly lift 50lbs Security Clearance: TS, with SCI eligibility Eligibility for access to Special Access Program Information Willingness to submit to a Counterintelligence polygraph Employee Benefits: Competitive salary for well qualified applicants 401(k) plan Annual performance bonus Certification and advanced degree attainment bonuses Student Loan / Tuition reimbursement Health Care Insurance (medical, dental, vision) Up to four weeks of paid vacation 11 Federal Holidays, and 3 Floating Holidays Team bonding events RedTrace Technologies is an EOE employer Powered by JazzHR 9XbYYqgKb5
Cybersecurity Information System Security Officer (ISSO) L3
Keenbee Talent Soluitions Albuquerque, New Mexico
As a key member of our cybersecurity team, you will be instrumental in guiding the application of IT security controls that ensure the confidentiality, integrity, and availability of system data and resources. Your solutions will align with existing system and network configurations, collaborating closely with configuration managers to maintain seamless security integration. In this position, you will lead critical functions related to the Risk Management Framework (RMF), overseeing the approval, sustainment, and disposition of Department of Defense (DoD) Information Systems. This includes continuous monitoring, vulnerability assessments, and coordination with Certified Defense Contractors to ensure compliance. You will also facilitate changes, maintenance approvals, and work alongside the Security Control Assessor (SCA) and Authorizing Official Designated Representative (AODR). Additionally, you will maintain organizational networks, manage accounts, audit systems, and conduct vulnerability scans. Your expertise will serve as a key resource, providing vital cybersecurity insights and guidance to civilian and military personnel, and senior leadership. You'll play an essential role in government inspections and audits, ensuring that all systems comply with the highest regulatory standards. Skills / Experience Required Top Secret with Sensitive Compartmented Information (TS/SCI) eligible May be required to consent to and successfully complete a Government Counterintelligence Scope Polygraph 10+ years of relevant experience within the Department of Defense 4+ years experience in SAP/SCI environment and worked in this environment within the last five years Ability to work in a dynamic environment with a diverse group of individuals focused on the accomplishment of a common objectives Provide recommendations to senior leadership to help ensure mission success Capable of conveying complex information in a simplistic manner Able to take proactive measures to prevent problems rather than reactive by nature Excellent written and oral interpersonal skills and attention to detail Strong critical thinking and problem-solving skills Education / Certifications Master of Arts/Master of Science/Master of Engineering in Computer Science, Cybersecurity, MIS, or related degree Relevant work experience/training certifications may be considered in lieu of a degree Minimum 1 year of experience using Risk Management Framework (RMF) IT security controls and policies Minimum DoD 8140/DoD 8570 IASAE Level II Certification Benefits Medical, dental, vision, disability, and life insurance Flexible Spending Accounts 401(k) PTO Paid Parental leave Tuition reimbursement Paid federal holidays Keenbee Talent Solutions is a Native Alaskan Women owned sdb specializing in the placement of highly skilled professionals in Accounting and Finance, IT/MIS and Biomedical. Keenbee has been in business since 1997 servicing New Mexico and the surrounding states with high results. Keenbee Talent Solutions is an equal opportunity employment agency. We do not discriminate based on race, color, national origin, religion, ancestry, sex, age, disability, serious medical condition, spousal affiliation, sexual orientation, gender identity, or other classifications protected under the law.
09/15/2026
As a key member of our cybersecurity team, you will be instrumental in guiding the application of IT security controls that ensure the confidentiality, integrity, and availability of system data and resources. Your solutions will align with existing system and network configurations, collaborating closely with configuration managers to maintain seamless security integration. In this position, you will lead critical functions related to the Risk Management Framework (RMF), overseeing the approval, sustainment, and disposition of Department of Defense (DoD) Information Systems. This includes continuous monitoring, vulnerability assessments, and coordination with Certified Defense Contractors to ensure compliance. You will also facilitate changes, maintenance approvals, and work alongside the Security Control Assessor (SCA) and Authorizing Official Designated Representative (AODR). Additionally, you will maintain organizational networks, manage accounts, audit systems, and conduct vulnerability scans. Your expertise will serve as a key resource, providing vital cybersecurity insights and guidance to civilian and military personnel, and senior leadership. You'll play an essential role in government inspections and audits, ensuring that all systems comply with the highest regulatory standards. Skills / Experience Required Top Secret with Sensitive Compartmented Information (TS/SCI) eligible May be required to consent to and successfully complete a Government Counterintelligence Scope Polygraph 10+ years of relevant experience within the Department of Defense 4+ years experience in SAP/SCI environment and worked in this environment within the last five years Ability to work in a dynamic environment with a diverse group of individuals focused on the accomplishment of a common objectives Provide recommendations to senior leadership to help ensure mission success Capable of conveying complex information in a simplistic manner Able to take proactive measures to prevent problems rather than reactive by nature Excellent written and oral interpersonal skills and attention to detail Strong critical thinking and problem-solving skills Education / Certifications Master of Arts/Master of Science/Master of Engineering in Computer Science, Cybersecurity, MIS, or related degree Relevant work experience/training certifications may be considered in lieu of a degree Minimum 1 year of experience using Risk Management Framework (RMF) IT security controls and policies Minimum DoD 8140/DoD 8570 IASAE Level II Certification Benefits Medical, dental, vision, disability, and life insurance Flexible Spending Accounts 401(k) PTO Paid Parental leave Tuition reimbursement Paid federal holidays Keenbee Talent Solutions is a Native Alaskan Women owned sdb specializing in the placement of highly skilled professionals in Accounting and Finance, IT/MIS and Biomedical. Keenbee has been in business since 1997 servicing New Mexico and the surrounding states with high results. Keenbee Talent Solutions is an equal opportunity employment agency. We do not discriminate based on race, color, national origin, religion, ancestry, sex, age, disability, serious medical condition, spousal affiliation, sexual orientation, gender identity, or other classifications protected under the law.
Information System Security Specialist III
Prosync Crane, Indiana
Job Description Job Description ProSync is seeking passionate Information System Security Specialist III to help provide mid level cybersecurity support for Navy information systems, networks, and mission environments. This role assists in implementing, maintaining, and monitoring security controls in accordance with DoD and federal cybersecurity policies. ProSync Technology Group, LLC (ProSync) is an award-winning, SDVOSB Defense Contracting company with a strong military heritage and a record of excellence in supporting the Department of Defense and the Intelligence Community. If you have prior military service or government contracting experience, are proud to serve and support our nation, and want to help support ProSync's mission to "Define and Redefine the State of Possible," please apply today! RESPONSIBILITIES The Information System Security Specialist is responsible for supporting all aspects of a Program Information Assurance (IA) processes tailored to include minimum qualification standards, fundamental awareness and familiarity to demonstrated competency with specific experience in Cyber Security, Engineering, Test & Evaluation, (T&E) and/or Security Control Assessor (SCA) under a Certification & Accreditation (C&A) and/or Assessment & Authorization (A&A) process. The specialist should demonstrate a working knowledge of the Risk Management Framework (RMF) process and/or include prior experience with the Defense Information Assurance & Certification Accreditation Process (DIACAP). Familiarity with security policies & guidance documents to assist with the preparation and maintenance of process artifacts, traceability documents purposed for compliance with Authority to Operate (ATO) requirements. The specialist is expected to evaluate security solutions to ensure they meet security requirements for processing up to classified information, and supervise and/or maintain the operational security posture for an information system or program. Support the development, documentation, and maintenance of system security plans, procedures, and authorization artifacts. Assist in implementing security controls and ensuring compliance with applicable cybersecurity frameworks (e.g., RMF, NIST, DoD directives). Conduct routine security assessments, vulnerability scans, and configuration checks to identify and report security risks. Support incident response activities, including evidence collection, initial triage, and coordination with senior cybersecurity personnel. Maintain awareness of system configurations, user access requirements, and security posture changes. Assist in preparing documentation for system authorization, continuous monitoring, and audit readiness. Provide user support on security procedures, access requirements, and proper handling of sensitive information. Requirements A minimum of 5 years of practical experience in a Cybersecurity, Engineering, T&E or A&A (formerly C&A) related field. Must have experience working with Information Assurance tools such as DISA Enterprise Mission Assurance Support Service (eMASS), Assured Compliance Assessment Solution (ACAS) A minimum Top Secret security clearance or higher with the ability to obtain a Top Secret w/ SCI is required to be considered for this position. EDUCATIONAL REQUIREMENTS A college degree in a technical or managerial related discipline is preferred. Note: a high school diploma or high school equivalency certificate is acceptable with 2 additional years of practical experience. CERTIFICATION REQUIREMENTS May be required to hold an Interim Security Control Assessor qualification. Benefits Join PROSYNC and enjoy our great benefits! Compensation We offer sign on bonuses! We also offer bonuses that are awarded quarterly to our employees and our compensation rates are highly competitive. Health & Retirement We offer a comprehensive Health Benefits package and 401K retirement plan so you can take care of yourself and your family, now and in the future. Other health-related benefits include an employee assistance program for those difficult times or when you need to take care of your mental health. Education Individual growth is a priority at ProSync. Employees are encouraged to take advantage of our company-sponsored continuing education program so they can get their degree or that next certification they need to propel them to the next level. Work/Life Balance A healthy work/life balance is essential for building and executing your work effectively at ProSync, but it's also necessary to allow you the room to pursue everything else you want to develop in your personal life. We offer generous Paid Time Off and 11 paid holidays a year. ProSync also provides flexible work options that work with your schedule and lifestyle.
09/07/2026
Full time
Job Description Job Description ProSync is seeking passionate Information System Security Specialist III to help provide mid level cybersecurity support for Navy information systems, networks, and mission environments. This role assists in implementing, maintaining, and monitoring security controls in accordance with DoD and federal cybersecurity policies. ProSync Technology Group, LLC (ProSync) is an award-winning, SDVOSB Defense Contracting company with a strong military heritage and a record of excellence in supporting the Department of Defense and the Intelligence Community. If you have prior military service or government contracting experience, are proud to serve and support our nation, and want to help support ProSync's mission to "Define and Redefine the State of Possible," please apply today! RESPONSIBILITIES The Information System Security Specialist is responsible for supporting all aspects of a Program Information Assurance (IA) processes tailored to include minimum qualification standards, fundamental awareness and familiarity to demonstrated competency with specific experience in Cyber Security, Engineering, Test & Evaluation, (T&E) and/or Security Control Assessor (SCA) under a Certification & Accreditation (C&A) and/or Assessment & Authorization (A&A) process. The specialist should demonstrate a working knowledge of the Risk Management Framework (RMF) process and/or include prior experience with the Defense Information Assurance & Certification Accreditation Process (DIACAP). Familiarity with security policies & guidance documents to assist with the preparation and maintenance of process artifacts, traceability documents purposed for compliance with Authority to Operate (ATO) requirements. The specialist is expected to evaluate security solutions to ensure they meet security requirements for processing up to classified information, and supervise and/or maintain the operational security posture for an information system or program. Support the development, documentation, and maintenance of system security plans, procedures, and authorization artifacts. Assist in implementing security controls and ensuring compliance with applicable cybersecurity frameworks (e.g., RMF, NIST, DoD directives). Conduct routine security assessments, vulnerability scans, and configuration checks to identify and report security risks. Support incident response activities, including evidence collection, initial triage, and coordination with senior cybersecurity personnel. Maintain awareness of system configurations, user access requirements, and security posture changes. Assist in preparing documentation for system authorization, continuous monitoring, and audit readiness. Provide user support on security procedures, access requirements, and proper handling of sensitive information. Requirements A minimum of 5 years of practical experience in a Cybersecurity, Engineering, T&E or A&A (formerly C&A) related field. Must have experience working with Information Assurance tools such as DISA Enterprise Mission Assurance Support Service (eMASS), Assured Compliance Assessment Solution (ACAS) A minimum Top Secret security clearance or higher with the ability to obtain a Top Secret w/ SCI is required to be considered for this position. EDUCATIONAL REQUIREMENTS A college degree in a technical or managerial related discipline is preferred. Note: a high school diploma or high school equivalency certificate is acceptable with 2 additional years of practical experience. CERTIFICATION REQUIREMENTS May be required to hold an Interim Security Control Assessor qualification. Benefits Join PROSYNC and enjoy our great benefits! Compensation We offer sign on bonuses! We also offer bonuses that are awarded quarterly to our employees and our compensation rates are highly competitive. Health & Retirement We offer a comprehensive Health Benefits package and 401K retirement plan so you can take care of yourself and your family, now and in the future. Other health-related benefits include an employee assistance program for those difficult times or when you need to take care of your mental health. Education Individual growth is a priority at ProSync. Employees are encouraged to take advantage of our company-sponsored continuing education program so they can get their degree or that next certification they need to propel them to the next level. Work/Life Balance A healthy work/life balance is essential for building and executing your work effectively at ProSync, but it's also necessary to allow you the room to pursue everything else you want to develop in your personal life. We offer generous Paid Time Off and 11 paid holidays a year. ProSync also provides flexible work options that work with your schedule and lifestyle.
Information System Security Specialist II
Prosync Crane, Indiana
Job Description Job Description ProSync is seeking passionate Information System Security Specialist II to help provide mid level cybersecurity support for Navy information systems, networks, and mission environments. This role assists in implementing, maintaining, and monitoring security controls in accordance with DoD and federal cybersecurity policies. ProSync Technology Group, LLC (ProSync) is an award-winning, SDVOSB Defense Contracting company with a strong military heritage and a record of excellence in supporting the Department of Defense and the Intelligence Community. If you have prior military service or government contracting experience, are proud to serve and support our nation, and want to help support ProSync's mission to "Define and Redefine the State of Possible," please apply today! RESPONSIBILITIES The Information System Security Specialist is responsible for supporting all aspects of a Program Information Assurance (IA) processes tailored to include minimum qualification standards, fundamental awareness and familiarity to demonstrated competency with specific experience in Cyber Security, Engineering, Test & Evaluation, (T&E) and/or Security Control Assessor (SCA) under a Certification & Accreditation (C&A) and/or Assessment & Authorization (A&A) process. The specialist should demonstrate a working knowledge of the Risk Management Framework (RMF) process and/or include prior experience with the Defense Information Assurance & Certification Accreditation Process (DIACAP). Familiarity with security policies & guidance documents to assist with the preparation and maintenance of process artifacts, traceability documents purposed for compliance with Authority to Operate (ATO) requirements. The specialist is expected to evaluate security solutions to ensure they meet security requirements for processing up to classified information, and supervise and/or maintain the operational security posture for an information system or program. Support the development, documentation, and maintenance of system security plans, procedures, and authorization artifacts. Assist in implementing security controls and ensuring compliance with applicable cybersecurity frameworks (e.g., RMF, NIST, DoD directives). Conduct routine security assessments, vulnerability scans, and configuration checks to identify and report security risks. Support incident response activities, including evidence collection, initial triage, and coordination with senior cybersecurity personnel. Maintain awareness of system configurations, user access requirements, and security posture changes. Assist in preparing documentation for system authorization, continuous monitoring, and audit readiness. Provide user support on security procedures, access requirements, and proper handling of sensitive information. Requirements A minimum of 2 years of practical experience in a Cybersecurity, Engineering, T&E or A&A (formerly C&A) related field. Must have experience working with Information Assurance tools such as DISA Enterprise Mission Assurance Support Service (eMASS), Assured Compliance Assessment Solution (ACAS) A minimum Top Secret security clearance or higher with the ability to obtain a Top Secret w/ SCI is required to be considered for this position. EDUCATIONAL REQUIREMENTS A High school diploma or HS equivalency certificate is acceptable. CERTIFICATION REQUIREMENTS May be required to hold an Interim Security Control Assessor qualification. Benefits Join PROSYNC and enjoy our great benefits! Compensation We offer sign on bonuses! We also offer bonuses that are awarded quarterly to our employees and our compensation rates are highly competitive. Health & Retirement We offer a comprehensive Health Benefits package and 401K retirement plan so you can take care of yourself and your family, now and in the future. Other health-related benefits include an employee assistance program for those difficult times or when you need to take care of your mental health. Education Individual growth is a priority at ProSync. Employees are encouraged to take advantage of our company-sponsored continuing education program so they can get their degree or that next certification they need to propel them to the next level. Work/Life Balance A healthy work/life balance is essential for building and executing your work effectively at ProSync, but it's also necessary to allow you the room to pursue everything else you want to develop in your personal life. We offer generous Paid Time Off and 11 paid holidays a year. ProSync also provides flexible work options that work with your schedule and lifestyle.
09/07/2026
Full time
Job Description Job Description ProSync is seeking passionate Information System Security Specialist II to help provide mid level cybersecurity support for Navy information systems, networks, and mission environments. This role assists in implementing, maintaining, and monitoring security controls in accordance with DoD and federal cybersecurity policies. ProSync Technology Group, LLC (ProSync) is an award-winning, SDVOSB Defense Contracting company with a strong military heritage and a record of excellence in supporting the Department of Defense and the Intelligence Community. If you have prior military service or government contracting experience, are proud to serve and support our nation, and want to help support ProSync's mission to "Define and Redefine the State of Possible," please apply today! RESPONSIBILITIES The Information System Security Specialist is responsible for supporting all aspects of a Program Information Assurance (IA) processes tailored to include minimum qualification standards, fundamental awareness and familiarity to demonstrated competency with specific experience in Cyber Security, Engineering, Test & Evaluation, (T&E) and/or Security Control Assessor (SCA) under a Certification & Accreditation (C&A) and/or Assessment & Authorization (A&A) process. The specialist should demonstrate a working knowledge of the Risk Management Framework (RMF) process and/or include prior experience with the Defense Information Assurance & Certification Accreditation Process (DIACAP). Familiarity with security policies & guidance documents to assist with the preparation and maintenance of process artifacts, traceability documents purposed for compliance with Authority to Operate (ATO) requirements. The specialist is expected to evaluate security solutions to ensure they meet security requirements for processing up to classified information, and supervise and/or maintain the operational security posture for an information system or program. Support the development, documentation, and maintenance of system security plans, procedures, and authorization artifacts. Assist in implementing security controls and ensuring compliance with applicable cybersecurity frameworks (e.g., RMF, NIST, DoD directives). Conduct routine security assessments, vulnerability scans, and configuration checks to identify and report security risks. Support incident response activities, including evidence collection, initial triage, and coordination with senior cybersecurity personnel. Maintain awareness of system configurations, user access requirements, and security posture changes. Assist in preparing documentation for system authorization, continuous monitoring, and audit readiness. Provide user support on security procedures, access requirements, and proper handling of sensitive information. Requirements A minimum of 2 years of practical experience in a Cybersecurity, Engineering, T&E or A&A (formerly C&A) related field. Must have experience working with Information Assurance tools such as DISA Enterprise Mission Assurance Support Service (eMASS), Assured Compliance Assessment Solution (ACAS) A minimum Top Secret security clearance or higher with the ability to obtain a Top Secret w/ SCI is required to be considered for this position. EDUCATIONAL REQUIREMENTS A High school diploma or HS equivalency certificate is acceptable. CERTIFICATION REQUIREMENTS May be required to hold an Interim Security Control Assessor qualification. Benefits Join PROSYNC and enjoy our great benefits! Compensation We offer sign on bonuses! We also offer bonuses that are awarded quarterly to our employees and our compensation rates are highly competitive. Health & Retirement We offer a comprehensive Health Benefits package and 401K retirement plan so you can take care of yourself and your family, now and in the future. Other health-related benefits include an employee assistance program for those difficult times or when you need to take care of your mental health. Education Individual growth is a priority at ProSync. Employees are encouraged to take advantage of our company-sponsored continuing education program so they can get their degree or that next certification they need to propel them to the next level. Work/Life Balance A healthy work/life balance is essential for building and executing your work effectively at ProSync, but it's also necessary to allow you the room to pursue everything else you want to develop in your personal life. We offer generous Paid Time Off and 11 paid holidays a year. ProSync also provides flexible work options that work with your schedule and lifestyle.

Modal Window

  • Home
  • Contact
  • About Us
  • FAQs
  • Terms & Conditions
  • Privacy
  • Employer
  • Post a Job
  • Search Resumes
  • Sign in
  • Job Seeker
  • Find Jobs
  • Create Resume
  • Sign in
  • IT blog
  • Facebook
  • Twitter
  • LinkedIn
  • Youtube
© 2008-2026 IT Job Board