Job Description Job Description Overview Senior Cybersecurity Engineer (SCAR) Location : El Segundo, CA Job Status: Full time SALARY RANGE: Estimated $160,000 + annually depending on experience, certifications, and qualifications Clearance Required: Active DoD TS/SCI Astrion is seeking a Senior Cybersecurity Engineer SME to join our prime contract supporting STS-3 in El Segundo, CA. This role will provide direct Assessment & Authorization (A&A) support to the Space Systems Command Authorizing Officia and Security Conrol Assessor (SCA), ensuring the secure operations of enterprise networks, mission-critical systems, and sensitive data across Space Systems Command (RDT&E) Authorizing Official (AO) subordinate enclave. You will play a hands-on role in Cybersecurity Analysis, Engineering, and Risk Management Framework (RMF) compliance, and Enterprise policy driving mission assurance for some of the nation's most important space systems. REQUIRED QUALIFICATIONS / SKILLS 15+ years of cybersecurity experience supporting USSF, DoD, or related federal organizations. Familiarity with Risk Management Framework (RMF) protocols. Knowledge of USSF A&A procedures with hands-on experience with eMASS Active DoD TS/SCI clearance (with current investigation). CompTIA Security+ or equivalent DoD 8570/8140 IAT/IAM certification. PREFERRED QUALIFICATIONS / SKILLS Prior SCA / SCAR / ASCA experience within DoW and USSF. CISSP, GIAC, or equivalent advanced cybersecurity certification. Strong organizational, interpersonal, and communication skills with attention to detail. Technical MA or MS degree Advanced skills in Microsoft Word, Excel, PowerPoint, and Outlook. RESPONSIBILITIES Support the Authorizing Official and Security Control Assessor by ensuring adherence to the DoD RMF process, driving cyber hardening efforts, and tracking progress along the Road to ATO. Support A&A activities and provide cybersecurity engineering expertise for enterprise mission systems. Develop, update, and manage Enterprise Mission Assurance Support Service (eMASS) entries and coordinate A&A packages in accordance with DoDI 8510.01 (RMF). Maintain and report on C&A schedules, package status, and system registrations in ITIPS (formerly EITDR) in compliance with FISMA. Review and refine certification policies, procedures, and reports for new and evolving cyber system requirements. Conduct research and analysis to assess the impact of new DoD, USSF, DIA, and DISA cybersecurity directives. Support Vulnerability Management System (VMS) processes by documenting, tracking, and closing compliance findings. Contribute to Security Test & Evaluation (ST&E) efforts, penetration testing, and validation of cybersecurity controls. Revalidate cyber and IA controls for accredited systems and recommend improvements to strengthen mission assurance. Assess policy changes from higher headquarters and determine impact on current mission system security posture. Travel is required during onsite assessments.
09/20/2026
Full time
Job Description Job Description Overview Senior Cybersecurity Engineer (SCAR) Location : El Segundo, CA Job Status: Full time SALARY RANGE: Estimated $160,000 + annually depending on experience, certifications, and qualifications Clearance Required: Active DoD TS/SCI Astrion is seeking a Senior Cybersecurity Engineer SME to join our prime contract supporting STS-3 in El Segundo, CA. This role will provide direct Assessment & Authorization (A&A) support to the Space Systems Command Authorizing Officia and Security Conrol Assessor (SCA), ensuring the secure operations of enterprise networks, mission-critical systems, and sensitive data across Space Systems Command (RDT&E) Authorizing Official (AO) subordinate enclave. You will play a hands-on role in Cybersecurity Analysis, Engineering, and Risk Management Framework (RMF) compliance, and Enterprise policy driving mission assurance for some of the nation's most important space systems. REQUIRED QUALIFICATIONS / SKILLS 15+ years of cybersecurity experience supporting USSF, DoD, or related federal organizations. Familiarity with Risk Management Framework (RMF) protocols. Knowledge of USSF A&A procedures with hands-on experience with eMASS Active DoD TS/SCI clearance (with current investigation). CompTIA Security+ or equivalent DoD 8570/8140 IAT/IAM certification. PREFERRED QUALIFICATIONS / SKILLS Prior SCA / SCAR / ASCA experience within DoW and USSF. CISSP, GIAC, or equivalent advanced cybersecurity certification. Strong organizational, interpersonal, and communication skills with attention to detail. Technical MA or MS degree Advanced skills in Microsoft Word, Excel, PowerPoint, and Outlook. RESPONSIBILITIES Support the Authorizing Official and Security Control Assessor by ensuring adherence to the DoD RMF process, driving cyber hardening efforts, and tracking progress along the Road to ATO. Support A&A activities and provide cybersecurity engineering expertise for enterprise mission systems. Develop, update, and manage Enterprise Mission Assurance Support Service (eMASS) entries and coordinate A&A packages in accordance with DoDI 8510.01 (RMF). Maintain and report on C&A schedules, package status, and system registrations in ITIPS (formerly EITDR) in compliance with FISMA. Review and refine certification policies, procedures, and reports for new and evolving cyber system requirements. Conduct research and analysis to assess the impact of new DoD, USSF, DIA, and DISA cybersecurity directives. Support Vulnerability Management System (VMS) processes by documenting, tracking, and closing compliance findings. Contribute to Security Test & Evaluation (ST&E) efforts, penetration testing, and validation of cybersecurity controls. Revalidate cyber and IA controls for accredited systems and recommend improvements to strengthen mission assurance. Assess policy changes from higher headquarters and determine impact on current mission system security posture. Travel is required during onsite assessments.
Job Description Job Description Security Control Accessor II REQ-26-J-0055 The SCA is responsible for conducting a comprehensive assessment of the management, operational, and technical security controls employed within or inherited by an IS to determine the overall effectiveness of the controls (i.e., the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for the system). SCAs also provide an assessment of the severity of weaknesses or deficiencies discovered in the IS and its environment of operation and recommend corrective actions to address identified vulnerabilities. Responsibilities will cover Collateral, Sensitive Compartmented Information (SCI) and Special Access Program (SAP) activities within the customer's area of responsibility. Performance shall include: Perform oversight of the development, implementation and evaluation of IS security program policy; special emphasis placed upon integration of existing SAP network infrastructure. Perform assessment of ISs, based upon the Risk Management Framework (RMF) methodology in accordance with the Joint Special Access Program (SAP) Implementation Guide (JSIG). Advise the Information System Owner (ISO), Information Data Owner (IDO), Program Security. Officer (PSO), and the Delegated and/or Authorizing Official (DAO/AO) on any assessment and authorization issues. Evaluate Authorization packages and make recommendation to the AO and/or DAO for authorization. Evaluate IS threats and vulnerabilities to determine whether additional safeguards are required. Advise the Government concerning the impact levels for Confidentiality, Integrity, and Availability for the information on a system. Ensure security assessments are completed and results documented and prepare the Security Assessment Report (SAR) for the Authorization boundary. Initiate a Plan of Action and Milestones (POA&M) with identified weaknesses for each Authorization Boundaries assessed, based on findings and recommendations from the SAR. Evaluate security assessment documentation and provide written recommendations for security authorization to the Government. Discuss recommendation for authorization and submit the security authorization package to the AO/DAO Assess proposed changes to Authorization boundaries operating environment and mission needs to determine the continuation to operate. Review and concur with all sanitizations and clearing procedures in accordance with Government guidance and/or policy. Assist the Government compliance inspections. Assist the Government with security incidents that relate to cybersecurity and ensure that the proper and corrective measures have been taken. Ensure organization are addressing and conducting all phases of the system development life cycle (SDLC). Evaluate Hardware and Software to determine security impact that it might have on Authorization boundaries. Evaluate the effectiveness and implementation of Continuous Monitoring Plans. Represent the customer on inspection teams. EDUCATION: Bachelor's degree or equivalent experience (4 years) CLEARANCE: Top-Secret w/SCI Eligibility MANDATORY: 7-9 years related experience; 4+ years' experience in SAP, SCI, or Collateral Information Systems (S) security and implantation of regulations identified in the description of duties; Prior performance in the role of ISSO and ISSM or SCA; TRAINING: IAM Level II (in lieu of IAT Level III) BENEFITS: We offer a competitive compensation package including a generous PTO and Flexible holiday package, tax-free healthcare cost reimbursement, and an immediate vesting 401K with 4% matching.
09/20/2026
Full time
Job Description Job Description Security Control Accessor II REQ-26-J-0055 The SCA is responsible for conducting a comprehensive assessment of the management, operational, and technical security controls employed within or inherited by an IS to determine the overall effectiveness of the controls (i.e., the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for the system). SCAs also provide an assessment of the severity of weaknesses or deficiencies discovered in the IS and its environment of operation and recommend corrective actions to address identified vulnerabilities. Responsibilities will cover Collateral, Sensitive Compartmented Information (SCI) and Special Access Program (SAP) activities within the customer's area of responsibility. Performance shall include: Perform oversight of the development, implementation and evaluation of IS security program policy; special emphasis placed upon integration of existing SAP network infrastructure. Perform assessment of ISs, based upon the Risk Management Framework (RMF) methodology in accordance with the Joint Special Access Program (SAP) Implementation Guide (JSIG). Advise the Information System Owner (ISO), Information Data Owner (IDO), Program Security. Officer (PSO), and the Delegated and/or Authorizing Official (DAO/AO) on any assessment and authorization issues. Evaluate Authorization packages and make recommendation to the AO and/or DAO for authorization. Evaluate IS threats and vulnerabilities to determine whether additional safeguards are required. Advise the Government concerning the impact levels for Confidentiality, Integrity, and Availability for the information on a system. Ensure security assessments are completed and results documented and prepare the Security Assessment Report (SAR) for the Authorization boundary. Initiate a Plan of Action and Milestones (POA&M) with identified weaknesses for each Authorization Boundaries assessed, based on findings and recommendations from the SAR. Evaluate security assessment documentation and provide written recommendations for security authorization to the Government. Discuss recommendation for authorization and submit the security authorization package to the AO/DAO Assess proposed changes to Authorization boundaries operating environment and mission needs to determine the continuation to operate. Review and concur with all sanitizations and clearing procedures in accordance with Government guidance and/or policy. Assist the Government compliance inspections. Assist the Government with security incidents that relate to cybersecurity and ensure that the proper and corrective measures have been taken. Ensure organization are addressing and conducting all phases of the system development life cycle (SDLC). Evaluate Hardware and Software to determine security impact that it might have on Authorization boundaries. Evaluate the effectiveness and implementation of Continuous Monitoring Plans. Represent the customer on inspection teams. EDUCATION: Bachelor's degree or equivalent experience (4 years) CLEARANCE: Top-Secret w/SCI Eligibility MANDATORY: 7-9 years related experience; 4+ years' experience in SAP, SCI, or Collateral Information Systems (S) security and implantation of regulations identified in the description of duties; Prior performance in the role of ISSO and ISSM or SCA; TRAINING: IAM Level II (in lieu of IAT Level III) BENEFITS: We offer a competitive compensation package including a generous PTO and Flexible holiday package, tax-free healthcare cost reimbursement, and an immediate vesting 401K with 4% matching.
Job Description Job Description Pivot Point Solutions Pivot Point Solutions is a California-based technology consulting firm that specializes in delivering IT solutions and support for the construction and utility industries. We partner with organizations across the state to provide reliable technology services that improve operational efficiency, enhance project delivery, and support critical business systems. Our team understands the unique technology challenges facing construction and utility organizations, from field operations and infrastructure projects to enterprise applications and cybersecurity. By combining industry expertise with responsive service, we help clients modernize their technology environments, streamline workflows, and maintain secure, reliable IT systems that support long-term growth. Job Overview Title: Cyber Security Controls Assessor Sector: Information Technology / Cybersecurity Seniority: Mid to Senior Level Location: California (Hybrid) Job Type: Contract Contract Length: 6+ Months Compensation: $104K - $145K About the Role PPS is seeking a Cyber Security Controls Assessor to support the protection of critical energy infrastructure through the assessment and validation of cybersecurity controls across enterprise and operational technology (OT) environments. This role evaluates compliance with cybersecurity policies, regulatory requirements, and industry standards to ensure the confidentiality, integrity, and availability of systems supporting electric and gas utility operations. The ideal candidate brings strong experience in security assessments, risk management, compliance, and control validation, with a focus on protecting critical infrastructure and supporting regulatory obligations. Key Responsibilities Conduct cybersecurity control assessments for enterprise IT, cloud, and OT/industrial control system environments Evaluate security controls against NIST CSF, NIST 800-53, NERC CIP, CIS Controls, and security policies Identify security risks, control deficiencies, and compliance gaps, and recommend corrective actions Prepare assessment reports detailing findings, risk ratings, remediation recommendations, and control effectiveness Partner with cybersecurity, engineering, IT, OT, compliance, and business stakeholders on risk identification and management Validate implementation and effectiveness of security controls for new projects, system upgrades, and technology deployments Support internal audits, regulatory reviews, and compliance initiatives related to critical infrastructure protection Track remediation activities and validate closure of cybersecurity findings Maintain assessment methodologies, standards, and procedures supporting cybersecurity programs Mentor junior assessors and contribute to continuous improvement initiatives within the Cybersecurity Risk & Compliance team Qualifications Required: Bachelor's degree in Cybersecurity, Information Security, Computer Science, Engineering, IT, or related field; or equivalent experience 5+ years of experience in cybersecurity, risk management, compliance, audit, or security controls assessment Experience performing security assessments and evaluating cybersecurity controls Knowledge of cybersecurity frameworks such as NIST CSF, NIST 800-53, CIS Controls, and risk management methodologies Experience with regulatory compliance programs and audit support Strong analytical, communication, and technical documentation skills Ability to communicate security risks and recommendations to technical and non-technical stakeholders Preferred: Experience within electric utilities, critical infrastructure, energy, or other regulated industries Knowledge of NERC CIP standards and compliance requirements Experience assessing OT, SCADA, ICS, or energy management systems Familiarity with cloud security environments (Azure, AWS) Experience with GRC platforms Professional certifications: CISSP, CISA, CRISC, GICSP, Security+, or equivalent Work Environment Standard office/field environment supporting critical infrastructure operations
09/20/2026
Full time
Job Description Job Description Pivot Point Solutions Pivot Point Solutions is a California-based technology consulting firm that specializes in delivering IT solutions and support for the construction and utility industries. We partner with organizations across the state to provide reliable technology services that improve operational efficiency, enhance project delivery, and support critical business systems. Our team understands the unique technology challenges facing construction and utility organizations, from field operations and infrastructure projects to enterprise applications and cybersecurity. By combining industry expertise with responsive service, we help clients modernize their technology environments, streamline workflows, and maintain secure, reliable IT systems that support long-term growth. Job Overview Title: Cyber Security Controls Assessor Sector: Information Technology / Cybersecurity Seniority: Mid to Senior Level Location: California (Hybrid) Job Type: Contract Contract Length: 6+ Months Compensation: $104K - $145K About the Role PPS is seeking a Cyber Security Controls Assessor to support the protection of critical energy infrastructure through the assessment and validation of cybersecurity controls across enterprise and operational technology (OT) environments. This role evaluates compliance with cybersecurity policies, regulatory requirements, and industry standards to ensure the confidentiality, integrity, and availability of systems supporting electric and gas utility operations. The ideal candidate brings strong experience in security assessments, risk management, compliance, and control validation, with a focus on protecting critical infrastructure and supporting regulatory obligations. Key Responsibilities Conduct cybersecurity control assessments for enterprise IT, cloud, and OT/industrial control system environments Evaluate security controls against NIST CSF, NIST 800-53, NERC CIP, CIS Controls, and security policies Identify security risks, control deficiencies, and compliance gaps, and recommend corrective actions Prepare assessment reports detailing findings, risk ratings, remediation recommendations, and control effectiveness Partner with cybersecurity, engineering, IT, OT, compliance, and business stakeholders on risk identification and management Validate implementation and effectiveness of security controls for new projects, system upgrades, and technology deployments Support internal audits, regulatory reviews, and compliance initiatives related to critical infrastructure protection Track remediation activities and validate closure of cybersecurity findings Maintain assessment methodologies, standards, and procedures supporting cybersecurity programs Mentor junior assessors and contribute to continuous improvement initiatives within the Cybersecurity Risk & Compliance team Qualifications Required: Bachelor's degree in Cybersecurity, Information Security, Computer Science, Engineering, IT, or related field; or equivalent experience 5+ years of experience in cybersecurity, risk management, compliance, audit, or security controls assessment Experience performing security assessments and evaluating cybersecurity controls Knowledge of cybersecurity frameworks such as NIST CSF, NIST 800-53, CIS Controls, and risk management methodologies Experience with regulatory compliance programs and audit support Strong analytical, communication, and technical documentation skills Ability to communicate security risks and recommendations to technical and non-technical stakeholders Preferred: Experience within electric utilities, critical infrastructure, energy, or other regulated industries Knowledge of NERC CIP standards and compliance requirements Experience assessing OT, SCADA, ICS, or energy management systems Familiarity with cloud security environments (Azure, AWS) Experience with GRC platforms Professional certifications: CISSP, CISA, CRISC, GICSP, Security+, or equivalent Work Environment Standard office/field environment supporting critical infrastructure operations
Job Description Job Description Type: Full Time Location: Philadelphia, PA Overtime Exempt: Exempt Reports To: ARMADA HQ Travel Required: Yes Security Clearance Required: Active Secret Security Clearance CONTINGENT UPON AWARD Duties & Responsibilities: Specialist, Information System Security III (SISS3) will conduct risk and vulnerability assessments of planned and installed systems to identify vulnerabilities, risks and protection needs; conduct systems security evaluation, audits, and reviews; determine the residual risk of a package based on package content and assessment results and documenting for the Security Controls Assessor's (SCA) and higher level review. Execute Security Assessment Plans (SAPs) by conducting on-site testing for afloat and PIT ashore systems. Examples include executing STIGs, SRGs, ACAS scanning, and applying patches assets to obtain cybersecurity compliance and remediate vulnerabilities. Specialist, Information System Security III (SISS3) will conduct systems security reviews, audits, or evaluations, as appropriate, to ensure accreditation documents are accurate and represent the current risk posture of the system. Perform analysis of logs, events, and reporting of various data collections tools including: vulnerability monitoring via Assured Compliance Assessment System (ACAS) and related tools, Host Based Security Systems (HBSS), web content filters, Security Information and event management (SIEM), firewall systems, network devices, server devices, workstations, and intrusion detection and prevention systems (ID/PS). Specialist, Information System Security III (SISS3) will assess impacts from observed risks and report via the Cybersecurity Program chain of command. Executing Security Assessment Plans (SAPs) by conducting on-site testing for afloat and PIT ashore systems. Examples include executing STIGs, SRGs, ACAS scanning, and applying patches assets to obtain cybersecurity compliance and remediate vulnerabilities. Perform the evaluation of system administrator, security engineer, and/or system owner proposed corrections to ensure compliance and best-fit solution. Specialist, Information System Security III (SISS3) will present and submit data to management, develop reports, and produce procedural documentation in a comprehensive and cohesive manner. Perform risk management and security engineering for Research, Development, Testing, and Evaluation (RDT&E) RMF Afloat systems include Information Assurance Vulnerability Management (IAVM) support, remediation, patching, scanning and associated boundary maintenance. Specialist, Information System Security III (SISS3) will document residual risks in a plan of actions and milestones formatted in compliance with the current package system, currently eMASS. Specialist, Information System Security III (SISS3) will maintain current vulnerability scan data and residual risk plan of actions and milestones in Vulnerability Remediation Asset Manager (VRAM). Manage, attend, and support configuration control board practices. Create and verify the accuracy of POA&Ms/RARs as identified by vulnerability actual test results. Specialist, Information System Security III (SISS3) shall write technical documentation such as user manuals, reports, documentation, policies, presentations, Plan of Action and Milestones (POA&Ms), risk assessments, proposals, outlines, and summaries in support of both ashore and afloat systems across multiple platforms. Support developing of technical documents across multiple platforms including configuration management, milestone, issue tracking, web site content management and RMF documentation. Specialist, Information System Security III (SISS3) may be required to travel CONUS (any state in USA) and OCONUS (primarily Japan, and any country in Europe). The estimated number of trips is 14 per year (estimated 25%-30% travel). Other duties as assigned. Knowledge, Skills, and Abilities (KSAs): Ability to travel CONUS (any state in USA) and OCONUS (primarily Japan, and any country in Europe). Proficient in Microsoft Windows Operating System Administration, including Windows 11, Windows 10, Windows 7, and Windows XP (at a minimum). Ability to work as a team member, communicate, perform office functions and use office tools, customer focused and deliver exceptional performance. Possess excellent organizational and file management skills and the ability to plan and execute administrative work with little supervision. Possess excellent oral and written communication skills. Required Certifications: Minimum of one (1) IAT Level II listed certificate required: CompTIA Security+ (CE) CompTIA CySA+ GIAC Security Essentials (GSEC) ISC SSCP (Systems Security Certified Practitioner) Minimum/General Experience: Five (5) years of experience in the following: Cybersecurity, Engineering, Test and Evaluation (T&E) or Authorization and Assessment (A&A) (formerly C&A) related field. Information Assurance tools such as Defense Information Systems Agency (DISA) Enterprise Mission Assurance Support Service (eMASS), Assured Compliance Assessment Solution (ACAS). Command line interface, PowerShell, and performing automated tasking through use of code. Minimum Education: College degree in any technical discipline from an accredited college or university. Disclaimer: The above information has been designed to indicate the general nature and level of work to be performed. It is not designed to contain or be interpreted as a comprehensive inventory of all duties, responsibilities, and qualifications required of the contractor assigned to this position. Applying: If you feel you have the knowledge, skills and abilities for this position visit our careers page at . Special Notes: Relocation is not available for these jobs ARMADA provides equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion, gender, sexual orientation, gender identity or expression, national origin, age, disability, genetic information, marital status, amnesty, or status as a covered veteran in accordance with applicable federal, state and local laws. ARMADA complies with applicable state and local laws governing non-discrimination in employment in every location in which the company has facilities. This policy applies to all terms and conditions of employment, including, but not limited to, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation, and training. Must be able to successfully pass a background check, and pre-employment drug testing. Job offers are contingent upon results of background check and drug testing.
09/20/2026
Full time
Job Description Job Description Type: Full Time Location: Philadelphia, PA Overtime Exempt: Exempt Reports To: ARMADA HQ Travel Required: Yes Security Clearance Required: Active Secret Security Clearance CONTINGENT UPON AWARD Duties & Responsibilities: Specialist, Information System Security III (SISS3) will conduct risk and vulnerability assessments of planned and installed systems to identify vulnerabilities, risks and protection needs; conduct systems security evaluation, audits, and reviews; determine the residual risk of a package based on package content and assessment results and documenting for the Security Controls Assessor's (SCA) and higher level review. Execute Security Assessment Plans (SAPs) by conducting on-site testing for afloat and PIT ashore systems. Examples include executing STIGs, SRGs, ACAS scanning, and applying patches assets to obtain cybersecurity compliance and remediate vulnerabilities. Specialist, Information System Security III (SISS3) will conduct systems security reviews, audits, or evaluations, as appropriate, to ensure accreditation documents are accurate and represent the current risk posture of the system. Perform analysis of logs, events, and reporting of various data collections tools including: vulnerability monitoring via Assured Compliance Assessment System (ACAS) and related tools, Host Based Security Systems (HBSS), web content filters, Security Information and event management (SIEM), firewall systems, network devices, server devices, workstations, and intrusion detection and prevention systems (ID/PS). Specialist, Information System Security III (SISS3) will assess impacts from observed risks and report via the Cybersecurity Program chain of command. Executing Security Assessment Plans (SAPs) by conducting on-site testing for afloat and PIT ashore systems. Examples include executing STIGs, SRGs, ACAS scanning, and applying patches assets to obtain cybersecurity compliance and remediate vulnerabilities. Perform the evaluation of system administrator, security engineer, and/or system owner proposed corrections to ensure compliance and best-fit solution. Specialist, Information System Security III (SISS3) will present and submit data to management, develop reports, and produce procedural documentation in a comprehensive and cohesive manner. Perform risk management and security engineering for Research, Development, Testing, and Evaluation (RDT&E) RMF Afloat systems include Information Assurance Vulnerability Management (IAVM) support, remediation, patching, scanning and associated boundary maintenance. Specialist, Information System Security III (SISS3) will document residual risks in a plan of actions and milestones formatted in compliance with the current package system, currently eMASS. Specialist, Information System Security III (SISS3) will maintain current vulnerability scan data and residual risk plan of actions and milestones in Vulnerability Remediation Asset Manager (VRAM). Manage, attend, and support configuration control board practices. Create and verify the accuracy of POA&Ms/RARs as identified by vulnerability actual test results. Specialist, Information System Security III (SISS3) shall write technical documentation such as user manuals, reports, documentation, policies, presentations, Plan of Action and Milestones (POA&Ms), risk assessments, proposals, outlines, and summaries in support of both ashore and afloat systems across multiple platforms. Support developing of technical documents across multiple platforms including configuration management, milestone, issue tracking, web site content management and RMF documentation. Specialist, Information System Security III (SISS3) may be required to travel CONUS (any state in USA) and OCONUS (primarily Japan, and any country in Europe). The estimated number of trips is 14 per year (estimated 25%-30% travel). Other duties as assigned. Knowledge, Skills, and Abilities (KSAs): Ability to travel CONUS (any state in USA) and OCONUS (primarily Japan, and any country in Europe). Proficient in Microsoft Windows Operating System Administration, including Windows 11, Windows 10, Windows 7, and Windows XP (at a minimum). Ability to work as a team member, communicate, perform office functions and use office tools, customer focused and deliver exceptional performance. Possess excellent organizational and file management skills and the ability to plan and execute administrative work with little supervision. Possess excellent oral and written communication skills. Required Certifications: Minimum of one (1) IAT Level II listed certificate required: CompTIA Security+ (CE) CompTIA CySA+ GIAC Security Essentials (GSEC) ISC SSCP (Systems Security Certified Practitioner) Minimum/General Experience: Five (5) years of experience in the following: Cybersecurity, Engineering, Test and Evaluation (T&E) or Authorization and Assessment (A&A) (formerly C&A) related field. Information Assurance tools such as Defense Information Systems Agency (DISA) Enterprise Mission Assurance Support Service (eMASS), Assured Compliance Assessment Solution (ACAS). Command line interface, PowerShell, and performing automated tasking through use of code. Minimum Education: College degree in any technical discipline from an accredited college or university. Disclaimer: The above information has been designed to indicate the general nature and level of work to be performed. It is not designed to contain or be interpreted as a comprehensive inventory of all duties, responsibilities, and qualifications required of the contractor assigned to this position. Applying: If you feel you have the knowledge, skills and abilities for this position visit our careers page at . Special Notes: Relocation is not available for these jobs ARMADA provides equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion, gender, sexual orientation, gender identity or expression, national origin, age, disability, genetic information, marital status, amnesty, or status as a covered veteran in accordance with applicable federal, state and local laws. ARMADA complies with applicable state and local laws governing non-discrimination in employment in every location in which the company has facilities. This policy applies to all terms and conditions of employment, including, but not limited to, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation, and training. Must be able to successfully pass a background check, and pre-employment drug testing. Job offers are contingent upon results of background check and drug testing.
Job Description Job Description Type: Full Time Location: Philadelphia, PA Overtime Exempt: Exempt Reports To: ARMADA HQ Travel Required: Yes Security Clearance Required: Active Secret Security Clearance CONTINGENT UPON AWARD Duties & Responsibilities: The Navy Validator III will conduct validation activities in accordance with Navy SCA office. Register and be listed on the official list of Navy Qualified Validators; perform and support activities of Validators of Navy (RMF) Risk Management Framework packages. The Navy Validator III will ensure separation of duties between the System ISSM/ISSE and NQV. Prepare the Security Assessment Plan (SAP) with input from the system's ISSE and ISSM. The SAP is to be submitted and approved by the SCA. The Navy Validator III will perform as an independent third party who assesses and validates that the system has or has not implemented the approved security control baseline. On-site validation may be required for conducting required testing. The Validator acts as a trusted agent to the (SCA) Security Control Assessor and SCA Liaison. Utilize the Security Assessment Report (SAR) to document the residual risk of the non-compliant security controls remaining after the risk assessment work is complete; documentation of the residual risk shall be in the Risk Assessment Report (RAR) in accordance (NAVSEAINST 9400.2) instruction. The Navy Validator III will develop the SAR Executive Summary and Functional Security Controls Assessor (FSCA) Appendix and brief the required PM/ISSM. The Navy Validator III will write technical documentation such as user manuals, reports, documentation, policies, presentations, Plan of Action and Milestones (POA&Ms), risk assessments, proposals, outlines, and summaries in support of both ashore and afloat systems across multiple platforms. Support development of technical documents across multiple platforms including configuration management, milestone, issue tracking, web site content management and RMF documentation. The Navy Validator III will may be required to travel CONUS (any state in USA) and OCONUS (primarily Japan, and any country in Europe). The estimated number of trips is 14 per year (estimated 25%-30% travel). Other duties as assigned. Knowledge, Skills, and Abilities (KSAs): Ability to travel CONUS (any state in USA) and OCONUS (primarily Japan, and any country in Europe). Proficient in Microsoft Windows Operating System Administration, including Windows 11, Windows 10, Windows 7, and Windows XP (at a minimum). Ability to work as a team member, communicate, perform office functions and use office tools, customer focused and deliver exceptional performance. Possess excellent organizational and file management skills and the ability to plan and execute administrative work with little supervision. Possess excellent oral and written communication skills. Required Certifications: Must provide evidence of current Navy Qualified Validator (NQV) Level III certification. Minimum of one (1) IAT Level II listed certificate required: CompTIA Security+ (CE) CompTIA CySA+ GIAC Security Essentials (GSEC) ISC SSCP (Systems Security Certified Practitioner) Minimum/General Experience: Five (5) years of professional experience in the management of Information Assurance Technical (IAT), certification agents and system engineers on the compliance requirements to achieve certification and accreditation IAW the DoD RMF program and the Department of Navy (DON) Chief Information Officer (CIO) IA Policy for Platform Information Technology (PIT) Systems. Professional experience in support of the Department of Navy (DON) or Department of Defense (DoD) is preferred. Minimum Education: Bachelor's degree in computer science from an accredited college or university. Disclaimer: The above information has been designed to indicate the general nature and level of work to be performed. It is not designed to contain or be interpreted as a comprehensive inventory of all duties, responsibilities, and qualifications required of the contractor assigned to this position. Applying: If you feel you have the knowledge, skills and abilities for this position visit our careers page at . Special Notes: Relocation is not available for these jobs ARMADA provides equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion, gender, sexual orientation, gender identity or expression, national origin, age, disability, genetic information, marital status, amnesty, or status as a covered veteran in accordance with applicable federal, state and local laws. ARMADA complies with applicable state and local laws governing non-discrimination in employment in every location in which the company has facilities. This policy applies to all terms and conditions of employment, including, but not limited to, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation, and training. Must be able to successfully pass a background check, and pre-employment drug testing. Job offers are contingent upon results of background check and drug testing.
09/20/2026
Full time
Job Description Job Description Type: Full Time Location: Philadelphia, PA Overtime Exempt: Exempt Reports To: ARMADA HQ Travel Required: Yes Security Clearance Required: Active Secret Security Clearance CONTINGENT UPON AWARD Duties & Responsibilities: The Navy Validator III will conduct validation activities in accordance with Navy SCA office. Register and be listed on the official list of Navy Qualified Validators; perform and support activities of Validators of Navy (RMF) Risk Management Framework packages. The Navy Validator III will ensure separation of duties between the System ISSM/ISSE and NQV. Prepare the Security Assessment Plan (SAP) with input from the system's ISSE and ISSM. The SAP is to be submitted and approved by the SCA. The Navy Validator III will perform as an independent third party who assesses and validates that the system has or has not implemented the approved security control baseline. On-site validation may be required for conducting required testing. The Validator acts as a trusted agent to the (SCA) Security Control Assessor and SCA Liaison. Utilize the Security Assessment Report (SAR) to document the residual risk of the non-compliant security controls remaining after the risk assessment work is complete; documentation of the residual risk shall be in the Risk Assessment Report (RAR) in accordance (NAVSEAINST 9400.2) instruction. The Navy Validator III will develop the SAR Executive Summary and Functional Security Controls Assessor (FSCA) Appendix and brief the required PM/ISSM. The Navy Validator III will write technical documentation such as user manuals, reports, documentation, policies, presentations, Plan of Action and Milestones (POA&Ms), risk assessments, proposals, outlines, and summaries in support of both ashore and afloat systems across multiple platforms. Support development of technical documents across multiple platforms including configuration management, milestone, issue tracking, web site content management and RMF documentation. The Navy Validator III will may be required to travel CONUS (any state in USA) and OCONUS (primarily Japan, and any country in Europe). The estimated number of trips is 14 per year (estimated 25%-30% travel). Other duties as assigned. Knowledge, Skills, and Abilities (KSAs): Ability to travel CONUS (any state in USA) and OCONUS (primarily Japan, and any country in Europe). Proficient in Microsoft Windows Operating System Administration, including Windows 11, Windows 10, Windows 7, and Windows XP (at a minimum). Ability to work as a team member, communicate, perform office functions and use office tools, customer focused and deliver exceptional performance. Possess excellent organizational and file management skills and the ability to plan and execute administrative work with little supervision. Possess excellent oral and written communication skills. Required Certifications: Must provide evidence of current Navy Qualified Validator (NQV) Level III certification. Minimum of one (1) IAT Level II listed certificate required: CompTIA Security+ (CE) CompTIA CySA+ GIAC Security Essentials (GSEC) ISC SSCP (Systems Security Certified Practitioner) Minimum/General Experience: Five (5) years of professional experience in the management of Information Assurance Technical (IAT), certification agents and system engineers on the compliance requirements to achieve certification and accreditation IAW the DoD RMF program and the Department of Navy (DON) Chief Information Officer (CIO) IA Policy for Platform Information Technology (PIT) Systems. Professional experience in support of the Department of Navy (DON) or Department of Defense (DoD) is preferred. Minimum Education: Bachelor's degree in computer science from an accredited college or university. Disclaimer: The above information has been designed to indicate the general nature and level of work to be performed. It is not designed to contain or be interpreted as a comprehensive inventory of all duties, responsibilities, and qualifications required of the contractor assigned to this position. Applying: If you feel you have the knowledge, skills and abilities for this position visit our careers page at . Special Notes: Relocation is not available for these jobs ARMADA provides equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion, gender, sexual orientation, gender identity or expression, national origin, age, disability, genetic information, marital status, amnesty, or status as a covered veteran in accordance with applicable federal, state and local laws. ARMADA complies with applicable state and local laws governing non-discrimination in employment in every location in which the company has facilities. This policy applies to all terms and conditions of employment, including, but not limited to, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation, and training. Must be able to successfully pass a background check, and pre-employment drug testing. Job offers are contingent upon results of background check and drug testing.
Job Description Job Description 11-009 - Security Control Assessor (SCA) II Location: Crystal City, VA Salary: $168,932.71 Billet Number: JUSTIFIED-0055 Skill Level: 2 Current Vacancy-Specific Requirements MANDATORY: 7-9 years related experience; 4+ years experience in SAP, SCI, or Collateral Information Systems (S) security and implementation of regulations identified in the description of duties; Prior performance in the role of ISSO and ISSM or SCA; TRAINING: IAM Level II (in lieu of IAT Level III) Position Description The SCA is responsible for conducting a comprehensive assessment of the management, operational, and technical security controls employed within or inherited by an IS to determine the overall effectiveness of the controls (i.e., the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for the system). SCAs also provide an assessment of the severity of weaknesses or deficiencies discovered in the IS and its environment of operation and recommend corrective actions to address identified vulnerabilities. Responsibilities will cover Collateral, Sensitive Compartmented Information (SCI) and Special Access Program (SAP) activities within the customer's area of responsibility. Performance shall include: Perform oversight of the development, implementation and evaluation of IS security program policy; special emphasis placed upon integration of existing SAP network infrastructure Perform assessment of ISs, based upon the Risk Management Framework (RMF) methodology in accordance with the Joint Special Access Program (SAP) Implementation Guide (JSIG) Advise the Information System Owner (ISO), Information Data Owner (IDO), Program Security Officer (PSO), and the Delegated and/or Authorizing Official (DAO/AO) on any assessment and authorization issues Evaluate Authorization packages and make recommendation to the AO and/or DAO for authorization Evaluate IS threats and vulnerabilities to determine whether additional safeguards are required Advise the Government concerning the impact levels for Confidentiality, Integrity, and Availability for the information on a system Ensure security assessments are completed and results documented and prepare the Security Assessment Report (SAR) for the Authorization boundary Initiate a Plan of Action and Milestones (POA&M) with identified weaknesses for each Authorization Boundaries assessed, based on findings and recommendations from the SAR Evaluate security assessment documentation and provide written recommendations for security authorization to the Government Discuss recommendation for authorization and submit the security authorization package to the AO/DAO Assess proposed changes to Authorization boundaries operating environment and mission needs to determine the continuation to operate. Review and concur with all sanitization and clearing procedures in accordance with Government guidance and/or policy Assist the Government compliance inspections Assist the Government with security incidents that relate to cybersecurity and ensure that the proper and corrective measures have been taken Ensure organization are addressing and conducting all phases of the system development life cycle (SDLC) Evaluate Hardware and Software to determine security impact that it might have on Authorization boundaries Evaluate the effectiveness and implementation of Continuous Monitoring Plans Represent the customer on inspection teams Experience: 7 - 9 years related experience Minimum of four (4) years' experience in SAP, SCI or Collateral Information Systems (IS) Security and the implementation of regulations identified in the description of duties. Prior performance in the role of ISSO and ISSM or SCA Education: Bachelor's degree in a related discipline or equivalent experience (4 years) Certifications: Must meet position and certification requirements outlined in DoD Directive 8570.01-M for Information Assurance Technician Level III or Information Assurance Manager Level II within 6 months of the date of hire Security Clearance: Current clearance as defined in the Task Order Eligibility for access to Special Access Program Information Willingness to submit to a Counterintelligence polygraph Other Requirements: Must be able to regularly lift 50lbs Top Secret/Special Compartmented Information (TS/SCI) Individuals must possess current Top Secret/Special Compartmented Information (TS/SCI) eligibility with an in scope BI, or enrollment into Continuous Evaluation, or an in scope open PR. Depending on the position, additional security screening may also be required (e.g., polygraph examination, etc.).
09/20/2026
Full time
Job Description Job Description 11-009 - Security Control Assessor (SCA) II Location: Crystal City, VA Salary: $168,932.71 Billet Number: JUSTIFIED-0055 Skill Level: 2 Current Vacancy-Specific Requirements MANDATORY: 7-9 years related experience; 4+ years experience in SAP, SCI, or Collateral Information Systems (S) security and implementation of regulations identified in the description of duties; Prior performance in the role of ISSO and ISSM or SCA; TRAINING: IAM Level II (in lieu of IAT Level III) Position Description The SCA is responsible for conducting a comprehensive assessment of the management, operational, and technical security controls employed within or inherited by an IS to determine the overall effectiveness of the controls (i.e., the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for the system). SCAs also provide an assessment of the severity of weaknesses or deficiencies discovered in the IS and its environment of operation and recommend corrective actions to address identified vulnerabilities. Responsibilities will cover Collateral, Sensitive Compartmented Information (SCI) and Special Access Program (SAP) activities within the customer's area of responsibility. Performance shall include: Perform oversight of the development, implementation and evaluation of IS security program policy; special emphasis placed upon integration of existing SAP network infrastructure Perform assessment of ISs, based upon the Risk Management Framework (RMF) methodology in accordance with the Joint Special Access Program (SAP) Implementation Guide (JSIG) Advise the Information System Owner (ISO), Information Data Owner (IDO), Program Security Officer (PSO), and the Delegated and/or Authorizing Official (DAO/AO) on any assessment and authorization issues Evaluate Authorization packages and make recommendation to the AO and/or DAO for authorization Evaluate IS threats and vulnerabilities to determine whether additional safeguards are required Advise the Government concerning the impact levels for Confidentiality, Integrity, and Availability for the information on a system Ensure security assessments are completed and results documented and prepare the Security Assessment Report (SAR) for the Authorization boundary Initiate a Plan of Action and Milestones (POA&M) with identified weaknesses for each Authorization Boundaries assessed, based on findings and recommendations from the SAR Evaluate security assessment documentation and provide written recommendations for security authorization to the Government Discuss recommendation for authorization and submit the security authorization package to the AO/DAO Assess proposed changes to Authorization boundaries operating environment and mission needs to determine the continuation to operate. Review and concur with all sanitization and clearing procedures in accordance with Government guidance and/or policy Assist the Government compliance inspections Assist the Government with security incidents that relate to cybersecurity and ensure that the proper and corrective measures have been taken Ensure organization are addressing and conducting all phases of the system development life cycle (SDLC) Evaluate Hardware and Software to determine security impact that it might have on Authorization boundaries Evaluate the effectiveness and implementation of Continuous Monitoring Plans Represent the customer on inspection teams Experience: 7 - 9 years related experience Minimum of four (4) years' experience in SAP, SCI or Collateral Information Systems (IS) Security and the implementation of regulations identified in the description of duties. Prior performance in the role of ISSO and ISSM or SCA Education: Bachelor's degree in a related discipline or equivalent experience (4 years) Certifications: Must meet position and certification requirements outlined in DoD Directive 8570.01-M for Information Assurance Technician Level III or Information Assurance Manager Level II within 6 months of the date of hire Security Clearance: Current clearance as defined in the Task Order Eligibility for access to Special Access Program Information Willingness to submit to a Counterintelligence polygraph Other Requirements: Must be able to regularly lift 50lbs Top Secret/Special Compartmented Information (TS/SCI) Individuals must possess current Top Secret/Special Compartmented Information (TS/SCI) eligibility with an in scope BI, or enrollment into Continuous Evaluation, or an in scope open PR. Depending on the position, additional security screening may also be required (e.g., polygraph examination, etc.).
Job Description Job Description About Us AGE Solutions is a premier technology and professional services company, providing in-depth consulting, advanced technology solutions, and essential services throughout the U.S. government, defense, and intelligence sectors. Prioritizing innovation and client-focused solutions, we assist major agencies in addressing intricate issues and ensuring a more secure future. AGE Solutions is looking for Senior Security Control Assessors to join our team in support of a cybersecurity risk management and assessment program with our DoD customer. Responsibilities: Conduct cybersecurity assessments, audits, and inspections for DoD organizations and partners handling DoD information or connecting to the DoDIN. Evaluate systems and Defensive Cyberspace Operations using cyber threat emulation and performance-based testing. Adhere to policies and processes for each assessment type. Support assessment development and execution to ensure security expertise is properly applied. Coordinate logistics, test plans, and scope with the SCA Team Lead. Perform vulnerability assessments, capture results using STIG Viewer or designated tools, and document findings in eMASS. Analyze security gaps and provide mitigation recommendations. Validate cybersecurity controls, TTPs, STIGs, RMF controls, and compliance with DoD policies and guidelines. Provide risk analysis and assessment results for authorization recommendations. Participate in daily assessment reviews, in-briefs, and out-briefs, sharing findings with the SCA-R. Mentor and guide personnel by providing technical expertise, best practices, and professional development support to enhance team capabilities and knowledge. Requirements: Bachelor's degree (IT-related field preferred) Eight (8) years of overall experience in cybersecurity or network security position Five (5) years of experience in a Certification and Accreditation/A&A role Must have and maintain an active DoD Top Secret clearance with SCI eligibility Must be able and willing to travel up to approximately 85% of the time, inside and outside the continental United States and internationally (CONUS / OCONUS) DoD 8570 IA Technical (IAT) Level III certification Demonstrated experience with STIGs (Security Technical Implementation Guides), Security Requirement Guides (SRGs), Plan of Action and Milestones (POA&Ms) and cybersecurity best practices Advanced understanding of the RMF process, NIST SP 800- 37, NIST SP 800-53, CNSSI 1253 Demonstrated experience with relevant tools such as eMASS, STIG Viewer, Nessus, ACAS, SCAP, or HBSS Advanced understanding of key technologies areas/domain such as: Network, Mobility, Windows, UNIX, Cloud Environments and Cloud Native Tools/Services, Host Based Security System (HBSS)/Endpoint Security Solutions (ESS), Databases, Applications Strong written and verbal communication skills for reporting assessment findings. Compensation: $95,000 - $105,000 This posting is part of a pipeline for future opportunities supporting the current TASS contract. Employment is contingent upon position availability and government customer approval. AGE Solutions is actively engaging talent and encourages incumbents and new candidates to express interest to be considered if/when opportunities may become available. At AGE Solutions, we reward performance, invest in growth, and share success. Our benefits support the whole person, professionally, financially, and personally. 26 Days Paid Leave: Includes vacation, sick, personal time, and holidays. You choose how to use it. Performance Bonuses: Performance bonuses are awarded based on individual contributions and company-wide results, aligning recognition with impact. 401(k) with Match: We match 3% of your contributions with immediate vesting. Financial Protection: Company-paid life insurance up to $300K and options for additional coverage for you and your dependents. Health Benefits: Multiple medical plans, dental, vision, FSA and HSA options to fit your needs. Parental Leave: 15 days of fully paid leave for new parents, because family matters. Military Differential Pay: We bridge the gap for employees on active duty, so they don't take a financial hit while serving. Professional Growth: Paid training and certifications, tuition reimbursement, and the tools and tech to get the job done right. Shared Success: In the event of a company sale, our CEO has committed to returning 80% of net proceeds to employees. This ensures our team shares in the long term value they help create. At AGE, you'll do work that matters, supported by a company that delivers for its people.
09/20/2026
Full time
Job Description Job Description About Us AGE Solutions is a premier technology and professional services company, providing in-depth consulting, advanced technology solutions, and essential services throughout the U.S. government, defense, and intelligence sectors. Prioritizing innovation and client-focused solutions, we assist major agencies in addressing intricate issues and ensuring a more secure future. AGE Solutions is looking for Senior Security Control Assessors to join our team in support of a cybersecurity risk management and assessment program with our DoD customer. Responsibilities: Conduct cybersecurity assessments, audits, and inspections for DoD organizations and partners handling DoD information or connecting to the DoDIN. Evaluate systems and Defensive Cyberspace Operations using cyber threat emulation and performance-based testing. Adhere to policies and processes for each assessment type. Support assessment development and execution to ensure security expertise is properly applied. Coordinate logistics, test plans, and scope with the SCA Team Lead. Perform vulnerability assessments, capture results using STIG Viewer or designated tools, and document findings in eMASS. Analyze security gaps and provide mitigation recommendations. Validate cybersecurity controls, TTPs, STIGs, RMF controls, and compliance with DoD policies and guidelines. Provide risk analysis and assessment results for authorization recommendations. Participate in daily assessment reviews, in-briefs, and out-briefs, sharing findings with the SCA-R. Mentor and guide personnel by providing technical expertise, best practices, and professional development support to enhance team capabilities and knowledge. Requirements: Bachelor's degree (IT-related field preferred) Eight (8) years of overall experience in cybersecurity or network security position Five (5) years of experience in a Certification and Accreditation/A&A role Must have and maintain an active DoD Top Secret clearance with SCI eligibility Must be able and willing to travel up to approximately 85% of the time, inside and outside the continental United States and internationally (CONUS / OCONUS) DoD 8570 IA Technical (IAT) Level III certification Demonstrated experience with STIGs (Security Technical Implementation Guides), Security Requirement Guides (SRGs), Plan of Action and Milestones (POA&Ms) and cybersecurity best practices Advanced understanding of the RMF process, NIST SP 800- 37, NIST SP 800-53, CNSSI 1253 Demonstrated experience with relevant tools such as eMASS, STIG Viewer, Nessus, ACAS, SCAP, or HBSS Advanced understanding of key technologies areas/domain such as: Network, Mobility, Windows, UNIX, Cloud Environments and Cloud Native Tools/Services, Host Based Security System (HBSS)/Endpoint Security Solutions (ESS), Databases, Applications Strong written and verbal communication skills for reporting assessment findings. Compensation: $95,000 - $105,000 This posting is part of a pipeline for future opportunities supporting the current TASS contract. Employment is contingent upon position availability and government customer approval. AGE Solutions is actively engaging talent and encourages incumbents and new candidates to express interest to be considered if/when opportunities may become available. At AGE Solutions, we reward performance, invest in growth, and share success. Our benefits support the whole person, professionally, financially, and personally. 26 Days Paid Leave: Includes vacation, sick, personal time, and holidays. You choose how to use it. Performance Bonuses: Performance bonuses are awarded based on individual contributions and company-wide results, aligning recognition with impact. 401(k) with Match: We match 3% of your contributions with immediate vesting. Financial Protection: Company-paid life insurance up to $300K and options for additional coverage for you and your dependents. Health Benefits: Multiple medical plans, dental, vision, FSA and HSA options to fit your needs. Parental Leave: 15 days of fully paid leave for new parents, because family matters. Military Differential Pay: We bridge the gap for employees on active duty, so they don't take a financial hit while serving. Professional Growth: Paid training and certifications, tuition reimbursement, and the tools and tech to get the job done right. Shared Success: In the event of a company sale, our CEO has committed to returning 80% of net proceeds to employees. This ensures our team shares in the long term value they help create. At AGE, you'll do work that matters, supported by a company that delivers for its people.
Job Description Job Description Mission Context LV8D Solutions supports national security space and intelligence customers delivering next-generation sensing and exploitation capabilities. The role of a Security Control Assessor (SCA) is focused on providing information security Assessment and Authorization (A&A) support throughout the mission program's lifecycle. Position Overview LV8D Solutions is seeking a SCA to conduct independent assessments of the management, operational, and technical security controls employed within or inherited by an information technology (IT) system to determine the overall effectiveness of the security controls. A Security Control Assessor (SCA) performs comprehensive INFOSEC assessment of management, operational, and technical security controls to determine overall effectiveness of the controls for A&A determination throughout a program's system lifecycle. SCAs provide an assessment of the severity of weakness or deficiencies discovered in the Information System (IS) and its environment of operation and recommend corrective actions to address identified vulnerabilities. Prior to initiating the security control assessment, the SCA reviews the System Security Plan (SSP) to ensure the plan provides a set of security controls for the ISs that meet the stated security requirements. Additionally, the SCA must verify that all allocated controls have an acceptable status (i.e., implemented, excepted, or inherited) with appropriate documented details and provides responses in the Government's Risk Management Framework (RMF) tools. Interested candidates need to thrive in an innovative, fast-paced environment; are highly motivated and not afraid to take on uncharted territory; possess strong communication, leadership, and organizational skills; and be able to prioritize their time to be effective in a dynamic environment. Requirements Key Responsibilities Reviews IS for compliance with applicable Intelligence Community (IC), Department of War (DoW), and National Directorate (ND) guidance, and make recommendations to the Government. Provides ISs security advice and guidance Joint Analytical Workstation (JAW) applicable IC, DoW, and NDs and guidance to Government and industry partners for the protection of data at all classification levels including Sensitive Compartmented Information (SCI). Evaluates threats and vulnerabilities to ISs to ascertain the need for additional safeguards and recommend approval, disapproval, or waiver(s) for IS processing national security data at industry and/or Government facilities. Supports development and implementation of directives and guidance for policies. Provides input for consideration in the promulgation of future ISs security policy. Supports and/or conduct site visits and assessments to inspect and verify IS reports. Ensures security control assessments are completed for each IS. Supports the preparation and delivery of presentations, briefings, reports, and memoranda associated with the RMF process. Uses the RMF system of record to complete RMF workflow duties and maintain the asset documentation repository. Establishes and maintains means and methods to track RMF process workflow activities to inform task volume, velocity, and duration of activities. Prepares the final Security Assessment Report (SAR) containing the results and findings from the assessment at the conclusion of each security control assessment activity and the Authorization Recommendation. Ensures appropriate IS security requirements including applicable Interface Control Documents (ICDs), DoW Instructions, NDs and other guidance are addressed and applied and appropriate documentation is prepared by the system owners or programs. The documentation will be contained in the Security Assessment Package, including, but not limited to, the Concept of Operations (CONOP), SSP, Systems Requirements Traceability Matrix, Risk Management Matrix, Test Results, interface control documents, requests for changes, test plans, and other related program security documentation. Collaborates with Information Security Officers (ISOs) and Common Control Providers to initiate Plan of Action and Milestones (POAMs) for ISs based on findings and recommendations from the SAR. Reviews and approves the IS Security Assessment Plan which is comprised of the Security Controls Traceability Matrix and the Security Control Assessment Procedures. Tracks the completion of the SAR. Reviews, coordinates, and responds to security issues as requested by the Government. Provides A&A support to the Government for the protection of special programs and tactical operations related activities. Supplies the effort needed to conduct the reviews and write reports to support Integrated Security Assessment Program (ISAP) or Technical Information Systems Security Reviews (TISSRs). Required Qualifications Practical experience performing information systems A&A as defined in applicable ICDs and guidance Practical experience utilizing risk management strategies for information technology solutions Technical understanding of emerging technologies and their implementation within Government system and network environments Knowledge of information technology concepts used in the evaluation of security performance and integrity of state-of-the-art applications, communications systems, hardware, software, satellite control systems, and information processing systems Technical understanding of information technology systems, software, and networks Ability to effectively coordinate A&A activities of industry and Government information systems to meet acquisition milestone requirements Effective technical report and general correspondence writing ability Ability to manage and track systems or programs involved in the A&A process Experience developing and implementing security related directives and guidance for Information Assurance, Information Technology, and Information Management Experience working with a mixed level skill team to ensure that appropriate knowledge and skill transfer occurs High school's degree and 7+ years of relevant experience, or Associate's degree and 7+ years of relevant experience, or Bachelor's degree and 5+ years of relevant experience, or Master's degree and 3+ years of relevant experience Certifications Must have one of the following IAM Level 2 Certification: CGRC (Previously CAP) CASP CISM CISSP GSLC CCISO Security Requirements U.S. Citizenship Active Top Secret/Sensitive Compartmented Information (TS/SCI) clearance Active Counterintelligence (CI) or Full Scope (FS) Polygraph Work Environment On-site work in a government or contractor facility Occasional travel (up to 10%) This position is dependent on a contract seat being awarded. About LV8D Solutions LV8D Solutions is an elite Systems Engineering and Technical Advisory (SETA) company that delivers advanced systems engineering, integration, acquisition, mission operations, network communications, and cybersecurity support to our defense and intelligence customers. Founded in 2019, we apply our deep technical expertise, understanding, and mission-first mindset to design, acquire, and implement complex, high-impact solutions for our Intelligence Community (IC) and Department of War (DoW) customers. We specialize in every aspect of our customers' space and ground mission systems while offering exceptional work-life balance and an exemplary compensation and total rewards package designed to recruit, train, and retain top talent and committed to national defense and career growth. Equal Employment Opportunity Statement LV8D Solutions LLC is an Equal Opportunity Employer committed to diversity and inclusion. All qualified applicants will receive consideration without regard to race, religion, gender, national origin, disability, veteran status, or other protected categories. Benefits Performance & Recognition Period of Performance (PoP) Bonus Opportunities Performance-based bonus opportunities tied to contract or organizational performance. Retention Incentive Benefit Bounty Receive a payout for unused annual company contributions designated for health insurance premiums and professional training. Referral Bonus Earn up to $5,000 for each successful employee referral. Customer Recognition Letter of Appreciation (LoA) Bonus Opportunities Bonus opportunities based on customer recognition received through Letters of Appreciation. Milestone Rewards Celebrate your career achievements with anniversary awards on your 1st, 5th, 10th, and 20th years of service. Financial & Retirement Benefits Profit Sharing Receive an annual contribution equal to 4% of your W-2 gross earnings into your 401 (k), with immediate vesting. 401(k) Company Match The company matches your 401 (k) contributions dollar-for-dollar up to 6% of your monthly contribution, with immediate vesting. Career Development The company invests in your professional growth through: Annual financial support for professional training and industry certifications. Enhanced financial support for employees actively pursuing a degree at an accredited institution. Work-Life Balance . click apply for full job details
09/19/2026
Full time
Job Description Job Description Mission Context LV8D Solutions supports national security space and intelligence customers delivering next-generation sensing and exploitation capabilities. The role of a Security Control Assessor (SCA) is focused on providing information security Assessment and Authorization (A&A) support throughout the mission program's lifecycle. Position Overview LV8D Solutions is seeking a SCA to conduct independent assessments of the management, operational, and technical security controls employed within or inherited by an information technology (IT) system to determine the overall effectiveness of the security controls. A Security Control Assessor (SCA) performs comprehensive INFOSEC assessment of management, operational, and technical security controls to determine overall effectiveness of the controls for A&A determination throughout a program's system lifecycle. SCAs provide an assessment of the severity of weakness or deficiencies discovered in the Information System (IS) and its environment of operation and recommend corrective actions to address identified vulnerabilities. Prior to initiating the security control assessment, the SCA reviews the System Security Plan (SSP) to ensure the plan provides a set of security controls for the ISs that meet the stated security requirements. Additionally, the SCA must verify that all allocated controls have an acceptable status (i.e., implemented, excepted, or inherited) with appropriate documented details and provides responses in the Government's Risk Management Framework (RMF) tools. Interested candidates need to thrive in an innovative, fast-paced environment; are highly motivated and not afraid to take on uncharted territory; possess strong communication, leadership, and organizational skills; and be able to prioritize their time to be effective in a dynamic environment. Requirements Key Responsibilities Reviews IS for compliance with applicable Intelligence Community (IC), Department of War (DoW), and National Directorate (ND) guidance, and make recommendations to the Government. Provides ISs security advice and guidance Joint Analytical Workstation (JAW) applicable IC, DoW, and NDs and guidance to Government and industry partners for the protection of data at all classification levels including Sensitive Compartmented Information (SCI). Evaluates threats and vulnerabilities to ISs to ascertain the need for additional safeguards and recommend approval, disapproval, or waiver(s) for IS processing national security data at industry and/or Government facilities. Supports development and implementation of directives and guidance for policies. Provides input for consideration in the promulgation of future ISs security policy. Supports and/or conduct site visits and assessments to inspect and verify IS reports. Ensures security control assessments are completed for each IS. Supports the preparation and delivery of presentations, briefings, reports, and memoranda associated with the RMF process. Uses the RMF system of record to complete RMF workflow duties and maintain the asset documentation repository. Establishes and maintains means and methods to track RMF process workflow activities to inform task volume, velocity, and duration of activities. Prepares the final Security Assessment Report (SAR) containing the results and findings from the assessment at the conclusion of each security control assessment activity and the Authorization Recommendation. Ensures appropriate IS security requirements including applicable Interface Control Documents (ICDs), DoW Instructions, NDs and other guidance are addressed and applied and appropriate documentation is prepared by the system owners or programs. The documentation will be contained in the Security Assessment Package, including, but not limited to, the Concept of Operations (CONOP), SSP, Systems Requirements Traceability Matrix, Risk Management Matrix, Test Results, interface control documents, requests for changes, test plans, and other related program security documentation. Collaborates with Information Security Officers (ISOs) and Common Control Providers to initiate Plan of Action and Milestones (POAMs) for ISs based on findings and recommendations from the SAR. Reviews and approves the IS Security Assessment Plan which is comprised of the Security Controls Traceability Matrix and the Security Control Assessment Procedures. Tracks the completion of the SAR. Reviews, coordinates, and responds to security issues as requested by the Government. Provides A&A support to the Government for the protection of special programs and tactical operations related activities. Supplies the effort needed to conduct the reviews and write reports to support Integrated Security Assessment Program (ISAP) or Technical Information Systems Security Reviews (TISSRs). Required Qualifications Practical experience performing information systems A&A as defined in applicable ICDs and guidance Practical experience utilizing risk management strategies for information technology solutions Technical understanding of emerging technologies and their implementation within Government system and network environments Knowledge of information technology concepts used in the evaluation of security performance and integrity of state-of-the-art applications, communications systems, hardware, software, satellite control systems, and information processing systems Technical understanding of information technology systems, software, and networks Ability to effectively coordinate A&A activities of industry and Government information systems to meet acquisition milestone requirements Effective technical report and general correspondence writing ability Ability to manage and track systems or programs involved in the A&A process Experience developing and implementing security related directives and guidance for Information Assurance, Information Technology, and Information Management Experience working with a mixed level skill team to ensure that appropriate knowledge and skill transfer occurs High school's degree and 7+ years of relevant experience, or Associate's degree and 7+ years of relevant experience, or Bachelor's degree and 5+ years of relevant experience, or Master's degree and 3+ years of relevant experience Certifications Must have one of the following IAM Level 2 Certification: CGRC (Previously CAP) CASP CISM CISSP GSLC CCISO Security Requirements U.S. Citizenship Active Top Secret/Sensitive Compartmented Information (TS/SCI) clearance Active Counterintelligence (CI) or Full Scope (FS) Polygraph Work Environment On-site work in a government or contractor facility Occasional travel (up to 10%) This position is dependent on a contract seat being awarded. About LV8D Solutions LV8D Solutions is an elite Systems Engineering and Technical Advisory (SETA) company that delivers advanced systems engineering, integration, acquisition, mission operations, network communications, and cybersecurity support to our defense and intelligence customers. Founded in 2019, we apply our deep technical expertise, understanding, and mission-first mindset to design, acquire, and implement complex, high-impact solutions for our Intelligence Community (IC) and Department of War (DoW) customers. We specialize in every aspect of our customers' space and ground mission systems while offering exceptional work-life balance and an exemplary compensation and total rewards package designed to recruit, train, and retain top talent and committed to national defense and career growth. Equal Employment Opportunity Statement LV8D Solutions LLC is an Equal Opportunity Employer committed to diversity and inclusion. All qualified applicants will receive consideration without regard to race, religion, gender, national origin, disability, veteran status, or other protected categories. Benefits Performance & Recognition Period of Performance (PoP) Bonus Opportunities Performance-based bonus opportunities tied to contract or organizational performance. Retention Incentive Benefit Bounty Receive a payout for unused annual company contributions designated for health insurance premiums and professional training. Referral Bonus Earn up to $5,000 for each successful employee referral. Customer Recognition Letter of Appreciation (LoA) Bonus Opportunities Bonus opportunities based on customer recognition received through Letters of Appreciation. Milestone Rewards Celebrate your career achievements with anniversary awards on your 1st, 5th, 10th, and 20th years of service. Financial & Retirement Benefits Profit Sharing Receive an annual contribution equal to 4% of your W-2 gross earnings into your 401 (k), with immediate vesting. 401(k) Company Match The company matches your 401 (k) contributions dollar-for-dollar up to 6% of your monthly contribution, with immediate vesting. Career Development The company invests in your professional growth through: Annual financial support for professional training and industry certifications. Enhanced financial support for employees actively pursuing a degree at an accredited institution. Work-Life Balance . click apply for full job details
Job Description Job Description Information Security Specialist Officer, Technical Lead, AWS Security • RMF & ATO • NIST 800-53 • Cloud Application Security Clearance: Active CBP, DHS, or Top Secret Clearance required Work Arrangement: Hybrid - onsite 3 days/week during standard business hours in Ashburn, VA About the Role Dev Technology Group is seeking a Senior Information Security Specialist to lead and develop a mid-sized team of ISSOs supporting the security, compliance, and authorization of mission-critical federal applications and information systems hosted in AWS. This is a hands-on technical leadership role combining people leadership, federal cybersecurity expertise, and direct collaboration with government and technical stakeholders. You will mentor junior and mid-level ISSOs while partnering with system owners, developers, architects, cloud/infrastructure engineers, security professionals, and government stakeholders throughout the system development lifecycle. You will provide practical security guidance for AWS-hosted applications, lead Risk Management Framework (RMF) and Authority to Operate (ATO) activities, oversee vulnerability management and continuous monitoring, and translate federal cybersecurity requirements into actionable guidance for technical teams. What You'll Do Lead, mentor, and develop a team of ISSOs by establishing priorities, providing technical direction and coaching, and promoting accountability and consistent security practices. Lead and oversee RMF, ATO, security authorization, compliance, vulnerability management, and continuous monitoring activities across a portfolio of federal systems and applications. Partner with ISSMs, system owners, assessors, developers, architects, engineers, and government stakeholders to maintain authorizations, identify risks, and address security requirements. Lead vulnerability management efforts, prioritizing remediation, developing mitigation strategies, and tracking corrective actions through resolution. Develop, assess, document, and support implementation of security controls aligned with FISMA, NIST 800-53, DHS, and client requirements . Prepare and maintain security and authorization documentation, including SSPs, ISAs, audit artifacts, and RMF documentation . Provide cybersecurity guidance for applications and systems deployed in AWS and integrate security throughout the software development lifecycle. Validate security implementation through technical reviews, discussions, interviews, assessments, and tabletop exercises. Support security audits, assessments, compliance reviews, and reviews of information systems and network connections. Interpret federal and client security policies and translate requirements into practical guidance for technical and development teams. Identify and escalate security risks, communicate priorities and remediation status, and provide clear visibility to Dev Technology leadership and government stakeholders. Develop and present security metrics, status reports, risk assessments, and executive briefings . Establish and improve security processes, procedures, templates, dashboards, and workflows to improve consistency, accountability, and efficiency across the ISSO team. Build trusted relationships with government clients through proactive communication, collaboration, and face-to-face engagement. Required Education, Experience & Skills Bachelor's degree and 7+ years of experience securing federal information systems. Demonstrated experience leading and mentoring information security professionals , including junior and mid-level ISSOs. Experience leading cybersecurity activities in a federal government client environment and working directly with government stakeholders.' Strong working knowledge of NIST Risk Management Framework (RMF) and experience supporting federal systems through security authorization and ATO activities . Experience developing, implementing, assessing, or documenting security controls aligned with FISMA and NIST 800-53 . Experience with vulnerability management, continuous monitoring, security assessments, audits, or compliance reviews for federal systems. Experience providing cybersecurity guidance for AWS-hosted applications and systems . Strong understanding of modern information systems and their technical security considerations. Ability to work effectively with developers, architects, engineers, government stakeholders, and technical and non-technical audiences. Strong written and verbal communication skills, including the ability to communicate security risks and technical findings and develop/present security documentation and executive briefings. Ability to establish priorities, manage competing demands, independently manage security activities, and escalate issues appropriately. Proactive, solutions-oriented approach to identifying risks and improving security practices. Current CBP, DHS, or Top Secret Clearance. Ability to work onsite 3 days per week in Ashburn, VA during standard business hours. Cybersecurity certification such as CISSP, CISM, GIAC, Security+, or another recognized cybersecurity certification. Preferred Education, Experience & Skills Experience developing or supporting RMF and authorization artifacts, including SSPs, ISAs, PTAs, ATTs, POA&Ms , and related documentation. Experience partnering with application development, cloud engineering, and DevSecOps teams to integrate security throughout the SDLC. Experience working in an Agile software development environment using Jira or similar platforms. Experience with GRC tools such as CSAM or similar platforms supporting authorization, compliance, vulnerability management, and security activities. Understanding of AI concepts and practical applications of AI for cybersecurity operations, risk analysis, compliance, or security program management. Our estimated salary range for this position is $88,000 - $ 150,000. This presented salary range is not a guarantee of compensation or salary. Offered salary is based on experience, geographic location, and possibly contractual requirements as appropriate to the role. Salary could fall outside of this range. Who We Are Dev Technology is a growing IT company with an employee-centric culture that works on mission-critical projects for the federal government. We partner with our federal customers to deliver technology services and solutions, and to drive our client's missions forward through innovation. We use Agile and DevSecOps principles to provide services including application development, biometrics and identity management, cloud and infrastructure optimization, IT and legacy modernization, and data management. As a Washington Post Top Workplace award winner for the past THIRTEEN years in a row, the Top Workplaces USA for the past five years, and a recipient of the Companies As Responsive Employers (CARE) Award for the past six years, Dev Technology employees enjoy: Generous and flexible time-off policy Flexible work schedules and telework options, including remote work availability for eligible projects Career development opportunities including a mentorship program, technical and management training through Dev University, hands-on learning through DevLab, tuition reimbursement, and paid training opportunities Industry-leading benefits including a choice of two health plans that include dental and vision, flexible spending account, commuter benefits, life insurance, and more 401K matching with a 5% matching contribution Regular team and company social events including our annual party, happy hours, fitness challenges, and more A focus on community engagement including company wide support activities, employer match for donations, and time off for volunteer efforts To learn more about working at Dev Technology, visit Working At Dev Technology Group Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans Dev Technology Group operates in the following states: AL, AR, AZ, CO, DC, FL, GA, ID, IL, IN, MD, MA, ME, MI, MN, MO, MS, NC, NJ, OH, OR, PA, SC, TN, TX, VA, WV.
09/18/2026
Full time
Job Description Job Description Information Security Specialist Officer, Technical Lead, AWS Security • RMF & ATO • NIST 800-53 • Cloud Application Security Clearance: Active CBP, DHS, or Top Secret Clearance required Work Arrangement: Hybrid - onsite 3 days/week during standard business hours in Ashburn, VA About the Role Dev Technology Group is seeking a Senior Information Security Specialist to lead and develop a mid-sized team of ISSOs supporting the security, compliance, and authorization of mission-critical federal applications and information systems hosted in AWS. This is a hands-on technical leadership role combining people leadership, federal cybersecurity expertise, and direct collaboration with government and technical stakeholders. You will mentor junior and mid-level ISSOs while partnering with system owners, developers, architects, cloud/infrastructure engineers, security professionals, and government stakeholders throughout the system development lifecycle. You will provide practical security guidance for AWS-hosted applications, lead Risk Management Framework (RMF) and Authority to Operate (ATO) activities, oversee vulnerability management and continuous monitoring, and translate federal cybersecurity requirements into actionable guidance for technical teams. What You'll Do Lead, mentor, and develop a team of ISSOs by establishing priorities, providing technical direction and coaching, and promoting accountability and consistent security practices. Lead and oversee RMF, ATO, security authorization, compliance, vulnerability management, and continuous monitoring activities across a portfolio of federal systems and applications. Partner with ISSMs, system owners, assessors, developers, architects, engineers, and government stakeholders to maintain authorizations, identify risks, and address security requirements. Lead vulnerability management efforts, prioritizing remediation, developing mitigation strategies, and tracking corrective actions through resolution. Develop, assess, document, and support implementation of security controls aligned with FISMA, NIST 800-53, DHS, and client requirements . Prepare and maintain security and authorization documentation, including SSPs, ISAs, audit artifacts, and RMF documentation . Provide cybersecurity guidance for applications and systems deployed in AWS and integrate security throughout the software development lifecycle. Validate security implementation through technical reviews, discussions, interviews, assessments, and tabletop exercises. Support security audits, assessments, compliance reviews, and reviews of information systems and network connections. Interpret federal and client security policies and translate requirements into practical guidance for technical and development teams. Identify and escalate security risks, communicate priorities and remediation status, and provide clear visibility to Dev Technology leadership and government stakeholders. Develop and present security metrics, status reports, risk assessments, and executive briefings . Establish and improve security processes, procedures, templates, dashboards, and workflows to improve consistency, accountability, and efficiency across the ISSO team. Build trusted relationships with government clients through proactive communication, collaboration, and face-to-face engagement. Required Education, Experience & Skills Bachelor's degree and 7+ years of experience securing federal information systems. Demonstrated experience leading and mentoring information security professionals , including junior and mid-level ISSOs. Experience leading cybersecurity activities in a federal government client environment and working directly with government stakeholders.' Strong working knowledge of NIST Risk Management Framework (RMF) and experience supporting federal systems through security authorization and ATO activities . Experience developing, implementing, assessing, or documenting security controls aligned with FISMA and NIST 800-53 . Experience with vulnerability management, continuous monitoring, security assessments, audits, or compliance reviews for federal systems. Experience providing cybersecurity guidance for AWS-hosted applications and systems . Strong understanding of modern information systems and their technical security considerations. Ability to work effectively with developers, architects, engineers, government stakeholders, and technical and non-technical audiences. Strong written and verbal communication skills, including the ability to communicate security risks and technical findings and develop/present security documentation and executive briefings. Ability to establish priorities, manage competing demands, independently manage security activities, and escalate issues appropriately. Proactive, solutions-oriented approach to identifying risks and improving security practices. Current CBP, DHS, or Top Secret Clearance. Ability to work onsite 3 days per week in Ashburn, VA during standard business hours. Cybersecurity certification such as CISSP, CISM, GIAC, Security+, or another recognized cybersecurity certification. Preferred Education, Experience & Skills Experience developing or supporting RMF and authorization artifacts, including SSPs, ISAs, PTAs, ATTs, POA&Ms , and related documentation. Experience partnering with application development, cloud engineering, and DevSecOps teams to integrate security throughout the SDLC. Experience working in an Agile software development environment using Jira or similar platforms. Experience with GRC tools such as CSAM or similar platforms supporting authorization, compliance, vulnerability management, and security activities. Understanding of AI concepts and practical applications of AI for cybersecurity operations, risk analysis, compliance, or security program management. Our estimated salary range for this position is $88,000 - $ 150,000. This presented salary range is not a guarantee of compensation or salary. Offered salary is based on experience, geographic location, and possibly contractual requirements as appropriate to the role. Salary could fall outside of this range. Who We Are Dev Technology is a growing IT company with an employee-centric culture that works on mission-critical projects for the federal government. We partner with our federal customers to deliver technology services and solutions, and to drive our client's missions forward through innovation. We use Agile and DevSecOps principles to provide services including application development, biometrics and identity management, cloud and infrastructure optimization, IT and legacy modernization, and data management. As a Washington Post Top Workplace award winner for the past THIRTEEN years in a row, the Top Workplaces USA for the past five years, and a recipient of the Companies As Responsive Employers (CARE) Award for the past six years, Dev Technology employees enjoy: Generous and flexible time-off policy Flexible work schedules and telework options, including remote work availability for eligible projects Career development opportunities including a mentorship program, technical and management training through Dev University, hands-on learning through DevLab, tuition reimbursement, and paid training opportunities Industry-leading benefits including a choice of two health plans that include dental and vision, flexible spending account, commuter benefits, life insurance, and more 401K matching with a 5% matching contribution Regular team and company social events including our annual party, happy hours, fitness challenges, and more A focus on community engagement including company wide support activities, employer match for donations, and time off for volunteer efforts To learn more about working at Dev Technology, visit Working At Dev Technology Group Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans Dev Technology Group operates in the following states: AL, AR, AZ, CO, DC, FL, GA, ID, IL, IN, MD, MA, ME, MI, MN, MO, MS, NC, NJ, OH, OR, PA, SC, TN, TX, VA, WV.
Watermark Risk Management International
Arlington, Virginia
Job Description Job Description Come make your mark with Watermark! FOUNDED BY USAF VETERANS in 2007, we are proud to be a Service-Disabled Veteran Owned Small Business. SUBJECT MATTER EXPERTS specializing in security and risk management. We're intimately familiar with DOD security programs and mission requirements. OUR CORE VALUES drive every action we take as a company. We strive to exhibit PERSPECTIVE, PASSION, COMMUNICATION, INTEGRITY AND ETHICS, and BALANCE in all we do. COMPETITIVE BENEFITS PACKAGE to address our employees' physical, mental, emotional, and financial well-being. This includes 100% employer- paid medical insurance, ample paid leave, a free employee assistance program, and a competitive 401k savings plan. At Watermark, our people come first! Security Control Assessor (SCA) II The SCA is responsible for conducting a comprehensive assessment of the management, operational, and technical security controls employed within or inherited by an IS to determine the overall effectiveness of the controls (i.e., the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for the system). SCAs also provide an assessment of the severity of weaknesses or deficiencies discovered in the IS and its environment of operation and recommend corrective actions to address identified vulnerabilities. Responsibilities will cover Collateral, Sensitive Compartmented Information (SCI) and Special Access Program (SAP) activities within the customer's area of responsibility. In this role you will . Perform oversight of the development, implementation and evaluation of IS security program policy; special emphasis placed upon integration of existing SAP network infrastructure Perform assessment of ISs, based upon the Risk Management Framework (RMF) methodology in accordance with the Joint Special Access Program (SAP) Implementation Guide (JSIG) Advise the Information System Owner (ISO), Information Data Owner (IDO), Program Security Officer (PSO), and the Delegated and/or Authorizing Official (DAO/AO) on any assessment and authorization issues Evaluate Authorization packages and make recommendation to the AO and/or DAO for authorization Evaluate IS threats and vulnerabilities to determine whether additional safeguards are required Advise the Government concerning the impact levels for Confidentiality, Integrity, and Availability for the information on a system Ensure security assessments are completed and results documented and prepare the Security Assessment Report (SAR) for the Authorization boundary Initiate a Plan of Action and Milestones (POA&M) with identified weaknesses for each Authorization Boundaries assessed, based on findings and recommendations from the SAR Evaluate security assessment documentation and provide written recommendations for security authorization to the Government Discuss recommendation for authorization and submit the security authorization package to the AO/DAO Assess proposed changes to Authorization boundaries operating environment and mission needs to determine the continuation to operate. Review and concur with all sanitization and clearing procedures in accordance with Government guidance and/or policy Assist the Government compliance inspections Assist the Government with security incidents that relate to cybersecurity and ensure that the proper and corrective measures have been taken Ensure organization are addressing and conducting all phases of the system development life cycle (SDLC) Evaluate Hardware and Software to determine security impact that it might have on Authorization boundaries Evaluate the effectiveness and implementation of Continuous Monitoring Plans Represent the customer on inspection teams Additional duties as assigned Experience Requirements: 7-9 years related experience Minimum of four (4) years' experience in SAP, SCI or Collateral Information Systems (IS) Security and the implementation of regulations identified in the description of duties. Prior performance in the role of ISSO and ISSM or SCA Education Requirements: Bachelor's degree in a related area OR Associate's degree in a related area + 2 years' experience OR equivalent experience (4 years) Certification Requirements: Must meet position and certification requirements outlined in DoD Directive 8570.01-M for Information Assurance Technician Level III or Information Assurance Manager Level II within 6 months of the date of hire Security Clearance Requirements: Active TS/SCI clearance Eligibility for access to Special Access Program Information Willingness to submit to a Counterintelligence polygraph Other Requirements: Must be able to regularly lift up to 50 lbs. May require sedentary work at least 50% of the time Reports to a physical location which occasionally requires the ability to traverse between buildings Ability to manage stress with a high degree of maturity/professionalism Demonstrated critical thinking and leadership skills and the ability to work well with others Effective verbal and written communication skills All Level I & Level II positions - candidate should possess some Special Access Program (SAP) experience All Level III positions -candidate should possess 2+ years of Special Access Program (SAP) experience Watermark provides salary ranges with job postings in states where it is legally required; any other salary ranges associated with our postings are third party estimates and may not be an accurate reflection of Watermark's total compensation package. Multiple considerations are taken into account when determining the final salary/hourly rate, including but not limited to, Contract Wage Determination, education and certifications, relevant work experience, related skills and competencies, as well as Federal Government Contract Labor Categories. Central to Watermark's employment philosophy is the wellbeing of our employees which is why we offer a robust benefits package and wellness program alongside of annual base compensation. Watermark is an equal opportunity employer. All terms and conditions of employment are established without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, pregnancy, genetic information, disability, veteran status, or any other protected category under applicable federal, state, and local laws. Powered by JazzHR Ulb7SEozj9
09/16/2026
Full time
Job Description Job Description Come make your mark with Watermark! FOUNDED BY USAF VETERANS in 2007, we are proud to be a Service-Disabled Veteran Owned Small Business. SUBJECT MATTER EXPERTS specializing in security and risk management. We're intimately familiar with DOD security programs and mission requirements. OUR CORE VALUES drive every action we take as a company. We strive to exhibit PERSPECTIVE, PASSION, COMMUNICATION, INTEGRITY AND ETHICS, and BALANCE in all we do. COMPETITIVE BENEFITS PACKAGE to address our employees' physical, mental, emotional, and financial well-being. This includes 100% employer- paid medical insurance, ample paid leave, a free employee assistance program, and a competitive 401k savings plan. At Watermark, our people come first! Security Control Assessor (SCA) II The SCA is responsible for conducting a comprehensive assessment of the management, operational, and technical security controls employed within or inherited by an IS to determine the overall effectiveness of the controls (i.e., the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for the system). SCAs also provide an assessment of the severity of weaknesses or deficiencies discovered in the IS and its environment of operation and recommend corrective actions to address identified vulnerabilities. Responsibilities will cover Collateral, Sensitive Compartmented Information (SCI) and Special Access Program (SAP) activities within the customer's area of responsibility. In this role you will . Perform oversight of the development, implementation and evaluation of IS security program policy; special emphasis placed upon integration of existing SAP network infrastructure Perform assessment of ISs, based upon the Risk Management Framework (RMF) methodology in accordance with the Joint Special Access Program (SAP) Implementation Guide (JSIG) Advise the Information System Owner (ISO), Information Data Owner (IDO), Program Security Officer (PSO), and the Delegated and/or Authorizing Official (DAO/AO) on any assessment and authorization issues Evaluate Authorization packages and make recommendation to the AO and/or DAO for authorization Evaluate IS threats and vulnerabilities to determine whether additional safeguards are required Advise the Government concerning the impact levels for Confidentiality, Integrity, and Availability for the information on a system Ensure security assessments are completed and results documented and prepare the Security Assessment Report (SAR) for the Authorization boundary Initiate a Plan of Action and Milestones (POA&M) with identified weaknesses for each Authorization Boundaries assessed, based on findings and recommendations from the SAR Evaluate security assessment documentation and provide written recommendations for security authorization to the Government Discuss recommendation for authorization and submit the security authorization package to the AO/DAO Assess proposed changes to Authorization boundaries operating environment and mission needs to determine the continuation to operate. Review and concur with all sanitization and clearing procedures in accordance with Government guidance and/or policy Assist the Government compliance inspections Assist the Government with security incidents that relate to cybersecurity and ensure that the proper and corrective measures have been taken Ensure organization are addressing and conducting all phases of the system development life cycle (SDLC) Evaluate Hardware and Software to determine security impact that it might have on Authorization boundaries Evaluate the effectiveness and implementation of Continuous Monitoring Plans Represent the customer on inspection teams Additional duties as assigned Experience Requirements: 7-9 years related experience Minimum of four (4) years' experience in SAP, SCI or Collateral Information Systems (IS) Security and the implementation of regulations identified in the description of duties. Prior performance in the role of ISSO and ISSM or SCA Education Requirements: Bachelor's degree in a related area OR Associate's degree in a related area + 2 years' experience OR equivalent experience (4 years) Certification Requirements: Must meet position and certification requirements outlined in DoD Directive 8570.01-M for Information Assurance Technician Level III or Information Assurance Manager Level II within 6 months of the date of hire Security Clearance Requirements: Active TS/SCI clearance Eligibility for access to Special Access Program Information Willingness to submit to a Counterintelligence polygraph Other Requirements: Must be able to regularly lift up to 50 lbs. May require sedentary work at least 50% of the time Reports to a physical location which occasionally requires the ability to traverse between buildings Ability to manage stress with a high degree of maturity/professionalism Demonstrated critical thinking and leadership skills and the ability to work well with others Effective verbal and written communication skills All Level I & Level II positions - candidate should possess some Special Access Program (SAP) experience All Level III positions -candidate should possess 2+ years of Special Access Program (SAP) experience Watermark provides salary ranges with job postings in states where it is legally required; any other salary ranges associated with our postings are third party estimates and may not be an accurate reflection of Watermark's total compensation package. Multiple considerations are taken into account when determining the final salary/hourly rate, including but not limited to, Contract Wage Determination, education and certifications, relevant work experience, related skills and competencies, as well as Federal Government Contract Labor Categories. Central to Watermark's employment philosophy is the wellbeing of our employees which is why we offer a robust benefits package and wellness program alongside of annual base compensation. Watermark is an equal opportunity employer. All terms and conditions of employment are established without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, pregnancy, genetic information, disability, veteran status, or any other protected category under applicable federal, state, and local laws. Powered by JazzHR Ulb7SEozj9
Job Description Job Description Pivot Point Solutions Pivot Point Solutions is a California-based technology consulting firm that specializes in delivering IT solutions and support for the construction and utility industries. We partner with organizations across the state to provide reliable technology services that improve operational efficiency, enhance project delivery, and support critical business systems. Our team understands the unique technology challenges facing construction and utility organizations, from field operations and infrastructure projects to enterprise applications and cybersecurity. By combining industry expertise with responsive service, we help clients modernize their technology environments, streamline workflows, and maintain secure, reliable IT systems that support long-term growth. Job Overview Title: Cyber Security Controls Assessor Sector: Information Technology / Cybersecurity Seniority: Mid to Senior Level Location: California (Hybrid) Job Type: Contract Contract Length: 6+ Months Compensation: $104K - $145K About the Role PPS is seeking a Cyber Security Controls Assessor to support the protection of critical energy infrastructure through the assessment and validation of cybersecurity controls across enterprise and operational technology (OT) environments. This role evaluates compliance with cybersecurity policies, regulatory requirements, and industry standards to ensure the confidentiality, integrity, and availability of systems supporting electric and gas utility operations. The ideal candidate brings strong experience in security assessments, risk management, compliance, and control validation, with a focus on protecting critical infrastructure and supporting regulatory obligations. Key Responsibilities Conduct cybersecurity control assessments for enterprise IT, cloud, and OT/industrial control system environments Evaluate security controls against NIST CSF, NIST 800-53, NERC CIP, CIS Controls, and security policies Identify security risks, control deficiencies, and compliance gaps, and recommend corrective actions Prepare assessment reports detailing findings, risk ratings, remediation recommendations, and control effectiveness Partner with cybersecurity, engineering, IT, OT, compliance, and business stakeholders on risk identification and management Validate implementation and effectiveness of security controls for new projects, system upgrades, and technology deployments Support internal audits, regulatory reviews, and compliance initiatives related to critical infrastructure protection Track remediation activities and validate closure of cybersecurity findings Maintain assessment methodologies, standards, and procedures supporting cybersecurity programs Mentor junior assessors and contribute to continuous improvement initiatives within the Cybersecurity Risk & Compliance team Qualifications Required: Bachelor's degree in Cybersecurity, Information Security, Computer Science, Engineering, IT, or related field; or equivalent experience 5+ years of experience in cybersecurity, risk management, compliance, audit, or security controls assessment Experience performing security assessments and evaluating cybersecurity controls Knowledge of cybersecurity frameworks such as NIST CSF, NIST 800-53, CIS Controls, and risk management methodologies Experience with regulatory compliance programs and audit support Strong analytical, communication, and technical documentation skills Ability to communicate security risks and recommendations to technical and non-technical stakeholders Preferred: Experience within electric utilities, critical infrastructure, energy, or other regulated industries Knowledge of NERC CIP standards and compliance requirements Experience assessing OT, SCADA, ICS, or energy management systems Familiarity with cloud security environments (Azure, AWS) Experience with GRC platforms Professional certifications: CISSP, CISA, CRISC, GICSP, Security+, or equivalent Work Environment Standard office/field environment supporting critical infrastructure operations
09/15/2026
Full time
Job Description Job Description Pivot Point Solutions Pivot Point Solutions is a California-based technology consulting firm that specializes in delivering IT solutions and support for the construction and utility industries. We partner with organizations across the state to provide reliable technology services that improve operational efficiency, enhance project delivery, and support critical business systems. Our team understands the unique technology challenges facing construction and utility organizations, from field operations and infrastructure projects to enterprise applications and cybersecurity. By combining industry expertise with responsive service, we help clients modernize their technology environments, streamline workflows, and maintain secure, reliable IT systems that support long-term growth. Job Overview Title: Cyber Security Controls Assessor Sector: Information Technology / Cybersecurity Seniority: Mid to Senior Level Location: California (Hybrid) Job Type: Contract Contract Length: 6+ Months Compensation: $104K - $145K About the Role PPS is seeking a Cyber Security Controls Assessor to support the protection of critical energy infrastructure through the assessment and validation of cybersecurity controls across enterprise and operational technology (OT) environments. This role evaluates compliance with cybersecurity policies, regulatory requirements, and industry standards to ensure the confidentiality, integrity, and availability of systems supporting electric and gas utility operations. The ideal candidate brings strong experience in security assessments, risk management, compliance, and control validation, with a focus on protecting critical infrastructure and supporting regulatory obligations. Key Responsibilities Conduct cybersecurity control assessments for enterprise IT, cloud, and OT/industrial control system environments Evaluate security controls against NIST CSF, NIST 800-53, NERC CIP, CIS Controls, and security policies Identify security risks, control deficiencies, and compliance gaps, and recommend corrective actions Prepare assessment reports detailing findings, risk ratings, remediation recommendations, and control effectiveness Partner with cybersecurity, engineering, IT, OT, compliance, and business stakeholders on risk identification and management Validate implementation and effectiveness of security controls for new projects, system upgrades, and technology deployments Support internal audits, regulatory reviews, and compliance initiatives related to critical infrastructure protection Track remediation activities and validate closure of cybersecurity findings Maintain assessment methodologies, standards, and procedures supporting cybersecurity programs Mentor junior assessors and contribute to continuous improvement initiatives within the Cybersecurity Risk & Compliance team Qualifications Required: Bachelor's degree in Cybersecurity, Information Security, Computer Science, Engineering, IT, or related field; or equivalent experience 5+ years of experience in cybersecurity, risk management, compliance, audit, or security controls assessment Experience performing security assessments and evaluating cybersecurity controls Knowledge of cybersecurity frameworks such as NIST CSF, NIST 800-53, CIS Controls, and risk management methodologies Experience with regulatory compliance programs and audit support Strong analytical, communication, and technical documentation skills Ability to communicate security risks and recommendations to technical and non-technical stakeholders Preferred: Experience within electric utilities, critical infrastructure, energy, or other regulated industries Knowledge of NERC CIP standards and compliance requirements Experience assessing OT, SCADA, ICS, or energy management systems Familiarity with cloud security environments (Azure, AWS) Experience with GRC platforms Professional certifications: CISSP, CISA, CRISC, GICSP, Security+, or equivalent Work Environment Standard office/field environment supporting critical infrastructure operations
Job Description Job Description Pivot Point Solutions Pivot Point Solutions is a California-based technology consulting firm that specializes in delivering IT solutions and support for the construction and utility industries. We partner with organizations across the state to provide reliable technology services that improve operational efficiency, enhance project delivery, and support critical business systems. Our team understands the unique technology challenges facing construction and utility organizations, from field operations and infrastructure projects to enterprise applications and cybersecurity. By combining industry expertise with responsive service, we help clients modernize their technology environments, streamline workflows, and maintain secure, reliable IT systems that support long-term growth. Job Overview Title: Cyber Security Controls Assessor Sector: Information Technology / Cybersecurity Seniority: Mid to Senior Level Location: California (Hybrid) Job Type: Contract Contract Length: 6+ Months Compensation: $104K - $145K About the Role PPS is seeking a Cyber Security Controls Assessor to support the protection of critical energy infrastructure through the assessment and validation of cybersecurity controls across enterprise and operational technology (OT) environments. This role evaluates compliance with cybersecurity policies, regulatory requirements, and industry standards to ensure the confidentiality, integrity, and availability of systems supporting electric and gas utility operations. The ideal candidate brings strong experience in security assessments, risk management, compliance, and control validation, with a focus on protecting critical infrastructure and supporting regulatory obligations. Key Responsibilities Conduct cybersecurity control assessments for enterprise IT, cloud, and OT/industrial control system environments Evaluate security controls against NIST CSF, NIST 800-53, NERC CIP, CIS Controls, and security policies Identify security risks, control deficiencies, and compliance gaps, and recommend corrective actions Prepare assessment reports detailing findings, risk ratings, remediation recommendations, and control effectiveness Partner with cybersecurity, engineering, IT, OT, compliance, and business stakeholders on risk identification and management Validate implementation and effectiveness of security controls for new projects, system upgrades, and technology deployments Support internal audits, regulatory reviews, and compliance initiatives related to critical infrastructure protection Track remediation activities and validate closure of cybersecurity findings Maintain assessment methodologies, standards, and procedures supporting cybersecurity programs Mentor junior assessors and contribute to continuous improvement initiatives within the Cybersecurity Risk & Compliance team Qualifications Required: Bachelor's degree in Cybersecurity, Information Security, Computer Science, Engineering, IT, or related field; or equivalent experience 5+ years of experience in cybersecurity, risk management, compliance, audit, or security controls assessment Experience performing security assessments and evaluating cybersecurity controls Knowledge of cybersecurity frameworks such as NIST CSF, NIST 800-53, CIS Controls, and risk management methodologies Experience with regulatory compliance programs and audit support Strong analytical, communication, and technical documentation skills Ability to communicate security risks and recommendations to technical and non-technical stakeholders Preferred: Experience within electric utilities, critical infrastructure, energy, or other regulated industries Knowledge of NERC CIP standards and compliance requirements Experience assessing OT, SCADA, ICS, or energy management systems Familiarity with cloud security environments (Azure, AWS) Experience with GRC platforms Professional certifications: CISSP, CISA, CRISC, GICSP, Security+, or equivalent Work Environment Standard office/field environment supporting critical infrastructure operations
09/15/2026
Full time
Job Description Job Description Pivot Point Solutions Pivot Point Solutions is a California-based technology consulting firm that specializes in delivering IT solutions and support for the construction and utility industries. We partner with organizations across the state to provide reliable technology services that improve operational efficiency, enhance project delivery, and support critical business systems. Our team understands the unique technology challenges facing construction and utility organizations, from field operations and infrastructure projects to enterprise applications and cybersecurity. By combining industry expertise with responsive service, we help clients modernize their technology environments, streamline workflows, and maintain secure, reliable IT systems that support long-term growth. Job Overview Title: Cyber Security Controls Assessor Sector: Information Technology / Cybersecurity Seniority: Mid to Senior Level Location: California (Hybrid) Job Type: Contract Contract Length: 6+ Months Compensation: $104K - $145K About the Role PPS is seeking a Cyber Security Controls Assessor to support the protection of critical energy infrastructure through the assessment and validation of cybersecurity controls across enterprise and operational technology (OT) environments. This role evaluates compliance with cybersecurity policies, regulatory requirements, and industry standards to ensure the confidentiality, integrity, and availability of systems supporting electric and gas utility operations. The ideal candidate brings strong experience in security assessments, risk management, compliance, and control validation, with a focus on protecting critical infrastructure and supporting regulatory obligations. Key Responsibilities Conduct cybersecurity control assessments for enterprise IT, cloud, and OT/industrial control system environments Evaluate security controls against NIST CSF, NIST 800-53, NERC CIP, CIS Controls, and security policies Identify security risks, control deficiencies, and compliance gaps, and recommend corrective actions Prepare assessment reports detailing findings, risk ratings, remediation recommendations, and control effectiveness Partner with cybersecurity, engineering, IT, OT, compliance, and business stakeholders on risk identification and management Validate implementation and effectiveness of security controls for new projects, system upgrades, and technology deployments Support internal audits, regulatory reviews, and compliance initiatives related to critical infrastructure protection Track remediation activities and validate closure of cybersecurity findings Maintain assessment methodologies, standards, and procedures supporting cybersecurity programs Mentor junior assessors and contribute to continuous improvement initiatives within the Cybersecurity Risk & Compliance team Qualifications Required: Bachelor's degree in Cybersecurity, Information Security, Computer Science, Engineering, IT, or related field; or equivalent experience 5+ years of experience in cybersecurity, risk management, compliance, audit, or security controls assessment Experience performing security assessments and evaluating cybersecurity controls Knowledge of cybersecurity frameworks such as NIST CSF, NIST 800-53, CIS Controls, and risk management methodologies Experience with regulatory compliance programs and audit support Strong analytical, communication, and technical documentation skills Ability to communicate security risks and recommendations to technical and non-technical stakeholders Preferred: Experience within electric utilities, critical infrastructure, energy, or other regulated industries Knowledge of NERC CIP standards and compliance requirements Experience assessing OT, SCADA, ICS, or energy management systems Familiarity with cloud security environments (Azure, AWS) Experience with GRC platforms Professional certifications: CISSP, CISA, CRISC, GICSP, Security+, or equivalent Work Environment Standard office/field environment supporting critical infrastructure operations
Job Description Job Description Description: Job Title: Security Control Assessor Location: On Site in Arlington, VA Department: Cyber Security Services Reports To: Management FLSA Status: Full Time/Non-exempt Job Purpose: The security control assessor (SCAs) supports a critical, objective role to evaluate the effectiveness of implemented controls in mitigating security risks. The SCA will support a critical mission within the intelligence community. In the role as a SCA, you are expected to use automated scanning tools, manual techniques, and specialized testing methodologies to identify weaknesses and vulnerabilities. The SCA is expected to be a collaborative member of the RMF program of the organization, to provide intelligent input to system security architectures in order to align with RMF principles and guidelines. This includes ensuring to guide the RMF process so that security controls are integrated seamlessly into system designs to provide comprehensive protection against threats and vulnerabilities. Duties & Responsibilities: The SCA's specific duties include: Advise the Information System Owner (ISO) concerning the impact levels for Confidentiality, Integrity, and Availability for the information on systems. Ensure security assessments are completed for each IS. Initiate a POA&M with identified weaknesses and suspense dates for each IS based on findings and recommendations from the SAR. Evaluate security assessment documentation and provide written recommendations for security authorization to the CISO and AO. Assess proposed changes to Information Systems, their environment of operation, and mission needs that could affect system authorization. Serve as a cybersecurity technical advisor to the CISO and AO under their purview. Be integral to the development of the monitoring strategy. The system-level continuous monitoring strategy must conform to all applicable published DoD enterprise-level or DoD Component-level continuous monitoring strategies. Determine and document in the SAR a risk level for every noncompliant security control in the system baseline. Determine and document in the SAR an aggregate level of risk to the system and identify the key drivers for the assessment. The SCA's risk assessment considers threats, vulnerabilities, and potential impacts as well as existing and planned risk mitigation. Develop the continuous monitoring plan specific to the information system. The SCA is responsible for the RMF deliverables associated with Step 4 of DOD and IC RMF Policies for assigned systems. This includes, but is not limited to: Security Assessment Plans tailored to specific systems control requirements Security control assessment input, which includes narratives for the review of controls and artifacts Security Assessment Reports ATO recommendations or ATO with Condition Memorandums Conduct initial remediation actions once a security assessment has been completed to ensure proper hand off to the ISSM and ISSOs. Assessment of selected controls IAW continuous monitoring strategy The SCA is expected to have additional duties as assigned in support of corporate cyber security services. Additional details are reviewed in accordance with company policies. Requirements: Required Skills & Experience: Strong knowledge of Risk Management Framework (RMF) 800-37 and continuous monitoring 800-137 Expert knowledge and hands-on experience with FISMA Systems, NIST 800-series guidelines, FIPS, Security Assessment & Authorization (SA&A) requirements and processes, Continuous Monitoring Framework experience and its tools, Plan of Action & Milestones (POA&M) policies, and vulnerability/patch management, risk management, project management, proficient with Microsoft products - Word, Excel, PowerPoint. Proficient with vulnerability and scanning tools and well-versed in interpreting risk posture resulting from assessment reports. Experience in project management and tracking, and the Microsoft suite of office products Experience of assessing cloud-based security authorizations (FedRamp, AWS & Azure) as well as the NIST control responsibilities Experience with SAP/JSIG Expert with documenting and or reviewing of security materials such as; system security plans (SSP), Security Assessment Report (SAR), and Security Assessment Plan (SAP), and other documents per NIST 800 guidelines. Experience supporting cloud-based security authorizations (FedRamp, AWS, & Azure) Experience creating Security Assessment Plans, Security Assessment Reports, and Executive-level briefings Qualifications: Bachelor's Degree in Computer Science or a related technical discipline Master's Degree preferred. Minimum 6-10 years of experience. Must currently possess an active TS/SCI with the ability to obtain and maintain a CI polygraph. DOD 8140 IAM Level II (CAP, CASP, CISM, CISSP, GSLC, CCISO) is required Systems Security Engineering background preferred. Effective communication skills to collaborate with cross-functional teams and stakeholders on implementing security measures organization-wide. Strong analytical skills for identifying system vulnerabilities and documenting control remediation recommendations through collaboration on System Impact Analysis and Documented Risk Acceptance. Detail-oriented with the ability to manage multiple tasks and prioritize effectively. Comprehensive knowledge of RMF activities at a senior level (ability to articulate to Executive audiences preferred). Familiarity with federal regulatory requirements, contractual obligations, and industry standards related to information security. Evaluate adherence to standards such as Privacy, GDPR, and HIPAA Other: This is typical office or administrative work, and there is no exposure to adverse environmental conditions. This position requires sedentary work. Sedentary work is defined as: Exerting up to 10 pounds of force occasionally and/or a negligible amount of force frequently or constantly to lift, carry, push, pull or otherwise move objects, including the human body. Sedentary work involves sitting most of the time. Jobs are sedentary if walking and standing are required only occasionally, and all other sedentary criteria are met.
09/15/2026
Full time
Job Description Job Description Description: Job Title: Security Control Assessor Location: On Site in Arlington, VA Department: Cyber Security Services Reports To: Management FLSA Status: Full Time/Non-exempt Job Purpose: The security control assessor (SCAs) supports a critical, objective role to evaluate the effectiveness of implemented controls in mitigating security risks. The SCA will support a critical mission within the intelligence community. In the role as a SCA, you are expected to use automated scanning tools, manual techniques, and specialized testing methodologies to identify weaknesses and vulnerabilities. The SCA is expected to be a collaborative member of the RMF program of the organization, to provide intelligent input to system security architectures in order to align with RMF principles and guidelines. This includes ensuring to guide the RMF process so that security controls are integrated seamlessly into system designs to provide comprehensive protection against threats and vulnerabilities. Duties & Responsibilities: The SCA's specific duties include: Advise the Information System Owner (ISO) concerning the impact levels for Confidentiality, Integrity, and Availability for the information on systems. Ensure security assessments are completed for each IS. Initiate a POA&M with identified weaknesses and suspense dates for each IS based on findings and recommendations from the SAR. Evaluate security assessment documentation and provide written recommendations for security authorization to the CISO and AO. Assess proposed changes to Information Systems, their environment of operation, and mission needs that could affect system authorization. Serve as a cybersecurity technical advisor to the CISO and AO under their purview. Be integral to the development of the monitoring strategy. The system-level continuous monitoring strategy must conform to all applicable published DoD enterprise-level or DoD Component-level continuous monitoring strategies. Determine and document in the SAR a risk level for every noncompliant security control in the system baseline. Determine and document in the SAR an aggregate level of risk to the system and identify the key drivers for the assessment. The SCA's risk assessment considers threats, vulnerabilities, and potential impacts as well as existing and planned risk mitigation. Develop the continuous monitoring plan specific to the information system. The SCA is responsible for the RMF deliverables associated with Step 4 of DOD and IC RMF Policies for assigned systems. This includes, but is not limited to: Security Assessment Plans tailored to specific systems control requirements Security control assessment input, which includes narratives for the review of controls and artifacts Security Assessment Reports ATO recommendations or ATO with Condition Memorandums Conduct initial remediation actions once a security assessment has been completed to ensure proper hand off to the ISSM and ISSOs. Assessment of selected controls IAW continuous monitoring strategy The SCA is expected to have additional duties as assigned in support of corporate cyber security services. Additional details are reviewed in accordance with company policies. Requirements: Required Skills & Experience: Strong knowledge of Risk Management Framework (RMF) 800-37 and continuous monitoring 800-137 Expert knowledge and hands-on experience with FISMA Systems, NIST 800-series guidelines, FIPS, Security Assessment & Authorization (SA&A) requirements and processes, Continuous Monitoring Framework experience and its tools, Plan of Action & Milestones (POA&M) policies, and vulnerability/patch management, risk management, project management, proficient with Microsoft products - Word, Excel, PowerPoint. Proficient with vulnerability and scanning tools and well-versed in interpreting risk posture resulting from assessment reports. Experience in project management and tracking, and the Microsoft suite of office products Experience of assessing cloud-based security authorizations (FedRamp, AWS & Azure) as well as the NIST control responsibilities Experience with SAP/JSIG Expert with documenting and or reviewing of security materials such as; system security plans (SSP), Security Assessment Report (SAR), and Security Assessment Plan (SAP), and other documents per NIST 800 guidelines. Experience supporting cloud-based security authorizations (FedRamp, AWS, & Azure) Experience creating Security Assessment Plans, Security Assessment Reports, and Executive-level briefings Qualifications: Bachelor's Degree in Computer Science or a related technical discipline Master's Degree preferred. Minimum 6-10 years of experience. Must currently possess an active TS/SCI with the ability to obtain and maintain a CI polygraph. DOD 8140 IAM Level II (CAP, CASP, CISM, CISSP, GSLC, CCISO) is required Systems Security Engineering background preferred. Effective communication skills to collaborate with cross-functional teams and stakeholders on implementing security measures organization-wide. Strong analytical skills for identifying system vulnerabilities and documenting control remediation recommendations through collaboration on System Impact Analysis and Documented Risk Acceptance. Detail-oriented with the ability to manage multiple tasks and prioritize effectively. Comprehensive knowledge of RMF activities at a senior level (ability to articulate to Executive audiences preferred). Familiarity with federal regulatory requirements, contractual obligations, and industry standards related to information security. Evaluate adherence to standards such as Privacy, GDPR, and HIPAA Other: This is typical office or administrative work, and there is no exposure to adverse environmental conditions. This position requires sedentary work. Sedentary work is defined as: Exerting up to 10 pounds of force occasionally and/or a negligible amount of force frequently or constantly to lift, carry, push, pull or otherwise move objects, including the human body. Sedentary work involves sitting most of the time. Jobs are sedentary if walking and standing are required only occasionally, and all other sedentary criteria are met.
Job Description Job Description Job Title: Security Control Assessor Location: On Site in Arlington, VA Department: Cyber Security Services Reports To: Management FLSA Status: Full Time/Non-exempt Clearance: Top Secret clearance with the ability to obtain SCI with CI Polygraph Job Purpose: The security control assessor (SCAs) supports a critical, objective role to evaluate the effectiveness of implemented controls in mitigating security risks. The SCA will support a critical mission within the intelligence community. In the role as a SCA, you are expected to use automated scanning tools, manual techniques, and specialized testing methodologies to identify weaknesses and vulnerabilities. The SCA is expected to be a collaborative member of the RMF program of the organization, to provide intelligent input to system security architectures in order to align with RMF principles and guidelines. This includes ensuring to guide the RMF process so that security controls are integrated seamlessly into system designs to provide comprehensive protection against threats and vulnerabilities. Duties & Responsibilities: The SCA's specific duties include: Advise the Information System Owner (ISO) concerning the impact levels for Confidentiality, Integrity, and Availability for the information on systems. Ensure security assessments are completed for each IS. Initiate a POA&M with identified weaknesses and suspense dates for each IS based on findings and recommendations from the SAR. Evaluate security assessment documentation and provide written recommendations for security authorization to the CISO and AO. Assess proposed changes to Information Systems, their environment of operation, and mission needs that could affect system authorization. Serve as a cybersecurity technical advisor to the CISO and AO under their purview. Be integral to the development of the monitoring strategy. The system-level continuous monitoring strategy must conform to all applicable published DoD enterprise-level or DoD Component-level continuous monitoring strategies. Determine and document in the SAR a risk level for every noncompliant security control in the system baseline. Determine and document in the SAR an aggregate level of risk to the system and identify the key drivers for the assessment. The SCA's risk assessment considers threats, vulnerabilities, and potential impacts as well as existing and planned risk mitigation. Develop the continuous monitoring plan specific to the information system. The SCA is responsible for the RMF deliverables associated with Step 4 of DOD and IC RMF Policies for assigned systems. This includes, but is not limited to: Security Assessment Plans tailored to specific systems control requirements Security control assessment input, which includes narratives for the review of controls and artifacts Security Assessment Reports ATO recommendations or ATO with Condition Memorandums Conduct initial remediation actions once a security assessment has been completed to ensure proper hand off to the ISSM and ISSOs. Assessment of selected controls IAW continuous monitoring strategy The SCA is expected to have additional duties as assigned in support of corporate cyber security services. Additional details are reviewed in accordance with company policies. Requirements Required Skills & Experience: Strong knowledge of Risk Management Framework (RMF) 800-37 and continuous monitoring 800-137 Expert knowledge and hands-on experience with FISMA Systems, NIST 800-series guidelines, FIPS, Security Assessment & Authorization (SA&A) requirements and processes, Continuous Monitoring Framework experience and its tools, Plan of Action & Milestones (POA&M) policies, and vulnerability/patch management, risk management, project management, proficient with Microsoft products - Word, Excel, PowerPoint. Proficient with vulnerability and scanning tools and well-versed in interpreting risk posture resulting from assessment reports. Experience in project management and tracking, and the Microsoft suite of office products Experience of assessing cloud-based security authorizations (FedRamp, AWS & Azure) as well as the NIST control responsibilities Experience with SAP/JSIG Expert with documenting and or reviewing of security materials such as; system security plans (SSP), Security Assessment Report (SAR), and Security Assessment Plan (SAP), and other documents per NIST 800 guidelines. Experience supporting cloud-based security authorizations (FedRamp, AWS, & Azure) Experience creating Security Assessment Plans, Security Assessment Reports, and Executive-level briefings Qualifications: Bachelor's Degree in Computer Science or a related technical discipline Master's Degree preferred. Minimum 6-10 years of experience. Must currently possess an active Top Secret clearance with the ability to obtain SCI with CI Polygraph. DOD 8140 IAM Level II (CAP, CASP, CISM, CISSP, GSLC, CCISO) is required Systems Security Engineering background preferred. Effective communication skills to collaborate with cross-functional teams and stakeholders on implementing security measures organization-wide. Strong analytical skills for identifying system vulnerabilities and documenting control remediation recommendations through collaboration on System Impact Analysis and Documented Risk Acceptance. Detail-oriented with the ability to manage multiple tasks and prioritize effectively. Comprehensive knowledge of RMF activities at a senior level (ability to articulate to Executive audiences preferred). Familiarity with federal regulatory requirements, contractual obligations, and industry standards related to information security. Evaluate adherence to standards such as Privacy, GDPR, and HIPAA Powered by JazzHR I48iVzr4Ds
09/15/2026
Full time
Job Description Job Description Job Title: Security Control Assessor Location: On Site in Arlington, VA Department: Cyber Security Services Reports To: Management FLSA Status: Full Time/Non-exempt Clearance: Top Secret clearance with the ability to obtain SCI with CI Polygraph Job Purpose: The security control assessor (SCAs) supports a critical, objective role to evaluate the effectiveness of implemented controls in mitigating security risks. The SCA will support a critical mission within the intelligence community. In the role as a SCA, you are expected to use automated scanning tools, manual techniques, and specialized testing methodologies to identify weaknesses and vulnerabilities. The SCA is expected to be a collaborative member of the RMF program of the organization, to provide intelligent input to system security architectures in order to align with RMF principles and guidelines. This includes ensuring to guide the RMF process so that security controls are integrated seamlessly into system designs to provide comprehensive protection against threats and vulnerabilities. Duties & Responsibilities: The SCA's specific duties include: Advise the Information System Owner (ISO) concerning the impact levels for Confidentiality, Integrity, and Availability for the information on systems. Ensure security assessments are completed for each IS. Initiate a POA&M with identified weaknesses and suspense dates for each IS based on findings and recommendations from the SAR. Evaluate security assessment documentation and provide written recommendations for security authorization to the CISO and AO. Assess proposed changes to Information Systems, their environment of operation, and mission needs that could affect system authorization. Serve as a cybersecurity technical advisor to the CISO and AO under their purview. Be integral to the development of the monitoring strategy. The system-level continuous monitoring strategy must conform to all applicable published DoD enterprise-level or DoD Component-level continuous monitoring strategies. Determine and document in the SAR a risk level for every noncompliant security control in the system baseline. Determine and document in the SAR an aggregate level of risk to the system and identify the key drivers for the assessment. The SCA's risk assessment considers threats, vulnerabilities, and potential impacts as well as existing and planned risk mitigation. Develop the continuous monitoring plan specific to the information system. The SCA is responsible for the RMF deliverables associated with Step 4 of DOD and IC RMF Policies for assigned systems. This includes, but is not limited to: Security Assessment Plans tailored to specific systems control requirements Security control assessment input, which includes narratives for the review of controls and artifacts Security Assessment Reports ATO recommendations or ATO with Condition Memorandums Conduct initial remediation actions once a security assessment has been completed to ensure proper hand off to the ISSM and ISSOs. Assessment of selected controls IAW continuous monitoring strategy The SCA is expected to have additional duties as assigned in support of corporate cyber security services. Additional details are reviewed in accordance with company policies. Requirements Required Skills & Experience: Strong knowledge of Risk Management Framework (RMF) 800-37 and continuous monitoring 800-137 Expert knowledge and hands-on experience with FISMA Systems, NIST 800-series guidelines, FIPS, Security Assessment & Authorization (SA&A) requirements and processes, Continuous Monitoring Framework experience and its tools, Plan of Action & Milestones (POA&M) policies, and vulnerability/patch management, risk management, project management, proficient with Microsoft products - Word, Excel, PowerPoint. Proficient with vulnerability and scanning tools and well-versed in interpreting risk posture resulting from assessment reports. Experience in project management and tracking, and the Microsoft suite of office products Experience of assessing cloud-based security authorizations (FedRamp, AWS & Azure) as well as the NIST control responsibilities Experience with SAP/JSIG Expert with documenting and or reviewing of security materials such as; system security plans (SSP), Security Assessment Report (SAR), and Security Assessment Plan (SAP), and other documents per NIST 800 guidelines. Experience supporting cloud-based security authorizations (FedRamp, AWS, & Azure) Experience creating Security Assessment Plans, Security Assessment Reports, and Executive-level briefings Qualifications: Bachelor's Degree in Computer Science or a related technical discipline Master's Degree preferred. Minimum 6-10 years of experience. Must currently possess an active Top Secret clearance with the ability to obtain SCI with CI Polygraph. DOD 8140 IAM Level II (CAP, CASP, CISM, CISSP, GSLC, CCISO) is required Systems Security Engineering background preferred. Effective communication skills to collaborate with cross-functional teams and stakeholders on implementing security measures organization-wide. Strong analytical skills for identifying system vulnerabilities and documenting control remediation recommendations through collaboration on System Impact Analysis and Documented Risk Acceptance. Detail-oriented with the ability to manage multiple tasks and prioritize effectively. Comprehensive knowledge of RMF activities at a senior level (ability to articulate to Executive audiences preferred). Familiarity with federal regulatory requirements, contractual obligations, and industry standards related to information security. Evaluate adherence to standards such as Privacy, GDPR, and HIPAA Powered by JazzHR I48iVzr4Ds
Job Description Job Description Job Summary Newberry Group seeks a Jr. Security Control Assessor to support its Government Client. This role requires 85% travel to various government locations both domestically and internationally. Location Hybrid position - approx. 25% remote support with up to 75% CONUS and OCONUS travel. Clearance Active Secret Clearance (will sponsor). DoD Top Secret/SCI Clearance required or Interim Top Secret preferred. Certifications DoD 8570 IAT II (active or will obtain within 90 days of hire) Contingencies If an opening is not currently available, candidates applying to this role will be placed in our pipeline for future openings within this contract's program. Compensation $50,000 - $60,000 Primary Responsibilities: Conduct cybersecurity assessments, audits, and inspections for DoD organizations and partners handling DoD information or connecting to the DoDIN. Evaluate systems and Defensive Cyberspace Operations using cyber threat emulation and performance-based testing. Adhere to policies and processes for each assessment type. Support assessment development and execution to ensure security expertise is properly applied. Coordinate logistics, test plans, and scope with the SCA Team Lead. Perform vulnerability assessments, capture results using STIG Viewer or designated tools, and document findings in eMASS. Analyze security gaps and provide mitigation recommendations. Validate cybersecurity controls, TTPs, STIGs, RMF controls, and compliance with DoD policies and guidelines. Provide risk analysis and assessment results for authorization recommendations. Participate in daily assessment reviews, in-briefs, and out-briefs, sharing findings with the SCA-R. For each RMF Review, the assessors shall perform the following: The candidate will be required to review applicable controls to determine compliance status and enter all test results into the designated repository (Enterprise Mission Assurance Support Service (eMASS) Providing key assessment results to the team lead to include the number of controls reviewed and risk/residual information for inclusion in the authorization recommendation. The candidate will be required to be certified via the ACP IAW the ACP CONOPS before conducting any assessments. The candidate must be certified in a minimum of two (2) technologies and RMF Control Validation before conducting any assessments. Training through the DISA program will be provided after hire and consist of at least 3 months. The contractor shall maintain active accounts to the tools and systems required to perform risk assessments. The candidate will be required to participate in the in-brief and out-brief of each assessment. Qualifications: Bachelor's degree in a related area of study (i.e. Security, Information Technology). 0-1 year of experience required. Willing to train on both technologies and RMF. Active DoD Top Secret clearance with SCI eligibility is preferred but can begin with a secret clearance. IAT Level II certification active or will obtain within 90 days of hire. CompTIA Cybersecurity Analyst (CySA+) CompTIA Security. EC-Council Certified Network Defense (CND) v3. Red Hat Certified System Administrator (RHCSA) CCNA Security. Global Industrial Cyber Security Professional (GICSP) GIAC Security Essentials (GSEC) Systems Security Certified Practitioner (SSCP) Familiarity with STIGs (Security Technical Implementation Guides), Security Requirement Guides (SRGs), Plan of Action and Milestones (POA&Ms) and cybersecurity best practices desired. Understanding of the RMF process, NIST SP 800- 37, NIST SP 800-53, CNSSI 1253 desired Familiarity with relevant tools such as eMASS, STIG Viewer, Nessus, ACAS, SCAP, or HBSS desired Strong written and verbal communication skills for reporting assessment findings. Who We Are Today's leading government agencies are putting their trust in Newberry Group, and for good reason. Newberry brings strength to our clients, from the inside out, through: • client intimacy and superior quality, • presence and accountability in our relationships, and • Public sector best practices. Newberry Group is a professional services firm, providing information security compliance, governance, program/project management, and mission-critical project-based consulting to public sector clients nationwide. The strength of our company is a direct reflection of our highly skilled and talented workforce. Benefits and Perks In addition to competitive wages, Newberry Group offers an outstanding benefit package. This includes medical coverage with three plan options, dental and vision coverage, personal time off, paid holidays, paid parental leave, telecommuting if available, retirement savings accounts (Pre-Tax and Roth), flexible and dependent care savings accounts, life insurance, long and short-term disability coverage, tuition and training reimbursement, employee assistance program, and more. The Newberry Group, Inc. is an Equal Opportunity Employer - EEO/AA/Disability/Veterans. Powered by JazzHR 5whc8Lvtfu
09/15/2026
Full time
Job Description Job Description Job Summary Newberry Group seeks a Jr. Security Control Assessor to support its Government Client. This role requires 85% travel to various government locations both domestically and internationally. Location Hybrid position - approx. 25% remote support with up to 75% CONUS and OCONUS travel. Clearance Active Secret Clearance (will sponsor). DoD Top Secret/SCI Clearance required or Interim Top Secret preferred. Certifications DoD 8570 IAT II (active or will obtain within 90 days of hire) Contingencies If an opening is not currently available, candidates applying to this role will be placed in our pipeline for future openings within this contract's program. Compensation $50,000 - $60,000 Primary Responsibilities: Conduct cybersecurity assessments, audits, and inspections for DoD organizations and partners handling DoD information or connecting to the DoDIN. Evaluate systems and Defensive Cyberspace Operations using cyber threat emulation and performance-based testing. Adhere to policies and processes for each assessment type. Support assessment development and execution to ensure security expertise is properly applied. Coordinate logistics, test plans, and scope with the SCA Team Lead. Perform vulnerability assessments, capture results using STIG Viewer or designated tools, and document findings in eMASS. Analyze security gaps and provide mitigation recommendations. Validate cybersecurity controls, TTPs, STIGs, RMF controls, and compliance with DoD policies and guidelines. Provide risk analysis and assessment results for authorization recommendations. Participate in daily assessment reviews, in-briefs, and out-briefs, sharing findings with the SCA-R. For each RMF Review, the assessors shall perform the following: The candidate will be required to review applicable controls to determine compliance status and enter all test results into the designated repository (Enterprise Mission Assurance Support Service (eMASS) Providing key assessment results to the team lead to include the number of controls reviewed and risk/residual information for inclusion in the authorization recommendation. The candidate will be required to be certified via the ACP IAW the ACP CONOPS before conducting any assessments. The candidate must be certified in a minimum of two (2) technologies and RMF Control Validation before conducting any assessments. Training through the DISA program will be provided after hire and consist of at least 3 months. The contractor shall maintain active accounts to the tools and systems required to perform risk assessments. The candidate will be required to participate in the in-brief and out-brief of each assessment. Qualifications: Bachelor's degree in a related area of study (i.e. Security, Information Technology). 0-1 year of experience required. Willing to train on both technologies and RMF. Active DoD Top Secret clearance with SCI eligibility is preferred but can begin with a secret clearance. IAT Level II certification active or will obtain within 90 days of hire. CompTIA Cybersecurity Analyst (CySA+) CompTIA Security. EC-Council Certified Network Defense (CND) v3. Red Hat Certified System Administrator (RHCSA) CCNA Security. Global Industrial Cyber Security Professional (GICSP) GIAC Security Essentials (GSEC) Systems Security Certified Practitioner (SSCP) Familiarity with STIGs (Security Technical Implementation Guides), Security Requirement Guides (SRGs), Plan of Action and Milestones (POA&Ms) and cybersecurity best practices desired. Understanding of the RMF process, NIST SP 800- 37, NIST SP 800-53, CNSSI 1253 desired Familiarity with relevant tools such as eMASS, STIG Viewer, Nessus, ACAS, SCAP, or HBSS desired Strong written and verbal communication skills for reporting assessment findings. Who We Are Today's leading government agencies are putting their trust in Newberry Group, and for good reason. Newberry brings strength to our clients, from the inside out, through: • client intimacy and superior quality, • presence and accountability in our relationships, and • Public sector best practices. Newberry Group is a professional services firm, providing information security compliance, governance, program/project management, and mission-critical project-based consulting to public sector clients nationwide. The strength of our company is a direct reflection of our highly skilled and talented workforce. Benefits and Perks In addition to competitive wages, Newberry Group offers an outstanding benefit package. This includes medical coverage with three plan options, dental and vision coverage, personal time off, paid holidays, paid parental leave, telecommuting if available, retirement savings accounts (Pre-Tax and Roth), flexible and dependent care savings accounts, life insurance, long and short-term disability coverage, tuition and training reimbursement, employee assistance program, and more. The Newberry Group, Inc. is an Equal Opportunity Employer - EEO/AA/Disability/Veterans. Powered by JazzHR 5whc8Lvtfu
Job Description Job Description RiVidium Inc. is seeking a Security Control Assessor who conducts independent comprehensive assessments of the management, operational, and technical security controls and control enhancements employed within or inherited by an information technology (IT) system to determine the overall effectiveness of the controls (as defined in NIST 800-37). TASKS: Manage and approve Accreditation Packages (e.g., ISO/IEC 15026-2). Plan and conduct security authorization reviews and assurance case development for initial installation of systems and networks. Review authorization and assurance documents to confirm that the level of risk is within acceptable limits for each software application, system, and network. Verify that application software/network/system security postures are implemented as stated, document deviations, and recommend required actions to correct those deviations. Develop security compliance processes and/or audits for external services (e.g., cloud service providers, data centers). Establish acceptable limits for the software application, network, or system. Manage Accreditation Packages (e.g., ISO/IEC 15026-2). Perform security reviews, identify gaps in security architecture, and develop a security risk management plan. Perform security reviews and identify security gaps in security architecture resulting in recommendations for inclusion in the risk mitigation strategy. Perform risk analysis (e.g., threat, vulnerability, and probability of occurrence) whenever an application or system undergoes a major change. Provide input to the Risk Management Framework process activities and related documentation (e.g., system life-cycle support plans, concept of operations, operational procedures, and maintenance training materials). Verify and update security documentation reflecting the application/system security design features. Participate in Risk Governance process to provide security risks, mitigations, and input on other technical risk. Ensure that plans of actions and milestones or remediation plans are in place for vulnerabilities identified during risk assessments, audits, inspections, etc. Assure successful implementation and functionality of security requirements and appropriate information technology (IT) policies and procedures that are consistent with the organization's mission and goals. Define and document how the implementation of a new system or new interfaces between systems impacts the security posture of the current environment. Ensure that security design and cybersecurity development activities are properly documented (providing a functional description of security implementation) and updated as necessary. Support necessary compliance activities (e.g., ensure that system security configuration guidelines are followed, compliance monitoring occurs). Ensure that all acquisitions, procurements, and outsourcing efforts address information security requirements consistent with organization goals. Assess the effectiveness of security controls. Assess all the configuration management (change configuration/release management) processes. ABILITIES: Ability to identify systemic security issues based on the analysis of vulnerability and configuration data. Ability to answer questions in a clear and concise manner. Ability to ask clarifying questions. Ability to communicate complex information, concepts, or ideas in a confident and well-organized manner through verbal, written, and/or visual means. Ability to communicate effectively when writing.A0015: Ability to conduct vulnerability scans and recognize vulnerabilities in security systems.A0016: Ability to facilitate small group discussions.A0018: Ability to prepare and present briefings. Ability to produce technical documentation. Ability to design valid and reliable assessments. Ability to analyze test data. Ability to collect, verify, and validate test data. Ability to dissect a problem and examine the interrelationships between data that may appear unrelated. Ability to identify basic common coding flaws at a high level. Ability to translate data and test results into evaluative conclusions. Ability to ensure security practices are followed throughout the acquisition process. Ability to apply collaborative skills and strategies. Ability to apply critical reading/thinking skills. Ability to effectively collaborate via virtual teams. Ability to evaluate information for reliability, validity, and relevance. Ability to evaluate, analyze, and synthesize large quantities of data (which may be fragmented and contradictory) into high quality, fused targeting/intelligence products. Requirements: Bachelor degree or higher from an accredited college or university. Prefer an accredited Computer Science, Cyber Security, Information Technology, Software Engineering, Information Systems, or Computer Engineering degree; or a degree in a Mathematics or Engineering field. IAT/IAM Level 2 certification The annual salary range for this position is $135,000-$140,000. The listed salary range represents a general guideline; however, RiVidium Inc. considers a number of factors when determining base salary offers such as the scope and responsibilities of the position and the candidate's experience, education, skills, and current market conditions. At RiVidium Inc. it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case.
09/15/2026
Full time
Job Description Job Description RiVidium Inc. is seeking a Security Control Assessor who conducts independent comprehensive assessments of the management, operational, and technical security controls and control enhancements employed within or inherited by an information technology (IT) system to determine the overall effectiveness of the controls (as defined in NIST 800-37). TASKS: Manage and approve Accreditation Packages (e.g., ISO/IEC 15026-2). Plan and conduct security authorization reviews and assurance case development for initial installation of systems and networks. Review authorization and assurance documents to confirm that the level of risk is within acceptable limits for each software application, system, and network. Verify that application software/network/system security postures are implemented as stated, document deviations, and recommend required actions to correct those deviations. Develop security compliance processes and/or audits for external services (e.g., cloud service providers, data centers). Establish acceptable limits for the software application, network, or system. Manage Accreditation Packages (e.g., ISO/IEC 15026-2). Perform security reviews, identify gaps in security architecture, and develop a security risk management plan. Perform security reviews and identify security gaps in security architecture resulting in recommendations for inclusion in the risk mitigation strategy. Perform risk analysis (e.g., threat, vulnerability, and probability of occurrence) whenever an application or system undergoes a major change. Provide input to the Risk Management Framework process activities and related documentation (e.g., system life-cycle support plans, concept of operations, operational procedures, and maintenance training materials). Verify and update security documentation reflecting the application/system security design features. Participate in Risk Governance process to provide security risks, mitigations, and input on other technical risk. Ensure that plans of actions and milestones or remediation plans are in place for vulnerabilities identified during risk assessments, audits, inspections, etc. Assure successful implementation and functionality of security requirements and appropriate information technology (IT) policies and procedures that are consistent with the organization's mission and goals. Define and document how the implementation of a new system or new interfaces between systems impacts the security posture of the current environment. Ensure that security design and cybersecurity development activities are properly documented (providing a functional description of security implementation) and updated as necessary. Support necessary compliance activities (e.g., ensure that system security configuration guidelines are followed, compliance monitoring occurs). Ensure that all acquisitions, procurements, and outsourcing efforts address information security requirements consistent with organization goals. Assess the effectiveness of security controls. Assess all the configuration management (change configuration/release management) processes. ABILITIES: Ability to identify systemic security issues based on the analysis of vulnerability and configuration data. Ability to answer questions in a clear and concise manner. Ability to ask clarifying questions. Ability to communicate complex information, concepts, or ideas in a confident and well-organized manner through verbal, written, and/or visual means. Ability to communicate effectively when writing.A0015: Ability to conduct vulnerability scans and recognize vulnerabilities in security systems.A0016: Ability to facilitate small group discussions.A0018: Ability to prepare and present briefings. Ability to produce technical documentation. Ability to design valid and reliable assessments. Ability to analyze test data. Ability to collect, verify, and validate test data. Ability to dissect a problem and examine the interrelationships between data that may appear unrelated. Ability to identify basic common coding flaws at a high level. Ability to translate data and test results into evaluative conclusions. Ability to ensure security practices are followed throughout the acquisition process. Ability to apply collaborative skills and strategies. Ability to apply critical reading/thinking skills. Ability to effectively collaborate via virtual teams. Ability to evaluate information for reliability, validity, and relevance. Ability to evaluate, analyze, and synthesize large quantities of data (which may be fragmented and contradictory) into high quality, fused targeting/intelligence products. Requirements: Bachelor degree or higher from an accredited college or university. Prefer an accredited Computer Science, Cyber Security, Information Technology, Software Engineering, Information Systems, or Computer Engineering degree; or a degree in a Mathematics or Engineering field. IAT/IAM Level 2 certification The annual salary range for this position is $135,000-$140,000. The listed salary range represents a general guideline; however, RiVidium Inc. considers a number of factors when determining base salary offers such as the scope and responsibilities of the position and the candidate's experience, education, skills, and current market conditions. At RiVidium Inc. it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case.
Job Description Job Description: VIATEQ Corporation is looking for a Security Control Assessor (SCA) to support a comprehensive enterprise cybersecurity services program for a federal government client. This position requires the ability to obtain and maintain a Minimum Background Investigation (MBI) or higher, PIV credentials, and all requisite IT access authorizations prior to performing work. Primary work will be performed at the client site in Washington, DC and approved remote/telework locations. This role serves as a key technical contributor responsible for the independent assessment and evaluation of security and privacy controls across the client's enterprise IT portfolio, spanning on-premises, cloud-hosted, and hybrid systems, in support of the agency's Federal Information Security Modernization Act (FISMA) compliance program, Risk Management Framework (RMF) activities, and Ongoing Authorization (OA) initiatives. The ideal candidate is a detail-oriented and technically proficient security assessment professional with demonstrated experience conducting NIST SP 800-53 security and privacy controls assessments, developing Security Assessment Reports (SARs), supporting Authority to Operate (ATO) activities, and executing continuous monitoring assessments across a diverse federal enterprise IT environment. This individual must possess the ability to work independently across complex, multi-technology system boundaries and deliver thorough, accurate, and well-written assessment artifacts that meet rigorous federal documentation standards. The Security Control Assessor will serve as an independent technical evaluator responsible for planning, executing, and reporting on security and privacy controls assessments for assigned systems and services across the client's enterprise IT portfolio. This individual is responsible for assessing the implementation and effectiveness of NIST SP 800-53 security and privacy controls, documenting assessment findings in accordance with NIST SP 800-53A methodologies, producing high-quality assessment artifacts, and supporting the full RMF assessment lifecycle from initial planning through final report delivery and POA&M development. The SCA works closely with ISSOs, system owners, security engineers, and Government stakeholders to ensure assessments are thorough, accurate, and completed within required timelines. Responsibilities: Security & Privacy Controls Assessment Plan, execute, and report on comprehensive security and privacy controls assessments for assigned federal information systems and services, including on-premises, IaaS, PaaS, and SaaS implementations, in accordance with NIST SP 800-53 Rev 5, NIST SP 800-53A Rev 5, and applicable agency implementation procedures. Conduct point-in-time full controls assessments, annual controls assessments, multi-year one-third assessments, and Ongoing Authorization (OA) evaluation assessments in accordance with the agency's assessment schedule and applicable implementation procedures. Develop and deliver draft Security Assessment Plans (SAPs) no less than ten (10) business days prior to beginning each assessment, clearly documenting the assessment scope, boundaries, sampling strategies, test methods, and schedule. Execute NIST SP 800-53A Determine If Statements (DISs) for all in-scope controls, documenting assessment findings to a level of detail sufficient to demonstrate that the implementation of each control objective is validated or not validated, avoiding high-level summary statements and ensuring technical depth across all technology types within the system boundary. Conduct technical controls assessments across all technology types within each system boundary, including Windows and UNIX servers, network devices (routers, switches, Cisco, F5 load balancers), web applications, databases, cloud platforms, and endpoint systems, applying appropriate sampling strategies approved by the Government prior to implementation. Develop Government-approved sampling strategies encompassing all asset types within each system boundary, typically between ten (10) and twenty (20) percent of applicable assets where appropriate, ensuring sampling covers all relevant device types, users, and services. Map identified vulnerabilities and assessment findings to applicable NIST SP 800-53 Rev 5 controls and control families, ensuring accurate and complete linkage between technical findings and corresponding control deficiencies. Produce comprehensive draft and final Security Assessment Reports (SARs) within required timelines, ensuring reports are comprehensive to the scope identified in the SAP, fully aligned to the agency's Governance, Risk, and Compliance (GRC) tool, include visual representation against the NIST Cybersecurity Framework (CSF), and are peer-reviewed for accuracy and grammar prior to submission. Develop draft Plans of Action and Milestones (POA&M) entries for identified control deficiencies, typically using the agency's GRC tool, delivering draft POA&Ms within thirty (30) calendar days from point-in-time assessment kickoff. Develop draft Annual Assessment Reports (AARs) per in-scope system within one-hundred-twenty (120) business days from point-in-time annual assessment kickoff, and deliver draft summary reports for multi-year assessment efforts no later than sixty (60) business days prior to the end of each Fiscal Year. Incorporate all Government feedback into assessment artifacts within five (5) business days of receipt of comments, delivering finalized deliverables that accurately reflect all Government-provided corrections, questions, and recommendations. Ongoing Authorization (OA) Evaluation Support Conduct Ongoing Authorization (OA) controls assessments for systems approved for OA, applying agency-specific OA test procedures that replace traditional NIST SP 800-53A test procedures for OA-approved systems. Execute OA Positive Testing monthly for OA-approved systems, using automated or semi-automated techniques to determine whether controls are operating effectively under normal circumstances, documenting results in the agency GRC tool in accordance with OA implementation procedures. Execute OA Negative Testing annually for OA-approved systems, using automated or semi-automated techniques to determine whether controls respond as expected under abnormal circumstances where misuse is injected to attempt to circumvent the control, coordinating as necessary with penetration testing purple team resources. Assist in the development and submission of OA Playbooks for Government approval, documenting the testing methodology for each OA core control including Test Strategy, Test Design, Test Execution, Results Evaluation, and Visualization components. Conduct OA testing comprehensively across all technology types within each target system's boundary, including sampling across in-scope devices, users, and services, documenting all test results in detail within the agency GRC tool in accordance with applicable OA implementation procedures. Ensure all OA Positive and Negative Testing documentation is peer-reviewed for accuracy and grammar prior to submission to the Government. ISSO Support & Collaboration Collaborate closely with assigned ISSOs to support their development of in-depth technical and operational knowledge about assigned systems, providing assessment expertise, technical guidance, and documentation support as needed. Provide technical support and expertise to ISSOs in the development and maintenance of all security documentation in the ATO package, including System Security Plans (SSPs), Configuration Management Plans (CMPs), Information System Contingency Plans (ISCPs), and other RMF artifacts, ensuring documentation aligns with applicable agency implementation procedures and template requirements. Support ISSOs in reviewing and validating system security documentation for technical accuracy, completeness, and alignment with the system boundary and technology stack, providing specific and actionable feedback to improve documentation quality. Assist ISSOs in ensuring control implementation descriptions within SSPs are written to the required level of technical detail, clearly explaining how each control is implemented across all technologies within the system boundary using specific naming conventions, configurations, and operational procedures rather than high-level general statements. Participate in Enterprise Change Control Board (ECCB) activities as needed, providing security assessment expertise to support the evaluation of proposed system changes and their potential impact on the system's security posture and ATO status. Audit & Compliance Support Support internal and external audit activities for assigned FISMA systems, facilitating meetings and walkthroughs of key cybersecurity capabilities, coordinating with system support personnel, and supplying auditors with requested artifacts and evidence within required timeframes. Ensure audit artifacts are complete, accurate, and delivered on time to avoid repeated requests from auditors, communicating any issues or problems to the Government immediately upon discovery. Support FISMA continuous monitoring activities, including the collection, validation, and submission of system-level FISMA metrics for assigned systems in alignment with federal CIO metrics requirements and agency reporting schedules. Assist in the development and maintenance of automated visualizations and dashboards that reflect the status and effectiveness of security controls for assigned systems, providing continuous visibility into the security posture and compliance status of assigned systems. Support High Value Asset (HVA) assessment activities for designated HVA systems, including vulnerability scanning and remediation validation, monitoring and analysis of relevant audit logs . click apply for full job details
09/15/2026
Full time
Job Description Job Description: VIATEQ Corporation is looking for a Security Control Assessor (SCA) to support a comprehensive enterprise cybersecurity services program for a federal government client. This position requires the ability to obtain and maintain a Minimum Background Investigation (MBI) or higher, PIV credentials, and all requisite IT access authorizations prior to performing work. Primary work will be performed at the client site in Washington, DC and approved remote/telework locations. This role serves as a key technical contributor responsible for the independent assessment and evaluation of security and privacy controls across the client's enterprise IT portfolio, spanning on-premises, cloud-hosted, and hybrid systems, in support of the agency's Federal Information Security Modernization Act (FISMA) compliance program, Risk Management Framework (RMF) activities, and Ongoing Authorization (OA) initiatives. The ideal candidate is a detail-oriented and technically proficient security assessment professional with demonstrated experience conducting NIST SP 800-53 security and privacy controls assessments, developing Security Assessment Reports (SARs), supporting Authority to Operate (ATO) activities, and executing continuous monitoring assessments across a diverse federal enterprise IT environment. This individual must possess the ability to work independently across complex, multi-technology system boundaries and deliver thorough, accurate, and well-written assessment artifacts that meet rigorous federal documentation standards. The Security Control Assessor will serve as an independent technical evaluator responsible for planning, executing, and reporting on security and privacy controls assessments for assigned systems and services across the client's enterprise IT portfolio. This individual is responsible for assessing the implementation and effectiveness of NIST SP 800-53 security and privacy controls, documenting assessment findings in accordance with NIST SP 800-53A methodologies, producing high-quality assessment artifacts, and supporting the full RMF assessment lifecycle from initial planning through final report delivery and POA&M development. The SCA works closely with ISSOs, system owners, security engineers, and Government stakeholders to ensure assessments are thorough, accurate, and completed within required timelines. Responsibilities: Security & Privacy Controls Assessment Plan, execute, and report on comprehensive security and privacy controls assessments for assigned federal information systems and services, including on-premises, IaaS, PaaS, and SaaS implementations, in accordance with NIST SP 800-53 Rev 5, NIST SP 800-53A Rev 5, and applicable agency implementation procedures. Conduct point-in-time full controls assessments, annual controls assessments, multi-year one-third assessments, and Ongoing Authorization (OA) evaluation assessments in accordance with the agency's assessment schedule and applicable implementation procedures. Develop and deliver draft Security Assessment Plans (SAPs) no less than ten (10) business days prior to beginning each assessment, clearly documenting the assessment scope, boundaries, sampling strategies, test methods, and schedule. Execute NIST SP 800-53A Determine If Statements (DISs) for all in-scope controls, documenting assessment findings to a level of detail sufficient to demonstrate that the implementation of each control objective is validated or not validated, avoiding high-level summary statements and ensuring technical depth across all technology types within the system boundary. Conduct technical controls assessments across all technology types within each system boundary, including Windows and UNIX servers, network devices (routers, switches, Cisco, F5 load balancers), web applications, databases, cloud platforms, and endpoint systems, applying appropriate sampling strategies approved by the Government prior to implementation. Develop Government-approved sampling strategies encompassing all asset types within each system boundary, typically between ten (10) and twenty (20) percent of applicable assets where appropriate, ensuring sampling covers all relevant device types, users, and services. Map identified vulnerabilities and assessment findings to applicable NIST SP 800-53 Rev 5 controls and control families, ensuring accurate and complete linkage between technical findings and corresponding control deficiencies. Produce comprehensive draft and final Security Assessment Reports (SARs) within required timelines, ensuring reports are comprehensive to the scope identified in the SAP, fully aligned to the agency's Governance, Risk, and Compliance (GRC) tool, include visual representation against the NIST Cybersecurity Framework (CSF), and are peer-reviewed for accuracy and grammar prior to submission. Develop draft Plans of Action and Milestones (POA&M) entries for identified control deficiencies, typically using the agency's GRC tool, delivering draft POA&Ms within thirty (30) calendar days from point-in-time assessment kickoff. Develop draft Annual Assessment Reports (AARs) per in-scope system within one-hundred-twenty (120) business days from point-in-time annual assessment kickoff, and deliver draft summary reports for multi-year assessment efforts no later than sixty (60) business days prior to the end of each Fiscal Year. Incorporate all Government feedback into assessment artifacts within five (5) business days of receipt of comments, delivering finalized deliverables that accurately reflect all Government-provided corrections, questions, and recommendations. Ongoing Authorization (OA) Evaluation Support Conduct Ongoing Authorization (OA) controls assessments for systems approved for OA, applying agency-specific OA test procedures that replace traditional NIST SP 800-53A test procedures for OA-approved systems. Execute OA Positive Testing monthly for OA-approved systems, using automated or semi-automated techniques to determine whether controls are operating effectively under normal circumstances, documenting results in the agency GRC tool in accordance with OA implementation procedures. Execute OA Negative Testing annually for OA-approved systems, using automated or semi-automated techniques to determine whether controls respond as expected under abnormal circumstances where misuse is injected to attempt to circumvent the control, coordinating as necessary with penetration testing purple team resources. Assist in the development and submission of OA Playbooks for Government approval, documenting the testing methodology for each OA core control including Test Strategy, Test Design, Test Execution, Results Evaluation, and Visualization components. Conduct OA testing comprehensively across all technology types within each target system's boundary, including sampling across in-scope devices, users, and services, documenting all test results in detail within the agency GRC tool in accordance with applicable OA implementation procedures. Ensure all OA Positive and Negative Testing documentation is peer-reviewed for accuracy and grammar prior to submission to the Government. ISSO Support & Collaboration Collaborate closely with assigned ISSOs to support their development of in-depth technical and operational knowledge about assigned systems, providing assessment expertise, technical guidance, and documentation support as needed. Provide technical support and expertise to ISSOs in the development and maintenance of all security documentation in the ATO package, including System Security Plans (SSPs), Configuration Management Plans (CMPs), Information System Contingency Plans (ISCPs), and other RMF artifacts, ensuring documentation aligns with applicable agency implementation procedures and template requirements. Support ISSOs in reviewing and validating system security documentation for technical accuracy, completeness, and alignment with the system boundary and technology stack, providing specific and actionable feedback to improve documentation quality. Assist ISSOs in ensuring control implementation descriptions within SSPs are written to the required level of technical detail, clearly explaining how each control is implemented across all technologies within the system boundary using specific naming conventions, configurations, and operational procedures rather than high-level general statements. Participate in Enterprise Change Control Board (ECCB) activities as needed, providing security assessment expertise to support the evaluation of proposed system changes and their potential impact on the system's security posture and ATO status. Audit & Compliance Support Support internal and external audit activities for assigned FISMA systems, facilitating meetings and walkthroughs of key cybersecurity capabilities, coordinating with system support personnel, and supplying auditors with requested artifacts and evidence within required timeframes. Ensure audit artifacts are complete, accurate, and delivered on time to avoid repeated requests from auditors, communicating any issues or problems to the Government immediately upon discovery. Support FISMA continuous monitoring activities, including the collection, validation, and submission of system-level FISMA metrics for assigned systems in alignment with federal CIO metrics requirements and agency reporting schedules. Assist in the development and maintenance of automated visualizations and dashboards that reflect the status and effectiveness of security controls for assigned systems, providing continuous visibility into the security posture and compliance status of assigned systems. Support High Value Asset (HVA) assessment activities for designated HVA systems, including vulnerability scanning and remediation validation, monitoring and analysis of relevant audit logs . click apply for full job details
Job Description Job Description Description: P-11 Security is seeking a SCA who is responsible for conducting a comprehensive assessment of the management, operational, and technical security controls employed within or inherited by an IS to determine the overall effectiveness of the controls (i.e., the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for the system). SCAs also provide an assessment of the severity of weaknesses or deficiencies discovered in the IS and its environment of operation and recommend corrective actions to address identified vulnerabilities. Responsibilities will cover Collateral, Sensitive Compartmented Information (SCI) and Special Access Program (SAP) activities within the customer's area of responsibility. Performance shall include: Perform oversight of the development, implementation and evaluation of IS security program policy; special emphasis placed upon integration of existing SAP network infrastructure Perform assessment of ISs, based upon the Risk Management Framework (RMF) methodology in accordance with the Joint Special Access Program (SAP) Implementation Guide (JSIG) Advise the Information System Owner (ISO), Information Data Owner (IDO), Program Security Officer (PSO), and the Delegated and/or Authorizing Official (DAO/AO) on any assessment and authorization issues Evaluate Authorization packages and make recommendation to the AO and/or DAO for authorization Evaluate IS threats and vulnerabilities to determine whether additional safeguards are required Advise the Government concerning the impact levels for Confidentiality, Integrity, and Availability for the information on a system Ensure security assessments are completed and results documented and prepare the Security Assessment Report (SAR) for the Authorization boundary Initiate a Plan of Action and Milestones (POA&M) with identified weaknesses for each Authorization Boundaries assessed, based on findings and recommendations from the SAR Evaluate security assessment documentation and provide written recommendations for security authorization to the Government Discuss recommendation for authorization and submit the security authorization package to the AO/DAO Assess proposed changes to Authorization boundaries operating environment and mission needs to determine the continuation to operate. Review and concur with all sanitization and clearing procedures in accordance with Government guidance and/or policy Assist the Government compliance inspections Assist the Government with security incidents that relate to cybersecurity and ensure that the proper and corrective measures have been taken Ensure organization are addressing and conducting all phases of the system development life cycle (SDLC) Evaluate Hardware and Software to determine security impact that it might have on Authorization boundaries Evaluate the effectiveness and implementation of Continuous Monitoring Plans Represent the customer on inspection teams Requirements: Experience: 7 - 9 years related experience Minimum of four (4) years' experience in SAP, SCI or Collateral Information Systems (IS) Security and the implementation of regulations identified in the description of duties. Prior performance in the role of ISSO and ISSM or SCA Education : Bachelor's degree in a related discipline or equivalent experience (4 years) Certifications: Must meet position and certification requirements outlined in DoD Directive 8570.01-M for Information Assurance Technician Level III or Information Assurance Manager Level II within 6 months of the date of hire Security Clearance: Current Top Secret Clearance with SCI Eligibility Eligibility for access to Special Access Program Information Willingness to submit to a Counterintelligence polygraph Other Requirements: Must be able to regularly lift 50lbs
09/15/2026
Full time
Job Description Job Description Description: P-11 Security is seeking a SCA who is responsible for conducting a comprehensive assessment of the management, operational, and technical security controls employed within or inherited by an IS to determine the overall effectiveness of the controls (i.e., the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for the system). SCAs also provide an assessment of the severity of weaknesses or deficiencies discovered in the IS and its environment of operation and recommend corrective actions to address identified vulnerabilities. Responsibilities will cover Collateral, Sensitive Compartmented Information (SCI) and Special Access Program (SAP) activities within the customer's area of responsibility. Performance shall include: Perform oversight of the development, implementation and evaluation of IS security program policy; special emphasis placed upon integration of existing SAP network infrastructure Perform assessment of ISs, based upon the Risk Management Framework (RMF) methodology in accordance with the Joint Special Access Program (SAP) Implementation Guide (JSIG) Advise the Information System Owner (ISO), Information Data Owner (IDO), Program Security Officer (PSO), and the Delegated and/or Authorizing Official (DAO/AO) on any assessment and authorization issues Evaluate Authorization packages and make recommendation to the AO and/or DAO for authorization Evaluate IS threats and vulnerabilities to determine whether additional safeguards are required Advise the Government concerning the impact levels for Confidentiality, Integrity, and Availability for the information on a system Ensure security assessments are completed and results documented and prepare the Security Assessment Report (SAR) for the Authorization boundary Initiate a Plan of Action and Milestones (POA&M) with identified weaknesses for each Authorization Boundaries assessed, based on findings and recommendations from the SAR Evaluate security assessment documentation and provide written recommendations for security authorization to the Government Discuss recommendation for authorization and submit the security authorization package to the AO/DAO Assess proposed changes to Authorization boundaries operating environment and mission needs to determine the continuation to operate. Review and concur with all sanitization and clearing procedures in accordance with Government guidance and/or policy Assist the Government compliance inspections Assist the Government with security incidents that relate to cybersecurity and ensure that the proper and corrective measures have been taken Ensure organization are addressing and conducting all phases of the system development life cycle (SDLC) Evaluate Hardware and Software to determine security impact that it might have on Authorization boundaries Evaluate the effectiveness and implementation of Continuous Monitoring Plans Represent the customer on inspection teams Requirements: Experience: 7 - 9 years related experience Minimum of four (4) years' experience in SAP, SCI or Collateral Information Systems (IS) Security and the implementation of regulations identified in the description of duties. Prior performance in the role of ISSO and ISSM or SCA Education : Bachelor's degree in a related discipline or equivalent experience (4 years) Certifications: Must meet position and certification requirements outlined in DoD Directive 8570.01-M for Information Assurance Technician Level III or Information Assurance Manager Level II within 6 months of the date of hire Security Clearance: Current Top Secret Clearance with SCI Eligibility Eligibility for access to Special Access Program Information Willingness to submit to a Counterintelligence polygraph Other Requirements: Must be able to regularly lift 50lbs
Job Description Job Description Make a difference here. UltraViolet Cyber is a leading platform-enabled unified security operations company providing a comprehensive suite of security operations solutions. Founded and operated by security practitioners with decades of experience, the UltraViolet Cyber security-as-code platform combines technology innovation and human expertise to make advanced real-time cybersecurity accessible for all organizations by eliminating risks of separate red and blue teams. By creating continuously optimized identification, detection, and resilience from today's dynamic threat landscape, UltraViolet Cyber provides both managed and custom-tailored unified security operations solutions to the Fortune 500, Federal Government, and Commercial clients. UltraViolet Cyber is headquartered in McLean, Virginia, with global offices across the U.S. and in India. UltraViolet Cyber is seeking to hire a Senior Security Control Assessor (SCA) to act as an independent evaluator to ensure the effectiveness of management, operational, and technical security controls. The candidate will lead cybersecurity compliance assessments, identify control gaps and vulnerabilities, and recommend risk-mitigation strategies to support enterprise system authorization. What You'll Do: Assessment Execution: Plan and execute comprehensive security control assessments in accordance with frameworks like the Risk Management Framework (RMF) and FISMA. Testing & Evaluation: Review system configurations, evaluate evidence, and perform technical testing (e.g., vulnerability scanning) to validate security posture. Documentation & Reporting: Compile assessment results into Security Assessment Reports (SARs) and generate risk determinations for Authorizing Officials (AOs). Remediation & Tracking: Identify control weaknesses and support the development of Plans of Action and Milestones (POA&Ms). Team Leadership: Guide junior assessors, review deliverables, and coordinate assessment activities with ISSOs, system owners, and stakeholders. What You've Done: US Citizenship is required for this role. Education: Bachelor's degree in cybersecurity, computer science, information systems, or a related field. (Or 6 years of experience equivalency) Experience: 7+ years of hands-on experience in cybersecurity, audit, or compliance, with specialized focus on RMF and NIST 800-series publications. Regulatory Expertise: Deep understanding of statutory guidance such as NIST SP 800-53, NIST SP 800-53A, and FISMA. Certifications: Industry-recognized credentials such as the Certified Information Systems Security Professional (CISSP), Certified Information Systems Auditor (CISA), or Certified Authorization Professional (CAP). Background Investigation: This role requires a Federal background investigation. A current or prior DHS suitability is highly preferred. What We Offer: 401(k), including an employer match of 100% of the first 3% contributed and 50% of the next 2% contributed Medical, Dental, and Vision Insurance (available on the 1st day of the month following your first day of employment) Group Term Life, Short-Term Disability, Long-Term Disability Voluntary Life, Hospital Indemnity, Accident, and/or Critical Illness Participation in the Discretionary Time Off (DTO) Program 11 Paid Holidays Annually UltraViolet Cyber maintains broad salary ranges for its roles in order to account for variations in knowledge, skills, experience, market conditions and locations, as well as reflect our company's differing products, services, industries and lines of business. Candidates are typically placed into the range based on the preceding factors. We sincerely thank all applicants in advance for submitting their interest in this position. We know your time is valuable. UltraViolet Cyber welcomes and encourages diversity in the workplace regardless of race, gender, religion, age, sexual orientation, gender identity, disability, or veteran status. If you want to make an impact, UltraViolet Cyber is the place for you! We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
09/15/2026
Full time
Job Description Job Description Make a difference here. UltraViolet Cyber is a leading platform-enabled unified security operations company providing a comprehensive suite of security operations solutions. Founded and operated by security practitioners with decades of experience, the UltraViolet Cyber security-as-code platform combines technology innovation and human expertise to make advanced real-time cybersecurity accessible for all organizations by eliminating risks of separate red and blue teams. By creating continuously optimized identification, detection, and resilience from today's dynamic threat landscape, UltraViolet Cyber provides both managed and custom-tailored unified security operations solutions to the Fortune 500, Federal Government, and Commercial clients. UltraViolet Cyber is headquartered in McLean, Virginia, with global offices across the U.S. and in India. UltraViolet Cyber is seeking to hire a Senior Security Control Assessor (SCA) to act as an independent evaluator to ensure the effectiveness of management, operational, and technical security controls. The candidate will lead cybersecurity compliance assessments, identify control gaps and vulnerabilities, and recommend risk-mitigation strategies to support enterprise system authorization. What You'll Do: Assessment Execution: Plan and execute comprehensive security control assessments in accordance with frameworks like the Risk Management Framework (RMF) and FISMA. Testing & Evaluation: Review system configurations, evaluate evidence, and perform technical testing (e.g., vulnerability scanning) to validate security posture. Documentation & Reporting: Compile assessment results into Security Assessment Reports (SARs) and generate risk determinations for Authorizing Officials (AOs). Remediation & Tracking: Identify control weaknesses and support the development of Plans of Action and Milestones (POA&Ms). Team Leadership: Guide junior assessors, review deliverables, and coordinate assessment activities with ISSOs, system owners, and stakeholders. What You've Done: US Citizenship is required for this role. Education: Bachelor's degree in cybersecurity, computer science, information systems, or a related field. (Or 6 years of experience equivalency) Experience: 7+ years of hands-on experience in cybersecurity, audit, or compliance, with specialized focus on RMF and NIST 800-series publications. Regulatory Expertise: Deep understanding of statutory guidance such as NIST SP 800-53, NIST SP 800-53A, and FISMA. Certifications: Industry-recognized credentials such as the Certified Information Systems Security Professional (CISSP), Certified Information Systems Auditor (CISA), or Certified Authorization Professional (CAP). Background Investigation: This role requires a Federal background investigation. A current or prior DHS suitability is highly preferred. What We Offer: 401(k), including an employer match of 100% of the first 3% contributed and 50% of the next 2% contributed Medical, Dental, and Vision Insurance (available on the 1st day of the month following your first day of employment) Group Term Life, Short-Term Disability, Long-Term Disability Voluntary Life, Hospital Indemnity, Accident, and/or Critical Illness Participation in the Discretionary Time Off (DTO) Program 11 Paid Holidays Annually UltraViolet Cyber maintains broad salary ranges for its roles in order to account for variations in knowledge, skills, experience, market conditions and locations, as well as reflect our company's differing products, services, industries and lines of business. Candidates are typically placed into the range based on the preceding factors. We sincerely thank all applicants in advance for submitting their interest in this position. We know your time is valuable. UltraViolet Cyber welcomes and encourages diversity in the workplace regardless of race, gender, religion, age, sexual orientation, gender identity, disability, or veteran status. If you want to make an impact, UltraViolet Cyber is the place for you! We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
Job Description Job Description Dark Wolf Solutions is seeking Security Control Assessor/Representatives (SCA/Rs) to lead security control assessments across high-priority projects. Working at the intersection of cybersecurity engineering, cloud architecture, and DevSecOps prototyping, you will evaluate security controls for cutting-edge AI/LLM technologies across multiple classification levels. This position is ideal for a pragmatic cloud assessor or SCAR who excels in fast-paced DevSecOps environments, understands AWS cloud security, and is eager to shape the cybersecurity posture of next-generation DoD AI capabilities.This position will be based out of Arlington, VA. Additional responsibilities include: Key Responsibilities Execute formal SCA/R duties. Lead security assessment efforts, establishing reusable security playbooks and assessment frameworks for rapid AI deployment into enterprise workflows. Evaluate technical control effectiveness across AWS cloud infrastructure, DevSecOps pipelines, microservices, containerized workloads, and GenAI/LLM application stacks. Partner directly with cybersecurity engineering and DevSecOps prototyping teams to integrate security controls early in the development lifecycle. Review, author, and maintain assessment packages-including System Security Plans (SSPs), Security Assessment Plans (SAPs), Security Assessment Reports (SARs), and POA&Ms-tailored to rapid prototyping and AI systems. Assess technical security risks specific to AI/LLM implementations, such as API exposure, vector database access controls, model integration surface area, and software supply chain dependencies. Support continuous monitoring (ConMon), technical risk evaluations, and cloud architecture reviews across multi-tenant, multi-classification environments. Coordinate with Authorizing Officials (AOs), program managers, and engineering leads to deliver decision-ready risk briefings and ATO recommendations. Provide technical input and oversight for cybersecurity engineering and penetration testing activities across prototype projects. Required Qualifications Active Top Secret security clearance Current DoD 8570/8140 IAM Level II or Level III certification (e.g., Security+, CySA+, CISM, CISSP, CCISO, CAP/CISC) 3-5+ years of experience conducting security control assessments, compliance testing, or A&A/RMF activities for DoD or federal information systems Solid operational understanding of core AWS cloud services (EC2, S3, IAM, VPCs, Security Groups, Security Hub) and how security controls function within cloud-native and CI/CD pipeline environments. Strong working knowledge of NIST SP 800-53 (Rev. 4/5), NIST SP 800-37 (RMF), DoD Cloud Computing SRG, and FedRAMP baselines. Demonstrated experience writing and evaluating core RMF artifacts (SSPs, SAPs, SARs, POA&Ms) Exceptional written and verbal communication skills, with the ability to articulate technical risk clearly to executive stakeholders, Authorizing Officials, and engineering teams. Hands-on experience navigating government GRC repositories, such as eMASS or XACTA. Desired Qualifications Hands-on experience mapping security controls to the NIST AI Risk Management Framework (AI RMF), the OWASP Top 10 for LLM Applications, or the DoD Responsible AI (RAI) Guidelines. Familiarity evaluating secure design patterns for autonomous AI Agents (e.g., tool-calling permissions, sandboxing agent execution environments, prompt boundaries, and ReAct/LangGraph architectures). Experience assessing cloud-managed AI ecosystems and foundation model platforms (e.g., AWS Bedrock, AWS SageMaker, Hugging Face Enterprise, or self-hosted open-source models). Understanding of data protection, access controls, and boundary security for RAG pipelines and vector databases (e.g., OpenSearch Vector Engine, Pinecone, Milvus, or PostgreSQL pgvector). Familiarity evaluating risks unique to LLMs-including prompt injection, data poisoning, model inversion, insecure output handling, and open-source supply chain vulnerabilities in AI libraries (PyTorch, LangChain, LlamaIndex). Exposure to LLM guardrail platforms, evaluation frameworks, or AI security tools (e.g., Promptfoo, Garak, Giskard, NeMo Guardrails) used to test model robustness and output safety. Experience with cATO methodologies, Infrastructure as Code (IaC) templates (Terraform, CloudFormation), and container security (AWS EKS/ECS, Docker). Active AWS Certifications (e.g., AWS Certified Security - Specialty or AWS Certified Solutions Architect). Background or familiarity with offensive security, penetration testing The salary range for this position is estimated to be between $135,000.00 - $150,000.00, commensurate on experience and technical skillset. We are proud to be an EEO/AA employer Minorities/Women/Veterans/Disabled and other protected categories. In compliance with federal law, all persons hired will be required to verify identity, confirm US Citizenship, and complete the required employment eligibility verification upon hire. We are strictly looking for direct, full-time W2 employees. We do not engage with third-party staffing agencies, C2C, or 1099 independent contractors for this role.
09/15/2026
Full time
Job Description Job Description Dark Wolf Solutions is seeking Security Control Assessor/Representatives (SCA/Rs) to lead security control assessments across high-priority projects. Working at the intersection of cybersecurity engineering, cloud architecture, and DevSecOps prototyping, you will evaluate security controls for cutting-edge AI/LLM technologies across multiple classification levels. This position is ideal for a pragmatic cloud assessor or SCAR who excels in fast-paced DevSecOps environments, understands AWS cloud security, and is eager to shape the cybersecurity posture of next-generation DoD AI capabilities.This position will be based out of Arlington, VA. Additional responsibilities include: Key Responsibilities Execute formal SCA/R duties. Lead security assessment efforts, establishing reusable security playbooks and assessment frameworks for rapid AI deployment into enterprise workflows. Evaluate technical control effectiveness across AWS cloud infrastructure, DevSecOps pipelines, microservices, containerized workloads, and GenAI/LLM application stacks. Partner directly with cybersecurity engineering and DevSecOps prototyping teams to integrate security controls early in the development lifecycle. Review, author, and maintain assessment packages-including System Security Plans (SSPs), Security Assessment Plans (SAPs), Security Assessment Reports (SARs), and POA&Ms-tailored to rapid prototyping and AI systems. Assess technical security risks specific to AI/LLM implementations, such as API exposure, vector database access controls, model integration surface area, and software supply chain dependencies. Support continuous monitoring (ConMon), technical risk evaluations, and cloud architecture reviews across multi-tenant, multi-classification environments. Coordinate with Authorizing Officials (AOs), program managers, and engineering leads to deliver decision-ready risk briefings and ATO recommendations. Provide technical input and oversight for cybersecurity engineering and penetration testing activities across prototype projects. Required Qualifications Active Top Secret security clearance Current DoD 8570/8140 IAM Level II or Level III certification (e.g., Security+, CySA+, CISM, CISSP, CCISO, CAP/CISC) 3-5+ years of experience conducting security control assessments, compliance testing, or A&A/RMF activities for DoD or federal information systems Solid operational understanding of core AWS cloud services (EC2, S3, IAM, VPCs, Security Groups, Security Hub) and how security controls function within cloud-native and CI/CD pipeline environments. Strong working knowledge of NIST SP 800-53 (Rev. 4/5), NIST SP 800-37 (RMF), DoD Cloud Computing SRG, and FedRAMP baselines. Demonstrated experience writing and evaluating core RMF artifacts (SSPs, SAPs, SARs, POA&Ms) Exceptional written and verbal communication skills, with the ability to articulate technical risk clearly to executive stakeholders, Authorizing Officials, and engineering teams. Hands-on experience navigating government GRC repositories, such as eMASS or XACTA. Desired Qualifications Hands-on experience mapping security controls to the NIST AI Risk Management Framework (AI RMF), the OWASP Top 10 for LLM Applications, or the DoD Responsible AI (RAI) Guidelines. Familiarity evaluating secure design patterns for autonomous AI Agents (e.g., tool-calling permissions, sandboxing agent execution environments, prompt boundaries, and ReAct/LangGraph architectures). Experience assessing cloud-managed AI ecosystems and foundation model platforms (e.g., AWS Bedrock, AWS SageMaker, Hugging Face Enterprise, or self-hosted open-source models). Understanding of data protection, access controls, and boundary security for RAG pipelines and vector databases (e.g., OpenSearch Vector Engine, Pinecone, Milvus, or PostgreSQL pgvector). Familiarity evaluating risks unique to LLMs-including prompt injection, data poisoning, model inversion, insecure output handling, and open-source supply chain vulnerabilities in AI libraries (PyTorch, LangChain, LlamaIndex). Exposure to LLM guardrail platforms, evaluation frameworks, or AI security tools (e.g., Promptfoo, Garak, Giskard, NeMo Guardrails) used to test model robustness and output safety. Experience with cATO methodologies, Infrastructure as Code (IaC) templates (Terraform, CloudFormation), and container security (AWS EKS/ECS, Docker). Active AWS Certifications (e.g., AWS Certified Security - Specialty or AWS Certified Solutions Architect). Background or familiarity with offensive security, penetration testing The salary range for this position is estimated to be between $135,000.00 - $150,000.00, commensurate on experience and technical skillset. We are proud to be an EEO/AA employer Minorities/Women/Veterans/Disabled and other protected categories. In compliance with federal law, all persons hired will be required to verify identity, confirm US Citizenship, and complete the required employment eligibility verification upon hire. We are strictly looking for direct, full-time W2 employees. We do not engage with third-party staffing agencies, C2C, or 1099 independent contractors for this role.