it job board logo
  • Home
  • Find IT Jobs
  • Register CV
  • Register as Employer
  • Contact us
  • Career Advice
  • Recruiting? Post a job
  • Sign in
  • Sign up
  • Home
  • Find IT Jobs
  • Register CV
  • Register as Employer
  • Contact us
  • Career Advice
Sorry, that job is no longer available. Here are some results that may be similar to the job you were looking for.

38 jobs found

Email me jobs like this
Refine Search
Current Search
security control assessor
Security Control Assessor Representative (SCAR)
Astrion El Segundo, California
Job Description Job Description Overview Senior Cybersecurity Engineer (SCAR) Location : El Segundo, CA Job Status: Full time SALARY RANGE: Estimated $160,000 + annually depending on experience, certifications, and qualifications Clearance Required: Active DoD TS/SCI Astrion is seeking a Senior Cybersecurity Engineer SME to join our prime contract supporting STS-3 in El Segundo, CA. This role will provide direct Assessment & Authorization (A&A) support to the Space Systems Command Authorizing Officia and Security Conrol Assessor (SCA), ensuring the secure operations of enterprise networks, mission-critical systems, and sensitive data across Space Systems Command (RDT&E) Authorizing Official (AO) subordinate enclave. You will play a hands-on role in Cybersecurity Analysis, Engineering, and Risk Management Framework (RMF) compliance, and Enterprise policy driving mission assurance for some of the nation's most important space systems. REQUIRED QUALIFICATIONS / SKILLS 15+ years of cybersecurity experience supporting USSF, DoD, or related federal organizations. Familiarity with Risk Management Framework (RMF) protocols. Knowledge of USSF A&A procedures with hands-on experience with eMASS Active DoD TS/SCI clearance (with current investigation). CompTIA Security+ or equivalent DoD 8570/8140 IAT/IAM certification. PREFERRED QUALIFICATIONS / SKILLS Prior SCA / SCAR / ASCA experience within DoW and USSF. CISSP, GIAC, or equivalent advanced cybersecurity certification. Strong organizational, interpersonal, and communication skills with attention to detail. Technical MA or MS degree Advanced skills in Microsoft Word, Excel, PowerPoint, and Outlook. RESPONSIBILITIES Support the Authorizing Official and Security Control Assessor by ensuring adherence to the DoD RMF process, driving cyber hardening efforts, and tracking progress along the Road to ATO. Support A&A activities and provide cybersecurity engineering expertise for enterprise mission systems. Develop, update, and manage Enterprise Mission Assurance Support Service (eMASS) entries and coordinate A&A packages in accordance with DoDI 8510.01 (RMF). Maintain and report on C&A schedules, package status, and system registrations in ITIPS (formerly EITDR) in compliance with FISMA. Review and refine certification policies, procedures, and reports for new and evolving cyber system requirements. Conduct research and analysis to assess the impact of new DoD, USSF, DIA, and DISA cybersecurity directives. Support Vulnerability Management System (VMS) processes by documenting, tracking, and closing compliance findings. Contribute to Security Test & Evaluation (ST&E) efforts, penetration testing, and validation of cybersecurity controls. Revalidate cyber and IA controls for accredited systems and recommend improvements to strengthen mission assurance. Assess policy changes from higher headquarters and determine impact on current mission system security posture. Travel is required during onsite assessments.
09/20/2026
Full time
Job Description Job Description Overview Senior Cybersecurity Engineer (SCAR) Location : El Segundo, CA Job Status: Full time SALARY RANGE: Estimated $160,000 + annually depending on experience, certifications, and qualifications Clearance Required: Active DoD TS/SCI Astrion is seeking a Senior Cybersecurity Engineer SME to join our prime contract supporting STS-3 in El Segundo, CA. This role will provide direct Assessment & Authorization (A&A) support to the Space Systems Command Authorizing Officia and Security Conrol Assessor (SCA), ensuring the secure operations of enterprise networks, mission-critical systems, and sensitive data across Space Systems Command (RDT&E) Authorizing Official (AO) subordinate enclave. You will play a hands-on role in Cybersecurity Analysis, Engineering, and Risk Management Framework (RMF) compliance, and Enterprise policy driving mission assurance for some of the nation's most important space systems. REQUIRED QUALIFICATIONS / SKILLS 15+ years of cybersecurity experience supporting USSF, DoD, or related federal organizations. Familiarity with Risk Management Framework (RMF) protocols. Knowledge of USSF A&A procedures with hands-on experience with eMASS Active DoD TS/SCI clearance (with current investigation). CompTIA Security+ or equivalent DoD 8570/8140 IAT/IAM certification. PREFERRED QUALIFICATIONS / SKILLS Prior SCA / SCAR / ASCA experience within DoW and USSF. CISSP, GIAC, or equivalent advanced cybersecurity certification. Strong organizational, interpersonal, and communication skills with attention to detail. Technical MA or MS degree Advanced skills in Microsoft Word, Excel, PowerPoint, and Outlook. RESPONSIBILITIES Support the Authorizing Official and Security Control Assessor by ensuring adherence to the DoD RMF process, driving cyber hardening efforts, and tracking progress along the Road to ATO. Support A&A activities and provide cybersecurity engineering expertise for enterprise mission systems. Develop, update, and manage Enterprise Mission Assurance Support Service (eMASS) entries and coordinate A&A packages in accordance with DoDI 8510.01 (RMF). Maintain and report on C&A schedules, package status, and system registrations in ITIPS (formerly EITDR) in compliance with FISMA. Review and refine certification policies, procedures, and reports for new and evolving cyber system requirements. Conduct research and analysis to assess the impact of new DoD, USSF, DIA, and DISA cybersecurity directives. Support Vulnerability Management System (VMS) processes by documenting, tracking, and closing compliance findings. Contribute to Security Test & Evaluation (ST&E) efforts, penetration testing, and validation of cybersecurity controls. Revalidate cyber and IA controls for accredited systems and recommend improvements to strengthen mission assurance. Assess policy changes from higher headquarters and determine impact on current mission system security posture. Travel is required during onsite assessments.
Security Control Assessor II (SCA II)
Targeted Solutions, LLC Arlington, Virginia
Job Description Job Description Security Control Accessor II REQ-26-J-0055 The SCA is responsible for conducting a comprehensive assessment of the management, operational, and technical security controls employed within or inherited by an IS to determine the overall effectiveness of the controls (i.e., the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for the system). SCAs also provide an assessment of the severity of weaknesses or deficiencies discovered in the IS and its environment of operation and recommend corrective actions to address identified vulnerabilities. Responsibilities will cover Collateral, Sensitive Compartmented Information (SCI) and Special Access Program (SAP) activities within the customer's area of responsibility. Performance shall include: Perform oversight of the development, implementation and evaluation of IS security program policy; special emphasis placed upon integration of existing SAP network infrastructure. Perform assessment of ISs, based upon the Risk Management Framework (RMF) methodology in accordance with the Joint Special Access Program (SAP) Implementation Guide (JSIG). Advise the Information System Owner (ISO), Information Data Owner (IDO), Program Security. Officer (PSO), and the Delegated and/or Authorizing Official (DAO/AO) on any assessment and authorization issues. Evaluate Authorization packages and make recommendation to the AO and/or DAO for authorization. Evaluate IS threats and vulnerabilities to determine whether additional safeguards are required. Advise the Government concerning the impact levels for Confidentiality, Integrity, and Availability for the information on a system. Ensure security assessments are completed and results documented and prepare the Security Assessment Report (SAR) for the Authorization boundary. Initiate a Plan of Action and Milestones (POA&M) with identified weaknesses for each Authorization Boundaries assessed, based on findings and recommendations from the SAR. Evaluate security assessment documentation and provide written recommendations for security authorization to the Government. Discuss recommendation for authorization and submit the security authorization package to the AO/DAO Assess proposed changes to Authorization boundaries operating environment and mission needs to determine the continuation to operate. Review and concur with all sanitizations and clearing procedures in accordance with Government guidance and/or policy. Assist the Government compliance inspections. Assist the Government with security incidents that relate to cybersecurity and ensure that the proper and corrective measures have been taken. Ensure organization are addressing and conducting all phases of the system development life cycle (SDLC). Evaluate Hardware and Software to determine security impact that it might have on Authorization boundaries. Evaluate the effectiveness and implementation of Continuous Monitoring Plans. Represent the customer on inspection teams. EDUCATION: Bachelor's degree or equivalent experience (4 years) CLEARANCE: Top-Secret w/SCI Eligibility MANDATORY: 7-9 years related experience; 4+ years' experience in SAP, SCI, or Collateral Information Systems (S) security and implantation of regulations identified in the description of duties; Prior performance in the role of ISSO and ISSM or SCA; TRAINING: IAM Level II (in lieu of IAT Level III) BENEFITS: We offer a competitive compensation package including a generous PTO and Flexible holiday package, tax-free healthcare cost reimbursement, and an immediate vesting 401K with 4% matching.
09/20/2026
Full time
Job Description Job Description Security Control Accessor II REQ-26-J-0055 The SCA is responsible for conducting a comprehensive assessment of the management, operational, and technical security controls employed within or inherited by an IS to determine the overall effectiveness of the controls (i.e., the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for the system). SCAs also provide an assessment of the severity of weaknesses or deficiencies discovered in the IS and its environment of operation and recommend corrective actions to address identified vulnerabilities. Responsibilities will cover Collateral, Sensitive Compartmented Information (SCI) and Special Access Program (SAP) activities within the customer's area of responsibility. Performance shall include: Perform oversight of the development, implementation and evaluation of IS security program policy; special emphasis placed upon integration of existing SAP network infrastructure. Perform assessment of ISs, based upon the Risk Management Framework (RMF) methodology in accordance with the Joint Special Access Program (SAP) Implementation Guide (JSIG). Advise the Information System Owner (ISO), Information Data Owner (IDO), Program Security. Officer (PSO), and the Delegated and/or Authorizing Official (DAO/AO) on any assessment and authorization issues. Evaluate Authorization packages and make recommendation to the AO and/or DAO for authorization. Evaluate IS threats and vulnerabilities to determine whether additional safeguards are required. Advise the Government concerning the impact levels for Confidentiality, Integrity, and Availability for the information on a system. Ensure security assessments are completed and results documented and prepare the Security Assessment Report (SAR) for the Authorization boundary. Initiate a Plan of Action and Milestones (POA&M) with identified weaknesses for each Authorization Boundaries assessed, based on findings and recommendations from the SAR. Evaluate security assessment documentation and provide written recommendations for security authorization to the Government. Discuss recommendation for authorization and submit the security authorization package to the AO/DAO Assess proposed changes to Authorization boundaries operating environment and mission needs to determine the continuation to operate. Review and concur with all sanitizations and clearing procedures in accordance with Government guidance and/or policy. Assist the Government compliance inspections. Assist the Government with security incidents that relate to cybersecurity and ensure that the proper and corrective measures have been taken. Ensure organization are addressing and conducting all phases of the system development life cycle (SDLC). Evaluate Hardware and Software to determine security impact that it might have on Authorization boundaries. Evaluate the effectiveness and implementation of Continuous Monitoring Plans. Represent the customer on inspection teams. EDUCATION: Bachelor's degree or equivalent experience (4 years) CLEARANCE: Top-Secret w/SCI Eligibility MANDATORY: 7-9 years related experience; 4+ years' experience in SAP, SCI, or Collateral Information Systems (S) security and implantation of regulations identified in the description of duties; Prior performance in the role of ISSO and ISSM or SCA; TRAINING: IAM Level II (in lieu of IAT Level III) BENEFITS: We offer a competitive compensation package including a generous PTO and Flexible holiday package, tax-free healthcare cost reimbursement, and an immediate vesting 401K with 4% matching.
Cyber Security Controls Assessor
Pivot Point Solutions Acton, California
Job Description Job Description Pivot Point Solutions Pivot Point Solutions is a California-based technology consulting firm that specializes in delivering IT solutions and support for the construction and utility industries. We partner with organizations across the state to provide reliable technology services that improve operational efficiency, enhance project delivery, and support critical business systems. Our team understands the unique technology challenges facing construction and utility organizations, from field operations and infrastructure projects to enterprise applications and cybersecurity. By combining industry expertise with responsive service, we help clients modernize their technology environments, streamline workflows, and maintain secure, reliable IT systems that support long-term growth. Job Overview Title: Cyber Security Controls Assessor Sector: Information Technology / Cybersecurity Seniority: Mid to Senior Level Location: California (Hybrid) Job Type: Contract Contract Length: 6+ Months Compensation: $104K - $145K About the Role PPS is seeking a Cyber Security Controls Assessor to support the protection of critical energy infrastructure through the assessment and validation of cybersecurity controls across enterprise and operational technology (OT) environments. This role evaluates compliance with cybersecurity policies, regulatory requirements, and industry standards to ensure the confidentiality, integrity, and availability of systems supporting electric and gas utility operations. The ideal candidate brings strong experience in security assessments, risk management, compliance, and control validation, with a focus on protecting critical infrastructure and supporting regulatory obligations. Key Responsibilities Conduct cybersecurity control assessments for enterprise IT, cloud, and OT/industrial control system environments Evaluate security controls against NIST CSF, NIST 800-53, NERC CIP, CIS Controls, and security policies Identify security risks, control deficiencies, and compliance gaps, and recommend corrective actions Prepare assessment reports detailing findings, risk ratings, remediation recommendations, and control effectiveness Partner with cybersecurity, engineering, IT, OT, compliance, and business stakeholders on risk identification and management Validate implementation and effectiveness of security controls for new projects, system upgrades, and technology deployments Support internal audits, regulatory reviews, and compliance initiatives related to critical infrastructure protection Track remediation activities and validate closure of cybersecurity findings Maintain assessment methodologies, standards, and procedures supporting cybersecurity programs Mentor junior assessors and contribute to continuous improvement initiatives within the Cybersecurity Risk & Compliance team Qualifications Required: Bachelor's degree in Cybersecurity, Information Security, Computer Science, Engineering, IT, or related field; or equivalent experience 5+ years of experience in cybersecurity, risk management, compliance, audit, or security controls assessment Experience performing security assessments and evaluating cybersecurity controls Knowledge of cybersecurity frameworks such as NIST CSF, NIST 800-53, CIS Controls, and risk management methodologies Experience with regulatory compliance programs and audit support Strong analytical, communication, and technical documentation skills Ability to communicate security risks and recommendations to technical and non-technical stakeholders Preferred: Experience within electric utilities, critical infrastructure, energy, or other regulated industries Knowledge of NERC CIP standards and compliance requirements Experience assessing OT, SCADA, ICS, or energy management systems Familiarity with cloud security environments (Azure, AWS) Experience with GRC platforms Professional certifications: CISSP, CISA, CRISC, GICSP, Security+, or equivalent Work Environment Standard office/field environment supporting critical infrastructure operations
09/20/2026
Full time
Job Description Job Description Pivot Point Solutions Pivot Point Solutions is a California-based technology consulting firm that specializes in delivering IT solutions and support for the construction and utility industries. We partner with organizations across the state to provide reliable technology services that improve operational efficiency, enhance project delivery, and support critical business systems. Our team understands the unique technology challenges facing construction and utility organizations, from field operations and infrastructure projects to enterprise applications and cybersecurity. By combining industry expertise with responsive service, we help clients modernize their technology environments, streamline workflows, and maintain secure, reliable IT systems that support long-term growth. Job Overview Title: Cyber Security Controls Assessor Sector: Information Technology / Cybersecurity Seniority: Mid to Senior Level Location: California (Hybrid) Job Type: Contract Contract Length: 6+ Months Compensation: $104K - $145K About the Role PPS is seeking a Cyber Security Controls Assessor to support the protection of critical energy infrastructure through the assessment and validation of cybersecurity controls across enterprise and operational technology (OT) environments. This role evaluates compliance with cybersecurity policies, regulatory requirements, and industry standards to ensure the confidentiality, integrity, and availability of systems supporting electric and gas utility operations. The ideal candidate brings strong experience in security assessments, risk management, compliance, and control validation, with a focus on protecting critical infrastructure and supporting regulatory obligations. Key Responsibilities Conduct cybersecurity control assessments for enterprise IT, cloud, and OT/industrial control system environments Evaluate security controls against NIST CSF, NIST 800-53, NERC CIP, CIS Controls, and security policies Identify security risks, control deficiencies, and compliance gaps, and recommend corrective actions Prepare assessment reports detailing findings, risk ratings, remediation recommendations, and control effectiveness Partner with cybersecurity, engineering, IT, OT, compliance, and business stakeholders on risk identification and management Validate implementation and effectiveness of security controls for new projects, system upgrades, and technology deployments Support internal audits, regulatory reviews, and compliance initiatives related to critical infrastructure protection Track remediation activities and validate closure of cybersecurity findings Maintain assessment methodologies, standards, and procedures supporting cybersecurity programs Mentor junior assessors and contribute to continuous improvement initiatives within the Cybersecurity Risk & Compliance team Qualifications Required: Bachelor's degree in Cybersecurity, Information Security, Computer Science, Engineering, IT, or related field; or equivalent experience 5+ years of experience in cybersecurity, risk management, compliance, audit, or security controls assessment Experience performing security assessments and evaluating cybersecurity controls Knowledge of cybersecurity frameworks such as NIST CSF, NIST 800-53, CIS Controls, and risk management methodologies Experience with regulatory compliance programs and audit support Strong analytical, communication, and technical documentation skills Ability to communicate security risks and recommendations to technical and non-technical stakeholders Preferred: Experience within electric utilities, critical infrastructure, energy, or other regulated industries Knowledge of NERC CIP standards and compliance requirements Experience assessing OT, SCADA, ICS, or energy management systems Familiarity with cloud security environments (Azure, AWS) Experience with GRC platforms Professional certifications: CISSP, CISA, CRISC, GICSP, Security+, or equivalent Work Environment Standard office/field environment supporting critical infrastructure operations
Specialist, Information System Security III (SISS3)
Armada Ltd Philadelphia, Pennsylvania
Job Description Job Description Type: Full Time Location: Philadelphia, PA Overtime Exempt: Exempt Reports To: ARMADA HQ Travel Required: Yes Security Clearance Required: Active Secret Security Clearance CONTINGENT UPON AWARD Duties & Responsibilities: Specialist, Information System Security III (SISS3) will conduct risk and vulnerability assessments of planned and installed systems to identify vulnerabilities, risks and protection needs; conduct systems security evaluation, audits, and reviews; determine the residual risk of a package based on package content and assessment results and documenting for the Security Controls Assessor's (SCA) and higher level review. Execute Security Assessment Plans (SAPs) by conducting on-site testing for afloat and PIT ashore systems. Examples include executing STIGs, SRGs, ACAS scanning, and applying patches assets to obtain cybersecurity compliance and remediate vulnerabilities. Specialist, Information System Security III (SISS3) will conduct systems security reviews, audits, or evaluations, as appropriate, to ensure accreditation documents are accurate and represent the current risk posture of the system. Perform analysis of logs, events, and reporting of various data collections tools including: vulnerability monitoring via Assured Compliance Assessment System (ACAS) and related tools, Host Based Security Systems (HBSS), web content filters, Security Information and event management (SIEM), firewall systems, network devices, server devices, workstations, and intrusion detection and prevention systems (ID/PS). Specialist, Information System Security III (SISS3) will assess impacts from observed risks and report via the Cybersecurity Program chain of command. Executing Security Assessment Plans (SAPs) by conducting on-site testing for afloat and PIT ashore systems. Examples include executing STIGs, SRGs, ACAS scanning, and applying patches assets to obtain cybersecurity compliance and remediate vulnerabilities. Perform the evaluation of system administrator, security engineer, and/or system owner proposed corrections to ensure compliance and best-fit solution. Specialist, Information System Security III (SISS3) will present and submit data to management, develop reports, and produce procedural documentation in a comprehensive and cohesive manner. Perform risk management and security engineering for Research, Development, Testing, and Evaluation (RDT&E) RMF Afloat systems include Information Assurance Vulnerability Management (IAVM) support, remediation, patching, scanning and associated boundary maintenance. Specialist, Information System Security III (SISS3) will document residual risks in a plan of actions and milestones formatted in compliance with the current package system, currently eMASS. Specialist, Information System Security III (SISS3) will maintain current vulnerability scan data and residual risk plan of actions and milestones in Vulnerability Remediation Asset Manager (VRAM). Manage, attend, and support configuration control board practices. Create and verify the accuracy of POA&Ms/RARs as identified by vulnerability actual test results. Specialist, Information System Security III (SISS3) shall write technical documentation such as user manuals, reports, documentation, policies, presentations, Plan of Action and Milestones (POA&Ms), risk assessments, proposals, outlines, and summaries in support of both ashore and afloat systems across multiple platforms. Support developing of technical documents across multiple platforms including configuration management, milestone, issue tracking, web site content management and RMF documentation. Specialist, Information System Security III (SISS3) may be required to travel CONUS (any state in USA) and OCONUS (primarily Japan, and any country in Europe). The estimated number of trips is 14 per year (estimated 25%-30% travel). Other duties as assigned. Knowledge, Skills, and Abilities (KSAs): Ability to travel CONUS (any state in USA) and OCONUS (primarily Japan, and any country in Europe). Proficient in Microsoft Windows Operating System Administration, including Windows 11, Windows 10, Windows 7, and Windows XP (at a minimum). Ability to work as a team member, communicate, perform office functions and use office tools, customer focused and deliver exceptional performance. Possess excellent organizational and file management skills and the ability to plan and execute administrative work with little supervision. Possess excellent oral and written communication skills. Required Certifications: Minimum of one (1) IAT Level II listed certificate required: CompTIA Security+ (CE) CompTIA CySA+ GIAC Security Essentials (GSEC) ISC SSCP (Systems Security Certified Practitioner) Minimum/General Experience: Five (5) years of experience in the following: Cybersecurity, Engineering, Test and Evaluation (T&E) or Authorization and Assessment (A&A) (formerly C&A) related field. Information Assurance tools such as Defense Information Systems Agency (DISA) Enterprise Mission Assurance Support Service (eMASS), Assured Compliance Assessment Solution (ACAS). Command line interface, PowerShell, and performing automated tasking through use of code. Minimum Education: College degree in any technical discipline from an accredited college or university. Disclaimer: The above information has been designed to indicate the general nature and level of work to be performed. It is not designed to contain or be interpreted as a comprehensive inventory of all duties, responsibilities, and qualifications required of the contractor assigned to this position. Applying: If you feel you have the knowledge, skills and abilities for this position visit our careers page at . Special Notes: Relocation is not available for these jobs ARMADA provides equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion, gender, sexual orientation, gender identity or expression, national origin, age, disability, genetic information, marital status, amnesty, or status as a covered veteran in accordance with applicable federal, state and local laws. ARMADA complies with applicable state and local laws governing non-discrimination in employment in every location in which the company has facilities. This policy applies to all terms and conditions of employment, including, but not limited to, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation, and training. Must be able to successfully pass a background check, and pre-employment drug testing. Job offers are contingent upon results of background check and drug testing.
09/20/2026
Full time
Job Description Job Description Type: Full Time Location: Philadelphia, PA Overtime Exempt: Exempt Reports To: ARMADA HQ Travel Required: Yes Security Clearance Required: Active Secret Security Clearance CONTINGENT UPON AWARD Duties & Responsibilities: Specialist, Information System Security III (SISS3) will conduct risk and vulnerability assessments of planned and installed systems to identify vulnerabilities, risks and protection needs; conduct systems security evaluation, audits, and reviews; determine the residual risk of a package based on package content and assessment results and documenting for the Security Controls Assessor's (SCA) and higher level review. Execute Security Assessment Plans (SAPs) by conducting on-site testing for afloat and PIT ashore systems. Examples include executing STIGs, SRGs, ACAS scanning, and applying patches assets to obtain cybersecurity compliance and remediate vulnerabilities. Specialist, Information System Security III (SISS3) will conduct systems security reviews, audits, or evaluations, as appropriate, to ensure accreditation documents are accurate and represent the current risk posture of the system. Perform analysis of logs, events, and reporting of various data collections tools including: vulnerability monitoring via Assured Compliance Assessment System (ACAS) and related tools, Host Based Security Systems (HBSS), web content filters, Security Information and event management (SIEM), firewall systems, network devices, server devices, workstations, and intrusion detection and prevention systems (ID/PS). Specialist, Information System Security III (SISS3) will assess impacts from observed risks and report via the Cybersecurity Program chain of command. Executing Security Assessment Plans (SAPs) by conducting on-site testing for afloat and PIT ashore systems. Examples include executing STIGs, SRGs, ACAS scanning, and applying patches assets to obtain cybersecurity compliance and remediate vulnerabilities. Perform the evaluation of system administrator, security engineer, and/or system owner proposed corrections to ensure compliance and best-fit solution. Specialist, Information System Security III (SISS3) will present and submit data to management, develop reports, and produce procedural documentation in a comprehensive and cohesive manner. Perform risk management and security engineering for Research, Development, Testing, and Evaluation (RDT&E) RMF Afloat systems include Information Assurance Vulnerability Management (IAVM) support, remediation, patching, scanning and associated boundary maintenance. Specialist, Information System Security III (SISS3) will document residual risks in a plan of actions and milestones formatted in compliance with the current package system, currently eMASS. Specialist, Information System Security III (SISS3) will maintain current vulnerability scan data and residual risk plan of actions and milestones in Vulnerability Remediation Asset Manager (VRAM). Manage, attend, and support configuration control board practices. Create and verify the accuracy of POA&Ms/RARs as identified by vulnerability actual test results. Specialist, Information System Security III (SISS3) shall write technical documentation such as user manuals, reports, documentation, policies, presentations, Plan of Action and Milestones (POA&Ms), risk assessments, proposals, outlines, and summaries in support of both ashore and afloat systems across multiple platforms. Support developing of technical documents across multiple platforms including configuration management, milestone, issue tracking, web site content management and RMF documentation. Specialist, Information System Security III (SISS3) may be required to travel CONUS (any state in USA) and OCONUS (primarily Japan, and any country in Europe). The estimated number of trips is 14 per year (estimated 25%-30% travel). Other duties as assigned. Knowledge, Skills, and Abilities (KSAs): Ability to travel CONUS (any state in USA) and OCONUS (primarily Japan, and any country in Europe). Proficient in Microsoft Windows Operating System Administration, including Windows 11, Windows 10, Windows 7, and Windows XP (at a minimum). Ability to work as a team member, communicate, perform office functions and use office tools, customer focused and deliver exceptional performance. Possess excellent organizational and file management skills and the ability to plan and execute administrative work with little supervision. Possess excellent oral and written communication skills. Required Certifications: Minimum of one (1) IAT Level II listed certificate required: CompTIA Security+ (CE) CompTIA CySA+ GIAC Security Essentials (GSEC) ISC SSCP (Systems Security Certified Practitioner) Minimum/General Experience: Five (5) years of experience in the following: Cybersecurity, Engineering, Test and Evaluation (T&E) or Authorization and Assessment (A&A) (formerly C&A) related field. Information Assurance tools such as Defense Information Systems Agency (DISA) Enterprise Mission Assurance Support Service (eMASS), Assured Compliance Assessment Solution (ACAS). Command line interface, PowerShell, and performing automated tasking through use of code. Minimum Education: College degree in any technical discipline from an accredited college or university. Disclaimer: The above information has been designed to indicate the general nature and level of work to be performed. It is not designed to contain or be interpreted as a comprehensive inventory of all duties, responsibilities, and qualifications required of the contractor assigned to this position. Applying: If you feel you have the knowledge, skills and abilities for this position visit our careers page at . Special Notes: Relocation is not available for these jobs ARMADA provides equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion, gender, sexual orientation, gender identity or expression, national origin, age, disability, genetic information, marital status, amnesty, or status as a covered veteran in accordance with applicable federal, state and local laws. ARMADA complies with applicable state and local laws governing non-discrimination in employment in every location in which the company has facilities. This policy applies to all terms and conditions of employment, including, but not limited to, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation, and training. Must be able to successfully pass a background check, and pre-employment drug testing. Job offers are contingent upon results of background check and drug testing.
Navy Validator III (FQNV3)
Armada Ltd Philadelphia, Pennsylvania
Job Description Job Description Type: Full Time Location: Philadelphia, PA Overtime Exempt: Exempt Reports To: ARMADA HQ Travel Required: Yes Security Clearance Required: Active Secret Security Clearance CONTINGENT UPON AWARD Duties & Responsibilities: The Navy Validator III will conduct validation activities in accordance with Navy SCA office. Register and be listed on the official list of Navy Qualified Validators; perform and support activities of Validators of Navy (RMF) Risk Management Framework packages. The Navy Validator III will ensure separation of duties between the System ISSM/ISSE and NQV. Prepare the Security Assessment Plan (SAP) with input from the system's ISSE and ISSM. The SAP is to be submitted and approved by the SCA. The Navy Validator III will perform as an independent third party who assesses and validates that the system has or has not implemented the approved security control baseline. On-site validation may be required for conducting required testing. The Validator acts as a trusted agent to the (SCA) Security Control Assessor and SCA Liaison. Utilize the Security Assessment Report (SAR) to document the residual risk of the non-compliant security controls remaining after the risk assessment work is complete; documentation of the residual risk shall be in the Risk Assessment Report (RAR) in accordance (NAVSEAINST 9400.2) instruction. The Navy Validator III will develop the SAR Executive Summary and Functional Security Controls Assessor (FSCA) Appendix and brief the required PM/ISSM. The Navy Validator III will write technical documentation such as user manuals, reports, documentation, policies, presentations, Plan of Action and Milestones (POA&Ms), risk assessments, proposals, outlines, and summaries in support of both ashore and afloat systems across multiple platforms. Support development of technical documents across multiple platforms including configuration management, milestone, issue tracking, web site content management and RMF documentation. The Navy Validator III will may be required to travel CONUS (any state in USA) and OCONUS (primarily Japan, and any country in Europe). The estimated number of trips is 14 per year (estimated 25%-30% travel). Other duties as assigned. Knowledge, Skills, and Abilities (KSAs): Ability to travel CONUS (any state in USA) and OCONUS (primarily Japan, and any country in Europe). Proficient in Microsoft Windows Operating System Administration, including Windows 11, Windows 10, Windows 7, and Windows XP (at a minimum). Ability to work as a team member, communicate, perform office functions and use office tools, customer focused and deliver exceptional performance. Possess excellent organizational and file management skills and the ability to plan and execute administrative work with little supervision. Possess excellent oral and written communication skills. Required Certifications: Must provide evidence of current Navy Qualified Validator (NQV) Level III certification. Minimum of one (1) IAT Level II listed certificate required: CompTIA Security+ (CE) CompTIA CySA+ GIAC Security Essentials (GSEC) ISC SSCP (Systems Security Certified Practitioner) Minimum/General Experience: Five (5) years of professional experience in the management of Information Assurance Technical (IAT), certification agents and system engineers on the compliance requirements to achieve certification and accreditation IAW the DoD RMF program and the Department of Navy (DON) Chief Information Officer (CIO) IA Policy for Platform Information Technology (PIT) Systems. Professional experience in support of the Department of Navy (DON) or Department of Defense (DoD) is preferred. Minimum Education: Bachelor's degree in computer science from an accredited college or university. Disclaimer: The above information has been designed to indicate the general nature and level of work to be performed. It is not designed to contain or be interpreted as a comprehensive inventory of all duties, responsibilities, and qualifications required of the contractor assigned to this position. Applying: If you feel you have the knowledge, skills and abilities for this position visit our careers page at . Special Notes: Relocation is not available for these jobs ARMADA provides equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion, gender, sexual orientation, gender identity or expression, national origin, age, disability, genetic information, marital status, amnesty, or status as a covered veteran in accordance with applicable federal, state and local laws. ARMADA complies with applicable state and local laws governing non-discrimination in employment in every location in which the company has facilities. This policy applies to all terms and conditions of employment, including, but not limited to, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation, and training. Must be able to successfully pass a background check, and pre-employment drug testing. Job offers are contingent upon results of background check and drug testing.
09/20/2026
Full time
Job Description Job Description Type: Full Time Location: Philadelphia, PA Overtime Exempt: Exempt Reports To: ARMADA HQ Travel Required: Yes Security Clearance Required: Active Secret Security Clearance CONTINGENT UPON AWARD Duties & Responsibilities: The Navy Validator III will conduct validation activities in accordance with Navy SCA office. Register and be listed on the official list of Navy Qualified Validators; perform and support activities of Validators of Navy (RMF) Risk Management Framework packages. The Navy Validator III will ensure separation of duties between the System ISSM/ISSE and NQV. Prepare the Security Assessment Plan (SAP) with input from the system's ISSE and ISSM. The SAP is to be submitted and approved by the SCA. The Navy Validator III will perform as an independent third party who assesses and validates that the system has or has not implemented the approved security control baseline. On-site validation may be required for conducting required testing. The Validator acts as a trusted agent to the (SCA) Security Control Assessor and SCA Liaison. Utilize the Security Assessment Report (SAR) to document the residual risk of the non-compliant security controls remaining after the risk assessment work is complete; documentation of the residual risk shall be in the Risk Assessment Report (RAR) in accordance (NAVSEAINST 9400.2) instruction. The Navy Validator III will develop the SAR Executive Summary and Functional Security Controls Assessor (FSCA) Appendix and brief the required PM/ISSM. The Navy Validator III will write technical documentation such as user manuals, reports, documentation, policies, presentations, Plan of Action and Milestones (POA&Ms), risk assessments, proposals, outlines, and summaries in support of both ashore and afloat systems across multiple platforms. Support development of technical documents across multiple platforms including configuration management, milestone, issue tracking, web site content management and RMF documentation. The Navy Validator III will may be required to travel CONUS (any state in USA) and OCONUS (primarily Japan, and any country in Europe). The estimated number of trips is 14 per year (estimated 25%-30% travel). Other duties as assigned. Knowledge, Skills, and Abilities (KSAs): Ability to travel CONUS (any state in USA) and OCONUS (primarily Japan, and any country in Europe). Proficient in Microsoft Windows Operating System Administration, including Windows 11, Windows 10, Windows 7, and Windows XP (at a minimum). Ability to work as a team member, communicate, perform office functions and use office tools, customer focused and deliver exceptional performance. Possess excellent organizational and file management skills and the ability to plan and execute administrative work with little supervision. Possess excellent oral and written communication skills. Required Certifications: Must provide evidence of current Navy Qualified Validator (NQV) Level III certification. Minimum of one (1) IAT Level II listed certificate required: CompTIA Security+ (CE) CompTIA CySA+ GIAC Security Essentials (GSEC) ISC SSCP (Systems Security Certified Practitioner) Minimum/General Experience: Five (5) years of professional experience in the management of Information Assurance Technical (IAT), certification agents and system engineers on the compliance requirements to achieve certification and accreditation IAW the DoD RMF program and the Department of Navy (DON) Chief Information Officer (CIO) IA Policy for Platform Information Technology (PIT) Systems. Professional experience in support of the Department of Navy (DON) or Department of Defense (DoD) is preferred. Minimum Education: Bachelor's degree in computer science from an accredited college or university. Disclaimer: The above information has been designed to indicate the general nature and level of work to be performed. It is not designed to contain or be interpreted as a comprehensive inventory of all duties, responsibilities, and qualifications required of the contractor assigned to this position. Applying: If you feel you have the knowledge, skills and abilities for this position visit our careers page at . Special Notes: Relocation is not available for these jobs ARMADA provides equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion, gender, sexual orientation, gender identity or expression, national origin, age, disability, genetic information, marital status, amnesty, or status as a covered veteran in accordance with applicable federal, state and local laws. ARMADA complies with applicable state and local laws governing non-discrimination in employment in every location in which the company has facilities. This policy applies to all terms and conditions of employment, including, but not limited to, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation, and training. Must be able to successfully pass a background check, and pre-employment drug testing. Job offers are contingent upon results of background check and drug testing.
11-009 - Security Control Assessor (SCA) II
Sandy Mac Evolution Arlington, Virginia
Job Description Job Description 11-009 - Security Control Assessor (SCA) II Location: Crystal City, VA Salary: $168,932.71 Billet Number: JUSTIFIED-0055 Skill Level: 2 Current Vacancy-Specific Requirements MANDATORY: 7-9 years related experience; 4+ years experience in SAP, SCI, or Collateral Information Systems (S) security and implementation of regulations identified in the description of duties; Prior performance in the role of ISSO and ISSM or SCA; TRAINING: IAM Level II (in lieu of IAT Level III) Position Description The SCA is responsible for conducting a comprehensive assessment of the management, operational, and technical security controls employed within or inherited by an IS to determine the overall effectiveness of the controls (i.e., the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for the system). SCAs also provide an assessment of the severity of weaknesses or deficiencies discovered in the IS and its environment of operation and recommend corrective actions to address identified vulnerabilities. Responsibilities will cover Collateral, Sensitive Compartmented Information (SCI) and Special Access Program (SAP) activities within the customer's area of responsibility. Performance shall include: Perform oversight of the development, implementation and evaluation of IS security program policy; special emphasis placed upon integration of existing SAP network infrastructure Perform assessment of ISs, based upon the Risk Management Framework (RMF) methodology in accordance with the Joint Special Access Program (SAP) Implementation Guide (JSIG) Advise the Information System Owner (ISO), Information Data Owner (IDO), Program Security Officer (PSO), and the Delegated and/or Authorizing Official (DAO/AO) on any assessment and authorization issues Evaluate Authorization packages and make recommendation to the AO and/or DAO for authorization Evaluate IS threats and vulnerabilities to determine whether additional safeguards are required Advise the Government concerning the impact levels for Confidentiality, Integrity, and Availability for the information on a system Ensure security assessments are completed and results documented and prepare the Security Assessment Report (SAR) for the Authorization boundary Initiate a Plan of Action and Milestones (POA&M) with identified weaknesses for each Authorization Boundaries assessed, based on findings and recommendations from the SAR Evaluate security assessment documentation and provide written recommendations for security authorization to the Government Discuss recommendation for authorization and submit the security authorization package to the AO/DAO Assess proposed changes to Authorization boundaries operating environment and mission needs to determine the continuation to operate. Review and concur with all sanitization and clearing procedures in accordance with Government guidance and/or policy Assist the Government compliance inspections Assist the Government with security incidents that relate to cybersecurity and ensure that the proper and corrective measures have been taken Ensure organization are addressing and conducting all phases of the system development life cycle (SDLC) Evaluate Hardware and Software to determine security impact that it might have on Authorization boundaries Evaluate the effectiveness and implementation of Continuous Monitoring Plans Represent the customer on inspection teams Experience: 7 - 9 years related experience Minimum of four (4) years' experience in SAP, SCI or Collateral Information Systems (IS) Security and the implementation of regulations identified in the description of duties. Prior performance in the role of ISSO and ISSM or SCA Education: Bachelor's degree in a related discipline or equivalent experience (4 years) Certifications: Must meet position and certification requirements outlined in DoD Directive 8570.01-M for Information Assurance Technician Level III or Information Assurance Manager Level II within 6 months of the date of hire Security Clearance: Current clearance as defined in the Task Order Eligibility for access to Special Access Program Information Willingness to submit to a Counterintelligence polygraph Other Requirements: Must be able to regularly lift 50lbs Top Secret/Special Compartmented Information (TS/SCI) Individuals must possess current Top Secret/Special Compartmented Information (TS/SCI) eligibility with an in scope BI, or enrollment into Continuous Evaluation, or an in scope open PR. Depending on the position, additional security screening may also be required (e.g., polygraph examination, etc.).
09/20/2026
Full time
Job Description Job Description 11-009 - Security Control Assessor (SCA) II Location: Crystal City, VA Salary: $168,932.71 Billet Number: JUSTIFIED-0055 Skill Level: 2 Current Vacancy-Specific Requirements MANDATORY: 7-9 years related experience; 4+ years experience in SAP, SCI, or Collateral Information Systems (S) security and implementation of regulations identified in the description of duties; Prior performance in the role of ISSO and ISSM or SCA; TRAINING: IAM Level II (in lieu of IAT Level III) Position Description The SCA is responsible for conducting a comprehensive assessment of the management, operational, and technical security controls employed within or inherited by an IS to determine the overall effectiveness of the controls (i.e., the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for the system). SCAs also provide an assessment of the severity of weaknesses or deficiencies discovered in the IS and its environment of operation and recommend corrective actions to address identified vulnerabilities. Responsibilities will cover Collateral, Sensitive Compartmented Information (SCI) and Special Access Program (SAP) activities within the customer's area of responsibility. Performance shall include: Perform oversight of the development, implementation and evaluation of IS security program policy; special emphasis placed upon integration of existing SAP network infrastructure Perform assessment of ISs, based upon the Risk Management Framework (RMF) methodology in accordance with the Joint Special Access Program (SAP) Implementation Guide (JSIG) Advise the Information System Owner (ISO), Information Data Owner (IDO), Program Security Officer (PSO), and the Delegated and/or Authorizing Official (DAO/AO) on any assessment and authorization issues Evaluate Authorization packages and make recommendation to the AO and/or DAO for authorization Evaluate IS threats and vulnerabilities to determine whether additional safeguards are required Advise the Government concerning the impact levels for Confidentiality, Integrity, and Availability for the information on a system Ensure security assessments are completed and results documented and prepare the Security Assessment Report (SAR) for the Authorization boundary Initiate a Plan of Action and Milestones (POA&M) with identified weaknesses for each Authorization Boundaries assessed, based on findings and recommendations from the SAR Evaluate security assessment documentation and provide written recommendations for security authorization to the Government Discuss recommendation for authorization and submit the security authorization package to the AO/DAO Assess proposed changes to Authorization boundaries operating environment and mission needs to determine the continuation to operate. Review and concur with all sanitization and clearing procedures in accordance with Government guidance and/or policy Assist the Government compliance inspections Assist the Government with security incidents that relate to cybersecurity and ensure that the proper and corrective measures have been taken Ensure organization are addressing and conducting all phases of the system development life cycle (SDLC) Evaluate Hardware and Software to determine security impact that it might have on Authorization boundaries Evaluate the effectiveness and implementation of Continuous Monitoring Plans Represent the customer on inspection teams Experience: 7 - 9 years related experience Minimum of four (4) years' experience in SAP, SCI or Collateral Information Systems (IS) Security and the implementation of regulations identified in the description of duties. Prior performance in the role of ISSO and ISSM or SCA Education: Bachelor's degree in a related discipline or equivalent experience (4 years) Certifications: Must meet position and certification requirements outlined in DoD Directive 8570.01-M for Information Assurance Technician Level III or Information Assurance Manager Level II within 6 months of the date of hire Security Clearance: Current clearance as defined in the Task Order Eligibility for access to Special Access Program Information Willingness to submit to a Counterintelligence polygraph Other Requirements: Must be able to regularly lift 50lbs Top Secret/Special Compartmented Information (TS/SCI) Individuals must possess current Top Secret/Special Compartmented Information (TS/SCI) eligibility with an in scope BI, or enrollment into Continuous Evaluation, or an in scope open PR. Depending on the position, additional security screening may also be required (e.g., polygraph examination, etc.).
TASS (Current Contract) - Security Control Assessor, Senior
AGE solutions Alexandria, Virginia
Job Description Job Description About Us AGE Solutions is a premier technology and professional services company, providing in-depth consulting, advanced technology solutions, and essential services throughout the U.S. government, defense, and intelligence sectors. Prioritizing innovation and client-focused solutions, we assist major agencies in addressing intricate issues and ensuring a more secure future. AGE Solutions is looking for Senior Security Control Assessors to join our team in support of a cybersecurity risk management and assessment program with our DoD customer. Responsibilities: Conduct cybersecurity assessments, audits, and inspections for DoD organizations and partners handling DoD information or connecting to the DoDIN. Evaluate systems and Defensive Cyberspace Operations using cyber threat emulation and performance-based testing. Adhere to policies and processes for each assessment type. Support assessment development and execution to ensure security expertise is properly applied. Coordinate logistics, test plans, and scope with the SCA Team Lead. Perform vulnerability assessments, capture results using STIG Viewer or designated tools, and document findings in eMASS. Analyze security gaps and provide mitigation recommendations. Validate cybersecurity controls, TTPs, STIGs, RMF controls, and compliance with DoD policies and guidelines. Provide risk analysis and assessment results for authorization recommendations. Participate in daily assessment reviews, in-briefs, and out-briefs, sharing findings with the SCA-R. Mentor and guide personnel by providing technical expertise, best practices, and professional development support to enhance team capabilities and knowledge. Requirements: Bachelor's degree (IT-related field preferred) Eight (8) years of overall experience in cybersecurity or network security position Five (5) years of experience in a Certification and Accreditation/A&A role Must have and maintain an active DoD Top Secret clearance with SCI eligibility Must be able and willing to travel up to approximately 85% of the time, inside and outside the continental United States and internationally (CONUS / OCONUS) DoD 8570 IA Technical (IAT) Level III certification Demonstrated experience with STIGs (Security Technical Implementation Guides), Security Requirement Guides (SRGs), Plan of Action and Milestones (POA&Ms) and cybersecurity best practices Advanced understanding of the RMF process, NIST SP 800- 37, NIST SP 800-53, CNSSI 1253 Demonstrated experience with relevant tools such as eMASS, STIG Viewer, Nessus, ACAS, SCAP, or HBSS Advanced understanding of key technologies areas/domain such as: Network, Mobility, Windows, UNIX, Cloud Environments and Cloud Native Tools/Services, Host Based Security System (HBSS)/Endpoint Security Solutions (ESS), Databases, Applications Strong written and verbal communication skills for reporting assessment findings. Compensation: $95,000 - $105,000 This posting is part of a pipeline for future opportunities supporting the current TASS contract. Employment is contingent upon position availability and government customer approval. AGE Solutions is actively engaging talent and encourages incumbents and new candidates to express interest to be considered if/when opportunities may become available. At AGE Solutions, we reward performance, invest in growth, and share success. Our benefits support the whole person, professionally, financially, and personally. 26 Days Paid Leave: Includes vacation, sick, personal time, and holidays. You choose how to use it. Performance Bonuses: Performance bonuses are awarded based on individual contributions and company-wide results, aligning recognition with impact. 401(k) with Match: We match 3% of your contributions with immediate vesting. Financial Protection: Company-paid life insurance up to $300K and options for additional coverage for you and your dependents. Health Benefits: Multiple medical plans, dental, vision, FSA and HSA options to fit your needs. Parental Leave: 15 days of fully paid leave for new parents, because family matters. Military Differential Pay: We bridge the gap for employees on active duty, so they don't take a financial hit while serving. Professional Growth: Paid training and certifications, tuition reimbursement, and the tools and tech to get the job done right. Shared Success: In the event of a company sale, our CEO has committed to returning 80% of net proceeds to employees. This ensures our team shares in the long term value they help create. At AGE, you'll do work that matters, supported by a company that delivers for its people.
09/20/2026
Full time
Job Description Job Description About Us AGE Solutions is a premier technology and professional services company, providing in-depth consulting, advanced technology solutions, and essential services throughout the U.S. government, defense, and intelligence sectors. Prioritizing innovation and client-focused solutions, we assist major agencies in addressing intricate issues and ensuring a more secure future. AGE Solutions is looking for Senior Security Control Assessors to join our team in support of a cybersecurity risk management and assessment program with our DoD customer. Responsibilities: Conduct cybersecurity assessments, audits, and inspections for DoD organizations and partners handling DoD information or connecting to the DoDIN. Evaluate systems and Defensive Cyberspace Operations using cyber threat emulation and performance-based testing. Adhere to policies and processes for each assessment type. Support assessment development and execution to ensure security expertise is properly applied. Coordinate logistics, test plans, and scope with the SCA Team Lead. Perform vulnerability assessments, capture results using STIG Viewer or designated tools, and document findings in eMASS. Analyze security gaps and provide mitigation recommendations. Validate cybersecurity controls, TTPs, STIGs, RMF controls, and compliance with DoD policies and guidelines. Provide risk analysis and assessment results for authorization recommendations. Participate in daily assessment reviews, in-briefs, and out-briefs, sharing findings with the SCA-R. Mentor and guide personnel by providing technical expertise, best practices, and professional development support to enhance team capabilities and knowledge. Requirements: Bachelor's degree (IT-related field preferred) Eight (8) years of overall experience in cybersecurity or network security position Five (5) years of experience in a Certification and Accreditation/A&A role Must have and maintain an active DoD Top Secret clearance with SCI eligibility Must be able and willing to travel up to approximately 85% of the time, inside and outside the continental United States and internationally (CONUS / OCONUS) DoD 8570 IA Technical (IAT) Level III certification Demonstrated experience with STIGs (Security Technical Implementation Guides), Security Requirement Guides (SRGs), Plan of Action and Milestones (POA&Ms) and cybersecurity best practices Advanced understanding of the RMF process, NIST SP 800- 37, NIST SP 800-53, CNSSI 1253 Demonstrated experience with relevant tools such as eMASS, STIG Viewer, Nessus, ACAS, SCAP, or HBSS Advanced understanding of key technologies areas/domain such as: Network, Mobility, Windows, UNIX, Cloud Environments and Cloud Native Tools/Services, Host Based Security System (HBSS)/Endpoint Security Solutions (ESS), Databases, Applications Strong written and verbal communication skills for reporting assessment findings. Compensation: $95,000 - $105,000 This posting is part of a pipeline for future opportunities supporting the current TASS contract. Employment is contingent upon position availability and government customer approval. AGE Solutions is actively engaging talent and encourages incumbents and new candidates to express interest to be considered if/when opportunities may become available. At AGE Solutions, we reward performance, invest in growth, and share success. Our benefits support the whole person, professionally, financially, and personally. 26 Days Paid Leave: Includes vacation, sick, personal time, and holidays. You choose how to use it. Performance Bonuses: Performance bonuses are awarded based on individual contributions and company-wide results, aligning recognition with impact. 401(k) with Match: We match 3% of your contributions with immediate vesting. Financial Protection: Company-paid life insurance up to $300K and options for additional coverage for you and your dependents. Health Benefits: Multiple medical plans, dental, vision, FSA and HSA options to fit your needs. Parental Leave: 15 days of fully paid leave for new parents, because family matters. Military Differential Pay: We bridge the gap for employees on active duty, so they don't take a financial hit while serving. Professional Growth: Paid training and certifications, tuition reimbursement, and the tools and tech to get the job done right. Shared Success: In the event of a company sale, our CEO has committed to returning 80% of net proceeds to employees. This ensures our team shares in the long term value they help create. At AGE, you'll do work that matters, supported by a company that delivers for its people.
Security Control Assessor
Boston Government Services, LLC Oak Ridge, Tennessee
Job Description Job Description Boston Government Services, LLC. (BGS) has created this Evergreen Talent Pool post for gathering qualified candidates for a position relating to Security Control Assessor to support our clients at Washington, DC Area. BGS is an engineering, technology, and security firm helping to advance missions of national importance for government programs, national laboratories, national security facilities, nuclear operations, and complex projects. We support clients at every stage, from strategic planning and program management to the execution of engineering and technical activities. We work to attract and retain the best talent because the best talent delivers the best results for our clients. Our capabilities are based on our experience in complex, secure, and highly regulated environments. We leverage our experience and capabilities to provide mission-driven solutions tuned to our client's mission needs and strategic direction. Work that Matters. People that Matter More. At BGS, we believe meaningful work starts with great people. We foster a culture built on respect, collaboration, and accountability-where employees are empowered to contribute ideas, grow professionally, and make an impact. We care about our employees' well-being through competitive benefits, clear expectations, and an environment that values both excellence and connection. If you align with BGS company values and culture, we would love for you to explore opportunities to join our growing team by checking out the job description below! Responsibilities: General understanding of cyber requirements. Ability to interpret cyber security plans for vendors to determine compliance with the National Institute of Standards and Technology (NIST) requirements. Ability to communicate with vendor IT and Cyber staff. Requirements: Working knowledge of NIST 800-171, NIST SP 800-53, NIST SP 800-53A. Ability to assess and document assessment results for NIST SP 800-171 security controls. Ability to aggregate risk for NIST SP 800-171 security controls into an overall risk assessment for a non-federal information system processing Controlled Unclassified Information (CUI) data. Knowledge of cyber controls. Familiarity with Defense Federal Acquisition Regulation Supplement (DFARS) requirements for processing CUI data on non-federal information systems. Must be U.S. citizen. Successful drug screening. Must be eligible to obtain and maintain a security or clearance badge. Preferred Qualifications: Cybersecurity Maturity Model Certification (CMMC), Certification as Certified CMMC Professional (CCP), Certification as Certified CMMC Assessor (CCA), Training associated with the assessment of NIST security controls. Location/Work Arrangement: Travel possible. Remote. Benefits: BGS offers a competitive total compensation package to eligible employees. Benefits include Health, Dental, Vision, Life Insurance, Paid Vacation, 401K, Long and Short-Term Disability. EEO: BGS is an Equal Opportunity/Affirmative Action employer. All qualified applicants are encouraged to apply and will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, or protected veteran status. Exclusive Agreement Disclaimer: BGS has standing contracts with federal agencies throughout the United States. We require an affirmative exclusive agreement to represent all candidates to our clients. By submitting this application, you are consenting to allow BGS to represent you as a candidate for the role in which you are applying. Travel possible. Remote. Schedule is full-time, Monday - Friday 40-hour work week.
09/19/2026
Full time
Job Description Job Description Boston Government Services, LLC. (BGS) has created this Evergreen Talent Pool post for gathering qualified candidates for a position relating to Security Control Assessor to support our clients at Washington, DC Area. BGS is an engineering, technology, and security firm helping to advance missions of national importance for government programs, national laboratories, national security facilities, nuclear operations, and complex projects. We support clients at every stage, from strategic planning and program management to the execution of engineering and technical activities. We work to attract and retain the best talent because the best talent delivers the best results for our clients. Our capabilities are based on our experience in complex, secure, and highly regulated environments. We leverage our experience and capabilities to provide mission-driven solutions tuned to our client's mission needs and strategic direction. Work that Matters. People that Matter More. At BGS, we believe meaningful work starts with great people. We foster a culture built on respect, collaboration, and accountability-where employees are empowered to contribute ideas, grow professionally, and make an impact. We care about our employees' well-being through competitive benefits, clear expectations, and an environment that values both excellence and connection. If you align with BGS company values and culture, we would love for you to explore opportunities to join our growing team by checking out the job description below! Responsibilities: General understanding of cyber requirements. Ability to interpret cyber security plans for vendors to determine compliance with the National Institute of Standards and Technology (NIST) requirements. Ability to communicate with vendor IT and Cyber staff. Requirements: Working knowledge of NIST 800-171, NIST SP 800-53, NIST SP 800-53A. Ability to assess and document assessment results for NIST SP 800-171 security controls. Ability to aggregate risk for NIST SP 800-171 security controls into an overall risk assessment for a non-federal information system processing Controlled Unclassified Information (CUI) data. Knowledge of cyber controls. Familiarity with Defense Federal Acquisition Regulation Supplement (DFARS) requirements for processing CUI data on non-federal information systems. Must be U.S. citizen. Successful drug screening. Must be eligible to obtain and maintain a security or clearance badge. Preferred Qualifications: Cybersecurity Maturity Model Certification (CMMC), Certification as Certified CMMC Professional (CCP), Certification as Certified CMMC Assessor (CCA), Training associated with the assessment of NIST security controls. Location/Work Arrangement: Travel possible. Remote. Benefits: BGS offers a competitive total compensation package to eligible employees. Benefits include Health, Dental, Vision, Life Insurance, Paid Vacation, 401K, Long and Short-Term Disability. EEO: BGS is an Equal Opportunity/Affirmative Action employer. All qualified applicants are encouraged to apply and will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, or protected veteran status. Exclusive Agreement Disclaimer: BGS has standing contracts with federal agencies throughout the United States. We require an affirmative exclusive agreement to represent all candidates to our clients. By submitting this application, you are consenting to allow BGS to represent you as a candidate for the role in which you are applying. Travel possible. Remote. Schedule is full-time, Monday - Friday 40-hour work week.
Security Control Assessor (SCA)
LV8D Solutions Chantilly, Virginia
Job Description Job Description Mission Context LV8D Solutions supports national security space and intelligence customers delivering next-generation sensing and exploitation capabilities. The role of a Security Control Assessor (SCA) is focused on providing information security Assessment and Authorization (A&A) support throughout the mission program's lifecycle. Position Overview LV8D Solutions is seeking a SCA to conduct independent assessments of the management, operational, and technical security controls employed within or inherited by an information technology (IT) system to determine the overall effectiveness of the security controls. A Security Control Assessor (SCA) performs comprehensive INFOSEC assessment of management, operational, and technical security controls to determine overall effectiveness of the controls for A&A determination throughout a program's system lifecycle. SCAs provide an assessment of the severity of weakness or deficiencies discovered in the Information System (IS) and its environment of operation and recommend corrective actions to address identified vulnerabilities. Prior to initiating the security control assessment, the SCA reviews the System Security Plan (SSP) to ensure the plan provides a set of security controls for the ISs that meet the stated security requirements. Additionally, the SCA must verify that all allocated controls have an acceptable status (i.e., implemented, excepted, or inherited) with appropriate documented details and provides responses in the Government's Risk Management Framework (RMF) tools. Interested candidates need to thrive in an innovative, fast-paced environment; are highly motivated and not afraid to take on uncharted territory; possess strong communication, leadership, and organizational skills; and be able to prioritize their time to be effective in a dynamic environment. Requirements Key Responsibilities Reviews IS for compliance with applicable Intelligence Community (IC), Department of War (DoW), and National Directorate (ND) guidance, and make recommendations to the Government. Provides ISs security advice and guidance Joint Analytical Workstation (JAW) applicable IC, DoW, and NDs and guidance to Government and industry partners for the protection of data at all classification levels including Sensitive Compartmented Information (SCI). Evaluates threats and vulnerabilities to ISs to ascertain the need for additional safeguards and recommend approval, disapproval, or waiver(s) for IS processing national security data at industry and/or Government facilities. Supports development and implementation of directives and guidance for policies. Provides input for consideration in the promulgation of future ISs security policy. Supports and/or conduct site visits and assessments to inspect and verify IS reports. Ensures security control assessments are completed for each IS. Supports the preparation and delivery of presentations, briefings, reports, and memoranda associated with the RMF process. Uses the RMF system of record to complete RMF workflow duties and maintain the asset documentation repository. Establishes and maintains means and methods to track RMF process workflow activities to inform task volume, velocity, and duration of activities. Prepares the final Security Assessment Report (SAR) containing the results and findings from the assessment at the conclusion of each security control assessment activity and the Authorization Recommendation. Ensures appropriate IS security requirements including applicable Interface Control Documents (ICDs), DoW Instructions, NDs and other guidance are addressed and applied and appropriate documentation is prepared by the system owners or programs. The documentation will be contained in the Security Assessment Package, including, but not limited to, the Concept of Operations (CONOP), SSP, Systems Requirements Traceability Matrix, Risk Management Matrix, Test Results, interface control documents, requests for changes, test plans, and other related program security documentation. Collaborates with Information Security Officers (ISOs) and Common Control Providers to initiate Plan of Action and Milestones (POAMs) for ISs based on findings and recommendations from the SAR. Reviews and approves the IS Security Assessment Plan which is comprised of the Security Controls Traceability Matrix and the Security Control Assessment Procedures. Tracks the completion of the SAR. Reviews, coordinates, and responds to security issues as requested by the Government. Provides A&A support to the Government for the protection of special programs and tactical operations related activities. Supplies the effort needed to conduct the reviews and write reports to support Integrated Security Assessment Program (ISAP) or Technical Information Systems Security Reviews (TISSRs). Required Qualifications Practical experience performing information systems A&A as defined in applicable ICDs and guidance Practical experience utilizing risk management strategies for information technology solutions Technical understanding of emerging technologies and their implementation within Government system and network environments Knowledge of information technology concepts used in the evaluation of security performance and integrity of state-of-the-art applications, communications systems, hardware, software, satellite control systems, and information processing systems Technical understanding of information technology systems, software, and networks Ability to effectively coordinate A&A activities of industry and Government information systems to meet acquisition milestone requirements Effective technical report and general correspondence writing ability Ability to manage and track systems or programs involved in the A&A process Experience developing and implementing security related directives and guidance for Information Assurance, Information Technology, and Information Management Experience working with a mixed level skill team to ensure that appropriate knowledge and skill transfer occurs High school's degree and 7+ years of relevant experience, or Associate's degree and 7+ years of relevant experience, or Bachelor's degree and 5+ years of relevant experience, or Master's degree and 3+ years of relevant experience Certifications Must have one of the following IAM Level 2 Certification: CGRC (Previously CAP) CASP CISM CISSP GSLC CCISO Security Requirements U.S. Citizenship Active Top Secret/Sensitive Compartmented Information (TS/SCI) clearance Active Counterintelligence (CI) or Full Scope (FS) Polygraph Work Environment On-site work in a government or contractor facility Occasional travel (up to 10%) This position is dependent on a contract seat being awarded. About LV8D Solutions LV8D Solutions is an elite Systems Engineering and Technical Advisory (SETA) company that delivers advanced systems engineering, integration, acquisition, mission operations, network communications, and cybersecurity support to our defense and intelligence customers. Founded in 2019, we apply our deep technical expertise, understanding, and mission-first mindset to design, acquire, and implement complex, high-impact solutions for our Intelligence Community (IC) and Department of War (DoW) customers. We specialize in every aspect of our customers' space and ground mission systems while offering exceptional work-life balance and an exemplary compensation and total rewards package designed to recruit, train, and retain top talent and committed to national defense and career growth. Equal Employment Opportunity Statement LV8D Solutions LLC is an Equal Opportunity Employer committed to diversity and inclusion. All qualified applicants will receive consideration without regard to race, religion, gender, national origin, disability, veteran status, or other protected categories. Benefits Performance & Recognition Period of Performance (PoP) Bonus Opportunities Performance-based bonus opportunities tied to contract or organizational performance. Retention Incentive Benefit Bounty Receive a payout for unused annual company contributions designated for health insurance premiums and professional training. Referral Bonus Earn up to $5,000 for each successful employee referral. Customer Recognition Letter of Appreciation (LoA) Bonus Opportunities Bonus opportunities based on customer recognition received through Letters of Appreciation. Milestone Rewards Celebrate your career achievements with anniversary awards on your 1st, 5th, 10th, and 20th years of service. Financial & Retirement Benefits Profit Sharing Receive an annual contribution equal to 4% of your W-2 gross earnings into your 401 (k), with immediate vesting. 401(k) Company Match The company matches your 401 (k) contributions dollar-for-dollar up to 6% of your monthly contribution, with immediate vesting. Career Development The company invests in your professional growth through: Annual financial support for professional training and industry certifications. Enhanced financial support for employees actively pursuing a degree at an accredited institution. Work-Life Balance . click apply for full job details
09/19/2026
Full time
Job Description Job Description Mission Context LV8D Solutions supports national security space and intelligence customers delivering next-generation sensing and exploitation capabilities. The role of a Security Control Assessor (SCA) is focused on providing information security Assessment and Authorization (A&A) support throughout the mission program's lifecycle. Position Overview LV8D Solutions is seeking a SCA to conduct independent assessments of the management, operational, and technical security controls employed within or inherited by an information technology (IT) system to determine the overall effectiveness of the security controls. A Security Control Assessor (SCA) performs comprehensive INFOSEC assessment of management, operational, and technical security controls to determine overall effectiveness of the controls for A&A determination throughout a program's system lifecycle. SCAs provide an assessment of the severity of weakness or deficiencies discovered in the Information System (IS) and its environment of operation and recommend corrective actions to address identified vulnerabilities. Prior to initiating the security control assessment, the SCA reviews the System Security Plan (SSP) to ensure the plan provides a set of security controls for the ISs that meet the stated security requirements. Additionally, the SCA must verify that all allocated controls have an acceptable status (i.e., implemented, excepted, or inherited) with appropriate documented details and provides responses in the Government's Risk Management Framework (RMF) tools. Interested candidates need to thrive in an innovative, fast-paced environment; are highly motivated and not afraid to take on uncharted territory; possess strong communication, leadership, and organizational skills; and be able to prioritize their time to be effective in a dynamic environment. Requirements Key Responsibilities Reviews IS for compliance with applicable Intelligence Community (IC), Department of War (DoW), and National Directorate (ND) guidance, and make recommendations to the Government. Provides ISs security advice and guidance Joint Analytical Workstation (JAW) applicable IC, DoW, and NDs and guidance to Government and industry partners for the protection of data at all classification levels including Sensitive Compartmented Information (SCI). Evaluates threats and vulnerabilities to ISs to ascertain the need for additional safeguards and recommend approval, disapproval, or waiver(s) for IS processing national security data at industry and/or Government facilities. Supports development and implementation of directives and guidance for policies. Provides input for consideration in the promulgation of future ISs security policy. Supports and/or conduct site visits and assessments to inspect and verify IS reports. Ensures security control assessments are completed for each IS. Supports the preparation and delivery of presentations, briefings, reports, and memoranda associated with the RMF process. Uses the RMF system of record to complete RMF workflow duties and maintain the asset documentation repository. Establishes and maintains means and methods to track RMF process workflow activities to inform task volume, velocity, and duration of activities. Prepares the final Security Assessment Report (SAR) containing the results and findings from the assessment at the conclusion of each security control assessment activity and the Authorization Recommendation. Ensures appropriate IS security requirements including applicable Interface Control Documents (ICDs), DoW Instructions, NDs and other guidance are addressed and applied and appropriate documentation is prepared by the system owners or programs. The documentation will be contained in the Security Assessment Package, including, but not limited to, the Concept of Operations (CONOP), SSP, Systems Requirements Traceability Matrix, Risk Management Matrix, Test Results, interface control documents, requests for changes, test plans, and other related program security documentation. Collaborates with Information Security Officers (ISOs) and Common Control Providers to initiate Plan of Action and Milestones (POAMs) for ISs based on findings and recommendations from the SAR. Reviews and approves the IS Security Assessment Plan which is comprised of the Security Controls Traceability Matrix and the Security Control Assessment Procedures. Tracks the completion of the SAR. Reviews, coordinates, and responds to security issues as requested by the Government. Provides A&A support to the Government for the protection of special programs and tactical operations related activities. Supplies the effort needed to conduct the reviews and write reports to support Integrated Security Assessment Program (ISAP) or Technical Information Systems Security Reviews (TISSRs). Required Qualifications Practical experience performing information systems A&A as defined in applicable ICDs and guidance Practical experience utilizing risk management strategies for information technology solutions Technical understanding of emerging technologies and their implementation within Government system and network environments Knowledge of information technology concepts used in the evaluation of security performance and integrity of state-of-the-art applications, communications systems, hardware, software, satellite control systems, and information processing systems Technical understanding of information technology systems, software, and networks Ability to effectively coordinate A&A activities of industry and Government information systems to meet acquisition milestone requirements Effective technical report and general correspondence writing ability Ability to manage and track systems or programs involved in the A&A process Experience developing and implementing security related directives and guidance for Information Assurance, Information Technology, and Information Management Experience working with a mixed level skill team to ensure that appropriate knowledge and skill transfer occurs High school's degree and 7+ years of relevant experience, or Associate's degree and 7+ years of relevant experience, or Bachelor's degree and 5+ years of relevant experience, or Master's degree and 3+ years of relevant experience Certifications Must have one of the following IAM Level 2 Certification: CGRC (Previously CAP) CASP CISM CISSP GSLC CCISO Security Requirements U.S. Citizenship Active Top Secret/Sensitive Compartmented Information (TS/SCI) clearance Active Counterintelligence (CI) or Full Scope (FS) Polygraph Work Environment On-site work in a government or contractor facility Occasional travel (up to 10%) This position is dependent on a contract seat being awarded. About LV8D Solutions LV8D Solutions is an elite Systems Engineering and Technical Advisory (SETA) company that delivers advanced systems engineering, integration, acquisition, mission operations, network communications, and cybersecurity support to our defense and intelligence customers. Founded in 2019, we apply our deep technical expertise, understanding, and mission-first mindset to design, acquire, and implement complex, high-impact solutions for our Intelligence Community (IC) and Department of War (DoW) customers. We specialize in every aspect of our customers' space and ground mission systems while offering exceptional work-life balance and an exemplary compensation and total rewards package designed to recruit, train, and retain top talent and committed to national defense and career growth. Equal Employment Opportunity Statement LV8D Solutions LLC is an Equal Opportunity Employer committed to diversity and inclusion. All qualified applicants will receive consideration without regard to race, religion, gender, national origin, disability, veteran status, or other protected categories. Benefits Performance & Recognition Period of Performance (PoP) Bonus Opportunities Performance-based bonus opportunities tied to contract or organizational performance. Retention Incentive Benefit Bounty Receive a payout for unused annual company contributions designated for health insurance premiums and professional training. Referral Bonus Earn up to $5,000 for each successful employee referral. Customer Recognition Letter of Appreciation (LoA) Bonus Opportunities Bonus opportunities based on customer recognition received through Letters of Appreciation. Milestone Rewards Celebrate your career achievements with anniversary awards on your 1st, 5th, 10th, and 20th years of service. Financial & Retirement Benefits Profit Sharing Receive an annual contribution equal to 4% of your W-2 gross earnings into your 401 (k), with immediate vesting. 401(k) Company Match The company matches your 401 (k) contributions dollar-for-dollar up to 6% of your monthly contribution, with immediate vesting. Career Development The company invests in your professional growth through: Annual financial support for professional training and industry certifications. Enhanced financial support for employees actively pursuing a degree at an accredited institution. Work-Life Balance . click apply for full job details
Senior Information Security Specialist
Dev Technology Ashburn, Virginia
Job Description Job Description Information Security Specialist Officer, Technical Lead, AWS Security • RMF & ATO • NIST 800-53 • Cloud Application Security Clearance: Active CBP, DHS, or Top Secret Clearance required Work Arrangement: Hybrid - onsite 3 days/week during standard business hours in Ashburn, VA About the Role Dev Technology Group is seeking a Senior Information Security Specialist to lead and develop a mid-sized team of ISSOs supporting the security, compliance, and authorization of mission-critical federal applications and information systems hosted in AWS. This is a hands-on technical leadership role combining people leadership, federal cybersecurity expertise, and direct collaboration with government and technical stakeholders. You will mentor junior and mid-level ISSOs while partnering with system owners, developers, architects, cloud/infrastructure engineers, security professionals, and government stakeholders throughout the system development lifecycle. You will provide practical security guidance for AWS-hosted applications, lead Risk Management Framework (RMF) and Authority to Operate (ATO) activities, oversee vulnerability management and continuous monitoring, and translate federal cybersecurity requirements into actionable guidance for technical teams. What You'll Do Lead, mentor, and develop a team of ISSOs by establishing priorities, providing technical direction and coaching, and promoting accountability and consistent security practices. Lead and oversee RMF, ATO, security authorization, compliance, vulnerability management, and continuous monitoring activities across a portfolio of federal systems and applications. Partner with ISSMs, system owners, assessors, developers, architects, engineers, and government stakeholders to maintain authorizations, identify risks, and address security requirements. Lead vulnerability management efforts, prioritizing remediation, developing mitigation strategies, and tracking corrective actions through resolution. Develop, assess, document, and support implementation of security controls aligned with FISMA, NIST 800-53, DHS, and client requirements . Prepare and maintain security and authorization documentation, including SSPs, ISAs, audit artifacts, and RMF documentation . Provide cybersecurity guidance for applications and systems deployed in AWS and integrate security throughout the software development lifecycle. Validate security implementation through technical reviews, discussions, interviews, assessments, and tabletop exercises. Support security audits, assessments, compliance reviews, and reviews of information systems and network connections. Interpret federal and client security policies and translate requirements into practical guidance for technical and development teams. Identify and escalate security risks, communicate priorities and remediation status, and provide clear visibility to Dev Technology leadership and government stakeholders. Develop and present security metrics, status reports, risk assessments, and executive briefings . Establish and improve security processes, procedures, templates, dashboards, and workflows to improve consistency, accountability, and efficiency across the ISSO team. Build trusted relationships with government clients through proactive communication, collaboration, and face-to-face engagement. Required Education, Experience & Skills Bachelor's degree and 7+ years of experience securing federal information systems. Demonstrated experience leading and mentoring information security professionals , including junior and mid-level ISSOs. Experience leading cybersecurity activities in a federal government client environment and working directly with government stakeholders.' Strong working knowledge of NIST Risk Management Framework (RMF) and experience supporting federal systems through security authorization and ATO activities . Experience developing, implementing, assessing, or documenting security controls aligned with FISMA and NIST 800-53 . Experience with vulnerability management, continuous monitoring, security assessments, audits, or compliance reviews for federal systems. Experience providing cybersecurity guidance for AWS-hosted applications and systems . Strong understanding of modern information systems and their technical security considerations. Ability to work effectively with developers, architects, engineers, government stakeholders, and technical and non-technical audiences. Strong written and verbal communication skills, including the ability to communicate security risks and technical findings and develop/present security documentation and executive briefings. Ability to establish priorities, manage competing demands, independently manage security activities, and escalate issues appropriately. Proactive, solutions-oriented approach to identifying risks and improving security practices. Current CBP, DHS, or Top Secret Clearance. Ability to work onsite 3 days per week in Ashburn, VA during standard business hours. Cybersecurity certification such as CISSP, CISM, GIAC, Security+, or another recognized cybersecurity certification. Preferred Education, Experience & Skills Experience developing or supporting RMF and authorization artifacts, including SSPs, ISAs, PTAs, ATTs, POA&Ms , and related documentation. Experience partnering with application development, cloud engineering, and DevSecOps teams to integrate security throughout the SDLC. Experience working in an Agile software development environment using Jira or similar platforms. Experience with GRC tools such as CSAM or similar platforms supporting authorization, compliance, vulnerability management, and security activities. Understanding of AI concepts and practical applications of AI for cybersecurity operations, risk analysis, compliance, or security program management. Our estimated salary range for this position is $88,000 - $ 150,000. This presented salary range is not a guarantee of compensation or salary. Offered salary is based on experience, geographic location, and possibly contractual requirements as appropriate to the role. Salary could fall outside of this range. Who We Are Dev Technology is a growing IT company with an employee-centric culture that works on mission-critical projects for the federal government. We partner with our federal customers to deliver technology services and solutions, and to drive our client's missions forward through innovation. We use Agile and DevSecOps principles to provide services including application development, biometrics and identity management, cloud and infrastructure optimization, IT and legacy modernization, and data management. As a Washington Post Top Workplace award winner for the past THIRTEEN years in a row, the Top Workplaces USA for the past five years, and a recipient of the Companies As Responsive Employers (CARE) Award for the past six years, Dev Technology employees enjoy: Generous and flexible time-off policy Flexible work schedules and telework options, including remote work availability for eligible projects Career development opportunities including a mentorship program, technical and management training through Dev University, hands-on learning through DevLab, tuition reimbursement, and paid training opportunities Industry-leading benefits including a choice of two health plans that include dental and vision, flexible spending account, commuter benefits, life insurance, and more 401K matching with a 5% matching contribution Regular team and company social events including our annual party, happy hours, fitness challenges, and more A focus on community engagement including company wide support activities, employer match for donations, and time off for volunteer efforts To learn more about working at Dev Technology, visit Working At Dev Technology Group Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans Dev Technology Group operates in the following states: AL, AR, AZ, CO, DC, FL, GA, ID, IL, IN, MD, MA, ME, MI, MN, MO, MS, NC, NJ, OH, OR, PA, SC, TN, TX, VA, WV.
09/18/2026
Full time
Job Description Job Description Information Security Specialist Officer, Technical Lead, AWS Security • RMF & ATO • NIST 800-53 • Cloud Application Security Clearance: Active CBP, DHS, or Top Secret Clearance required Work Arrangement: Hybrid - onsite 3 days/week during standard business hours in Ashburn, VA About the Role Dev Technology Group is seeking a Senior Information Security Specialist to lead and develop a mid-sized team of ISSOs supporting the security, compliance, and authorization of mission-critical federal applications and information systems hosted in AWS. This is a hands-on technical leadership role combining people leadership, federal cybersecurity expertise, and direct collaboration with government and technical stakeholders. You will mentor junior and mid-level ISSOs while partnering with system owners, developers, architects, cloud/infrastructure engineers, security professionals, and government stakeholders throughout the system development lifecycle. You will provide practical security guidance for AWS-hosted applications, lead Risk Management Framework (RMF) and Authority to Operate (ATO) activities, oversee vulnerability management and continuous monitoring, and translate federal cybersecurity requirements into actionable guidance for technical teams. What You'll Do Lead, mentor, and develop a team of ISSOs by establishing priorities, providing technical direction and coaching, and promoting accountability and consistent security practices. Lead and oversee RMF, ATO, security authorization, compliance, vulnerability management, and continuous monitoring activities across a portfolio of federal systems and applications. Partner with ISSMs, system owners, assessors, developers, architects, engineers, and government stakeholders to maintain authorizations, identify risks, and address security requirements. Lead vulnerability management efforts, prioritizing remediation, developing mitigation strategies, and tracking corrective actions through resolution. Develop, assess, document, and support implementation of security controls aligned with FISMA, NIST 800-53, DHS, and client requirements . Prepare and maintain security and authorization documentation, including SSPs, ISAs, audit artifacts, and RMF documentation . Provide cybersecurity guidance for applications and systems deployed in AWS and integrate security throughout the software development lifecycle. Validate security implementation through technical reviews, discussions, interviews, assessments, and tabletop exercises. Support security audits, assessments, compliance reviews, and reviews of information systems and network connections. Interpret federal and client security policies and translate requirements into practical guidance for technical and development teams. Identify and escalate security risks, communicate priorities and remediation status, and provide clear visibility to Dev Technology leadership and government stakeholders. Develop and present security metrics, status reports, risk assessments, and executive briefings . Establish and improve security processes, procedures, templates, dashboards, and workflows to improve consistency, accountability, and efficiency across the ISSO team. Build trusted relationships with government clients through proactive communication, collaboration, and face-to-face engagement. Required Education, Experience & Skills Bachelor's degree and 7+ years of experience securing federal information systems. Demonstrated experience leading and mentoring information security professionals , including junior and mid-level ISSOs. Experience leading cybersecurity activities in a federal government client environment and working directly with government stakeholders.' Strong working knowledge of NIST Risk Management Framework (RMF) and experience supporting federal systems through security authorization and ATO activities . Experience developing, implementing, assessing, or documenting security controls aligned with FISMA and NIST 800-53 . Experience with vulnerability management, continuous monitoring, security assessments, audits, or compliance reviews for federal systems. Experience providing cybersecurity guidance for AWS-hosted applications and systems . Strong understanding of modern information systems and their technical security considerations. Ability to work effectively with developers, architects, engineers, government stakeholders, and technical and non-technical audiences. Strong written and verbal communication skills, including the ability to communicate security risks and technical findings and develop/present security documentation and executive briefings. Ability to establish priorities, manage competing demands, independently manage security activities, and escalate issues appropriately. Proactive, solutions-oriented approach to identifying risks and improving security practices. Current CBP, DHS, or Top Secret Clearance. Ability to work onsite 3 days per week in Ashburn, VA during standard business hours. Cybersecurity certification such as CISSP, CISM, GIAC, Security+, or another recognized cybersecurity certification. Preferred Education, Experience & Skills Experience developing or supporting RMF and authorization artifacts, including SSPs, ISAs, PTAs, ATTs, POA&Ms , and related documentation. Experience partnering with application development, cloud engineering, and DevSecOps teams to integrate security throughout the SDLC. Experience working in an Agile software development environment using Jira or similar platforms. Experience with GRC tools such as CSAM or similar platforms supporting authorization, compliance, vulnerability management, and security activities. Understanding of AI concepts and practical applications of AI for cybersecurity operations, risk analysis, compliance, or security program management. Our estimated salary range for this position is $88,000 - $ 150,000. This presented salary range is not a guarantee of compensation or salary. Offered salary is based on experience, geographic location, and possibly contractual requirements as appropriate to the role. Salary could fall outside of this range. Who We Are Dev Technology is a growing IT company with an employee-centric culture that works on mission-critical projects for the federal government. We partner with our federal customers to deliver technology services and solutions, and to drive our client's missions forward through innovation. We use Agile and DevSecOps principles to provide services including application development, biometrics and identity management, cloud and infrastructure optimization, IT and legacy modernization, and data management. As a Washington Post Top Workplace award winner for the past THIRTEEN years in a row, the Top Workplaces USA for the past five years, and a recipient of the Companies As Responsive Employers (CARE) Award for the past six years, Dev Technology employees enjoy: Generous and flexible time-off policy Flexible work schedules and telework options, including remote work availability for eligible projects Career development opportunities including a mentorship program, technical and management training through Dev University, hands-on learning through DevLab, tuition reimbursement, and paid training opportunities Industry-leading benefits including a choice of two health plans that include dental and vision, flexible spending account, commuter benefits, life insurance, and more 401K matching with a 5% matching contribution Regular team and company social events including our annual party, happy hours, fitness challenges, and more A focus on community engagement including company wide support activities, employer match for donations, and time off for volunteer efforts To learn more about working at Dev Technology, visit Working At Dev Technology Group Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans Dev Technology Group operates in the following states: AL, AR, AZ, CO, DC, FL, GA, ID, IL, IN, MD, MA, ME, MI, MN, MO, MS, NC, NJ, OH, OR, PA, SC, TN, TX, VA, WV.
Cybersecurity Assessor
OneZero Solutions Alexandria, Virginia
Job Description Job Description We are an employee-centric company that truly values our team members and the contributions they make to our customers and the missions they support. We pride ourselves on being forward-leaning thinkers and on building teams that are, and continue to be, technically proficient across a broad range of cyber mission areas. OneZero full-time employees receive a highly competitive benefits package, including health, dental, vision, and life insurance, a 401(k) with company matching, paid time off and holidays, an employee referral program, and educational assistance. Additional details are available on our website: Position Title : Cybersecurity Assessor Location : Alexandria, VA Hybrid Clearance : TS/SCI Responsibilities: Plan and conduct technology assessments in support of DoD CORA and CCORI efforts. Perform interviews, examinations, and testing to evaluate compliance with DoD-mandated security engineering standards and policy requirements. Assist in preparing assessment deliverables, including Security Control Assessment Reports, Security Risk Assessments, and related documentation. Prepare and present briefings and reports detailing inspection results, critical areas of concern, and required remediation actions necessary to achieve compliance. Requirements: Active Top Secret (TS)/SCI security clearance. Current DoD 8570 IAT II-level certification . Working knowledge of DoD STIGs . Familiarity with DoD CND OPORDs and TASKORDs . Familiarity with DoD CCRI assessment areas , including Technical, Computer Network Defense (CND), and Contributing Factors. Experience with common assessment tools, such as STIG Viewer, ACAS/Nessus, WebInspect, Burp Suite, Red Seal , and similar tools. Demonstrated proficiency in one or more of the following technology areas: Windows 10/11 and Microsoft Server Linux Routing and switching Network defense appliances, including firewalls, IDS/IPS, and proxies Cloud services OneZero Solutions, LLC is an Equal Opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or protected veteran status. To request an accommodation, please contact us at or call . Job Posted by ApplicantPro
09/17/2026
Full time
Job Description Job Description We are an employee-centric company that truly values our team members and the contributions they make to our customers and the missions they support. We pride ourselves on being forward-leaning thinkers and on building teams that are, and continue to be, technically proficient across a broad range of cyber mission areas. OneZero full-time employees receive a highly competitive benefits package, including health, dental, vision, and life insurance, a 401(k) with company matching, paid time off and holidays, an employee referral program, and educational assistance. Additional details are available on our website: Position Title : Cybersecurity Assessor Location : Alexandria, VA Hybrid Clearance : TS/SCI Responsibilities: Plan and conduct technology assessments in support of DoD CORA and CCORI efforts. Perform interviews, examinations, and testing to evaluate compliance with DoD-mandated security engineering standards and policy requirements. Assist in preparing assessment deliverables, including Security Control Assessment Reports, Security Risk Assessments, and related documentation. Prepare and present briefings and reports detailing inspection results, critical areas of concern, and required remediation actions necessary to achieve compliance. Requirements: Active Top Secret (TS)/SCI security clearance. Current DoD 8570 IAT II-level certification . Working knowledge of DoD STIGs . Familiarity with DoD CND OPORDs and TASKORDs . Familiarity with DoD CCRI assessment areas , including Technical, Computer Network Defense (CND), and Contributing Factors. Experience with common assessment tools, such as STIG Viewer, ACAS/Nessus, WebInspect, Burp Suite, Red Seal , and similar tools. Demonstrated proficiency in one or more of the following technology areas: Windows 10/11 and Microsoft Server Linux Routing and switching Network defense appliances, including firewalls, IDS/IPS, and proxies Cloud services OneZero Solutions, LLC is an Equal Opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or protected veteran status. To request an accommodation, please contact us at or call . Job Posted by ApplicantPro
SCA II - Security Control Assessor
Watermark Risk Management International Arlington, Virginia
Job Description Job Description Come make your mark with Watermark! FOUNDED BY USAF VETERANS in 2007, we are proud to be a Service-Disabled Veteran Owned Small Business. SUBJECT MATTER EXPERTS specializing in security and risk management. We're intimately familiar with DOD security programs and mission requirements. OUR CORE VALUES drive every action we take as a company. We strive to exhibit PERSPECTIVE, PASSION, COMMUNICATION, INTEGRITY AND ETHICS, and BALANCE in all we do. COMPETITIVE BENEFITS PACKAGE to address our employees' physical, mental, emotional, and financial well-being. This includes 100% employer- paid medical insurance, ample paid leave, a free employee assistance program, and a competitive 401k savings plan. At Watermark, our people come first! Security Control Assessor (SCA) II The SCA is responsible for conducting a comprehensive assessment of the management, operational, and technical security controls employed within or inherited by an IS to determine the overall effectiveness of the controls (i.e., the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for the system). SCAs also provide an assessment of the severity of weaknesses or deficiencies discovered in the IS and its environment of operation and recommend corrective actions to address identified vulnerabilities. Responsibilities will cover Collateral, Sensitive Compartmented Information (SCI) and Special Access Program (SAP) activities within the customer's area of responsibility. In this role you will . Perform oversight of the development, implementation and evaluation of IS security program policy; special emphasis placed upon integration of existing SAP network infrastructure Perform assessment of ISs, based upon the Risk Management Framework (RMF) methodology in accordance with the Joint Special Access Program (SAP) Implementation Guide (JSIG) Advise the Information System Owner (ISO), Information Data Owner (IDO), Program Security Officer (PSO), and the Delegated and/or Authorizing Official (DAO/AO) on any assessment and authorization issues Evaluate Authorization packages and make recommendation to the AO and/or DAO for authorization Evaluate IS threats and vulnerabilities to determine whether additional safeguards are required Advise the Government concerning the impact levels for Confidentiality, Integrity, and Availability for the information on a system Ensure security assessments are completed and results documented and prepare the Security Assessment Report (SAR) for the Authorization boundary Initiate a Plan of Action and Milestones (POA&M) with identified weaknesses for each Authorization Boundaries assessed, based on findings and recommendations from the SAR Evaluate security assessment documentation and provide written recommendations for security authorization to the Government Discuss recommendation for authorization and submit the security authorization package to the AO/DAO Assess proposed changes to Authorization boundaries operating environment and mission needs to determine the continuation to operate. Review and concur with all sanitization and clearing procedures in accordance with Government guidance and/or policy Assist the Government compliance inspections Assist the Government with security incidents that relate to cybersecurity and ensure that the proper and corrective measures have been taken Ensure organization are addressing and conducting all phases of the system development life cycle (SDLC) Evaluate Hardware and Software to determine security impact that it might have on Authorization boundaries Evaluate the effectiveness and implementation of Continuous Monitoring Plans Represent the customer on inspection teams Additional duties as assigned Experience Requirements: 7-9 years related experience Minimum of four (4) years' experience in SAP, SCI or Collateral Information Systems (IS) Security and the implementation of regulations identified in the description of duties. Prior performance in the role of ISSO and ISSM or SCA Education Requirements: Bachelor's degree in a related area OR Associate's degree in a related area + 2 years' experience OR equivalent experience (4 years) Certification Requirements: Must meet position and certification requirements outlined in DoD Directive 8570.01-M for Information Assurance Technician Level III or Information Assurance Manager Level II within 6 months of the date of hire Security Clearance Requirements: Active TS/SCI clearance Eligibility for access to Special Access Program Information Willingness to submit to a Counterintelligence polygraph Other Requirements: Must be able to regularly lift up to 50 lbs. May require sedentary work at least 50% of the time Reports to a physical location which occasionally requires the ability to traverse between buildings Ability to manage stress with a high degree of maturity/professionalism Demonstrated critical thinking and leadership skills and the ability to work well with others Effective verbal and written communication skills All Level I & Level II positions - candidate should possess some Special Access Program (SAP) experience All Level III positions -candidate should possess 2+ years of Special Access Program (SAP) experience Watermark provides salary ranges with job postings in states where it is legally required; any other salary ranges associated with our postings are third party estimates and may not be an accurate reflection of Watermark's total compensation package. Multiple considerations are taken into account when determining the final salary/hourly rate, including but not limited to, Contract Wage Determination, education and certifications, relevant work experience, related skills and competencies, as well as Federal Government Contract Labor Categories. Central to Watermark's employment philosophy is the wellbeing of our employees which is why we offer a robust benefits package and wellness program alongside of annual base compensation. Watermark is an equal opportunity employer. All terms and conditions of employment are established without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, pregnancy, genetic information, disability, veteran status, or any other protected category under applicable federal, state, and local laws. Powered by JazzHR Ulb7SEozj9
09/16/2026
Full time
Job Description Job Description Come make your mark with Watermark! FOUNDED BY USAF VETERANS in 2007, we are proud to be a Service-Disabled Veteran Owned Small Business. SUBJECT MATTER EXPERTS specializing in security and risk management. We're intimately familiar with DOD security programs and mission requirements. OUR CORE VALUES drive every action we take as a company. We strive to exhibit PERSPECTIVE, PASSION, COMMUNICATION, INTEGRITY AND ETHICS, and BALANCE in all we do. COMPETITIVE BENEFITS PACKAGE to address our employees' physical, mental, emotional, and financial well-being. This includes 100% employer- paid medical insurance, ample paid leave, a free employee assistance program, and a competitive 401k savings plan. At Watermark, our people come first! Security Control Assessor (SCA) II The SCA is responsible for conducting a comprehensive assessment of the management, operational, and technical security controls employed within or inherited by an IS to determine the overall effectiveness of the controls (i.e., the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for the system). SCAs also provide an assessment of the severity of weaknesses or deficiencies discovered in the IS and its environment of operation and recommend corrective actions to address identified vulnerabilities. Responsibilities will cover Collateral, Sensitive Compartmented Information (SCI) and Special Access Program (SAP) activities within the customer's area of responsibility. In this role you will . Perform oversight of the development, implementation and evaluation of IS security program policy; special emphasis placed upon integration of existing SAP network infrastructure Perform assessment of ISs, based upon the Risk Management Framework (RMF) methodology in accordance with the Joint Special Access Program (SAP) Implementation Guide (JSIG) Advise the Information System Owner (ISO), Information Data Owner (IDO), Program Security Officer (PSO), and the Delegated and/or Authorizing Official (DAO/AO) on any assessment and authorization issues Evaluate Authorization packages and make recommendation to the AO and/or DAO for authorization Evaluate IS threats and vulnerabilities to determine whether additional safeguards are required Advise the Government concerning the impact levels for Confidentiality, Integrity, and Availability for the information on a system Ensure security assessments are completed and results documented and prepare the Security Assessment Report (SAR) for the Authorization boundary Initiate a Plan of Action and Milestones (POA&M) with identified weaknesses for each Authorization Boundaries assessed, based on findings and recommendations from the SAR Evaluate security assessment documentation and provide written recommendations for security authorization to the Government Discuss recommendation for authorization and submit the security authorization package to the AO/DAO Assess proposed changes to Authorization boundaries operating environment and mission needs to determine the continuation to operate. Review and concur with all sanitization and clearing procedures in accordance with Government guidance and/or policy Assist the Government compliance inspections Assist the Government with security incidents that relate to cybersecurity and ensure that the proper and corrective measures have been taken Ensure organization are addressing and conducting all phases of the system development life cycle (SDLC) Evaluate Hardware and Software to determine security impact that it might have on Authorization boundaries Evaluate the effectiveness and implementation of Continuous Monitoring Plans Represent the customer on inspection teams Additional duties as assigned Experience Requirements: 7-9 years related experience Minimum of four (4) years' experience in SAP, SCI or Collateral Information Systems (IS) Security and the implementation of regulations identified in the description of duties. Prior performance in the role of ISSO and ISSM or SCA Education Requirements: Bachelor's degree in a related area OR Associate's degree in a related area + 2 years' experience OR equivalent experience (4 years) Certification Requirements: Must meet position and certification requirements outlined in DoD Directive 8570.01-M for Information Assurance Technician Level III or Information Assurance Manager Level II within 6 months of the date of hire Security Clearance Requirements: Active TS/SCI clearance Eligibility for access to Special Access Program Information Willingness to submit to a Counterintelligence polygraph Other Requirements: Must be able to regularly lift up to 50 lbs. May require sedentary work at least 50% of the time Reports to a physical location which occasionally requires the ability to traverse between buildings Ability to manage stress with a high degree of maturity/professionalism Demonstrated critical thinking and leadership skills and the ability to work well with others Effective verbal and written communication skills All Level I & Level II positions - candidate should possess some Special Access Program (SAP) experience All Level III positions -candidate should possess 2+ years of Special Access Program (SAP) experience Watermark provides salary ranges with job postings in states where it is legally required; any other salary ranges associated with our postings are third party estimates and may not be an accurate reflection of Watermark's total compensation package. Multiple considerations are taken into account when determining the final salary/hourly rate, including but not limited to, Contract Wage Determination, education and certifications, relevant work experience, related skills and competencies, as well as Federal Government Contract Labor Categories. Central to Watermark's employment philosophy is the wellbeing of our employees which is why we offer a robust benefits package and wellness program alongside of annual base compensation. Watermark is an equal opportunity employer. All terms and conditions of employment are established without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, pregnancy, genetic information, disability, veteran status, or any other protected category under applicable federal, state, and local laws. Powered by JazzHR Ulb7SEozj9
Security Controls Assessor
Oneida Technical Solutions Shaw A F B, South Carolina
Job Description Job Description Oneida Technical Solutions, LLC (OTS), was founded in 2014 and quickly established itself as a reliable partner capable of providing a variety of information technology and cyber solutions across highly complex, highly regulated and highly secure environments, including the U.S. Department of Defense (DoD), healthcare, higher education, law enforcement, retail, casino gaming and more.Our innovative cyber capabilities and programs have made us trusted partners for IT modernization projects, implementing upgrades and accelerating the delivery of new solutions for the DoD and commercial industries with consumer-driven technology.OTS is seeking a Security Controls Assessor in providing cybersecurity support to AFCENT - this role is onsite at Shaw AFB in Sumter, SC.In this role you will perform comprehensive IT security control assessments on AFCENT systems and software applications. Assessments shall require physical travel to various contractor and Government sites inside and outside the continental United States (CONUS and OCONUS). Assessments shall determine the condition of the management, operational, and technical security controls employed within or inherited by an information system or software to determine the overall effectiveness of the controls (i.e., the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for the system).Duties for this role include, but are not limited to:Perform initial and continual security control assessment and validation for AFCENT networks, systems, and software applications.Utilize DOD approved tools such as, but not limited to - Assured Compliance Assessment Solution (ACAS), Nessus, Host Based Security Systems (HBSS), Continuous Monitoring Risk Scoring (CMRS), Online Compliance Reporting System (OCRS), and SolarWinds - to generate initial and continuous monitoring reports.Complete reports to support risk decisions from the AO, both as required and as requested.Provide an assessment on the severity of weaknesses or deficiencies discovered in the information system or software application and its environment of operation and recommend corrective actions to address identified vulnerabilities.Review the System Security Plan (SSP), prior to initiating the security control assessment and ensure the plan provides a set of security controls for the information system or software application that meet the stated security requirements.Advise the Information System Owner (ISO) concerning the impact values for confidentiality, integrity, and availability for the information on a system or software application.Evaluate threats and vulnerabilities to information systems or software application to ascertain the need for additional safeguards.Assist in creating, reviewing, and approving the information system or software application security assessment plan, which is comprised of the SSP, the Security Controls Traceability Matrix (SCTM), and the Security Control Assessment Procedure.Ensure security control assessments are completed for each information system or software application and ensure controls are working as intended and these controls protect the confidentiality, integrity and availability of IT resources at the appropriate levels.Assist with preparing the final Security Assessment Report (SAR) containing the results and findings from the assessment at the conclusion of each security control assessment activity.Ensure a Plan of Action and Milestones (POA&M) is initiated by the Information System Security Officer (ISSO) for the information system based on findings and recommendations from the SAR.Evaluate security control assessment documentation and provide written recommendations for security authorization to the AO.Provide expertise to execute vulnerability assessments on Platform IT systems.Assist with assembling and submitting the security authorization artifacts to the AO (consisting of, at a minimum, the SSP, the SAR, the POA&M, and a Risk Assessment Report (RAR).Assess the proposed changes to information systems or software application, their environment of operation, and mission needs to determine if they are security-relevant and could therefore affect system authorization.Utilize the RMF methodology to successfully implement an information technology process which shall effectively protect the element's information assets and its ability to perform its mission.Provide guidance to other assessors on the policies and procedures of the job; Provide detailed assessment findings using Government-specified processes and procedure.Provide solutions and recommendations to remedy security vulnerabilities, threats, to ultimately improve the protection of IT resources and to execute the AFCENT mission.Utilize assessment results to identify trends and to improve IA training, policies and processes.Develop reports and trend analysis's to support risk assessment decisions.Qualified candidates must meet the following mandatory requirements:Must possess and maintain a Secret ClearanceProof of IAT-III or IAM-III CertificationSenior (III) and higher positions (Preferred):- MA/MS in related field AND 3 or more years' relevant experience; or- BS in related field AND 5 or more years' relevant IT experience; or- 7 or more years' relevant IT experience.Mid-level (II) or lower positions:- BS in related field AND 1 or more years' relevant experience; or- Associates in related field and 3 or more years' relevant IT experience; or- 5 or more years' of relevant IT experience.Oneida Technical Solutions, LLC. is an equal opportunity employer and will consider all qualified applicants for employment without regard to race, color, religion, sex, national origin, age, disability, marital status, veteran status, sexual orientation, gender identity, genetic information or any other protected characteristic under applicable law. Job Posted by ApplicantPro
09/15/2026
Full time
Job Description Job Description Oneida Technical Solutions, LLC (OTS), was founded in 2014 and quickly established itself as a reliable partner capable of providing a variety of information technology and cyber solutions across highly complex, highly regulated and highly secure environments, including the U.S. Department of Defense (DoD), healthcare, higher education, law enforcement, retail, casino gaming and more.Our innovative cyber capabilities and programs have made us trusted partners for IT modernization projects, implementing upgrades and accelerating the delivery of new solutions for the DoD and commercial industries with consumer-driven technology.OTS is seeking a Security Controls Assessor in providing cybersecurity support to AFCENT - this role is onsite at Shaw AFB in Sumter, SC.In this role you will perform comprehensive IT security control assessments on AFCENT systems and software applications. Assessments shall require physical travel to various contractor and Government sites inside and outside the continental United States (CONUS and OCONUS). Assessments shall determine the condition of the management, operational, and technical security controls employed within or inherited by an information system or software to determine the overall effectiveness of the controls (i.e., the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for the system).Duties for this role include, but are not limited to:Perform initial and continual security control assessment and validation for AFCENT networks, systems, and software applications.Utilize DOD approved tools such as, but not limited to - Assured Compliance Assessment Solution (ACAS), Nessus, Host Based Security Systems (HBSS), Continuous Monitoring Risk Scoring (CMRS), Online Compliance Reporting System (OCRS), and SolarWinds - to generate initial and continuous monitoring reports.Complete reports to support risk decisions from the AO, both as required and as requested.Provide an assessment on the severity of weaknesses or deficiencies discovered in the information system or software application and its environment of operation and recommend corrective actions to address identified vulnerabilities.Review the System Security Plan (SSP), prior to initiating the security control assessment and ensure the plan provides a set of security controls for the information system or software application that meet the stated security requirements.Advise the Information System Owner (ISO) concerning the impact values for confidentiality, integrity, and availability for the information on a system or software application.Evaluate threats and vulnerabilities to information systems or software application to ascertain the need for additional safeguards.Assist in creating, reviewing, and approving the information system or software application security assessment plan, which is comprised of the SSP, the Security Controls Traceability Matrix (SCTM), and the Security Control Assessment Procedure.Ensure security control assessments are completed for each information system or software application and ensure controls are working as intended and these controls protect the confidentiality, integrity and availability of IT resources at the appropriate levels.Assist with preparing the final Security Assessment Report (SAR) containing the results and findings from the assessment at the conclusion of each security control assessment activity.Ensure a Plan of Action and Milestones (POA&M) is initiated by the Information System Security Officer (ISSO) for the information system based on findings and recommendations from the SAR.Evaluate security control assessment documentation and provide written recommendations for security authorization to the AO.Provide expertise to execute vulnerability assessments on Platform IT systems.Assist with assembling and submitting the security authorization artifacts to the AO (consisting of, at a minimum, the SSP, the SAR, the POA&M, and a Risk Assessment Report (RAR).Assess the proposed changes to information systems or software application, their environment of operation, and mission needs to determine if they are security-relevant and could therefore affect system authorization.Utilize the RMF methodology to successfully implement an information technology process which shall effectively protect the element's information assets and its ability to perform its mission.Provide guidance to other assessors on the policies and procedures of the job; Provide detailed assessment findings using Government-specified processes and procedure.Provide solutions and recommendations to remedy security vulnerabilities, threats, to ultimately improve the protection of IT resources and to execute the AFCENT mission.Utilize assessment results to identify trends and to improve IA training, policies and processes.Develop reports and trend analysis's to support risk assessment decisions.Qualified candidates must meet the following mandatory requirements:Must possess and maintain a Secret ClearanceProof of IAT-III or IAM-III CertificationSenior (III) and higher positions (Preferred):- MA/MS in related field AND 3 or more years' relevant experience; or- BS in related field AND 5 or more years' relevant IT experience; or- 7 or more years' relevant IT experience.Mid-level (II) or lower positions:- BS in related field AND 1 or more years' relevant experience; or- Associates in related field and 3 or more years' relevant IT experience; or- 5 or more years' of relevant IT experience.Oneida Technical Solutions, LLC. is an equal opportunity employer and will consider all qualified applicants for employment without regard to race, color, religion, sex, national origin, age, disability, marital status, veteran status, sexual orientation, gender identity, genetic information or any other protected characteristic under applicable law. Job Posted by ApplicantPro
Cyber Security Controls Assessor
Pivot Point Solutions San Francisco, California
Job Description Job Description Pivot Point Solutions Pivot Point Solutions is a California-based technology consulting firm that specializes in delivering IT solutions and support for the construction and utility industries. We partner with organizations across the state to provide reliable technology services that improve operational efficiency, enhance project delivery, and support critical business systems. Our team understands the unique technology challenges facing construction and utility organizations, from field operations and infrastructure projects to enterprise applications and cybersecurity. By combining industry expertise with responsive service, we help clients modernize their technology environments, streamline workflows, and maintain secure, reliable IT systems that support long-term growth. Job Overview Title: Cyber Security Controls Assessor Sector: Information Technology / Cybersecurity Seniority: Mid to Senior Level Location: California (Hybrid) Job Type: Contract Contract Length: 6+ Months Compensation: $104K - $145K About the Role PPS is seeking a Cyber Security Controls Assessor to support the protection of critical energy infrastructure through the assessment and validation of cybersecurity controls across enterprise and operational technology (OT) environments. This role evaluates compliance with cybersecurity policies, regulatory requirements, and industry standards to ensure the confidentiality, integrity, and availability of systems supporting electric and gas utility operations. The ideal candidate brings strong experience in security assessments, risk management, compliance, and control validation, with a focus on protecting critical infrastructure and supporting regulatory obligations. Key Responsibilities Conduct cybersecurity control assessments for enterprise IT, cloud, and OT/industrial control system environments Evaluate security controls against NIST CSF, NIST 800-53, NERC CIP, CIS Controls, and security policies Identify security risks, control deficiencies, and compliance gaps, and recommend corrective actions Prepare assessment reports detailing findings, risk ratings, remediation recommendations, and control effectiveness Partner with cybersecurity, engineering, IT, OT, compliance, and business stakeholders on risk identification and management Validate implementation and effectiveness of security controls for new projects, system upgrades, and technology deployments Support internal audits, regulatory reviews, and compliance initiatives related to critical infrastructure protection Track remediation activities and validate closure of cybersecurity findings Maintain assessment methodologies, standards, and procedures supporting cybersecurity programs Mentor junior assessors and contribute to continuous improvement initiatives within the Cybersecurity Risk & Compliance team Qualifications Required: Bachelor's degree in Cybersecurity, Information Security, Computer Science, Engineering, IT, or related field; or equivalent experience 5+ years of experience in cybersecurity, risk management, compliance, audit, or security controls assessment Experience performing security assessments and evaluating cybersecurity controls Knowledge of cybersecurity frameworks such as NIST CSF, NIST 800-53, CIS Controls, and risk management methodologies Experience with regulatory compliance programs and audit support Strong analytical, communication, and technical documentation skills Ability to communicate security risks and recommendations to technical and non-technical stakeholders Preferred: Experience within electric utilities, critical infrastructure, energy, or other regulated industries Knowledge of NERC CIP standards and compliance requirements Experience assessing OT, SCADA, ICS, or energy management systems Familiarity with cloud security environments (Azure, AWS) Experience with GRC platforms Professional certifications: CISSP, CISA, CRISC, GICSP, Security+, or equivalent Work Environment Standard office/field environment supporting critical infrastructure operations
09/15/2026
Full time
Job Description Job Description Pivot Point Solutions Pivot Point Solutions is a California-based technology consulting firm that specializes in delivering IT solutions and support for the construction and utility industries. We partner with organizations across the state to provide reliable technology services that improve operational efficiency, enhance project delivery, and support critical business systems. Our team understands the unique technology challenges facing construction and utility organizations, from field operations and infrastructure projects to enterprise applications and cybersecurity. By combining industry expertise with responsive service, we help clients modernize their technology environments, streamline workflows, and maintain secure, reliable IT systems that support long-term growth. Job Overview Title: Cyber Security Controls Assessor Sector: Information Technology / Cybersecurity Seniority: Mid to Senior Level Location: California (Hybrid) Job Type: Contract Contract Length: 6+ Months Compensation: $104K - $145K About the Role PPS is seeking a Cyber Security Controls Assessor to support the protection of critical energy infrastructure through the assessment and validation of cybersecurity controls across enterprise and operational technology (OT) environments. This role evaluates compliance with cybersecurity policies, regulatory requirements, and industry standards to ensure the confidentiality, integrity, and availability of systems supporting electric and gas utility operations. The ideal candidate brings strong experience in security assessments, risk management, compliance, and control validation, with a focus on protecting critical infrastructure and supporting regulatory obligations. Key Responsibilities Conduct cybersecurity control assessments for enterprise IT, cloud, and OT/industrial control system environments Evaluate security controls against NIST CSF, NIST 800-53, NERC CIP, CIS Controls, and security policies Identify security risks, control deficiencies, and compliance gaps, and recommend corrective actions Prepare assessment reports detailing findings, risk ratings, remediation recommendations, and control effectiveness Partner with cybersecurity, engineering, IT, OT, compliance, and business stakeholders on risk identification and management Validate implementation and effectiveness of security controls for new projects, system upgrades, and technology deployments Support internal audits, regulatory reviews, and compliance initiatives related to critical infrastructure protection Track remediation activities and validate closure of cybersecurity findings Maintain assessment methodologies, standards, and procedures supporting cybersecurity programs Mentor junior assessors and contribute to continuous improvement initiatives within the Cybersecurity Risk & Compliance team Qualifications Required: Bachelor's degree in Cybersecurity, Information Security, Computer Science, Engineering, IT, or related field; or equivalent experience 5+ years of experience in cybersecurity, risk management, compliance, audit, or security controls assessment Experience performing security assessments and evaluating cybersecurity controls Knowledge of cybersecurity frameworks such as NIST CSF, NIST 800-53, CIS Controls, and risk management methodologies Experience with regulatory compliance programs and audit support Strong analytical, communication, and technical documentation skills Ability to communicate security risks and recommendations to technical and non-technical stakeholders Preferred: Experience within electric utilities, critical infrastructure, energy, or other regulated industries Knowledge of NERC CIP standards and compliance requirements Experience assessing OT, SCADA, ICS, or energy management systems Familiarity with cloud security environments (Azure, AWS) Experience with GRC platforms Professional certifications: CISSP, CISA, CRISC, GICSP, Security+, or equivalent Work Environment Standard office/field environment supporting critical infrastructure operations
Cyber Security Controls Assessor
Pivot Point Solutions Isleton, California
Job Description Job Description Pivot Point Solutions Pivot Point Solutions is a California-based technology consulting firm that specializes in delivering IT solutions and support for the construction and utility industries. We partner with organizations across the state to provide reliable technology services that improve operational efficiency, enhance project delivery, and support critical business systems. Our team understands the unique technology challenges facing construction and utility organizations, from field operations and infrastructure projects to enterprise applications and cybersecurity. By combining industry expertise with responsive service, we help clients modernize their technology environments, streamline workflows, and maintain secure, reliable IT systems that support long-term growth. Job Overview Title: Cyber Security Controls Assessor Sector: Information Technology / Cybersecurity Seniority: Mid to Senior Level Location: California (Hybrid) Job Type: Contract Contract Length: 6+ Months Compensation: $104K - $145K About the Role PPS is seeking a Cyber Security Controls Assessor to support the protection of critical energy infrastructure through the assessment and validation of cybersecurity controls across enterprise and operational technology (OT) environments. This role evaluates compliance with cybersecurity policies, regulatory requirements, and industry standards to ensure the confidentiality, integrity, and availability of systems supporting electric and gas utility operations. The ideal candidate brings strong experience in security assessments, risk management, compliance, and control validation, with a focus on protecting critical infrastructure and supporting regulatory obligations. Key Responsibilities Conduct cybersecurity control assessments for enterprise IT, cloud, and OT/industrial control system environments Evaluate security controls against NIST CSF, NIST 800-53, NERC CIP, CIS Controls, and security policies Identify security risks, control deficiencies, and compliance gaps, and recommend corrective actions Prepare assessment reports detailing findings, risk ratings, remediation recommendations, and control effectiveness Partner with cybersecurity, engineering, IT, OT, compliance, and business stakeholders on risk identification and management Validate implementation and effectiveness of security controls for new projects, system upgrades, and technology deployments Support internal audits, regulatory reviews, and compliance initiatives related to critical infrastructure protection Track remediation activities and validate closure of cybersecurity findings Maintain assessment methodologies, standards, and procedures supporting cybersecurity programs Mentor junior assessors and contribute to continuous improvement initiatives within the Cybersecurity Risk & Compliance team Qualifications Required: Bachelor's degree in Cybersecurity, Information Security, Computer Science, Engineering, IT, or related field; or equivalent experience 5+ years of experience in cybersecurity, risk management, compliance, audit, or security controls assessment Experience performing security assessments and evaluating cybersecurity controls Knowledge of cybersecurity frameworks such as NIST CSF, NIST 800-53, CIS Controls, and risk management methodologies Experience with regulatory compliance programs and audit support Strong analytical, communication, and technical documentation skills Ability to communicate security risks and recommendations to technical and non-technical stakeholders Preferred: Experience within electric utilities, critical infrastructure, energy, or other regulated industries Knowledge of NERC CIP standards and compliance requirements Experience assessing OT, SCADA, ICS, or energy management systems Familiarity with cloud security environments (Azure, AWS) Experience with GRC platforms Professional certifications: CISSP, CISA, CRISC, GICSP, Security+, or equivalent Work Environment Standard office/field environment supporting critical infrastructure operations
09/15/2026
Full time
Job Description Job Description Pivot Point Solutions Pivot Point Solutions is a California-based technology consulting firm that specializes in delivering IT solutions and support for the construction and utility industries. We partner with organizations across the state to provide reliable technology services that improve operational efficiency, enhance project delivery, and support critical business systems. Our team understands the unique technology challenges facing construction and utility organizations, from field operations and infrastructure projects to enterprise applications and cybersecurity. By combining industry expertise with responsive service, we help clients modernize their technology environments, streamline workflows, and maintain secure, reliable IT systems that support long-term growth. Job Overview Title: Cyber Security Controls Assessor Sector: Information Technology / Cybersecurity Seniority: Mid to Senior Level Location: California (Hybrid) Job Type: Contract Contract Length: 6+ Months Compensation: $104K - $145K About the Role PPS is seeking a Cyber Security Controls Assessor to support the protection of critical energy infrastructure through the assessment and validation of cybersecurity controls across enterprise and operational technology (OT) environments. This role evaluates compliance with cybersecurity policies, regulatory requirements, and industry standards to ensure the confidentiality, integrity, and availability of systems supporting electric and gas utility operations. The ideal candidate brings strong experience in security assessments, risk management, compliance, and control validation, with a focus on protecting critical infrastructure and supporting regulatory obligations. Key Responsibilities Conduct cybersecurity control assessments for enterprise IT, cloud, and OT/industrial control system environments Evaluate security controls against NIST CSF, NIST 800-53, NERC CIP, CIS Controls, and security policies Identify security risks, control deficiencies, and compliance gaps, and recommend corrective actions Prepare assessment reports detailing findings, risk ratings, remediation recommendations, and control effectiveness Partner with cybersecurity, engineering, IT, OT, compliance, and business stakeholders on risk identification and management Validate implementation and effectiveness of security controls for new projects, system upgrades, and technology deployments Support internal audits, regulatory reviews, and compliance initiatives related to critical infrastructure protection Track remediation activities and validate closure of cybersecurity findings Maintain assessment methodologies, standards, and procedures supporting cybersecurity programs Mentor junior assessors and contribute to continuous improvement initiatives within the Cybersecurity Risk & Compliance team Qualifications Required: Bachelor's degree in Cybersecurity, Information Security, Computer Science, Engineering, IT, or related field; or equivalent experience 5+ years of experience in cybersecurity, risk management, compliance, audit, or security controls assessment Experience performing security assessments and evaluating cybersecurity controls Knowledge of cybersecurity frameworks such as NIST CSF, NIST 800-53, CIS Controls, and risk management methodologies Experience with regulatory compliance programs and audit support Strong analytical, communication, and technical documentation skills Ability to communicate security risks and recommendations to technical and non-technical stakeholders Preferred: Experience within electric utilities, critical infrastructure, energy, or other regulated industries Knowledge of NERC CIP standards and compliance requirements Experience assessing OT, SCADA, ICS, or energy management systems Familiarity with cloud security environments (Azure, AWS) Experience with GRC platforms Professional certifications: CISSP, CISA, CRISC, GICSP, Security+, or equivalent Work Environment Standard office/field environment supporting critical infrastructure operations
Security Control Assessor
LinTech Global Monterey, California
Job Description Job Description Security Control AssessorTarget Salary: $65K to $75KLOCATION: DLIFLC, 1759 Lewis Road, Monterey, CA 93944Position Overview:The Security Control Assessor is responsible for conducting independent, comprehensive assessments of the management, operational, and technical security controls and control enhancements within or inherited by an information technology (IT) system. The primary objective is to determine the overall effectiveness of these controls, as defined in NIST 800- 37.Job Duties:Conduct comprehensive assessments of management, operational, and technical security controls.Evaluate compliance with NIST SP 800-53, NIST RMF, FedRAMP, DoD RMF, and agency-specific requirements.Develop Security Assessment Plans (SAPs).Execute control testing and validation activities.Review system documentation, architectures, and security artifacts.Assess cybersecurity risks and determine residual risk levels.Identify control deficiencies and recommend remediation actions.Validate Plans of Action & Milestones (POA&Ms).Support Authorization to Operate (ATO) decisions.Ensure compliance with federal and regulatory requirements.Document findings, vulnerabilities, and risk determinations.Present assessment results to system owners, ISSOs, ISSMs, and Authorizing Officials.Track remediation efforts and reassessment activities.Job Requirements:Educational requirements include AA/AS from an accredited college or university or substitute with 3+ years of equivalent technical related experience.Must have following relevant Skills: ACAS, Microsoft Defender, STIGs, Microsoft 365, SaaS Security, RHEL, Windows Server, MacOS, and eMASS.Must be able to evaluate Security Controls: Perform thorough evaluations to ensure compliance with NIST 800- 37 and related standards.Must be able to identify and Recommend Improvements: Assess control effectiveness, identify vulnerabilities, and recommend enhancements.Must be able to document and Report Findings: Provide detailed reports and communicate findings to stakeholders.Must be able to collaborate with Teams: Work with IT and security teams to implement recommended measures.Required to Start Qualifications:IAT Level II Certification is required to Start (CCNA Security, CSA+, GICSP, GSEC, Security+ CE, or SSCP) CertificationA NACLC Public Trust Clearance is required to Start.Company DescriptionDexian Government Solutions is an award-winning, ISO 9001:2015 certified, business and GSA contract holder providing diversified Information Technology services to both Civilian and Defense agencies. Services include Software Development, Systems Integration, Data Management, Project Management, Operations & Maintenance, Cybersecurity, and Training and Audio/Visual (AV) Solutions. Dexian Government Solutions has received several recognitions, including rankings on "Top 50 Companies to Watch
09/15/2026
Full time
Job Description Job Description Security Control AssessorTarget Salary: $65K to $75KLOCATION: DLIFLC, 1759 Lewis Road, Monterey, CA 93944Position Overview:The Security Control Assessor is responsible for conducting independent, comprehensive assessments of the management, operational, and technical security controls and control enhancements within or inherited by an information technology (IT) system. The primary objective is to determine the overall effectiveness of these controls, as defined in NIST 800- 37.Job Duties:Conduct comprehensive assessments of management, operational, and technical security controls.Evaluate compliance with NIST SP 800-53, NIST RMF, FedRAMP, DoD RMF, and agency-specific requirements.Develop Security Assessment Plans (SAPs).Execute control testing and validation activities.Review system documentation, architectures, and security artifacts.Assess cybersecurity risks and determine residual risk levels.Identify control deficiencies and recommend remediation actions.Validate Plans of Action & Milestones (POA&Ms).Support Authorization to Operate (ATO) decisions.Ensure compliance with federal and regulatory requirements.Document findings, vulnerabilities, and risk determinations.Present assessment results to system owners, ISSOs, ISSMs, and Authorizing Officials.Track remediation efforts and reassessment activities.Job Requirements:Educational requirements include AA/AS from an accredited college or university or substitute with 3+ years of equivalent technical related experience.Must have following relevant Skills: ACAS, Microsoft Defender, STIGs, Microsoft 365, SaaS Security, RHEL, Windows Server, MacOS, and eMASS.Must be able to evaluate Security Controls: Perform thorough evaluations to ensure compliance with NIST 800- 37 and related standards.Must be able to identify and Recommend Improvements: Assess control effectiveness, identify vulnerabilities, and recommend enhancements.Must be able to document and Report Findings: Provide detailed reports and communicate findings to stakeholders.Must be able to collaborate with Teams: Work with IT and security teams to implement recommended measures.Required to Start Qualifications:IAT Level II Certification is required to Start (CCNA Security, CSA+, GICSP, GSEC, Security+ CE, or SSCP) CertificationA NACLC Public Trust Clearance is required to Start.Company DescriptionDexian Government Solutions is an award-winning, ISO 9001:2015 certified, business and GSA contract holder providing diversified Information Technology services to both Civilian and Defense agencies. Services include Software Development, Systems Integration, Data Management, Project Management, Operations & Maintenance, Cybersecurity, and Training and Audio/Visual (AV) Solutions. Dexian Government Solutions has received several recognitions, including rankings on "Top 50 Companies to Watch
Security Control Assessor
Apavo Corporation Arlington, Virginia
Job Description Job Description Description: Job Title: Security Control Assessor Location: On Site in Arlington, VA Department: Cyber Security Services Reports To: Management FLSA Status: Full Time/Non-exempt Job Purpose: The security control assessor (SCAs) supports a critical, objective role to evaluate the effectiveness of implemented controls in mitigating security risks. The SCA will support a critical mission within the intelligence community. In the role as a SCA, you are expected to use automated scanning tools, manual techniques, and specialized testing methodologies to identify weaknesses and vulnerabilities. The SCA is expected to be a collaborative member of the RMF program of the organization, to provide intelligent input to system security architectures in order to align with RMF principles and guidelines. This includes ensuring to guide the RMF process so that security controls are integrated seamlessly into system designs to provide comprehensive protection against threats and vulnerabilities. Duties & Responsibilities: The SCA's specific duties include: Advise the Information System Owner (ISO) concerning the impact levels for Confidentiality, Integrity, and Availability for the information on systems. Ensure security assessments are completed for each IS. Initiate a POA&M with identified weaknesses and suspense dates for each IS based on findings and recommendations from the SAR. Evaluate security assessment documentation and provide written recommendations for security authorization to the CISO and AO. Assess proposed changes to Information Systems, their environment of operation, and mission needs that could affect system authorization. Serve as a cybersecurity technical advisor to the CISO and AO under their purview. Be integral to the development of the monitoring strategy. The system-level continuous monitoring strategy must conform to all applicable published DoD enterprise-level or DoD Component-level continuous monitoring strategies. Determine and document in the SAR a risk level for every noncompliant security control in the system baseline. Determine and document in the SAR an aggregate level of risk to the system and identify the key drivers for the assessment. The SCA's risk assessment considers threats, vulnerabilities, and potential impacts as well as existing and planned risk mitigation. Develop the continuous monitoring plan specific to the information system. The SCA is responsible for the RMF deliverables associated with Step 4 of DOD and IC RMF Policies for assigned systems. This includes, but is not limited to: Security Assessment Plans tailored to specific systems control requirements Security control assessment input, which includes narratives for the review of controls and artifacts Security Assessment Reports ATO recommendations or ATO with Condition Memorandums Conduct initial remediation actions once a security assessment has been completed to ensure proper hand off to the ISSM and ISSOs. Assessment of selected controls IAW continuous monitoring strategy The SCA is expected to have additional duties as assigned in support of corporate cyber security services. Additional details are reviewed in accordance with company policies. Requirements: Required Skills & Experience: Strong knowledge of Risk Management Framework (RMF) 800-37 and continuous monitoring 800-137 Expert knowledge and hands-on experience with FISMA Systems, NIST 800-series guidelines, FIPS, Security Assessment & Authorization (SA&A) requirements and processes, Continuous Monitoring Framework experience and its tools, Plan of Action & Milestones (POA&M) policies, and vulnerability/patch management, risk management, project management, proficient with Microsoft products - Word, Excel, PowerPoint. Proficient with vulnerability and scanning tools and well-versed in interpreting risk posture resulting from assessment reports. Experience in project management and tracking, and the Microsoft suite of office products Experience of assessing cloud-based security authorizations (FedRamp, AWS & Azure) as well as the NIST control responsibilities Experience with SAP/JSIG Expert with documenting and or reviewing of security materials such as; system security plans (SSP), Security Assessment Report (SAR), and Security Assessment Plan (SAP), and other documents per NIST 800 guidelines. Experience supporting cloud-based security authorizations (FedRamp, AWS, & Azure) Experience creating Security Assessment Plans, Security Assessment Reports, and Executive-level briefings Qualifications: Bachelor's Degree in Computer Science or a related technical discipline Master's Degree preferred. Minimum 6-10 years of experience. Must currently possess an active TS/SCI with the ability to obtain and maintain a CI polygraph. DOD 8140 IAM Level II (CAP, CASP, CISM, CISSP, GSLC, CCISO) is required Systems Security Engineering background preferred. Effective communication skills to collaborate with cross-functional teams and stakeholders on implementing security measures organization-wide. Strong analytical skills for identifying system vulnerabilities and documenting control remediation recommendations through collaboration on System Impact Analysis and Documented Risk Acceptance. Detail-oriented with the ability to manage multiple tasks and prioritize effectively. Comprehensive knowledge of RMF activities at a senior level (ability to articulate to Executive audiences preferred). Familiarity with federal regulatory requirements, contractual obligations, and industry standards related to information security. Evaluate adherence to standards such as Privacy, GDPR, and HIPAA Other: This is typical office or administrative work, and there is no exposure to adverse environmental conditions. This position requires sedentary work. Sedentary work is defined as: Exerting up to 10 pounds of force occasionally and/or a negligible amount of force frequently or constantly to lift, carry, push, pull or otherwise move objects, including the human body. Sedentary work involves sitting most of the time. Jobs are sedentary if walking and standing are required only occasionally, and all other sedentary criteria are met.
09/15/2026
Full time
Job Description Job Description Description: Job Title: Security Control Assessor Location: On Site in Arlington, VA Department: Cyber Security Services Reports To: Management FLSA Status: Full Time/Non-exempt Job Purpose: The security control assessor (SCAs) supports a critical, objective role to evaluate the effectiveness of implemented controls in mitigating security risks. The SCA will support a critical mission within the intelligence community. In the role as a SCA, you are expected to use automated scanning tools, manual techniques, and specialized testing methodologies to identify weaknesses and vulnerabilities. The SCA is expected to be a collaborative member of the RMF program of the organization, to provide intelligent input to system security architectures in order to align with RMF principles and guidelines. This includes ensuring to guide the RMF process so that security controls are integrated seamlessly into system designs to provide comprehensive protection against threats and vulnerabilities. Duties & Responsibilities: The SCA's specific duties include: Advise the Information System Owner (ISO) concerning the impact levels for Confidentiality, Integrity, and Availability for the information on systems. Ensure security assessments are completed for each IS. Initiate a POA&M with identified weaknesses and suspense dates for each IS based on findings and recommendations from the SAR. Evaluate security assessment documentation and provide written recommendations for security authorization to the CISO and AO. Assess proposed changes to Information Systems, their environment of operation, and mission needs that could affect system authorization. Serve as a cybersecurity technical advisor to the CISO and AO under their purview. Be integral to the development of the monitoring strategy. The system-level continuous monitoring strategy must conform to all applicable published DoD enterprise-level or DoD Component-level continuous monitoring strategies. Determine and document in the SAR a risk level for every noncompliant security control in the system baseline. Determine and document in the SAR an aggregate level of risk to the system and identify the key drivers for the assessment. The SCA's risk assessment considers threats, vulnerabilities, and potential impacts as well as existing and planned risk mitigation. Develop the continuous monitoring plan specific to the information system. The SCA is responsible for the RMF deliverables associated with Step 4 of DOD and IC RMF Policies for assigned systems. This includes, but is not limited to: Security Assessment Plans tailored to specific systems control requirements Security control assessment input, which includes narratives for the review of controls and artifacts Security Assessment Reports ATO recommendations or ATO with Condition Memorandums Conduct initial remediation actions once a security assessment has been completed to ensure proper hand off to the ISSM and ISSOs. Assessment of selected controls IAW continuous monitoring strategy The SCA is expected to have additional duties as assigned in support of corporate cyber security services. Additional details are reviewed in accordance with company policies. Requirements: Required Skills & Experience: Strong knowledge of Risk Management Framework (RMF) 800-37 and continuous monitoring 800-137 Expert knowledge and hands-on experience with FISMA Systems, NIST 800-series guidelines, FIPS, Security Assessment & Authorization (SA&A) requirements and processes, Continuous Monitoring Framework experience and its tools, Plan of Action & Milestones (POA&M) policies, and vulnerability/patch management, risk management, project management, proficient with Microsoft products - Word, Excel, PowerPoint. Proficient with vulnerability and scanning tools and well-versed in interpreting risk posture resulting from assessment reports. Experience in project management and tracking, and the Microsoft suite of office products Experience of assessing cloud-based security authorizations (FedRamp, AWS & Azure) as well as the NIST control responsibilities Experience with SAP/JSIG Expert with documenting and or reviewing of security materials such as; system security plans (SSP), Security Assessment Report (SAR), and Security Assessment Plan (SAP), and other documents per NIST 800 guidelines. Experience supporting cloud-based security authorizations (FedRamp, AWS, & Azure) Experience creating Security Assessment Plans, Security Assessment Reports, and Executive-level briefings Qualifications: Bachelor's Degree in Computer Science or a related technical discipline Master's Degree preferred. Minimum 6-10 years of experience. Must currently possess an active TS/SCI with the ability to obtain and maintain a CI polygraph. DOD 8140 IAM Level II (CAP, CASP, CISM, CISSP, GSLC, CCISO) is required Systems Security Engineering background preferred. Effective communication skills to collaborate with cross-functional teams and stakeholders on implementing security measures organization-wide. Strong analytical skills for identifying system vulnerabilities and documenting control remediation recommendations through collaboration on System Impact Analysis and Documented Risk Acceptance. Detail-oriented with the ability to manage multiple tasks and prioritize effectively. Comprehensive knowledge of RMF activities at a senior level (ability to articulate to Executive audiences preferred). Familiarity with federal regulatory requirements, contractual obligations, and industry standards related to information security. Evaluate adherence to standards such as Privacy, GDPR, and HIPAA Other: This is typical office or administrative work, and there is no exposure to adverse environmental conditions. This position requires sedentary work. Sedentary work is defined as: Exerting up to 10 pounds of force occasionally and/or a negligible amount of force frequently or constantly to lift, carry, push, pull or otherwise move objects, including the human body. Sedentary work involves sitting most of the time. Jobs are sedentary if walking and standing are required only occasionally, and all other sedentary criteria are met.
Security Control Assessor
Omniscius Consulting Arlington, Virginia
Job Description Job Description Job Title: Security Control Assessor Location: On Site in Arlington, VA Department: Cyber Security Services Reports To: Management FLSA Status: Full Time/Non-exempt Clearance: Top Secret clearance with the ability to obtain SCI with CI Polygraph Job Purpose: The security control assessor (SCAs) supports a critical, objective role to evaluate the effectiveness of implemented controls in mitigating security risks. The SCA will support a critical mission within the intelligence community. In the role as a SCA, you are expected to use automated scanning tools, manual techniques, and specialized testing methodologies to identify weaknesses and vulnerabilities. The SCA is expected to be a collaborative member of the RMF program of the organization, to provide intelligent input to system security architectures in order to align with RMF principles and guidelines. This includes ensuring to guide the RMF process so that security controls are integrated seamlessly into system designs to provide comprehensive protection against threats and vulnerabilities. Duties & Responsibilities: The SCA's specific duties include: Advise the Information System Owner (ISO) concerning the impact levels for Confidentiality, Integrity, and Availability for the information on systems. Ensure security assessments are completed for each IS. Initiate a POA&M with identified weaknesses and suspense dates for each IS based on findings and recommendations from the SAR. Evaluate security assessment documentation and provide written recommendations for security authorization to the CISO and AO. Assess proposed changes to Information Systems, their environment of operation, and mission needs that could affect system authorization. Serve as a cybersecurity technical advisor to the CISO and AO under their purview. Be integral to the development of the monitoring strategy. The system-level continuous monitoring strategy must conform to all applicable published DoD enterprise-level or DoD Component-level continuous monitoring strategies. Determine and document in the SAR a risk level for every noncompliant security control in the system baseline. Determine and document in the SAR an aggregate level of risk to the system and identify the key drivers for the assessment. The SCA's risk assessment considers threats, vulnerabilities, and potential impacts as well as existing and planned risk mitigation. Develop the continuous monitoring plan specific to the information system. The SCA is responsible for the RMF deliverables associated with Step 4 of DOD and IC RMF Policies for assigned systems. This includes, but is not limited to: Security Assessment Plans tailored to specific systems control requirements Security control assessment input, which includes narratives for the review of controls and artifacts Security Assessment Reports ATO recommendations or ATO with Condition Memorandums Conduct initial remediation actions once a security assessment has been completed to ensure proper hand off to the ISSM and ISSOs. Assessment of selected controls IAW continuous monitoring strategy The SCA is expected to have additional duties as assigned in support of corporate cyber security services. Additional details are reviewed in accordance with company policies. Requirements Required Skills & Experience: Strong knowledge of Risk Management Framework (RMF) 800-37 and continuous monitoring 800-137 Expert knowledge and hands-on experience with FISMA Systems, NIST 800-series guidelines, FIPS, Security Assessment & Authorization (SA&A) requirements and processes, Continuous Monitoring Framework experience and its tools, Plan of Action & Milestones (POA&M) policies, and vulnerability/patch management, risk management, project management, proficient with Microsoft products - Word, Excel, PowerPoint. Proficient with vulnerability and scanning tools and well-versed in interpreting risk posture resulting from assessment reports. Experience in project management and tracking, and the Microsoft suite of office products Experience of assessing cloud-based security authorizations (FedRamp, AWS & Azure) as well as the NIST control responsibilities Experience with SAP/JSIG Expert with documenting and or reviewing of security materials such as; system security plans (SSP), Security Assessment Report (SAR), and Security Assessment Plan (SAP), and other documents per NIST 800 guidelines. Experience supporting cloud-based security authorizations (FedRamp, AWS, & Azure) Experience creating Security Assessment Plans, Security Assessment Reports, and Executive-level briefings Qualifications: Bachelor's Degree in Computer Science or a related technical discipline Master's Degree preferred. Minimum 6-10 years of experience. Must currently possess an active Top Secret clearance with the ability to obtain SCI with CI Polygraph. DOD 8140 IAM Level II (CAP, CASP, CISM, CISSP, GSLC, CCISO) is required Systems Security Engineering background preferred. Effective communication skills to collaborate with cross-functional teams and stakeholders on implementing security measures organization-wide. Strong analytical skills for identifying system vulnerabilities and documenting control remediation recommendations through collaboration on System Impact Analysis and Documented Risk Acceptance. Detail-oriented with the ability to manage multiple tasks and prioritize effectively. Comprehensive knowledge of RMF activities at a senior level (ability to articulate to Executive audiences preferred). Familiarity with federal regulatory requirements, contractual obligations, and industry standards related to information security. Evaluate adherence to standards such as Privacy, GDPR, and HIPAA Powered by JazzHR I48iVzr4Ds
09/15/2026
Full time
Job Description Job Description Job Title: Security Control Assessor Location: On Site in Arlington, VA Department: Cyber Security Services Reports To: Management FLSA Status: Full Time/Non-exempt Clearance: Top Secret clearance with the ability to obtain SCI with CI Polygraph Job Purpose: The security control assessor (SCAs) supports a critical, objective role to evaluate the effectiveness of implemented controls in mitigating security risks. The SCA will support a critical mission within the intelligence community. In the role as a SCA, you are expected to use automated scanning tools, manual techniques, and specialized testing methodologies to identify weaknesses and vulnerabilities. The SCA is expected to be a collaborative member of the RMF program of the organization, to provide intelligent input to system security architectures in order to align with RMF principles and guidelines. This includes ensuring to guide the RMF process so that security controls are integrated seamlessly into system designs to provide comprehensive protection against threats and vulnerabilities. Duties & Responsibilities: The SCA's specific duties include: Advise the Information System Owner (ISO) concerning the impact levels for Confidentiality, Integrity, and Availability for the information on systems. Ensure security assessments are completed for each IS. Initiate a POA&M with identified weaknesses and suspense dates for each IS based on findings and recommendations from the SAR. Evaluate security assessment documentation and provide written recommendations for security authorization to the CISO and AO. Assess proposed changes to Information Systems, their environment of operation, and mission needs that could affect system authorization. Serve as a cybersecurity technical advisor to the CISO and AO under their purview. Be integral to the development of the monitoring strategy. The system-level continuous monitoring strategy must conform to all applicable published DoD enterprise-level or DoD Component-level continuous monitoring strategies. Determine and document in the SAR a risk level for every noncompliant security control in the system baseline. Determine and document in the SAR an aggregate level of risk to the system and identify the key drivers for the assessment. The SCA's risk assessment considers threats, vulnerabilities, and potential impacts as well as existing and planned risk mitigation. Develop the continuous monitoring plan specific to the information system. The SCA is responsible for the RMF deliverables associated with Step 4 of DOD and IC RMF Policies for assigned systems. This includes, but is not limited to: Security Assessment Plans tailored to specific systems control requirements Security control assessment input, which includes narratives for the review of controls and artifacts Security Assessment Reports ATO recommendations or ATO with Condition Memorandums Conduct initial remediation actions once a security assessment has been completed to ensure proper hand off to the ISSM and ISSOs. Assessment of selected controls IAW continuous monitoring strategy The SCA is expected to have additional duties as assigned in support of corporate cyber security services. Additional details are reviewed in accordance with company policies. Requirements Required Skills & Experience: Strong knowledge of Risk Management Framework (RMF) 800-37 and continuous monitoring 800-137 Expert knowledge and hands-on experience with FISMA Systems, NIST 800-series guidelines, FIPS, Security Assessment & Authorization (SA&A) requirements and processes, Continuous Monitoring Framework experience and its tools, Plan of Action & Milestones (POA&M) policies, and vulnerability/patch management, risk management, project management, proficient with Microsoft products - Word, Excel, PowerPoint. Proficient with vulnerability and scanning tools and well-versed in interpreting risk posture resulting from assessment reports. Experience in project management and tracking, and the Microsoft suite of office products Experience of assessing cloud-based security authorizations (FedRamp, AWS & Azure) as well as the NIST control responsibilities Experience with SAP/JSIG Expert with documenting and or reviewing of security materials such as; system security plans (SSP), Security Assessment Report (SAR), and Security Assessment Plan (SAP), and other documents per NIST 800 guidelines. Experience supporting cloud-based security authorizations (FedRamp, AWS, & Azure) Experience creating Security Assessment Plans, Security Assessment Reports, and Executive-level briefings Qualifications: Bachelor's Degree in Computer Science or a related technical discipline Master's Degree preferred. Minimum 6-10 years of experience. Must currently possess an active Top Secret clearance with the ability to obtain SCI with CI Polygraph. DOD 8140 IAM Level II (CAP, CASP, CISM, CISSP, GSLC, CCISO) is required Systems Security Engineering background preferred. Effective communication skills to collaborate with cross-functional teams and stakeholders on implementing security measures organization-wide. Strong analytical skills for identifying system vulnerabilities and documenting control remediation recommendations through collaboration on System Impact Analysis and Documented Risk Acceptance. Detail-oriented with the ability to manage multiple tasks and prioritize effectively. Comprehensive knowledge of RMF activities at a senior level (ability to articulate to Executive audiences preferred). Familiarity with federal regulatory requirements, contractual obligations, and industry standards related to information security. Evaluate adherence to standards such as Privacy, GDPR, and HIPAA Powered by JazzHR I48iVzr4Ds
Junior Security Control Assessor
The Newberry Group Annapolis Junction, Maryland
Job Description Job Description Job Summary Newberry Group seeks a Jr. Security Control Assessor to support its Government Client. This role requires 85% travel to various government locations both domestically and internationally. Location Hybrid position - approx. 25% remote support with up to 75% CONUS and OCONUS travel. Clearance Active Secret Clearance (will sponsor). DoD Top Secret/SCI Clearance required or Interim Top Secret preferred. Certifications DoD 8570 IAT II (active or will obtain within 90 days of hire) Contingencies If an opening is not currently available, candidates applying to this role will be placed in our pipeline for future openings within this contract's program. Compensation $50,000 - $60,000 Primary Responsibilities: Conduct cybersecurity assessments, audits, and inspections for DoD organizations and partners handling DoD information or connecting to the DoDIN. Evaluate systems and Defensive Cyberspace Operations using cyber threat emulation and performance-based testing. Adhere to policies and processes for each assessment type. Support assessment development and execution to ensure security expertise is properly applied. Coordinate logistics, test plans, and scope with the SCA Team Lead. Perform vulnerability assessments, capture results using STIG Viewer or designated tools, and document findings in eMASS. Analyze security gaps and provide mitigation recommendations. Validate cybersecurity controls, TTPs, STIGs, RMF controls, and compliance with DoD policies and guidelines. Provide risk analysis and assessment results for authorization recommendations. Participate in daily assessment reviews, in-briefs, and out-briefs, sharing findings with the SCA-R. For each RMF Review, the assessors shall perform the following: The candidate will be required to review applicable controls to determine compliance status and enter all test results into the designated repository (Enterprise Mission Assurance Support Service (eMASS) Providing key assessment results to the team lead to include the number of controls reviewed and risk/residual information for inclusion in the authorization recommendation. The candidate will be required to be certified via the ACP IAW the ACP CONOPS before conducting any assessments. The candidate must be certified in a minimum of two (2) technologies and RMF Control Validation before conducting any assessments. Training through the DISA program will be provided after hire and consist of at least 3 months. The contractor shall maintain active accounts to the tools and systems required to perform risk assessments. The candidate will be required to participate in the in-brief and out-brief of each assessment. Qualifications: Bachelor's degree in a related area of study (i.e. Security, Information Technology). 0-1 year of experience required. Willing to train on both technologies and RMF. Active DoD Top Secret clearance with SCI eligibility is preferred but can begin with a secret clearance. IAT Level II certification active or will obtain within 90 days of hire. CompTIA Cybersecurity Analyst (CySA+) CompTIA Security. EC-Council Certified Network Defense (CND) v3. Red Hat Certified System Administrator (RHCSA) CCNA Security. Global Industrial Cyber Security Professional (GICSP) GIAC Security Essentials (GSEC) Systems Security Certified Practitioner (SSCP) Familiarity with STIGs (Security Technical Implementation Guides), Security Requirement Guides (SRGs), Plan of Action and Milestones (POA&Ms) and cybersecurity best practices desired. Understanding of the RMF process, NIST SP 800- 37, NIST SP 800-53, CNSSI 1253 desired Familiarity with relevant tools such as eMASS, STIG Viewer, Nessus, ACAS, SCAP, or HBSS desired Strong written and verbal communication skills for reporting assessment findings. Who We Are Today's leading government agencies are putting their trust in Newberry Group, and for good reason. Newberry brings strength to our clients, from the inside out, through: • client intimacy and superior quality, • presence and accountability in our relationships, and • Public sector best practices. Newberry Group is a professional services firm, providing information security compliance, governance, program/project management, and mission-critical project-based consulting to public sector clients nationwide. The strength of our company is a direct reflection of our highly skilled and talented workforce. Benefits and Perks In addition to competitive wages, Newberry Group offers an outstanding benefit package. This includes medical coverage with three plan options, dental and vision coverage, personal time off, paid holidays, paid parental leave, telecommuting if available, retirement savings accounts (Pre-Tax and Roth), flexible and dependent care savings accounts, life insurance, long and short-term disability coverage, tuition and training reimbursement, employee assistance program, and more. The Newberry Group, Inc. is an Equal Opportunity Employer - EEO/AA/Disability/Veterans. Powered by JazzHR 5whc8Lvtfu
09/15/2026
Full time
Job Description Job Description Job Summary Newberry Group seeks a Jr. Security Control Assessor to support its Government Client. This role requires 85% travel to various government locations both domestically and internationally. Location Hybrid position - approx. 25% remote support with up to 75% CONUS and OCONUS travel. Clearance Active Secret Clearance (will sponsor). DoD Top Secret/SCI Clearance required or Interim Top Secret preferred. Certifications DoD 8570 IAT II (active or will obtain within 90 days of hire) Contingencies If an opening is not currently available, candidates applying to this role will be placed in our pipeline for future openings within this contract's program. Compensation $50,000 - $60,000 Primary Responsibilities: Conduct cybersecurity assessments, audits, and inspections for DoD organizations and partners handling DoD information or connecting to the DoDIN. Evaluate systems and Defensive Cyberspace Operations using cyber threat emulation and performance-based testing. Adhere to policies and processes for each assessment type. Support assessment development and execution to ensure security expertise is properly applied. Coordinate logistics, test plans, and scope with the SCA Team Lead. Perform vulnerability assessments, capture results using STIG Viewer or designated tools, and document findings in eMASS. Analyze security gaps and provide mitigation recommendations. Validate cybersecurity controls, TTPs, STIGs, RMF controls, and compliance with DoD policies and guidelines. Provide risk analysis and assessment results for authorization recommendations. Participate in daily assessment reviews, in-briefs, and out-briefs, sharing findings with the SCA-R. For each RMF Review, the assessors shall perform the following: The candidate will be required to review applicable controls to determine compliance status and enter all test results into the designated repository (Enterprise Mission Assurance Support Service (eMASS) Providing key assessment results to the team lead to include the number of controls reviewed and risk/residual information for inclusion in the authorization recommendation. The candidate will be required to be certified via the ACP IAW the ACP CONOPS before conducting any assessments. The candidate must be certified in a minimum of two (2) technologies and RMF Control Validation before conducting any assessments. Training through the DISA program will be provided after hire and consist of at least 3 months. The contractor shall maintain active accounts to the tools and systems required to perform risk assessments. The candidate will be required to participate in the in-brief and out-brief of each assessment. Qualifications: Bachelor's degree in a related area of study (i.e. Security, Information Technology). 0-1 year of experience required. Willing to train on both technologies and RMF. Active DoD Top Secret clearance with SCI eligibility is preferred but can begin with a secret clearance. IAT Level II certification active or will obtain within 90 days of hire. CompTIA Cybersecurity Analyst (CySA+) CompTIA Security. EC-Council Certified Network Defense (CND) v3. Red Hat Certified System Administrator (RHCSA) CCNA Security. Global Industrial Cyber Security Professional (GICSP) GIAC Security Essentials (GSEC) Systems Security Certified Practitioner (SSCP) Familiarity with STIGs (Security Technical Implementation Guides), Security Requirement Guides (SRGs), Plan of Action and Milestones (POA&Ms) and cybersecurity best practices desired. Understanding of the RMF process, NIST SP 800- 37, NIST SP 800-53, CNSSI 1253 desired Familiarity with relevant tools such as eMASS, STIG Viewer, Nessus, ACAS, SCAP, or HBSS desired Strong written and verbal communication skills for reporting assessment findings. Who We Are Today's leading government agencies are putting their trust in Newberry Group, and for good reason. Newberry brings strength to our clients, from the inside out, through: • client intimacy and superior quality, • presence and accountability in our relationships, and • Public sector best practices. Newberry Group is a professional services firm, providing information security compliance, governance, program/project management, and mission-critical project-based consulting to public sector clients nationwide. The strength of our company is a direct reflection of our highly skilled and talented workforce. Benefits and Perks In addition to competitive wages, Newberry Group offers an outstanding benefit package. This includes medical coverage with three plan options, dental and vision coverage, personal time off, paid holidays, paid parental leave, telecommuting if available, retirement savings accounts (Pre-Tax and Roth), flexible and dependent care savings accounts, life insurance, long and short-term disability coverage, tuition and training reimbursement, employee assistance program, and more. The Newberry Group, Inc. is an Equal Opportunity Employer - EEO/AA/Disability/Veterans. Powered by JazzHR 5whc8Lvtfu
Security Control Assessor - Intermediate
RIVIDIUM Springfield, Virginia
Job Description Job Description RiVidium Inc. is seeking a Security Control Assessor who conducts independent comprehensive assessments of the management, operational, and technical security controls and control enhancements employed within or inherited by an information technology (IT) system to determine the overall effectiveness of the controls (as defined in NIST 800-37). TASKS: Manage and approve Accreditation Packages (e.g., ISO/IEC 15026-2). Plan and conduct security authorization reviews and assurance case development for initial installation of systems and networks. Review authorization and assurance documents to confirm that the level of risk is within acceptable limits for each software application, system, and network. Verify that application software/network/system security postures are implemented as stated, document deviations, and recommend required actions to correct those deviations. Develop security compliance processes and/or audits for external services (e.g., cloud service providers, data centers). Establish acceptable limits for the software application, network, or system. Manage Accreditation Packages (e.g., ISO/IEC 15026-2). Perform security reviews, identify gaps in security architecture, and develop a security risk management plan. Perform security reviews and identify security gaps in security architecture resulting in recommendations for inclusion in the risk mitigation strategy. Perform risk analysis (e.g., threat, vulnerability, and probability of occurrence) whenever an application or system undergoes a major change. Provide input to the Risk Management Framework process activities and related documentation (e.g., system life-cycle support plans, concept of operations, operational procedures, and maintenance training materials). Verify and update security documentation reflecting the application/system security design features. Participate in Risk Governance process to provide security risks, mitigations, and input on other technical risk. Ensure that plans of actions and milestones or remediation plans are in place for vulnerabilities identified during risk assessments, audits, inspections, etc. Assure successful implementation and functionality of security requirements and appropriate information technology (IT) policies and procedures that are consistent with the organization's mission and goals. Define and document how the implementation of a new system or new interfaces between systems impacts the security posture of the current environment. Ensure that security design and cybersecurity development activities are properly documented (providing a functional description of security implementation) and updated as necessary. Support necessary compliance activities (e.g., ensure that system security configuration guidelines are followed, compliance monitoring occurs). Ensure that all acquisitions, procurements, and outsourcing efforts address information security requirements consistent with organization goals. Assess the effectiveness of security controls. Assess all the configuration management (change configuration/release management) processes. ABILITIES: Ability to identify systemic security issues based on the analysis of vulnerability and configuration data. Ability to answer questions in a clear and concise manner. Ability to ask clarifying questions. Ability to communicate complex information, concepts, or ideas in a confident and well-organized manner through verbal, written, and/or visual means. Ability to communicate effectively when writing.A0015: Ability to conduct vulnerability scans and recognize vulnerabilities in security systems.A0016: Ability to facilitate small group discussions.A0018: Ability to prepare and present briefings. Ability to produce technical documentation. Ability to design valid and reliable assessments. Ability to analyze test data. Ability to collect, verify, and validate test data. Ability to dissect a problem and examine the interrelationships between data that may appear unrelated. Ability to identify basic common coding flaws at a high level. Ability to translate data and test results into evaluative conclusions. Ability to ensure security practices are followed throughout the acquisition process. Ability to apply collaborative skills and strategies. Ability to apply critical reading/thinking skills. Ability to effectively collaborate via virtual teams. Ability to evaluate information for reliability, validity, and relevance. Ability to evaluate, analyze, and synthesize large quantities of data (which may be fragmented and contradictory) into high quality, fused targeting/intelligence products. Requirements: Bachelor degree or higher from an accredited college or university. Prefer an accredited Computer Science, Cyber Security, Information Technology, Software Engineering, Information Systems, or Computer Engineering degree; or a degree in a Mathematics or Engineering field. IAT/IAM Level 2 certification The annual salary range for this position is $135,000-$140,000. The listed salary range represents a general guideline; however, RiVidium Inc. considers a number of factors when determining base salary offers such as the scope and responsibilities of the position and the candidate's experience, education, skills, and current market conditions. At RiVidium Inc. it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case.
09/15/2026
Full time
Job Description Job Description RiVidium Inc. is seeking a Security Control Assessor who conducts independent comprehensive assessments of the management, operational, and technical security controls and control enhancements employed within or inherited by an information technology (IT) system to determine the overall effectiveness of the controls (as defined in NIST 800-37). TASKS: Manage and approve Accreditation Packages (e.g., ISO/IEC 15026-2). Plan and conduct security authorization reviews and assurance case development for initial installation of systems and networks. Review authorization and assurance documents to confirm that the level of risk is within acceptable limits for each software application, system, and network. Verify that application software/network/system security postures are implemented as stated, document deviations, and recommend required actions to correct those deviations. Develop security compliance processes and/or audits for external services (e.g., cloud service providers, data centers). Establish acceptable limits for the software application, network, or system. Manage Accreditation Packages (e.g., ISO/IEC 15026-2). Perform security reviews, identify gaps in security architecture, and develop a security risk management plan. Perform security reviews and identify security gaps in security architecture resulting in recommendations for inclusion in the risk mitigation strategy. Perform risk analysis (e.g., threat, vulnerability, and probability of occurrence) whenever an application or system undergoes a major change. Provide input to the Risk Management Framework process activities and related documentation (e.g., system life-cycle support plans, concept of operations, operational procedures, and maintenance training materials). Verify and update security documentation reflecting the application/system security design features. Participate in Risk Governance process to provide security risks, mitigations, and input on other technical risk. Ensure that plans of actions and milestones or remediation plans are in place for vulnerabilities identified during risk assessments, audits, inspections, etc. Assure successful implementation and functionality of security requirements and appropriate information technology (IT) policies and procedures that are consistent with the organization's mission and goals. Define and document how the implementation of a new system or new interfaces between systems impacts the security posture of the current environment. Ensure that security design and cybersecurity development activities are properly documented (providing a functional description of security implementation) and updated as necessary. Support necessary compliance activities (e.g., ensure that system security configuration guidelines are followed, compliance monitoring occurs). Ensure that all acquisitions, procurements, and outsourcing efforts address information security requirements consistent with organization goals. Assess the effectiveness of security controls. Assess all the configuration management (change configuration/release management) processes. ABILITIES: Ability to identify systemic security issues based on the analysis of vulnerability and configuration data. Ability to answer questions in a clear and concise manner. Ability to ask clarifying questions. Ability to communicate complex information, concepts, or ideas in a confident and well-organized manner through verbal, written, and/or visual means. Ability to communicate effectively when writing.A0015: Ability to conduct vulnerability scans and recognize vulnerabilities in security systems.A0016: Ability to facilitate small group discussions.A0018: Ability to prepare and present briefings. Ability to produce technical documentation. Ability to design valid and reliable assessments. Ability to analyze test data. Ability to collect, verify, and validate test data. Ability to dissect a problem and examine the interrelationships between data that may appear unrelated. Ability to identify basic common coding flaws at a high level. Ability to translate data and test results into evaluative conclusions. Ability to ensure security practices are followed throughout the acquisition process. Ability to apply collaborative skills and strategies. Ability to apply critical reading/thinking skills. Ability to effectively collaborate via virtual teams. Ability to evaluate information for reliability, validity, and relevance. Ability to evaluate, analyze, and synthesize large quantities of data (which may be fragmented and contradictory) into high quality, fused targeting/intelligence products. Requirements: Bachelor degree or higher from an accredited college or university. Prefer an accredited Computer Science, Cyber Security, Information Technology, Software Engineering, Information Systems, or Computer Engineering degree; or a degree in a Mathematics or Engineering field. IAT/IAM Level 2 certification The annual salary range for this position is $135,000-$140,000. The listed salary range represents a general guideline; however, RiVidium Inc. considers a number of factors when determining base salary offers such as the scope and responsibilities of the position and the candidate's experience, education, skills, and current market conditions. At RiVidium Inc. it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case.

Modal Window

  • Home
  • Contact
  • About Us
  • FAQs
  • Terms & Conditions
  • Privacy
  • Employer
  • Post a Job
  • Search Resumes
  • Sign in
  • Job Seeker
  • Find Jobs
  • Create Resume
  • Sign in
  • IT blog
  • Facebook
  • Twitter
  • LinkedIn
  • Youtube
© 2008-2026 IT Job Board