it job board logo
  • Home
  • Find IT Jobs
  • Register CV
  • Register as Employer
  • Contact us
  • Career Advice
  • Recruiting? Post a job
  • Sign in
  • Sign up
  • Home
  • Find IT Jobs
  • Register CV
  • Register as Employer
  • Contact us
  • Career Advice
Sorry, that job is no longer available. Here are some results that may be similar to the job you were looking for.

9 jobs found

Email me jobs like this
Refine Search
Current Search
security control assessor ii sca ii ts w sci eligibility
Security Control Assessor II (SCA II) (TS, w/ SCI Eligibility) -
RedTrace Technologies Inc Colorado Springs, Colorado
Job Description Job Description SECURITY CLEARANCE REQUIREMENT: TS, WITH SCI ELIGIBILITY POSITION REQUIRES US CITIZENSHIP Position Title: Security Control Assessor (SCA) II Location: Peterson SFB, CO Position Description: The SCA is responsible for conducting a comprehensive assessment of the management, operational, and technical security controls employed within or inherited by an IS to determine the overall effectiveness of the controls (i.e., the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for the system). SCAs also provide an assessment of the severity of weaknesses or deficiencies discovered in the IS and its environment of operation and recommend corrective actions to address identified vulnerabilities. Responsibilities will cover Collateral, Sensitive Compartmented Information (SCI) and Special Access Program (SAP) activities within the customer's area of responsibility. We are seeking an Security Control Assessor (SCA) II to carry out the following duties and responsibilities: Perform oversight of the development, implementation and evaluation of IS security program policy; special emphasis placed upon integration of existing SAP network infrastructure Perform assessment of ISs, based upon the Risk Management Framework (RMF) methodology in accordance with the Joint Special Access Program (SAP) Implementation Guide (JSIG) Advise the Information System Owner (ISO), Information Data Owner (IDO), Program Security Officer (PSO), and the Delegated and/or Authorizing Official (DAO/AO) on any assessment and authorization issues Evaluate Authorization packages and make recommendation to the AO and/or DAO for authorization Evaluate IS threats and vulnerabilities to determine whether additional safeguards are required Advise the Government concerning the impact levels for Confidentiality, Integrity, and Availability for the information on a system Ensure security assessments are completed and results documented and prepare the Security Assessment Report (SAR) for the Authorization boundary Initiate a Plan of Action and Milestones (POA&M) with identified weaknesses for each Authorization Boundaries assessed, based on findings and recommendations from the SAR Evaluate security assessment documentation and provide written recommendations for security authorization to the Government Discuss recommendation for authorization and submit the security authorization package to the AO/DAO Assess proposed changes to Authorization boundaries operating environment and mission needs to determine the continuation to operate. Review and concur with all sanitization and clearing procedures in accordance with Government guidance and/or policy Assist the Government compliance inspections Assist the Government with security incidents that relate to cybersecurity and ensure that the proper and corrective measures have been taken Ensure organization are addressing and conducting all phases of the system development life cycle (SDLC) Evaluate Hardware and Software to determine security impact that it might have on Authorization boundaries Evaluate the effectiveness and implementation of Continuous Monitoring Plans Represent the customer on inspection teams Qualifications: Required: 7 - 9 years related experience Bachelor's degree in a related discipline or equivalent experience (4 years) Minimum of four (4) years' experience in SAP, SCI or Collateral Information Systems (IS) Security and the implementation of regulations identified in the description of duties Prior performance in the role of ISSO, ISSM, SCA Must meet position and certification requirements outlined in DoD Directive 8570.01-M for Information Assurance Manager Level II Must be able to regularly lift 50lbs Security Clearance: TS, with SCI eligibility Eligibility for access to Special Access Program Information Willingness to submit to a Counterintelligence polygraph Employee Benefits: Competitive salary for well qualified applicants 401(k) plan Annual performance bonus Certification and advanced degree attainment bonuses Student Loan / Tuition reimbursement Health Care Insurance (medical, dental, vision) Up to four weeks of paid vacation 11 Federal Holidays, and 3 Floating Holidays Team bonding events RedTrace Technologies is an EOE employer Powered by JazzHR 9XbYYqgKb5
09/28/2026
Full time
Job Description Job Description SECURITY CLEARANCE REQUIREMENT: TS, WITH SCI ELIGIBILITY POSITION REQUIRES US CITIZENSHIP Position Title: Security Control Assessor (SCA) II Location: Peterson SFB, CO Position Description: The SCA is responsible for conducting a comprehensive assessment of the management, operational, and technical security controls employed within or inherited by an IS to determine the overall effectiveness of the controls (i.e., the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for the system). SCAs also provide an assessment of the severity of weaknesses or deficiencies discovered in the IS and its environment of operation and recommend corrective actions to address identified vulnerabilities. Responsibilities will cover Collateral, Sensitive Compartmented Information (SCI) and Special Access Program (SAP) activities within the customer's area of responsibility. We are seeking an Security Control Assessor (SCA) II to carry out the following duties and responsibilities: Perform oversight of the development, implementation and evaluation of IS security program policy; special emphasis placed upon integration of existing SAP network infrastructure Perform assessment of ISs, based upon the Risk Management Framework (RMF) methodology in accordance with the Joint Special Access Program (SAP) Implementation Guide (JSIG) Advise the Information System Owner (ISO), Information Data Owner (IDO), Program Security Officer (PSO), and the Delegated and/or Authorizing Official (DAO/AO) on any assessment and authorization issues Evaluate Authorization packages and make recommendation to the AO and/or DAO for authorization Evaluate IS threats and vulnerabilities to determine whether additional safeguards are required Advise the Government concerning the impact levels for Confidentiality, Integrity, and Availability for the information on a system Ensure security assessments are completed and results documented and prepare the Security Assessment Report (SAR) for the Authorization boundary Initiate a Plan of Action and Milestones (POA&M) with identified weaknesses for each Authorization Boundaries assessed, based on findings and recommendations from the SAR Evaluate security assessment documentation and provide written recommendations for security authorization to the Government Discuss recommendation for authorization and submit the security authorization package to the AO/DAO Assess proposed changes to Authorization boundaries operating environment and mission needs to determine the continuation to operate. Review and concur with all sanitization and clearing procedures in accordance with Government guidance and/or policy Assist the Government compliance inspections Assist the Government with security incidents that relate to cybersecurity and ensure that the proper and corrective measures have been taken Ensure organization are addressing and conducting all phases of the system development life cycle (SDLC) Evaluate Hardware and Software to determine security impact that it might have on Authorization boundaries Evaluate the effectiveness and implementation of Continuous Monitoring Plans Represent the customer on inspection teams Qualifications: Required: 7 - 9 years related experience Bachelor's degree in a related discipline or equivalent experience (4 years) Minimum of four (4) years' experience in SAP, SCI or Collateral Information Systems (IS) Security and the implementation of regulations identified in the description of duties Prior performance in the role of ISSO, ISSM, SCA Must meet position and certification requirements outlined in DoD Directive 8570.01-M for Information Assurance Manager Level II Must be able to regularly lift 50lbs Security Clearance: TS, with SCI eligibility Eligibility for access to Special Access Program Information Willingness to submit to a Counterintelligence polygraph Employee Benefits: Competitive salary for well qualified applicants 401(k) plan Annual performance bonus Certification and advanced degree attainment bonuses Student Loan / Tuition reimbursement Health Care Insurance (medical, dental, vision) Up to four weeks of paid vacation 11 Federal Holidays, and 3 Floating Holidays Team bonding events RedTrace Technologies is an EOE employer Powered by JazzHR 9XbYYqgKb5
Security Control Assessor II
P-11 Security Inc Arlington, Virginia
Job Description Job Description Description: P-11 Security is seeking a SCA who is responsible for conducting a comprehensive assessment of the management, operational, and technical security controls employed within or inherited by an IS to determine the overall effectiveness of the controls (i.e., the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for the system). SCAs also provide an assessment of the severity of weaknesses or deficiencies discovered in the IS and its environment of operation and recommend corrective actions to address identified vulnerabilities. Responsibilities will cover Collateral, Sensitive Compartmented Information (SCI) and Special Access Program (SAP) activities within the customer's area of responsibility. Performance shall include: Perform oversight of the development, implementation and evaluation of IS security program policy; special emphasis placed upon integration of existing SAP network infrastructure Perform assessment of ISs, based upon the Risk Management Framework (RMF) methodology in accordance with the Joint Special Access Program (SAP) Implementation Guide (JSIG) Advise the Information System Owner (ISO), Information Data Owner (IDO), Program Security Officer (PSO), and the Delegated and/or Authorizing Official (DAO/AO) on any assessment and authorization issues Evaluate Authorization packages and make recommendation to the AO and/or DAO for authorization Evaluate IS threats and vulnerabilities to determine whether additional safeguards are required Advise the Government concerning the impact levels for Confidentiality, Integrity, and Availability for the information on a system Ensure security assessments are completed and results documented and prepare the Security Assessment Report (SAR) for the Authorization boundary Initiate a Plan of Action and Milestones (POA&M) with identified weaknesses for each Authorization Boundaries assessed, based on findings and recommendations from the SAR Evaluate security assessment documentation and provide written recommendations for security authorization to the Government Discuss recommendation for authorization and submit the security authorization package to the AO/DAO Assess proposed changes to Authorization boundaries operating environment and mission needs to determine the continuation to operate. Review and concur with all sanitization and clearing procedures in accordance with Government guidance and/or policy Assist the Government compliance inspections Assist the Government with security incidents that relate to cybersecurity and ensure that the proper and corrective measures have been taken Ensure organization are addressing and conducting all phases of the system development life cycle (SDLC) Evaluate Hardware and Software to determine security impact that it might have on Authorization boundaries Evaluate the effectiveness and implementation of Continuous Monitoring Plans Represent the customer on inspection teams Requirements: Experience: 7 - 9 years related experience Minimum of four (4) years' experience in SAP, SCI or Collateral Information Systems (IS) Security and the implementation of regulations identified in the description of duties. Prior performance in the role of ISSO and ISSM or SCA Education : Bachelor's degree in a related discipline or equivalent experience (4 years) Certifications: Must meet position and certification requirements outlined in DoD Directive 8570.01-M for Information Assurance Technician Level III or Information Assurance Manager Level II within 6 months of the date of hire Security Clearance: Current Top Secret Clearance with SCI Eligibility Eligibility for access to Special Access Program Information Willingness to submit to a Counterintelligence polygraph Other Requirements: Must be able to regularly lift 50lbs
09/26/2026
Full time
Job Description Job Description Description: P-11 Security is seeking a SCA who is responsible for conducting a comprehensive assessment of the management, operational, and technical security controls employed within or inherited by an IS to determine the overall effectiveness of the controls (i.e., the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for the system). SCAs also provide an assessment of the severity of weaknesses or deficiencies discovered in the IS and its environment of operation and recommend corrective actions to address identified vulnerabilities. Responsibilities will cover Collateral, Sensitive Compartmented Information (SCI) and Special Access Program (SAP) activities within the customer's area of responsibility. Performance shall include: Perform oversight of the development, implementation and evaluation of IS security program policy; special emphasis placed upon integration of existing SAP network infrastructure Perform assessment of ISs, based upon the Risk Management Framework (RMF) methodology in accordance with the Joint Special Access Program (SAP) Implementation Guide (JSIG) Advise the Information System Owner (ISO), Information Data Owner (IDO), Program Security Officer (PSO), and the Delegated and/or Authorizing Official (DAO/AO) on any assessment and authorization issues Evaluate Authorization packages and make recommendation to the AO and/or DAO for authorization Evaluate IS threats and vulnerabilities to determine whether additional safeguards are required Advise the Government concerning the impact levels for Confidentiality, Integrity, and Availability for the information on a system Ensure security assessments are completed and results documented and prepare the Security Assessment Report (SAR) for the Authorization boundary Initiate a Plan of Action and Milestones (POA&M) with identified weaknesses for each Authorization Boundaries assessed, based on findings and recommendations from the SAR Evaluate security assessment documentation and provide written recommendations for security authorization to the Government Discuss recommendation for authorization and submit the security authorization package to the AO/DAO Assess proposed changes to Authorization boundaries operating environment and mission needs to determine the continuation to operate. Review and concur with all sanitization and clearing procedures in accordance with Government guidance and/or policy Assist the Government compliance inspections Assist the Government with security incidents that relate to cybersecurity and ensure that the proper and corrective measures have been taken Ensure organization are addressing and conducting all phases of the system development life cycle (SDLC) Evaluate Hardware and Software to determine security impact that it might have on Authorization boundaries Evaluate the effectiveness and implementation of Continuous Monitoring Plans Represent the customer on inspection teams Requirements: Experience: 7 - 9 years related experience Minimum of four (4) years' experience in SAP, SCI or Collateral Information Systems (IS) Security and the implementation of regulations identified in the description of duties. Prior performance in the role of ISSO and ISSM or SCA Education : Bachelor's degree in a related discipline or equivalent experience (4 years) Certifications: Must meet position and certification requirements outlined in DoD Directive 8570.01-M for Information Assurance Technician Level III or Information Assurance Manager Level II within 6 months of the date of hire Security Clearance: Current Top Secret Clearance with SCI Eligibility Eligibility for access to Special Access Program Information Willingness to submit to a Counterintelligence polygraph Other Requirements: Must be able to regularly lift 50lbs
TASS (Current Contract) - Security Control Assessor, Senior
AGE solutions Alexandria, Virginia
Job Description Job Description About Us AGE Solutions is a premier technology and professional services company, providing in-depth consulting, advanced technology solutions, and essential services throughout the U.S. government, defense, and intelligence sectors. Prioritizing innovation and client-focused solutions, we assist major agencies in addressing intricate issues and ensuring a more secure future. AGE Solutions is looking for Senior Security Control Assessors to join our team in support of a cybersecurity risk management and assessment program with our DoD customer. Responsibilities: Conduct cybersecurity assessments, audits, and inspections for DoD organizations and partners handling DoD information or connecting to the DoDIN. Evaluate systems and Defensive Cyberspace Operations using cyber threat emulation and performance-based testing. Adhere to policies and processes for each assessment type. Support assessment development and execution to ensure security expertise is properly applied. Coordinate logistics, test plans, and scope with the SCA Team Lead. Perform vulnerability assessments, capture results using STIG Viewer or designated tools, and document findings in eMASS. Analyze security gaps and provide mitigation recommendations. Validate cybersecurity controls, TTPs, STIGs, RMF controls, and compliance with DoD policies and guidelines. Provide risk analysis and assessment results for authorization recommendations. Participate in daily assessment reviews, in-briefs, and out-briefs, sharing findings with the SCA-R. Mentor and guide personnel by providing technical expertise, best practices, and professional development support to enhance team capabilities and knowledge. Requirements: Bachelor's degree (IT-related field preferred) Eight (8) years of overall experience in cybersecurity or network security position Five (5) years of experience in a Certification and Accreditation/A&A role Must have and maintain an active DoD Top Secret clearance with SCI eligibility Must be able and willing to travel up to approximately 85% of the time, inside and outside the continental United States and internationally (CONUS / OCONUS) DoD 8570 IA Technical (IAT) Level III certification Demonstrated experience with STIGs (Security Technical Implementation Guides), Security Requirement Guides (SRGs), Plan of Action and Milestones (POA&Ms) and cybersecurity best practices Advanced understanding of the RMF process, NIST SP 800- 37, NIST SP 800-53, CNSSI 1253 Demonstrated experience with relevant tools such as eMASS, STIG Viewer, Nessus, ACAS, SCAP, or HBSS Advanced understanding of key technologies areas/domain such as: Network, Mobility, Windows, UNIX, Cloud Environments and Cloud Native Tools/Services, Host Based Security System (HBSS)/Endpoint Security Solutions (ESS), Databases, Applications Strong written and verbal communication skills for reporting assessment findings. Compensation: $95,000 - $105,000 This posting is part of a pipeline for future opportunities supporting the current TASS contract. Employment is contingent upon position availability and government customer approval. AGE Solutions is actively engaging talent and encourages incumbents and new candidates to express interest to be considered if/when opportunities may become available. At AGE Solutions, we reward performance, invest in growth, and share success. Our benefits support the whole person, professionally, financially, and personally. 26 Days Paid Leave: Includes vacation, sick, personal time, and holidays. You choose how to use it. Performance Bonuses: Performance bonuses are awarded based on individual contributions and company-wide results, aligning recognition with impact. 401(k) with Match: We match 3% of your contributions with immediate vesting. Financial Protection: Company-paid life insurance up to $300K and options for additional coverage for you and your dependents. Health Benefits: Multiple medical plans, dental, vision, FSA and HSA options to fit your needs. Parental Leave: 15 days of fully paid leave for new parents, because family matters. Military Differential Pay: We bridge the gap for employees on active duty, so they don't take a financial hit while serving. Professional Growth: Paid training and certifications, tuition reimbursement, and the tools and tech to get the job done right. Shared Success: In the event of a company sale, our CEO has committed to returning 80% of net proceeds to employees. This ensures our team shares in the long term value they help create. At AGE, you'll do work that matters, supported by a company that delivers for its people.
09/26/2026
Full time
Job Description Job Description About Us AGE Solutions is a premier technology and professional services company, providing in-depth consulting, advanced technology solutions, and essential services throughout the U.S. government, defense, and intelligence sectors. Prioritizing innovation and client-focused solutions, we assist major agencies in addressing intricate issues and ensuring a more secure future. AGE Solutions is looking for Senior Security Control Assessors to join our team in support of a cybersecurity risk management and assessment program with our DoD customer. Responsibilities: Conduct cybersecurity assessments, audits, and inspections for DoD organizations and partners handling DoD information or connecting to the DoDIN. Evaluate systems and Defensive Cyberspace Operations using cyber threat emulation and performance-based testing. Adhere to policies and processes for each assessment type. Support assessment development and execution to ensure security expertise is properly applied. Coordinate logistics, test plans, and scope with the SCA Team Lead. Perform vulnerability assessments, capture results using STIG Viewer or designated tools, and document findings in eMASS. Analyze security gaps and provide mitigation recommendations. Validate cybersecurity controls, TTPs, STIGs, RMF controls, and compliance with DoD policies and guidelines. Provide risk analysis and assessment results for authorization recommendations. Participate in daily assessment reviews, in-briefs, and out-briefs, sharing findings with the SCA-R. Mentor and guide personnel by providing technical expertise, best practices, and professional development support to enhance team capabilities and knowledge. Requirements: Bachelor's degree (IT-related field preferred) Eight (8) years of overall experience in cybersecurity or network security position Five (5) years of experience in a Certification and Accreditation/A&A role Must have and maintain an active DoD Top Secret clearance with SCI eligibility Must be able and willing to travel up to approximately 85% of the time, inside and outside the continental United States and internationally (CONUS / OCONUS) DoD 8570 IA Technical (IAT) Level III certification Demonstrated experience with STIGs (Security Technical Implementation Guides), Security Requirement Guides (SRGs), Plan of Action and Milestones (POA&Ms) and cybersecurity best practices Advanced understanding of the RMF process, NIST SP 800- 37, NIST SP 800-53, CNSSI 1253 Demonstrated experience with relevant tools such as eMASS, STIG Viewer, Nessus, ACAS, SCAP, or HBSS Advanced understanding of key technologies areas/domain such as: Network, Mobility, Windows, UNIX, Cloud Environments and Cloud Native Tools/Services, Host Based Security System (HBSS)/Endpoint Security Solutions (ESS), Databases, Applications Strong written and verbal communication skills for reporting assessment findings. Compensation: $95,000 - $105,000 This posting is part of a pipeline for future opportunities supporting the current TASS contract. Employment is contingent upon position availability and government customer approval. AGE Solutions is actively engaging talent and encourages incumbents and new candidates to express interest to be considered if/when opportunities may become available. At AGE Solutions, we reward performance, invest in growth, and share success. Our benefits support the whole person, professionally, financially, and personally. 26 Days Paid Leave: Includes vacation, sick, personal time, and holidays. You choose how to use it. Performance Bonuses: Performance bonuses are awarded based on individual contributions and company-wide results, aligning recognition with impact. 401(k) with Match: We match 3% of your contributions with immediate vesting. Financial Protection: Company-paid life insurance up to $300K and options for additional coverage for you and your dependents. Health Benefits: Multiple medical plans, dental, vision, FSA and HSA options to fit your needs. Parental Leave: 15 days of fully paid leave for new parents, because family matters. Military Differential Pay: We bridge the gap for employees on active duty, so they don't take a financial hit while serving. Professional Growth: Paid training and certifications, tuition reimbursement, and the tools and tech to get the job done right. Shared Success: In the event of a company sale, our CEO has committed to returning 80% of net proceeds to employees. This ensures our team shares in the long term value they help create. At AGE, you'll do work that matters, supported by a company that delivers for its people.
SCA II - Security Control Assessor
Watermark Risk Management International Arlington, Virginia
Job Description Job Description Come make your mark with Watermark! FOUNDED BY USAF VETERANS in 2007, we are proud to be a Service-Disabled Veteran Owned Small Business. SUBJECT MATTER EXPERTS specializing in security and risk management. We're intimately familiar with DOD security programs and mission requirements. OUR CORE VALUES drive every action we take as a company. We strive to exhibit PERSPECTIVE, PASSION, COMMUNICATION, INTEGRITY AND ETHICS, and BALANCE in all we do. COMPETITIVE BENEFITS PACKAGE to address our employees' physical, mental, emotional, and financial well-being. This includes 100% employer- paid medical insurance, ample paid leave, a free employee assistance program, and a competitive 401k savings plan. At Watermark, our people come first! Security Control Assessor (SCA) II The SCA is responsible for conducting a comprehensive assessment of the management, operational, and technical security controls employed within or inherited by an IS to determine the overall effectiveness of the controls (i.e., the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for the system). SCAs also provide an assessment of the severity of weaknesses or deficiencies discovered in the IS and its environment of operation and recommend corrective actions to address identified vulnerabilities. Responsibilities will cover Collateral, Sensitive Compartmented Information (SCI) and Special Access Program (SAP) activities within the customer's area of responsibility. In this role you will . Perform oversight of the development, implementation and evaluation of IS security program policy; special emphasis placed upon integration of existing SAP network infrastructure Perform assessment of ISs, based upon the Risk Management Framework (RMF) methodology in accordance with the Joint Special Access Program (SAP) Implementation Guide (JSIG) Advise the Information System Owner (ISO), Information Data Owner (IDO), Program Security Officer (PSO), and the Delegated and/or Authorizing Official (DAO/AO) on any assessment and authorization issues Evaluate Authorization packages and make recommendation to the AO and/or DAO for authorization Evaluate IS threats and vulnerabilities to determine whether additional safeguards are required Advise the Government concerning the impact levels for Confidentiality, Integrity, and Availability for the information on a system Ensure security assessments are completed and results documented and prepare the Security Assessment Report (SAR) for the Authorization boundary Initiate a Plan of Action and Milestones (POA&M) with identified weaknesses for each Authorization Boundaries assessed, based on findings and recommendations from the SAR Evaluate security assessment documentation and provide written recommendations for security authorization to the Government Discuss recommendation for authorization and submit the security authorization package to the AO/DAO Assess proposed changes to Authorization boundaries operating environment and mission needs to determine the continuation to operate. Review and concur with all sanitization and clearing procedures in accordance with Government guidance and/or policy Assist the Government compliance inspections Assist the Government with security incidents that relate to cybersecurity and ensure that the proper and corrective measures have been taken Ensure organization are addressing and conducting all phases of the system development life cycle (SDLC) Evaluate Hardware and Software to determine security impact that it might have on Authorization boundaries Evaluate the effectiveness and implementation of Continuous Monitoring Plans Represent the customer on inspection teams Additional duties as assigned Experience Requirements: 7-9 years related experience Minimum of four (4) years' experience in SAP, SCI or Collateral Information Systems (IS) Security and the implementation of regulations identified in the description of duties. Prior performance in the role of ISSO and ISSM or SCA Education Requirements: Bachelor's degree in a related area OR Associate's degree in a related area + 2 years' experience OR equivalent experience (4 years) Certification Requirements: Must meet position and certification requirements outlined in DoD Directive 8570.01-M for Information Assurance Technician Level III or Information Assurance Manager Level II within 6 months of the date of hire Security Clearance Requirements: Active TS/SCI clearance Eligibility for access to Special Access Program Information Willingness to submit to a Counterintelligence polygraph Other Requirements: Must be able to regularly lift up to 50 lbs. May require sedentary work at least 50% of the time Reports to a physical location which occasionally requires the ability to traverse between buildings Ability to manage stress with a high degree of maturity/professionalism Demonstrated critical thinking and leadership skills and the ability to work well with others Effective verbal and written communication skills All Level I & Level II positions - candidate should possess some Special Access Program (SAP) experience All Level III positions -candidate should possess 2+ years of Special Access Program (SAP) experience Watermark provides salary ranges with job postings in states where it is legally required; any other salary ranges associated with our postings are third party estimates and may not be an accurate reflection of Watermark's total compensation package. Multiple considerations are taken into account when determining the final salary/hourly rate, including but not limited to, Contract Wage Determination, education and certifications, relevant work experience, related skills and competencies, as well as Federal Government Contract Labor Categories. Central to Watermark's employment philosophy is the wellbeing of our employees which is why we offer a robust benefits package and wellness program alongside of annual base compensation. Watermark is an equal opportunity employer. All terms and conditions of employment are established without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, pregnancy, genetic information, disability, veteran status, or any other protected category under applicable federal, state, and local laws. Powered by JazzHR Ulb7SEozj9
09/26/2026
Full time
Job Description Job Description Come make your mark with Watermark! FOUNDED BY USAF VETERANS in 2007, we are proud to be a Service-Disabled Veteran Owned Small Business. SUBJECT MATTER EXPERTS specializing in security and risk management. We're intimately familiar with DOD security programs and mission requirements. OUR CORE VALUES drive every action we take as a company. We strive to exhibit PERSPECTIVE, PASSION, COMMUNICATION, INTEGRITY AND ETHICS, and BALANCE in all we do. COMPETITIVE BENEFITS PACKAGE to address our employees' physical, mental, emotional, and financial well-being. This includes 100% employer- paid medical insurance, ample paid leave, a free employee assistance program, and a competitive 401k savings plan. At Watermark, our people come first! Security Control Assessor (SCA) II The SCA is responsible for conducting a comprehensive assessment of the management, operational, and technical security controls employed within or inherited by an IS to determine the overall effectiveness of the controls (i.e., the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for the system). SCAs also provide an assessment of the severity of weaknesses or deficiencies discovered in the IS and its environment of operation and recommend corrective actions to address identified vulnerabilities. Responsibilities will cover Collateral, Sensitive Compartmented Information (SCI) and Special Access Program (SAP) activities within the customer's area of responsibility. In this role you will . Perform oversight of the development, implementation and evaluation of IS security program policy; special emphasis placed upon integration of existing SAP network infrastructure Perform assessment of ISs, based upon the Risk Management Framework (RMF) methodology in accordance with the Joint Special Access Program (SAP) Implementation Guide (JSIG) Advise the Information System Owner (ISO), Information Data Owner (IDO), Program Security Officer (PSO), and the Delegated and/or Authorizing Official (DAO/AO) on any assessment and authorization issues Evaluate Authorization packages and make recommendation to the AO and/or DAO for authorization Evaluate IS threats and vulnerabilities to determine whether additional safeguards are required Advise the Government concerning the impact levels for Confidentiality, Integrity, and Availability for the information on a system Ensure security assessments are completed and results documented and prepare the Security Assessment Report (SAR) for the Authorization boundary Initiate a Plan of Action and Milestones (POA&M) with identified weaknesses for each Authorization Boundaries assessed, based on findings and recommendations from the SAR Evaluate security assessment documentation and provide written recommendations for security authorization to the Government Discuss recommendation for authorization and submit the security authorization package to the AO/DAO Assess proposed changes to Authorization boundaries operating environment and mission needs to determine the continuation to operate. Review and concur with all sanitization and clearing procedures in accordance with Government guidance and/or policy Assist the Government compliance inspections Assist the Government with security incidents that relate to cybersecurity and ensure that the proper and corrective measures have been taken Ensure organization are addressing and conducting all phases of the system development life cycle (SDLC) Evaluate Hardware and Software to determine security impact that it might have on Authorization boundaries Evaluate the effectiveness and implementation of Continuous Monitoring Plans Represent the customer on inspection teams Additional duties as assigned Experience Requirements: 7-9 years related experience Minimum of four (4) years' experience in SAP, SCI or Collateral Information Systems (IS) Security and the implementation of regulations identified in the description of duties. Prior performance in the role of ISSO and ISSM or SCA Education Requirements: Bachelor's degree in a related area OR Associate's degree in a related area + 2 years' experience OR equivalent experience (4 years) Certification Requirements: Must meet position and certification requirements outlined in DoD Directive 8570.01-M for Information Assurance Technician Level III or Information Assurance Manager Level II within 6 months of the date of hire Security Clearance Requirements: Active TS/SCI clearance Eligibility for access to Special Access Program Information Willingness to submit to a Counterintelligence polygraph Other Requirements: Must be able to regularly lift up to 50 lbs. May require sedentary work at least 50% of the time Reports to a physical location which occasionally requires the ability to traverse between buildings Ability to manage stress with a high degree of maturity/professionalism Demonstrated critical thinking and leadership skills and the ability to work well with others Effective verbal and written communication skills All Level I & Level II positions - candidate should possess some Special Access Program (SAP) experience All Level III positions -candidate should possess 2+ years of Special Access Program (SAP) experience Watermark provides salary ranges with job postings in states where it is legally required; any other salary ranges associated with our postings are third party estimates and may not be an accurate reflection of Watermark's total compensation package. Multiple considerations are taken into account when determining the final salary/hourly rate, including but not limited to, Contract Wage Determination, education and certifications, relevant work experience, related skills and competencies, as well as Federal Government Contract Labor Categories. Central to Watermark's employment philosophy is the wellbeing of our employees which is why we offer a robust benefits package and wellness program alongside of annual base compensation. Watermark is an equal opportunity employer. All terms and conditions of employment are established without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, pregnancy, genetic information, disability, veteran status, or any other protected category under applicable federal, state, and local laws. Powered by JazzHR Ulb7SEozj9
Security Control Assessor (SCA)
Chenega Corporation Arlington, Virginia
Job Description Job Description Overview Security Control Assessor (SCA) Arlington, VA Are you ready to enhance your skills and build your career in a rapidly evolving business climate? Are you looking for a career where professional development is embedded in your employer's core culture? If so, Chenega Military, Intelligence & Operations Support (MIOS) could be the place for you! Join our team of professionals who support large-scale government operations by leveraging cutting-edge technology and take your career to the next level! SecuriGence delivers essential technology services to our customers in support of their missions to sustain the national security and economic interests of our nation. SecuriGence is seeking a talented Security Control Assessor to help contribute to our success. Come help us solve problems with Innovation Through Intelligence. Responsibilities Advise the A&A Manager concerning the impact levels for Confidentiality, Integrity, and Availability for the information on systems. Conduct a Security Assessment Plan (SAP) for each package assessment. Ensure security assessments are completed for each IS and package is submitted before or on target date. Initiate a POA&M with identified weaknesses and suspense dates for each IS based on findings and recommendations from the SAR. Evaluate security assessment documentation and provide written recommendations for security authorization to the A&A Manager, CISO and AO. Assess proposed changes to Information Systems, their environment of operation, and mission needs that could affect system authorization. Serve as a cybersecurity technical advisor to the A&A Manager under their purview. Be integral to the development of the monitoring strategy. The system-level continuous monitoring strategy must conform to all applicable published DoD enterprise-level or DoD Component-level continuous monitoring strategies. Determine and document in the SAR a risk level for every noncompliant security control in the system baseline. Determine and document in the SAR an aggregate level of risk to the system and identify the key drivers for the assessment. The SCA's risk assessment considers threats, vulnerabilities, and potential impacts as well as existing and planned risk mitigation. Develop a continuous monitoring plan specific to the information system. Other duties as assigned. Qualifications Bachelor's degree required OR Associate's degree with 2+ years of relevant experience OR High school diploma or GED equivalent with 4+ years relevant experience 5+ years relevant experience DOD 8140 IAM Level II (CAP, CASP, CISM, CISSP, GSLC, CCISO) required Top Secret clearance with SCI eligibility is required Knowledge, Skills and Abilities: Strong knowledge of Risk Management Framework (RMF) 800-37 and continuous monitoring 800-137 Expert knowledge and hands-on experience with FISMA Systems, NIST 800-series guidelines, FIPS, Security Assessment & Authorization (SA&A) requirements and processes, Continuous Monitoring Framework experience and its tools, Plan of Action & Milestones (POA&M) policies, and vulnerability/patch management, risk management, project management, proficient with Microsoft products - Word, Excel, PowerPoint. Proficient with vulnerability and scanning tools and well-versed in interpreting risk posture resulting from assessment reports. Experience in project management and tracking, and the Microsoft suite of office products Experience in assessing cloud-based security authorizations (FedRamp, AWS & Azure) as well as the NIST control responsibilities Strong knowledge of CSAM Expert with documenting and or reviewing security materials such as; system security plans (SSP), Security Assessment Report (SAR), Security Assessment Plan (SAP), and other documents per NIST 800 guidelines. Experience supporting cloud-based security authorizations (FedRamp, AWS, & Azure) Experience creating Security Assessment Plans, Security Assessment Reports, and Executive-level briefings. How you'll grow At Chenega MIOS, our professional development plan focuses on helping our team members at every level of their careers to identify and use their strengths to do their best work every day. From entry-level employees to senior leaders, we believe there's always room to learn. We offer opportunities to help sharpen skills in addition to hands-on experience in the global, fast-changing business world. From on-the-job learning experiences to formal development programs, our professionals have a variety of opportunities to continue to grow throughout their careers. Benefits At Chenega MIOS, we know that great people make a great organization. We value our team members and offer them a broad range of benefits. Learn more about what working at Chenega MIOS can mean for you. Chenega MIOS's culture Our positive and supportive culture encourages our team members to do their best work every day. We celebrate individuals by recognizing their uniqueness and offering them the flexibility to make daily choices that can help them be healthy, centered, confident, and aware. We offer well-being programs and continuously look for new ways to maintain a culture where we excel and lead healthy, happy lives. Corporate citizenship Chenega MIOS is led by a purpose to make an impact that matters. This purpose defines who we are and extends to relationships with our clients, our team members, and our communities. We believe that business has the power to inspire and transform. We focus on education, giving, skill-based volunteerism, and leadership to help drive positive social impact in our communities. Learn more about Chenega's impact on the world. Chenega MIOS News- Tips from your Talent Acquisition Team We want job seekers exploring opportunities at Chenega MIOS to feel prepared and confident. To help you with your research, we suggest you review the following links: Chenega MIOS web site - Glassdoor at-Chenega-MIOS- EI_IE369514.11,23.htm LinkedIn - Facebook -
09/26/2026
Full time
Job Description Job Description Overview Security Control Assessor (SCA) Arlington, VA Are you ready to enhance your skills and build your career in a rapidly evolving business climate? Are you looking for a career where professional development is embedded in your employer's core culture? If so, Chenega Military, Intelligence & Operations Support (MIOS) could be the place for you! Join our team of professionals who support large-scale government operations by leveraging cutting-edge technology and take your career to the next level! SecuriGence delivers essential technology services to our customers in support of their missions to sustain the national security and economic interests of our nation. SecuriGence is seeking a talented Security Control Assessor to help contribute to our success. Come help us solve problems with Innovation Through Intelligence. Responsibilities Advise the A&A Manager concerning the impact levels for Confidentiality, Integrity, and Availability for the information on systems. Conduct a Security Assessment Plan (SAP) for each package assessment. Ensure security assessments are completed for each IS and package is submitted before or on target date. Initiate a POA&M with identified weaknesses and suspense dates for each IS based on findings and recommendations from the SAR. Evaluate security assessment documentation and provide written recommendations for security authorization to the A&A Manager, CISO and AO. Assess proposed changes to Information Systems, their environment of operation, and mission needs that could affect system authorization. Serve as a cybersecurity technical advisor to the A&A Manager under their purview. Be integral to the development of the monitoring strategy. The system-level continuous monitoring strategy must conform to all applicable published DoD enterprise-level or DoD Component-level continuous monitoring strategies. Determine and document in the SAR a risk level for every noncompliant security control in the system baseline. Determine and document in the SAR an aggregate level of risk to the system and identify the key drivers for the assessment. The SCA's risk assessment considers threats, vulnerabilities, and potential impacts as well as existing and planned risk mitigation. Develop a continuous monitoring plan specific to the information system. Other duties as assigned. Qualifications Bachelor's degree required OR Associate's degree with 2+ years of relevant experience OR High school diploma or GED equivalent with 4+ years relevant experience 5+ years relevant experience DOD 8140 IAM Level II (CAP, CASP, CISM, CISSP, GSLC, CCISO) required Top Secret clearance with SCI eligibility is required Knowledge, Skills and Abilities: Strong knowledge of Risk Management Framework (RMF) 800-37 and continuous monitoring 800-137 Expert knowledge and hands-on experience with FISMA Systems, NIST 800-series guidelines, FIPS, Security Assessment & Authorization (SA&A) requirements and processes, Continuous Monitoring Framework experience and its tools, Plan of Action & Milestones (POA&M) policies, and vulnerability/patch management, risk management, project management, proficient with Microsoft products - Word, Excel, PowerPoint. Proficient with vulnerability and scanning tools and well-versed in interpreting risk posture resulting from assessment reports. Experience in project management and tracking, and the Microsoft suite of office products Experience in assessing cloud-based security authorizations (FedRamp, AWS & Azure) as well as the NIST control responsibilities Strong knowledge of CSAM Expert with documenting and or reviewing security materials such as; system security plans (SSP), Security Assessment Report (SAR), Security Assessment Plan (SAP), and other documents per NIST 800 guidelines. Experience supporting cloud-based security authorizations (FedRamp, AWS, & Azure) Experience creating Security Assessment Plans, Security Assessment Reports, and Executive-level briefings. How you'll grow At Chenega MIOS, our professional development plan focuses on helping our team members at every level of their careers to identify and use their strengths to do their best work every day. From entry-level employees to senior leaders, we believe there's always room to learn. We offer opportunities to help sharpen skills in addition to hands-on experience in the global, fast-changing business world. From on-the-job learning experiences to formal development programs, our professionals have a variety of opportunities to continue to grow throughout their careers. Benefits At Chenega MIOS, we know that great people make a great organization. We value our team members and offer them a broad range of benefits. Learn more about what working at Chenega MIOS can mean for you. Chenega MIOS's culture Our positive and supportive culture encourages our team members to do their best work every day. We celebrate individuals by recognizing their uniqueness and offering them the flexibility to make daily choices that can help them be healthy, centered, confident, and aware. We offer well-being programs and continuously look for new ways to maintain a culture where we excel and lead healthy, happy lives. Corporate citizenship Chenega MIOS is led by a purpose to make an impact that matters. This purpose defines who we are and extends to relationships with our clients, our team members, and our communities. We believe that business has the power to inspire and transform. We focus on education, giving, skill-based volunteerism, and leadership to help drive positive social impact in our communities. Learn more about Chenega's impact on the world. Chenega MIOS News- Tips from your Talent Acquisition Team We want job seekers exploring opportunities at Chenega MIOS to feel prepared and confident. To help you with your research, we suggest you review the following links: Chenega MIOS web site - Glassdoor at-Chenega-MIOS- EI_IE369514.11,23.htm LinkedIn - Facebook -
Senior Cloud Security Assessor
Spry Methods Washington, Washington DC
Job Description Job Description Experienced assessor sought to lead rigorous, evidence-based security assessments of cloud and hybrid systems supporting federal missions. Who we are looking for: Spry Methods is seeking an experienced Senior Cloud Security Assessor to join our team in the Washington, DC area. The successful candidate will bring extensive hands-on experience conducting independent security control assessments of cloud and hybrid systems, with particular depth in federal cloud environments. This role requires sound professional judgment, strong analytical skills, and a practical, common-sense approach to applying security requirements to system data, technical evidence, mission context, and actual risk. Key Responsibilities: • Lead full-cycle Security Assessment and Authorization (SA&A) activities for cloud, hybrid, and enterprise systems as an independent assessor. • Assess Microsoft Azure and Amazon Web Services (AWS) environments, including the implementation and operating effectiveness of administrative, operational, and technical security controls. • Retrieve and review FedRAMP authorization packages and supporting documentation, then analyze the package for applicability, control inheritance, residual risk, gaps, and customer responsibilities. • Conduct detailed analysis of assessment artifacts, including system security plans, policies, procedures, architecture and data-flow diagrams, inventories, configurations, logs, scan results, test outputs, and other supporting evidence. • Develop Security Assessment Plans (SAPs), Security Assessment Reports (SARs), Risk Assessment Reports (RARs), Required Evidence Lists, and Plans of Action and Milestones (POA&Ms). • Perform network, system, application, and NIST security control testing from administrative, operational, and technical perspectives. • Analyze vulnerability scan results, interpret risk, and use manual validation and corroborating evidence to distinguish actionable findings from false positives or unsupported conclusions. • Apply security requirements using practical judgment and data context rather than relying solely on checklist compliance. Evaluate whether evidence is relevant, reliable, sufficient, and representative of the assessed environment. • Clearly communicate findings, risk, root cause, and feasible mitigation options to technical teams, system owners, executives, and other assessment stakeholders. • Coordinate evidence requests, interviews, test activities, and assessment schedules with customer personnel and Information Systems Security Analysts. • Support security assessment program operations and contribute to consistent assessment methods, quality reviews, and defensible reporting. Minimum Qualifications • Active Certified Information Systems Security Professional (CISSP) certification is required. • At least eight years of demonstrated, hands-on experience conducting security control assessments, including substantial experience serving as an independent assessor for cloud and hybrid systems. • Extensive experience conducting independent security assessments of federal systems hosted in Microsoft Azure and AWS environments, including evaluation of security controls, architecture, inherited controls, customer-configured controls, and cloud-specific risks. • Demonstrated experience retrieving, navigating, and analyzing FedRAMP authorization packages and associated security artifacts. • Strong knowledge of federal Risk Management Framework (RMF) processes and NIST security control assessment practices. • Ability to analyze large volumes of technical and governance evidence, connect information across artifacts, identify inconsistencies, and reach clear, supportable conclusions. • Strong understanding of IT security requirements, technical countermeasures, vulnerability management, risk management, contingency planning, secure data communications, and system security architecture. • Excellent technical writing and stakeholder communication skills, with the ability to explain risk and recommended mitigation in clear, decision-oriented language. • Bachelor's degree in cybersecurity, information technology, computer science, or a related field, or eight additional years of relevant specialized experience. • Experience using CSAM or a comparable governance, risk, and compliance platform. Preferred Qualifications • Certificate of Cloud Security Knowledge (CCSK), Certified Cloud Security Professional (CCSP), Certified Governance, Risk and Compliance (CGRC), or comparable cloud or assessment certification. • Experience supporting federal cybersecurity programs and conducting assessments, audits, or control implementation reviews in accordance with NIST Special Publications. • Experience assessing cloud service offerings that rely on FedRAMP-authorized services and documenting control inheritance and customer responsibility requirements. • DoD 8570/8140 IAM Level II eligibility or an equivalent qualification, when required by the customer environment. • Experience evaluating privacy and data protection considerations as part of security assessments. Success in this role: The successful assessor is technically credible, independent, and evidence-driven. They know when the data supports a finding, when additional validation is needed, and when a requirement must be interpreted in light of architecture, mission use, and actual exposure. They produce assessment results that are clear, consistent, defensible, and actionable. We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
09/26/2026
Full time
Job Description Job Description Experienced assessor sought to lead rigorous, evidence-based security assessments of cloud and hybrid systems supporting federal missions. Who we are looking for: Spry Methods is seeking an experienced Senior Cloud Security Assessor to join our team in the Washington, DC area. The successful candidate will bring extensive hands-on experience conducting independent security control assessments of cloud and hybrid systems, with particular depth in federal cloud environments. This role requires sound professional judgment, strong analytical skills, and a practical, common-sense approach to applying security requirements to system data, technical evidence, mission context, and actual risk. Key Responsibilities: • Lead full-cycle Security Assessment and Authorization (SA&A) activities for cloud, hybrid, and enterprise systems as an independent assessor. • Assess Microsoft Azure and Amazon Web Services (AWS) environments, including the implementation and operating effectiveness of administrative, operational, and technical security controls. • Retrieve and review FedRAMP authorization packages and supporting documentation, then analyze the package for applicability, control inheritance, residual risk, gaps, and customer responsibilities. • Conduct detailed analysis of assessment artifacts, including system security plans, policies, procedures, architecture and data-flow diagrams, inventories, configurations, logs, scan results, test outputs, and other supporting evidence. • Develop Security Assessment Plans (SAPs), Security Assessment Reports (SARs), Risk Assessment Reports (RARs), Required Evidence Lists, and Plans of Action and Milestones (POA&Ms). • Perform network, system, application, and NIST security control testing from administrative, operational, and technical perspectives. • Analyze vulnerability scan results, interpret risk, and use manual validation and corroborating evidence to distinguish actionable findings from false positives or unsupported conclusions. • Apply security requirements using practical judgment and data context rather than relying solely on checklist compliance. Evaluate whether evidence is relevant, reliable, sufficient, and representative of the assessed environment. • Clearly communicate findings, risk, root cause, and feasible mitigation options to technical teams, system owners, executives, and other assessment stakeholders. • Coordinate evidence requests, interviews, test activities, and assessment schedules with customer personnel and Information Systems Security Analysts. • Support security assessment program operations and contribute to consistent assessment methods, quality reviews, and defensible reporting. Minimum Qualifications • Active Certified Information Systems Security Professional (CISSP) certification is required. • At least eight years of demonstrated, hands-on experience conducting security control assessments, including substantial experience serving as an independent assessor for cloud and hybrid systems. • Extensive experience conducting independent security assessments of federal systems hosted in Microsoft Azure and AWS environments, including evaluation of security controls, architecture, inherited controls, customer-configured controls, and cloud-specific risks. • Demonstrated experience retrieving, navigating, and analyzing FedRAMP authorization packages and associated security artifacts. • Strong knowledge of federal Risk Management Framework (RMF) processes and NIST security control assessment practices. • Ability to analyze large volumes of technical and governance evidence, connect information across artifacts, identify inconsistencies, and reach clear, supportable conclusions. • Strong understanding of IT security requirements, technical countermeasures, vulnerability management, risk management, contingency planning, secure data communications, and system security architecture. • Excellent technical writing and stakeholder communication skills, with the ability to explain risk and recommended mitigation in clear, decision-oriented language. • Bachelor's degree in cybersecurity, information technology, computer science, or a related field, or eight additional years of relevant specialized experience. • Experience using CSAM or a comparable governance, risk, and compliance platform. Preferred Qualifications • Certificate of Cloud Security Knowledge (CCSK), Certified Cloud Security Professional (CCSP), Certified Governance, Risk and Compliance (CGRC), or comparable cloud or assessment certification. • Experience supporting federal cybersecurity programs and conducting assessments, audits, or control implementation reviews in accordance with NIST Special Publications. • Experience assessing cloud service offerings that rely on FedRAMP-authorized services and documenting control inheritance and customer responsibility requirements. • DoD 8570/8140 IAM Level II eligibility or an equivalent qualification, when required by the customer environment. • Experience evaluating privacy and data protection considerations as part of security assessments. Success in this role: The successful assessor is technically credible, independent, and evidence-driven. They know when the data supports a finding, when additional validation is needed, and when a requirement must be interpreted in light of architecture, mission use, and actual exposure. They produce assessment results that are clear, consistent, defensible, and actionable. We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
Junior Security Control Assessor
The Newberry Group Annapolis Junction, Maryland
Job Description Job Description Job Summary Newberry Group seeks a Jr. Security Control Assessor to support its Government Client. This role requires 85% travel to various government locations both domestically and internationally. Location Hybrid position - approx. 25% remote support with up to 75% CONUS and OCONUS travel. Clearance Active Secret Clearance (will sponsor). DoD Top Secret/SCI Clearance required or Interim Top Secret preferred. Certifications DoD 8570 IAT II (active or will obtain within 90 days of hire) Contingencies If an opening is not currently available, candidates applying to this role will be placed in our pipeline for future openings within this contract's program. Compensation $50,000 - $60,000 Primary Responsibilities: Conduct cybersecurity assessments, audits, and inspections for DoD organizations and partners handling DoD information or connecting to the DoDIN. Evaluate systems and Defensive Cyberspace Operations using cyber threat emulation and performance-based testing. Adhere to policies and processes for each assessment type. Support assessment development and execution to ensure security expertise is properly applied. Coordinate logistics, test plans, and scope with the SCA Team Lead. Perform vulnerability assessments, capture results using STIG Viewer or designated tools, and document findings in eMASS. Analyze security gaps and provide mitigation recommendations. Validate cybersecurity controls, TTPs, STIGs, RMF controls, and compliance with DoD policies and guidelines. Provide risk analysis and assessment results for authorization recommendations. Participate in daily assessment reviews, in-briefs, and out-briefs, sharing findings with the SCA-R. For each RMF Review, the assessors shall perform the following: The candidate will be required to review applicable controls to determine compliance status and enter all test results into the designated repository (Enterprise Mission Assurance Support Service (eMASS) Providing key assessment results to the team lead to include the number of controls reviewed and risk/residual information for inclusion in the authorization recommendation. The candidate will be required to be certified via the ACP IAW the ACP CONOPS before conducting any assessments. The candidate must be certified in a minimum of two (2) technologies and RMF Control Validation before conducting any assessments. Training through the DISA program will be provided after hire and consist of at least 3 months. The contractor shall maintain active accounts to the tools and systems required to perform risk assessments. The candidate will be required to participate in the in-brief and out-brief of each assessment. Qualifications: Bachelor's degree in a related area of study (i.e. Security, Information Technology). 0-1 year of experience required. Willing to train on both technologies and RMF. Active DoD Top Secret clearance with SCI eligibility is preferred but can begin with a secret clearance. IAT Level II certification active or will obtain within 90 days of hire. CompTIA Cybersecurity Analyst (CySA+) CompTIA Security. EC-Council Certified Network Defense (CND) v3. Red Hat Certified System Administrator (RHCSA) CCNA Security. Global Industrial Cyber Security Professional (GICSP) GIAC Security Essentials (GSEC) Systems Security Certified Practitioner (SSCP) Familiarity with STIGs (Security Technical Implementation Guides), Security Requirement Guides (SRGs), Plan of Action and Milestones (POA&Ms) and cybersecurity best practices desired. Understanding of the RMF process, NIST SP 800- 37, NIST SP 800-53, CNSSI 1253 desired Familiarity with relevant tools such as eMASS, STIG Viewer, Nessus, ACAS, SCAP, or HBSS desired Strong written and verbal communication skills for reporting assessment findings. Who We Are Today's leading government agencies are putting their trust in Newberry Group, and for good reason. Newberry brings strength to our clients, from the inside out, through: • client intimacy and superior quality, • presence and accountability in our relationships, and • Public sector best practices. Newberry Group is a professional services firm, providing information security compliance, governance, program/project management, and mission-critical project-based consulting to public sector clients nationwide. The strength of our company is a direct reflection of our highly skilled and talented workforce. Benefits and Perks In addition to competitive wages, Newberry Group offers an outstanding benefit package. This includes medical coverage with three plan options, dental and vision coverage, personal time off, paid holidays, paid parental leave, telecommuting if available, retirement savings accounts (Pre-Tax and Roth), flexible and dependent care savings accounts, life insurance, long and short-term disability coverage, tuition and training reimbursement, employee assistance program, and more. The Newberry Group, Inc. is an Equal Opportunity Employer - EEO/AA/Disability/Veterans. Powered by JazzHR 5whc8Lvtfu
09/26/2026
Full time
Job Description Job Description Job Summary Newberry Group seeks a Jr. Security Control Assessor to support its Government Client. This role requires 85% travel to various government locations both domestically and internationally. Location Hybrid position - approx. 25% remote support with up to 75% CONUS and OCONUS travel. Clearance Active Secret Clearance (will sponsor). DoD Top Secret/SCI Clearance required or Interim Top Secret preferred. Certifications DoD 8570 IAT II (active or will obtain within 90 days of hire) Contingencies If an opening is not currently available, candidates applying to this role will be placed in our pipeline for future openings within this contract's program. Compensation $50,000 - $60,000 Primary Responsibilities: Conduct cybersecurity assessments, audits, and inspections for DoD organizations and partners handling DoD information or connecting to the DoDIN. Evaluate systems and Defensive Cyberspace Operations using cyber threat emulation and performance-based testing. Adhere to policies and processes for each assessment type. Support assessment development and execution to ensure security expertise is properly applied. Coordinate logistics, test plans, and scope with the SCA Team Lead. Perform vulnerability assessments, capture results using STIG Viewer or designated tools, and document findings in eMASS. Analyze security gaps and provide mitigation recommendations. Validate cybersecurity controls, TTPs, STIGs, RMF controls, and compliance with DoD policies and guidelines. Provide risk analysis and assessment results for authorization recommendations. Participate in daily assessment reviews, in-briefs, and out-briefs, sharing findings with the SCA-R. For each RMF Review, the assessors shall perform the following: The candidate will be required to review applicable controls to determine compliance status and enter all test results into the designated repository (Enterprise Mission Assurance Support Service (eMASS) Providing key assessment results to the team lead to include the number of controls reviewed and risk/residual information for inclusion in the authorization recommendation. The candidate will be required to be certified via the ACP IAW the ACP CONOPS before conducting any assessments. The candidate must be certified in a minimum of two (2) technologies and RMF Control Validation before conducting any assessments. Training through the DISA program will be provided after hire and consist of at least 3 months. The contractor shall maintain active accounts to the tools and systems required to perform risk assessments. The candidate will be required to participate in the in-brief and out-brief of each assessment. Qualifications: Bachelor's degree in a related area of study (i.e. Security, Information Technology). 0-1 year of experience required. Willing to train on both technologies and RMF. Active DoD Top Secret clearance with SCI eligibility is preferred but can begin with a secret clearance. IAT Level II certification active or will obtain within 90 days of hire. CompTIA Cybersecurity Analyst (CySA+) CompTIA Security. EC-Council Certified Network Defense (CND) v3. Red Hat Certified System Administrator (RHCSA) CCNA Security. Global Industrial Cyber Security Professional (GICSP) GIAC Security Essentials (GSEC) Systems Security Certified Practitioner (SSCP) Familiarity with STIGs (Security Technical Implementation Guides), Security Requirement Guides (SRGs), Plan of Action and Milestones (POA&Ms) and cybersecurity best practices desired. Understanding of the RMF process, NIST SP 800- 37, NIST SP 800-53, CNSSI 1253 desired Familiarity with relevant tools such as eMASS, STIG Viewer, Nessus, ACAS, SCAP, or HBSS desired Strong written and verbal communication skills for reporting assessment findings. Who We Are Today's leading government agencies are putting their trust in Newberry Group, and for good reason. Newberry brings strength to our clients, from the inside out, through: • client intimacy and superior quality, • presence and accountability in our relationships, and • Public sector best practices. Newberry Group is a professional services firm, providing information security compliance, governance, program/project management, and mission-critical project-based consulting to public sector clients nationwide. The strength of our company is a direct reflection of our highly skilled and talented workforce. Benefits and Perks In addition to competitive wages, Newberry Group offers an outstanding benefit package. This includes medical coverage with three plan options, dental and vision coverage, personal time off, paid holidays, paid parental leave, telecommuting if available, retirement savings accounts (Pre-Tax and Roth), flexible and dependent care savings accounts, life insurance, long and short-term disability coverage, tuition and training reimbursement, employee assistance program, and more. The Newberry Group, Inc. is an Equal Opportunity Employer - EEO/AA/Disability/Veterans. Powered by JazzHR 5whc8Lvtfu
Security Control Assessor II
Global Resource Solutions, Inc. Arlington, Virginia
Job Description Job Description Global Resource Solutions, Inc. (GRS) is seeking an enthusiastic, motivated, detail orientated, and talented individual for the position of Security Control Assessor II. Job Descriptio n: Summary : The SCA is responsible for conducting a comprehensive assessment of the management, operational, and technical security controls employed within or inherited by an IS to determine the overall effectiveness of the controls (i.e., the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for the system). SCAs also provide an assessment of the severity of weaknesses or deficiencies discovered in the IS and its environment of operation and recommend corrective actions to address identified vulnerabilities. Responsibilities will cover Collateral, Sensitive Compartmented Information (SCI) and Special Access Program (SAP) activities within the customer's area of responsibility. Essential Duties & Responsibilities: Perform oversight of the development, implementation and evaluation of IS security program policy; special emphasis placed upon integration of existing SAP network infrastructure Perform assessment of ISs, based upon the Risk Management Framework (RMF) or the JAFAN 6/3 process Advise the Government on any assessment and authorization issues Advise the Government on assessment methodologies and processes Evaluate Authorization packages and make recommendation to the AO and/or DAO for authorization Evaluate IS threats and vulnerabilities to determine whether additional safeguards are required Advise the Government concerning the impact levels for Confidentiality, Integrity, and Availability for the information on a system Review and approve the IS Security Assessment Plan, which is comprised of the SSP, the SCTM, and the Security Control Assessment Procedures Ensure security assessments are completed for each IS At the conclusion of each security assessment activity, prepare the final Security Assessment Report (SAR) containing the results and findings from the assessment Initiate a Plan of Action and Milestones (POA&M) with identified weaknesses and suspense dates for each IS based on findings and recommendations from the SAR Evaluate security assessment documentation and provide written recommendations for security authorization to the Government Develop recommendation for authorization and submit the security authorization package to the Government Assess proposed changes to ISs, their environment of operation, and mission needs that could affect system authorization Ensure approved procedures are in place for clearing, purging, declassifying, and releasing IS memory, media, and output Assist Government in compliance inspections Assist the Government with security incidents that relate to cybersecurity and ensure that the proper and corrective measures have been taken Assess changes within the IS boundary that could affect the authorization of the boundary Ensure that IS requirements are addressed during all phases of the system life cycle Requirement: Ten (10) to Twelve (12) years related experience Bachelor's Degree in a related area or equivalent experience (Four (4) years) Minimum of four (4) years' experience in SAP and Collateral Information Systems (IS) Security and the implementation of regulations identified in the description of duties. Must meet position and certification requirements outlined in DoD Directive 8570.01-M for Information Assurance Technician Level 3 or Information Assurance Manager Level 3 within 6 months of the date of hire Security Requirements: Current Top Secret Clearance with SCI Eligibility Eligibility for access to Special Access Programs Willingness to submit to a Counterintelligence Polygraph Skills: Must be familiar with current security policy/manuals Must have the ability to work in a dynamic environment and effectively interact with numerous DOD, military/civilian personnel and industry partners Working knowledge of Microsoft Office (Word, PowerPoint, and Excel) Possess a high degree of originality, creativity, initiative requiring minimal supervision Willingness to travel within the organizational geographic Area of Responsibility (AOR) (note - could be extensive, and will include both air and ground transportation) Must be able to lift 50 lbs Physical Requirements : This position requires employees to be willing and able to: sit, bend, reach, stoop, squat, stand, and walk. Communication: Excellent customer service via phone and face to face conversation, excellent written and oral command of English. GRS is an Equal Opportunity Employer. GRS will continue to abide by obligations under VEVRRA and Section 503 physical or mental disability, protected veteran status, or any other characteristics that are protected by law.
09/26/2026
Full time
Job Description Job Description Global Resource Solutions, Inc. (GRS) is seeking an enthusiastic, motivated, detail orientated, and talented individual for the position of Security Control Assessor II. Job Descriptio n: Summary : The SCA is responsible for conducting a comprehensive assessment of the management, operational, and technical security controls employed within or inherited by an IS to determine the overall effectiveness of the controls (i.e., the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for the system). SCAs also provide an assessment of the severity of weaknesses or deficiencies discovered in the IS and its environment of operation and recommend corrective actions to address identified vulnerabilities. Responsibilities will cover Collateral, Sensitive Compartmented Information (SCI) and Special Access Program (SAP) activities within the customer's area of responsibility. Essential Duties & Responsibilities: Perform oversight of the development, implementation and evaluation of IS security program policy; special emphasis placed upon integration of existing SAP network infrastructure Perform assessment of ISs, based upon the Risk Management Framework (RMF) or the JAFAN 6/3 process Advise the Government on any assessment and authorization issues Advise the Government on assessment methodologies and processes Evaluate Authorization packages and make recommendation to the AO and/or DAO for authorization Evaluate IS threats and vulnerabilities to determine whether additional safeguards are required Advise the Government concerning the impact levels for Confidentiality, Integrity, and Availability for the information on a system Review and approve the IS Security Assessment Plan, which is comprised of the SSP, the SCTM, and the Security Control Assessment Procedures Ensure security assessments are completed for each IS At the conclusion of each security assessment activity, prepare the final Security Assessment Report (SAR) containing the results and findings from the assessment Initiate a Plan of Action and Milestones (POA&M) with identified weaknesses and suspense dates for each IS based on findings and recommendations from the SAR Evaluate security assessment documentation and provide written recommendations for security authorization to the Government Develop recommendation for authorization and submit the security authorization package to the Government Assess proposed changes to ISs, their environment of operation, and mission needs that could affect system authorization Ensure approved procedures are in place for clearing, purging, declassifying, and releasing IS memory, media, and output Assist Government in compliance inspections Assist the Government with security incidents that relate to cybersecurity and ensure that the proper and corrective measures have been taken Assess changes within the IS boundary that could affect the authorization of the boundary Ensure that IS requirements are addressed during all phases of the system life cycle Requirement: Ten (10) to Twelve (12) years related experience Bachelor's Degree in a related area or equivalent experience (Four (4) years) Minimum of four (4) years' experience in SAP and Collateral Information Systems (IS) Security and the implementation of regulations identified in the description of duties. Must meet position and certification requirements outlined in DoD Directive 8570.01-M for Information Assurance Technician Level 3 or Information Assurance Manager Level 3 within 6 months of the date of hire Security Requirements: Current Top Secret Clearance with SCI Eligibility Eligibility for access to Special Access Programs Willingness to submit to a Counterintelligence Polygraph Skills: Must be familiar with current security policy/manuals Must have the ability to work in a dynamic environment and effectively interact with numerous DOD, military/civilian personnel and industry partners Working knowledge of Microsoft Office (Word, PowerPoint, and Excel) Possess a high degree of originality, creativity, initiative requiring minimal supervision Willingness to travel within the organizational geographic Area of Responsibility (AOR) (note - could be extensive, and will include both air and ground transportation) Must be able to lift 50 lbs Physical Requirements : This position requires employees to be willing and able to: sit, bend, reach, stoop, squat, stand, and walk. Communication: Excellent customer service via phone and face to face conversation, excellent written and oral command of English. GRS is an Equal Opportunity Employer. GRS will continue to abide by obligations under VEVRRA and Section 503 physical or mental disability, protected veteran status, or any other characteristics that are protected by law.
Security Control Assessor, Mid
AGE solutions
Job Description Job Description About Us AGE Solutions is a premier technology and professional services company, providing in-depth consulting, advanced technology solutions, and essential services throughout the U.S. government, defense, and intelligence sectors. Prioritizing innovation and client-focused solutions, we assist major agencies in addressing intricate issues and ensuring a more secure future. AGE Solutions is looking for a Security Control Assessor, Intermediate to join our team in support of a cybersecurity risk management and assessment program with our DoD customer. Responsibilities Include: Conduct cybersecurity assessments, audits, and inspections for DoD organizations and partners handling DoD information or connecting to the DoDIN. Evaluate systems and Defensive Cyberspace Operations using cyber threat emulation and performance-based testing. Adhere to policies and processes for each assessment type. Support assessment development and execution to ensure security expertise is properly applied. Coordinate logistics, test plans, and scope with the SCA Team Lead. Perform vulnerability assessments, capture results using STIG Viewer or designated tools, and document findings in eMASS. Analyze security gaps and provide mitigation recommendations. Validate cybersecurity controls, TTPs, STIGs, RMF controls, and compliance with DoD policies and guidelines. Provide risk analysis and assessment results for authorization recommendations. Participate in daily assessment reviews, in-briefs, and out-briefs, sharing findings with the SCA-R. Requirements: Bachelor's degree (IT-related field preferred) Five (5) years of overall experience in cybersecurity or network security position Three (3) years of experience in a Certification and Accreditation/A&A role Must have and maintain an active DoD Top Secret clearance with SCI eligibility DoD 8570 IA Technical (IAT) Level II certification Demonstrated experience with STIGs (Security Technical Implementation Guides), Security Requirement Guides (SRGs), Plan of Action and Milestones (POA&Ms) and cybersecurity best practices Strong understanding of the RMF process, NIST SP 800- 37, NIST SP 800-53, CNSSI 1253 Demonstrated experience with relevant tools such as eMASS, STIG Viewer, Nessus, ACAS, SCAP, or HBSS Demonstratable understanding of key technologies areas/domain such as: Network, Mobility, Windows, UNIX, Cloud Environments and Cloud Native Tools/Services, Host Based Security System (HBSS)/Endpoint Security Solutions (ESS), Databases, Applications Strong written and verbal communication skills for reporting assessment findings. Location: This is a remote role requiring approximately 85% travel, both CONUS and OCONUS. Candidates must possess a valid U.S. Passport or have the ability to obtain one in a timely manner. Strong preference will be given to candidates who currently reside in the DMV (Washington, DC, Maryland, Virginia) region or Pennsylvania, or who are willing to relocate to one of these areas to support customer requirements and team collaboration activities. The projected salary range for this position is $70,000+ annually. Final compensation will be determined based on factors including years of relevant experience, active security clearance level, certifications, technical skillset, contract requirements, and overall qualifications. At AGE Solutions, we reward performance, invest in growth, and share success. Our benefits support the whole person, professionally, financially, and personally. 26 Days Paid Leave: Includes vacation, sick, personal time, and holidays. You choose how to use it. Performance Bonuses: Performance bonuses are awarded based on individual contributions and company-wide results, aligning recognition with impact. 401(k) with Match: We match 3% of your contributions with immediate vesting. Financial Protection: Company-paid life insurance up to $300K and options for additional coverage for you and your dependents. Health Benefits: Multiple medical plans, dental, vision, FSA and HSA options to fit your needs. Parental Leave: 15 days of fully paid leave for new parents, because family matters. Military Differential Pay: We bridge the gap for employees on active duty, so they don't take a financial hit while serving. Professional Growth: Paid training and certifications, tuition reimbursement, and the tools and tech to get the job done right. Shared Success: In the event of a company sale, our CEO has committed to returning 80% of net proceeds to employees. This ensures our team shares in the long term value they help create. At AGE, you'll do work that matters, supported by a company that delivers for its people.
09/26/2026
Full time
Job Description Job Description About Us AGE Solutions is a premier technology and professional services company, providing in-depth consulting, advanced technology solutions, and essential services throughout the U.S. government, defense, and intelligence sectors. Prioritizing innovation and client-focused solutions, we assist major agencies in addressing intricate issues and ensuring a more secure future. AGE Solutions is looking for a Security Control Assessor, Intermediate to join our team in support of a cybersecurity risk management and assessment program with our DoD customer. Responsibilities Include: Conduct cybersecurity assessments, audits, and inspections for DoD organizations and partners handling DoD information or connecting to the DoDIN. Evaluate systems and Defensive Cyberspace Operations using cyber threat emulation and performance-based testing. Adhere to policies and processes for each assessment type. Support assessment development and execution to ensure security expertise is properly applied. Coordinate logistics, test plans, and scope with the SCA Team Lead. Perform vulnerability assessments, capture results using STIG Viewer or designated tools, and document findings in eMASS. Analyze security gaps and provide mitigation recommendations. Validate cybersecurity controls, TTPs, STIGs, RMF controls, and compliance with DoD policies and guidelines. Provide risk analysis and assessment results for authorization recommendations. Participate in daily assessment reviews, in-briefs, and out-briefs, sharing findings with the SCA-R. Requirements: Bachelor's degree (IT-related field preferred) Five (5) years of overall experience in cybersecurity or network security position Three (3) years of experience in a Certification and Accreditation/A&A role Must have and maintain an active DoD Top Secret clearance with SCI eligibility DoD 8570 IA Technical (IAT) Level II certification Demonstrated experience with STIGs (Security Technical Implementation Guides), Security Requirement Guides (SRGs), Plan of Action and Milestones (POA&Ms) and cybersecurity best practices Strong understanding of the RMF process, NIST SP 800- 37, NIST SP 800-53, CNSSI 1253 Demonstrated experience with relevant tools such as eMASS, STIG Viewer, Nessus, ACAS, SCAP, or HBSS Demonstratable understanding of key technologies areas/domain such as: Network, Mobility, Windows, UNIX, Cloud Environments and Cloud Native Tools/Services, Host Based Security System (HBSS)/Endpoint Security Solutions (ESS), Databases, Applications Strong written and verbal communication skills for reporting assessment findings. Location: This is a remote role requiring approximately 85% travel, both CONUS and OCONUS. Candidates must possess a valid U.S. Passport or have the ability to obtain one in a timely manner. Strong preference will be given to candidates who currently reside in the DMV (Washington, DC, Maryland, Virginia) region or Pennsylvania, or who are willing to relocate to one of these areas to support customer requirements and team collaboration activities. The projected salary range for this position is $70,000+ annually. Final compensation will be determined based on factors including years of relevant experience, active security clearance level, certifications, technical skillset, contract requirements, and overall qualifications. At AGE Solutions, we reward performance, invest in growth, and share success. Our benefits support the whole person, professionally, financially, and personally. 26 Days Paid Leave: Includes vacation, sick, personal time, and holidays. You choose how to use it. Performance Bonuses: Performance bonuses are awarded based on individual contributions and company-wide results, aligning recognition with impact. 401(k) with Match: We match 3% of your contributions with immediate vesting. Financial Protection: Company-paid life insurance up to $300K and options for additional coverage for you and your dependents. Health Benefits: Multiple medical plans, dental, vision, FSA and HSA options to fit your needs. Parental Leave: 15 days of fully paid leave for new parents, because family matters. Military Differential Pay: We bridge the gap for employees on active duty, so they don't take a financial hit while serving. Professional Growth: Paid training and certifications, tuition reimbursement, and the tools and tech to get the job done right. Shared Success: In the event of a company sale, our CEO has committed to returning 80% of net proceeds to employees. This ensures our team shares in the long term value they help create. At AGE, you'll do work that matters, supported by a company that delivers for its people.

Modal Window

  • Home
  • Contact
  • About Us
  • FAQs
  • Terms & Conditions
  • Privacy
  • Employer
  • Post a Job
  • Search Resumes
  • Sign in
  • Job Seeker
  • Find Jobs
  • Create Resume
  • Sign in
  • IT blog
  • Facebook
  • Twitter
  • LinkedIn
  • Youtube
© 2008-2026 IT Job Board