Junior Security Control Assessor

ANALYGENCE

Washington (District of Columbia)

On-site

USD 65,000 - 90,000

Full time

3 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Tharros is seeking a Junior Security Control Assessor to support A&A of classified and unclassified information systems, executing security control tests and documenting findings at a Government SCIF in Washington, DC.

You will perform vulnerability testing, review POA&Ms, and assist in preparing A&A packages using the RMF framework and NIST/ CNSSI standards. Strong communication skills and proficiency with MS Office are essential.

Qualifications

  • BS degree in Information Technology, Cybersecurity, Information Systems, or Computer Science OR minimum of 4 years' IT/cybersecurity experience.
  • Minimum 1 year of RMF security testing or assessment.
  • Active TS/SCI clearance and U.S. citizenship; willingness to undergo a DHS counterintelligence-scope polygraph.
  • Knowledge of RMF and NIST SP 800-53A assessment procedures.
  • Knowledge of CNSSI 1253 security control baselines.
  • Knowledge of vulnerability scanning and configuration compliance concepts (e.g., STIGs, SCAP).
  • Skill in using at least one scanning tool (e.g., Nessus/ACAS, SCAP Compliance Checker, Nmap, STIG Viewer).
  • Proficient in Microsoft Office Suite to include Teams or similar workplace chat and videoconferencing tools.
  • Excellent written and oral communications skills.
  • Desired: CompTIA Security+ or CySA+ certification.
  • Experience with RSA Archer or a similar GRC tool.

Responsibilities

  • Execute security control test procedures against NIST, CNSSI, and IC standards.
  • Conduct vulnerability and configuration testing against DISA STIGs and CIS Benchmarks.
  • Document control weaknesses and deficiencies for Security Assessment Reports.
  • Review POA&M entries for accuracy and completeness.
  • Perform quality assurance reviews of SSPs, Security Assessment Plans, and POA&Ms.
  • Assist in preparing A&A packages in the GRC tool.
  • Support System Security Test Reports and portfolio status reporting.

Skills

RMF knowledge
NIST SP 800-53A
Vulnerability testing
CNSSI 1253
SCAP/STIG testing
Nessus/ACAS
Nmap
STIG Viewer
Documentation
MS Office/Teams
Communication skills

Education

Bachelor's degree in IT/Cybersecurity/Info Systems/CS

Tools

Nessus
ACAS
SCAP Checker
Nmap
STIG Viewer

Job description

Tharros supports the Department of Homeland Security (DHS) with cybersecurity services across its Intelligence Enterprise. In support of this mission, we have an immediate opportunity for a Junior Security Control Assessor.

In this role you will support assessment and authorization (A&A) of classified and unclassified information systems, executing security control test procedures under the direction of senior assessors. You will run vulnerability and configuration scans, document findings, and help assemble authorization packages. This position is on-site in a Government SCIF in Washington, DC.

  • Execute security control test procedures against NIST, CNSSI, and IC standards.
  • Conduct vulnerability and configuration testing against DISA STIGs and CIS Benchmarks.
  • Document control weaknesses and deficiencies for Security Assessment Reports.
  • Review POA&M entries for accuracy and completeness.
  • Perform quality assurance reviews of SSPs, Security Assessment Plans, and POA&Ms.
  • Assist in preparing A&A packages in the GRC tool.
  • Support System Security Test Reports and portfolio status reporting.
  • BS degree in Information Technology, Cybersecurity, Information Systems, or Computer Science OR minimum of 4 years' experience in IT or cybersecurity.
  • Minimum of 1 year of experience in RMF security testing or assessment.
  • Active TS/SCI clearance and U.S. citizenship; willingness to undergo a DHS counterintelligence-scope polygraph.
  • Knowledge of the Risk Management Framework (RMF) and NIST SP 800-53A assessment procedures.
  • Knowledge of CNSSI 1253 security control baselines.
  • Knowledge of vulnerability scanning and configuration compliance concepts (e.g., STIGs, SCAP).
  • Skill in using at least one scanning tool (e.g., Nessus/ACAS, SCAP Compliance Checker, Nmap, STIG Viewer).
  • Ability to document findings clearly and accurately.
  • Proficient in Microsoft Office Suite to include Teams or similar workplace chat and videoconferencing tools.
  • Excellent written and oral communications skills.
Desired
  • CompTIA Security+ or CySA+ certification.
  • Experience with RSA Archer or a similar GRC tool.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Control Assessor
Security Control Assessor

ANALYGENCE • Washington

On-site
USD 120,000 - 180,000
Senior Security Control Assessor
Senior Security Control Assessor

ANALYGENCE • Washington

On-site
USD 140,000 - 170,000
Junior Security Control Assessor
Junior Security Control Assessor

Jimmy Jazz • Washington

On-site
USD 70,000 - 100,000
Junior Security Control Assessor - RMF & NIST Testing
Junior Security Control Assessor - RMF & NIST Testing

Jimmy Jazz • Washington

On-site
USD 70,000 - 100,000
Junior Information System Security Officer
Junior Information System Security Officer

ANALYGENCE • Washington

On-site
USD 70,000 - 100,000
Junior Security Engineer
Junior Security Engineer

ANALYGENCE • Washington

On-site
USD 75,000 - 110,000
Junior Security Control Assessor — RMF/NIST Testing
Junior Security Control Assessor — RMF/NIST Testing

ANALYGENCE • Washington

On-site
USD 65,000 - 90,000
Junior Security Engineer
Junior Security Engineer

Cybersecurity Jobs • Washington

On-site
USD 90,000 - 130,000
IT Security Operations Specialist
IT Security Operations Specialist

ANALYGENCE • Washington

On-site
USD 110,000 - 160,000
Security Governance and Policy Analyst
Security Governance and Policy Analyst

ANALYGENCE • Washington

On-site
USD 110,000 - 170,000