SCA Lead

Disruptive Solutions, LLC

Sterling (VA)

Hybrid

USD 150,000 - 190,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Disruptive Solutions, LLC, a SDVOSB delivering cybersecurity solutions for federal and commercial clients, seeks a Lead Security Control Assessor to lead security control assessments for DoD and federal agencies. The role covers on-prem, hybrid, and cloud environments, with RMF guidance and executive risk reporting. You will mentor teams, deliver SAPs and SARs, and present findings to senior leadership. This is a full-time position with flexible work arrangements.

Qualifications

  • 7+ years of cybersecurity experience supporting federal information systems.
  • 5+ years performing Security Control Assessments.
  • Experience leading teams of three or more cybersecurity professionals.
  • Expert knowledge of NIST SP 800-53 Rev. 5, 800-53A, 800-37, 800-115, 800-30.
  • Experience developing SAPs, SARs, and executive-level briefings.
  • Experience assessing enterprise networks and cloud environments (SaaS, PaaS, IaaS).
  • Experience interpreting vulnerability data and validating remediation activities.

Responsibilities

  • Lead teams of Security Control Assessors supporting multiple federal information systems.
  • Plan, coordinate, and execute security control assessments throughout the RMF lifecycle.
  • Develop SAPs, SARs, executive briefings, and risk recommendations.
  • Lead technical reviews of SSPs, POA&Ms, and authorization packages.
  • Evaluate technical, operational, and management controls across on-prem, cloud, and hybrid environments.
  • Assess AWS, Azure, SaaS, PaaS, and IaaS implementations for compliance.
  • Lead vulnerability analysis and validate remediation activities.
  • Support penetration testing activities and present findings to stakeholders.
  • Perform API security testing and use automation to improve assessment quality.
  • Review assessment quality, mentor junior assessors, and manage deliverables.

Skills

NIST RMF knowledge
Security Control Assessments
Leadership
Cloud security
Government cybersecurity
Executive communication
Vulnerability assessment tools
Scripting (PowerShell/Python)
API security testing

Tools

Tenable/Nessus
Qualys
Burp Suite
Imperva
Prisma Cloud
Core Impact
Netsparker/Invicti
AppDetective

Job description

Sterling, United States | Posted on 07/31/2026

Location: Remote / Hybrid / Onsite (Based on Customer Requirements)
Clearance Requirement: Ability to earn a U.S. Public Trust Clearance
Employment Type: Full-Time

About Company

Disruptive Solutions, a Service-Disabled Veteran-Owned Small Business (SDVOSB) delivering mission-focused cybersecurity and technology solutions for federal and commercial clients. We specialize in advanced cybersecurity operations, AI/ML integration, cloud modernization, data governance, and risk management. With a proven track record supporting agencies like the Department of Defense (DoD), Department of Homeland Security (DHS), Cybersecurity and Infrastructure Security Agency (CISA), and the Department of Treasury, we deliver innovative solutions that maximize efficiency and strengthen cyber resilience. At our core, we are dedicated partners committed to securing the mission with innovation, integrity, and measurable impact.

Job Summary

Disruptive Solutions is seeking a Lead Security Control Assessor (Lead SCA) to lead cybersecurity assessment activities supporting Department of Defense and Federal Civilian agencies. This individual will serve as the technical lead for Security Control Assessments (SCAs), providing oversight, quality assurance, and mentorship to assessment teams while serving as the primary cybersecurity advisor to government stakeholders. The Lead SCA will plan, coordinate, and execute security control assessments for on-premises, hybrid, and cloud environments in accordance with the NIST Risk Management Framework (RMF). This role requires extensive experience interpreting NIST security guidance, evaluating technical implementations, leading assessment teams, and presenting cybersecurity risk to executive leadership.

Key Responsibilities
  • Lead teams of Security Control Assessors supporting multiple federal information systems.
  • Serve as the technical Subject Matter Expert (SME) for NIST RMF, NIST SP 800-53 Rev. 5, 800-53A, 800-37, 800-115, and 800-30.
  • Plan, coordinate, and execute security control assessments throughout the Authorization to Operate (ATO) lifecycle.
  • Develop Security Assessment Plans (SAPs), Security Assessment Reports (SARs), executive briefings, and risk recommendations.
  • Lead technical reviews of System Security Plans (SSPs), POA&Ms, and authorization packages.
  • Evaluate technical, operational, and management controls across enterprise, cloud, and hybrid environments.
  • Assess AWS, Azure, SaaS, PaaS, and IaaS implementations for compliance with federal security requirements.
  • Lead vulnerability analysis using enterprise scanning platforms and validate remediation activities.
  • Support penetration testing activities, review Rules of Engagement, and present technical and executive-level findings.
  • Perform API security testing and evaluate application security controls.
  • Utilize scripting and automation to improve assessment quality and efficiency.
  • Review assessment quality, mentor junior assessors, and ensure consistency across assessment teams.
  • Manage schedules, resource allocation, customer communications, and assessment deliverables.
  • Present cybersecurity risks, recommendations, and assessment findings to senior government leadership.
Required Qualifications
  • 7+ years of cybersecurity experience supporting federal information systems.
  • 5+ years performing Security Control Assessments.
  • Demonstrated experience leading teams of three or more cybersecurity professionals.
  • Expert knowledge of: NIST SP 800-53 Rev. 5, NIST SP 800-53A, NIST SP 800-37, NIST SP 800-115, NIST SP 800-30.
  • Experience developing: Security Assessment Plans (SAPs), Security Assessment Reports (SARs), executive-level cybersecurity briefings.
  • Experience assessing enterprise network architectures and cloud environments including SaaS, PaaS, and IaaS.
  • Experience interpreting vulnerability data and validating remediation activities.
  • Experience using enterprise vulnerability assessment tools such as: Tenable/Nessus, Qualys, Burp Suite, Imperva, Prisma Cloud (Twistlock), Core Impact, Netsparker/Invicti, AppDetective.
  • Experience with scripting and automation using PowerShell, Python, Bash, or similar languages.
  • Experience performing API security assessments.
  • Experience utilizing cloud-native security assessment and compliance tools.
  • Experience supporting or leading penetration testing activities and reporting technical and executive-level results.
  • Strong written, verbal, and executive communication skills.
Preferred Qualifications
  • Certified Authorization Professional (CAP)
  • CASP+
  • CISM
  • CEH
  • GIAC certifications
Equal Opportunity Statement

Disruptive Solutions, LLC is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, protected veteran status, sexual orientation, gender identity, or any other characteristic protected by law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Control Assessor
Security Control Assessor

System High Corporation • Chantilly (VA)

On-site
USD 120,000 - 160,000
Security Control Assessor
Security Control Assessor

SAIC • Springfield (VA)

On-site
USD 120,000 - 160,000
Security Control Assessor SCA TSSCI
Security Control Assessor SCA TSSCI

Tau Six • Sully Square (VA)

On-site
USD 70,000 - 110,000
Security Control Assessor (SCA) (TS/SCI)
Security Control Assessor (SCA) (TS/SCI)

Tau Six, LLC • Sully Square (VA)

On-site
USD 80,000 - 110,000
Cyber Strategy & Planning Lead
Cyber Strategy & Planning Lead

Disruptive Solutions, LLC • Sterling (VA)

Hybrid
USD 150,000 - 210,000
Security Control Assessor
Security Control Assessor

Apavo Corporation • Arlington (VA)

On-site
USD 130,000 - 185,000
Security Assessor (RMF / GRC)
Security Assessor (RMF / GRC)

Digital Global Connectors • McLean (VA)

Hybrid
USD 110,000 - 160,000
Security Controls Assessor (Pipeline)
Security Controls Assessor (Pipeline)

electro soft • Belleville (IL)

On-site
USD 85,000 - 120,000
Comprehensive benefits
Team-building activities
Growth opportunities
Cybersecurity - Security Control Assessor Representative (SCA-R) with Security Clearance
Cybersecurity - Security Control Assessor Representative (SCA-R) with Security Clearance

Five Stones Research Corporation • Schriever Space Force Base (CO)

On-site
USD 150,000 - 170,000
401(k) Matching
Dental Insurance
Health Insurance
+9
Security Control Assessor/Representatives
Security Control Assessor/Representatives

Dark Wolf Solutions • Washington

Hybrid
USD 135,000 - 150,000