Security Control Assessor

NTG

Alexandria (VA)

On-site

USD 150,000 - 210,000

Full time

31 hours ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Northern Technologies Group (NTG) seeks an experienced Security Control Accessor to provide expert support to the DoD CIO’s SAP IT Cybersecurity program. You will lead RMF activities, prepare SSPs, SAPs, POA&Ms, and assist with ATO decisions in highly classified environments.

The role requires active TS/SCI clearance and IAT III or IAM III certifications, with extensive DoD cyber compliance experience. You will work on-site in Alexandria, VA, guiding system owners and program staff, developing

Qualifications

  • 15 years of experience with a Master’s in Cybersecurity, or 17 years with a Bachelor’s, or 21 years of relevant experience with no degree.
  • Leadership in RMF/A&A efforts and system accreditation.
  • Active TS/SCI clearance with eligibility for SAP access.
  • CISSP, CISM, CASP+ or equivalent IAT III/IAM III certification.

Responsibilities

  • Lead RMF activities: SSPs, SAPs, POA&M, SARs, SCTMs.
  • Advise the Authorizing Official on ATO decisions and risk posture.
  • Perform system security assessments and artifact evaluations (eMASS or equivalent).
  • Validate inheritance and implementation across hybrid, cloud, and cross-domain systems.
  • Guide system owners and program staff to maintain DoD cybersecurity compliance.
  • Develop SOPs, scorecards, and dashboards for security operations.
  • Support incident response documentation in classified environments.
  • Participate in policy updates and threat-awareness activities.
  • Serve as eMASS administrator: manage accounts, permissions, workflows, metrics.

Skills

RMF/A&A Leadership
eMASS Administration
DoD Cybersecurity Experience
Security Compliance Guidance

Education

Master’s degree in Cybersecurity
Bachelor’s degree
21+ years relevant experience (no degree)

Tools

eMASS

Job description

Northern Technologies Group (NTG) is seeking an experienced Security Control Accessor to provide expert-level support to the Department of Defense (DoD) Chief Information Officer’s SAP IT Cybersecurity program. This role delivers technical and managerial leadership across RMF activities, system accreditation, and enterprise-wide cyber compliance. The Security Control Accessor will serve as a trusted cybersecurity advisor, managing high-impact assessments and helping to ensure secure operations across highly classified SAP environments.

Essential Duties and Responsibilities
  • Lead Risk Management Framework (RMF) activities, including the development, review, and validation of:
  • System Security Plans (SSPs)
  • Security Assessment Plans (SAPs)
  • Plan of Action and Milestones (POA&Ms)
  • Security Assessment Reports (SARs)
  • Security Control Traceability Matrices (SCTMs)
  • Act as an advisor to the Authorizing Official (AO), providing SME input to support Authorization to Operate (ATO) decisions.
  • Perform system security assessments, documentation reviews, and artifact evaluations in eMASS or equivalent tools.
  • Validate control inheritance and implementation across hybrid, cloud, AI/ML-enabled, or cross-domain architectures.
  • Provide technical guidance to system owners, ISSMs, SCAs, and program staff to maintain compliance with DoD cybersecurity mandates.
  • Assist in development and standardization of SOPs, cybersecurity scorecards, and dashboards.
  • Support cybersecurity incident response documentation and post-event reporting in classified environments.
  • Participate in enterprise-wide security initiatives, policy updates (e.g., JSIG revisions), and threat awareness activities.
  • Serve as eMASS administrator: manage accounts, permissions, workflows, and enterprise-level metrics reporting.
Minimum Qualifications (Knowledge, Skills, and Abilities)
  • 15 years of experience and a Master’s degree in Cybersecurity (or equivalent); alternatively, 17 years of experience with a Bachelor’s degree, or 21 years of relevant experience with no degree.
  • Leadership in RMF/A&A efforts.
  • Clearance: Active TS/SCI with eligibility for SAP access
  • Certifications: Must hold a cybersecurity certification at IAT Level III or IAM Level III (e.g., CISSP, CISM, CASP+)
Preferred Qualifications:
Physical Demands and Work Environment

The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this position. Reasonable accommodations may be made to enable individuals with disabilities to perform these functions.

While performing the duties of this position, the employee is regularly required to talk or hear. The employee frequently is required to use hands or fingers, handle or feel objects, tools, or controls. The employee is occasionally required to stand; walk; sit; and reach with hands and arms. The employee must occasionally lift and/or move up to 25 pounds. Specific vision abilities required by this position include close vision, distance vision, and the ability to adjust focus. The noise level in the work environment is usually low to moderate.

Travel

Up to 10% - Local travel within NCR may be required; occasional CONUS travel possible

Shift
  • Standard 8-hour workdays, Monday–Friday (core hours: 9 AM–3 PM)
  • May require occasional travel within the National Capital Region (NCR) and limited CONUS travel
  • On-call response may be required for critical system issues or classified facility access
Note

This job description is not designed to cover or contain a comprehensive listing of activities, duties or responsibilities that are required of the employee for this job. Duties, responsibilities and activities may change at any time with or without notice. Employees will be required to follow any other job-related instructions and to perform any other job-related duties requested by any person authorized to give instructions or assignments. This document does not create an employment contract, implied or otherwise, other than an “at will” relationship.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Control Accessor
Security Control Accessor

NTG • Arlington (VA)

On-site
USD 150,000 - 190,000
Senior RMF Security Control Lead for DoD Cyber Compliance
Senior RMF Security Control Lead for DoD Cyber Compliance

NTG • Arlington (VA)

On-site
USD 150,000 - 190,000
Senior DoD RMF Security Assessments Lead
Senior DoD RMF Security Assessments Lead

NTG • Alexandria (VA)

On-site
USD 150,000 - 210,000
Security Controls Assessor
Security Controls Assessor

Modern Technology Solutions, Inc. (MTSI) • Chantilly (VA)

On-site
USD 100,000 - 130,000
Security Control Assessor
Security Control Assessor

Omniscius Consulting • Arlington (VA)

On-site
USD 120,000 - 180,000
Security Control Assessor
Security Control Assessor

Apavo Corporation • Arlington (VA)

On-site
USD 130,000 - 185,000
Security Control Assessor II
Security Control Assessor II

Jobtailor • Bedford (MA)

On-site
USD 120,000 - 170,000
Contractor Special Access Program Security Officer (CSSO) / Site Security Manager
Contractor Special Access Program Security Officer (CSSO) / Site Security Manager

Modern Technology Solutions, Inc. (MTSI) • Dayton (OH)

On-site
USD 100,000 - 130,000
Security Control Assessor (SCA) II
Security Control Assessor (SCA) II

Modern Technology Solutions, Inc. • Albuquerque (NM)

On-site
USD 90,000 - 140,000
PTO 20 days
Flexible schedules
401(k) match
+5
Senior Cybersecurity Specialist
Senior Cybersecurity Specialist

The Stacia Group, LLC • Chantilly (VA)

On-site
USD 194,000 - 237,000
401(k)
401(k) matching
Dental insurance
+3