Security Control Assessor

Apavo Corporation

Arlington (VA)

On-site

USD 130,000 - 185,000

Full time

42 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Apavo Corporation is seeking a Security Control Assessor to perform RMF-based security assessments for DoD/IC systems. You will use automated and manual testing, support RMF activities, and provide guidance to ensure controls are integrated into system designs.

The role requires TS/SCI clearance with CI polygraph eligibility, and extensive experience with RMF, NIST, and SA&A processes. This is an on-site Arlington, VA position supporting a sensitive mission.

Qualifications

  • Experience with RMF 800-37 and continuous monitoring 800-137.
  • Active TS/SCI with ability to obtain a CI polygraph.
  • DOD 8140 IAM Level II (CAP/CASP/CISM/CISSP/GSLC/CCISO) required.
  • Experience documenting SSP, SAR, SAP per NIST 800 guidance.
  • Strong communication and cross-functional collaboration.

Responsibilities

  • Advise the ISO on impact levels for Confidentiality, Integrity, Availability.
  • Ensure security assessments are completed for each IS.
  • Initiate a POA&M with identified weaknesses and deadlines.
  • Evaluate SAR and provide recommendations to CISO/AO.
  • Assess changes to systems that affect authorization.
  • Serve as cybersecurity advisor to CISO/AO.
  • Help develop the monitoring strategy and continuous monitoring plans.
  • Document SAR risk levels for noncompliant controls.
  • Document aggregate risk and key drivers for the assessment.
  • Develop the continuous monitoring plan for information systems.

Skills

RMF 800-37
Continuous Monitoring 800-137
NIST SA&A
POA&M
Vulnerability Scanning
Cloud Security (FedRAMP/AWS/Azure)
Documentation (SSP/SAR/SAP)
Project Management

Education

Bachelor's Degree in Computer Science
Master's Degree preferred

Tools

Vulnerability Scanning Tools
RMF Tools
POA&M Tracking Tools
Microsoft Office

Job description

Job Title: SecurityControl Assessor

Location:On Site inArlington, VA

Department: CyberSecurity Services

Reports To: Management

FLSA Status:Full Time/Non-exempt

JobPurpose:

The security control assessor (SCAs) supports a critical, objective role to evaluate the effectiveness of implemented controls in mitigating security risks.The SCA will support a critical mission within the intelligence community. In the role as a SCA, you are expected to use automated scanning tools, manual techniques, and specialized testing methodologies toidentifyweaknesses and vulnerabilities.The SCA is expected to be a collaborative member of the RMF program of the organization, to provide intelligent input to system security architecturesin order toalign with RMF principles and guidelines. This includes ensuring to guide the RMF process so that security controls are integrated seamlessly into system designs to provide comprehensive protection against threats and vulnerabilities.

Duties&Responsibilities:

The SCA's specific duties include:

  • Advisethe Information System Owner (ISO) concerning the impact levels for Confidentiality, Integrity, and Availability for the information on systems.
  • Ensure security assessments are completed for each IS.
  • Initiate a POA&M with identified weaknesses and suspense dates for each IS based on findings and recommendations from the SAR.
  • Evaluate security assessment documentation and provide written recommendations for security authorization tothe CISOand AO.
  • Assess proposed changes to Information Systems, their environment of operation, and mission needs that could affect system authorization.
  • Serve as a cybersecurity technical advisor to the CISO and AO under their purview.
  • Be integral to the development of the monitoring strategy. The system-level continuous monitoring strategy must conform to all applicable published DoD enterprise-level or DoD Component-level continuous monitoring strategies.
  • Determineand document in the SAR a risk level for every noncompliant security control in the system baseline.
  • Determineand document in the SAR an aggregate level of risk to the system andidentifythe key drivers for the assessment. The SCA's risk assessment considers threats, vulnerabilities, and potential impacts as well as existing and planned risk mitigation.
  • Develop the continuous monitoring plan specific to the information system.

The SCAis responsible forthe RMF deliverables associated with Step 4 of DOD and IC RMF Policies for assigned systems. This includes, but is not limited to:

  • Security Assessment Plans tailored to specific systems control requirements
  • Security control assessment input, which includes narratives for the review of controls and artifacts
  • Security Assessment Reports
  • ATO recommendations or ATO with Condition Memorandums
  • Conduct initial remediation actions once a security assessment has been completed to ensure properhand offto the ISSM and ISSOs.
  • Assessment of selected controls IAW continuous monitoring strategy

The SCA is expected to haveadditionalduties as assigned in support of corporate cyber security services.Additionaldetails are reviewedin accordance withcompany policies.

Requirements
Required Skills & Experience:
  • Strong knowledge of Risk Management Framework (RMF) 800-37 and continuous monitoring 800-137
  • Expert knowledge and hands-on experience with FISMA Systems, NIST 800-series guidelines, FIPS, Security Assessment & Authorization (SA&A) requirements and processes, Continuous Monitoring Framework experience and its tools, Plan of Action & Milestones (POA&M) policies, and vulnerability/patch management, risk management, project management, proficient with Microsoft products - Word, Excel, PowerPoint.
  • Proficient with vulnerability and scanning tools and well-versed in interpreting risk posture resulting from assessment reports. Experience in project management and tracking, and the Microsoft suite of office products
  • Experience of assessing cloud-based security authorizations (FedRamp, AWS & Azure) as well as the NIST control responsibilities
  • Experience with SAP/JSIG
  • Expert with documenting and or reviewing of security materials suchas;system security plans (SSP), Security Assessment Report (SAR), and Security Assessment Plan (SAP), and other documents per NIST 800 guidelines.
  • Experience supporting cloud-based security authorizations (FedRamp, AWS, & Azure)
  • Experiencecreating Security Assessment Plans, Security Assessment Reports, and Executive-level briefings
Qualifications:
  • Bachelor'sDegree in Computer Scienceor a related technical discipline
  • Master'sDegree preferred.
  • Minimum6-10 years of experience.
  • Must currentlypossessan active TS/SCI with the ability to obtain andmaintaina CI polygraph.
  • DOD 8140 IAM Level II (CAP, CASP, CISM, CISSP, GSLC, CCISO) isrequired
  • Systems Security Engineering background preferred.
  • Effective communication skills to collaborate with cross-functional teams and stakeholders on implementing security measures organization-wide.
  • Strong analytical skills foridentifyingsystem vulnerabilities anddocumenting control remediation recommendations through collaboration on System Impact Analysis and Documented Risk Acceptance.
  • Detail-oriented with the ability to manage multiple tasks and prioritize effectively.
  • Comprehensive knowledge of RMF activities at a senior level (ability to articulate to Executive audiences preferred).
  • Familiarity with federalregulatory requirements, contractual obligations, and industry standards related to information security. Evaluate adherence to standards such as Privacy, GDPR, and HIPAA
Other:

This is typical office or administrative work, and there is no exposure toadverse environmental conditions.

This position requires sedentary work. Sedentary work is defined as: Exerting up to 10 pounds of force occasionally and/or a negligible amount of forcefrequentlyor constantly to lift, carry, push, pull or otherwise move objects, including the human body. Sedentary work involves sitting most of the time. Jobs are sedentary if walking and standing arerequiredonlyoccasionally,and all other sedentary criteria are met.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Control Assessor
Security Control Assessor

SAIC • Springfield (VA)

On-site
USD 120,000 - 160,000
Security Control Assessor
Security Control Assessor

System High Corporation • Chantilly (VA)

On-site
USD 120,000 - 160,000
Security Assessor (RMF / GRC)
Security Assessor (RMF / GRC)

Digital Global Connectors • McLean (VA)

Hybrid
USD 110,000 - 160,000
Security Controls Assessor
Security Controls Assessor

Modern Technology Solutions, Inc. (MTSI) • Chantilly (VA)

On-site
USD 100,000 - 130,000
Security Control Assessor Representative
Security Control Assessor Representative

electro soft • Belleville (IL)

On-site
USD 100,000 - 115,000
Security Control Assessor II
Security Control Assessor II

GRS, Inc. • Albuquerque (NM)

On-site
USD <1,000
Security Controls Assessor (Pipeline)
Security Controls Assessor (Pipeline)

Electrosoft • Belleville (IL)

On-site
USD 90,000 - 120,000
Security Control Assessor II
Security Control Assessor II

P-11 Security, Inc. | SBA 8(a) Certified | EDWOSB • Colorado Springs (CO)

On-site
USD 110,000 - 160,000
Security Controls Assessor (Pipeline)
Security Controls Assessor (Pipeline)

electro soft • Belleville (IL)

On-site
USD 85,000 - 120,000
Comprehensive benefits
Team-building activities
Growth opportunities
Security Control Assessor (SCA) II
Security Control Assessor (SCA) II

GDIT • United States

On-site
USD 142,792 - 181,010
401K with company match
Comprehensive health package
Internal mobility program
+1