Security Control Assessor

Novul Solutions

Arlington (TX)

On-site

USD 120,000 - 180,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Paid Time Off (PTO)
Holidays
401(k) match
Health insurance
Tuition/Training reimbursement

Job summary

Novul Solutions is seeking an experienced Security Control Assessor to support DoD cybersecurity assessment and authorization activities. The role focuses on conducting in-depth assessments, validating control implementation, and supporting ATO packages.

The ideal candidate brings extensive RMF, NIST, and JSIG knowledge and can clearly communicate findings and remediation requirements to system owners and stakeholders.

Qualifications

  • Eight+ years in cybersecurity.
  • Five+ years in Certification and Authorization/Assessment and Authorization.
  • Expert knowledge of the DoD RMF.
  • Strong knowledge of NIST SP 800-37/53, CNSSI 1253, JSIG.
  • Experience conducting security control assessments and evaluating controls.
  • Experience preparing ATO packages and supporting documentation.
  • Leadership in assessment teams and communicating findings clearly.

Responsibilities

  • Conduct security control assessments for DoD information systems per NIST SP 800-53 and RMF.
  • Evaluate control implementation, document findings, risks, and remediation actions.
  • Communicate mitigation requirements to owners and stakeholders.
  • Assess system categorization and impact levels (High/Moderate/Low).
  • Validate inherited controls and Ports/Protocols/Services requirements.
  • Review security docs and evidence for accuracy and alignment.
  • Lead review, preparation, and QA of ATO packages and RMF docs.
  • Identify gaps and provide actionable remediation recommendations.
  • Coordinate with system owners, engineers, and government stakeholders.
  • Support Plans of Action and Milestones and risk-management documents.
  • Provide leadership to assessment teams on complex issues.

Skills

DoD RMF
NIST SP 800-53/37
Leadership experience
Communication skills
Security assessment

Education

Bachelor’s degree in cybersecurity/IT/CS/IS/engineering

Job description

Arlington, United States | Posted on 07/21/2026

  • Clearance Requirement Active Top Secret/SCI
  • IAT/IAM Requirement CompTIA Security+
Job Description
Position Overview

We are seeking an experienced Security Control Assessor to support cybersecurity assessment and authorization activities for Department of Defense information systems. This role is responsible for conducting in-depth security control assessments, validating control implementation, reviewing system security documentation, and supporting the development and maintenance of complete and accurate Authorization to Operate packages.

The ideal candidate will bring extensive experience with the Risk Management Framework, NIST security standards, DoD cybersecurity policies, and the Joint Special Access Program Implementation Guide. The individual must be capable of communicating assessment findings, remediation requirements, and government-approved mitigation strategies to system owners and technical stakeholders.

Key Responsibilities:
  • Conduct comprehensive security control assessments of DoD information systems in accordance with NIST SP 800-53, DoD RMF policies, CNSSI 1253, and the JSIG.
  • Evaluate the implementation and effectiveness of security controls and document assessment findings, risks, deficiencies, and recommended corrective actions.
  • Communicate government-approved mitigation and remediation requirements to system owners, cybersecurity personnel, and technical stakeholders in support of the RMF process.
  • Apply the cybersecurity principles of confidentiality, integrity, and availability when evaluating system categorization and impact levels, including High, Moderate, and Low classifications.
  • Validate security controls identified as inherited from hosting environments, connected systems, enterprise services, or other authorized systems.
  • Assess program compliance with security controls associated with registered Ports, Protocols, and Services, including the proper generation, retention, protection, and handling of system log files.
  • Review system security documentation and supporting evidence for accuracy, completeness, consistency, and alignment with applicable cybersecurity requirements.
  • Lead the review, preparation, and quality assurance of Authorization to Operate packages and related RMF documentation.
  • Identify control gaps, weaknesses, and areas of noncompliance and provide clear, actionable recommendations for remediation.
  • Coordinate with system owners, information system security personnel, engineers, program leadership, and government stakeholders throughout the assessment and authorization lifecycle.
  • Support the development, review, and validation of Plans of Action and Milestones and other risk-management documentation.
  • Provide leadership and technical guidance to assessment teams and support the resolution of complex cybersecurity compliance issues.
Requirements
Required Qualifications:
  • Bachelor’s degree in cybersecurity, information technology, computer science, information systems, engineering, or a related field.
  • Eight or more years of professional experience in cybersecurity.
  • Five or more years of experience supporting Certification and Accreditation or Assessment and Authorization activities.
  • Expert-level knowledge of the DoD Risk Management Framework.
  • Strong working knowledge of NIST SP 800-37, NIST SP 800-53, CNSSI 1253, and the JSIG.
  • Experience conducting security control assessments and evaluating technical, operational, and management controls.
  • Experience reviewing and preparing ATO packages and supporting documentation.
  • Experience validating inherited controls and assessing Ports, Protocols, and Services requirements.
  • Demonstrated leadership experience, including previous experience serving in a lead or senior assessment role.
  • Strong written and verbal communication skills, with the ability to clearly explain technical findings, risks, and remediation requirements to system owners and government stakeholders.
Preferred Qualifications
  • Experience supporting DoD Special Access Programs or other highly classified environments.
  • Experience working directly with system owners, ISSOs, ISSMs, security engineers, and Authorizing Official representatives.
  • Familiarity with security assessment reports, risk assessment reports, system security plans, POA&Ms, and continuous-monitoring documentation.
  • Experience leading assessment teams or overseeing multiple system authorization efforts.
  • Strong analytical, documentation-review, and quality-assurance skills.
Core Benefits:
  • Paid Time Off PTO):TEN (10) Paid days off & FIVE (5) Floating days off.
  • Holidays: 11 Paid Holidays. Flex time can be utilized instead of holiday time usage.
  • Payroll: Paid Bi-Monthly.
  • 401(k): Partnered with the SECOND LARGEST Retirement plan provider in the U.S. Guaranteed 3% match. Eligibility – 21 years of age or older, after 3 months of employment
  • Individual or company-wide performance and recognition awards (Quarterly)
  • UNITED HEALTHCARE PPO, extensive national coverage.
  • Eligible on the first of the month, immediately after the start date.
  • Submit the enrollment form within 30 days of your start date otherwise, you will have to wait until October for the new year enrollment.
Quality of Life Benefits:
  • Training & Career Development Reimbursement of Tuition and training needed to support career development.
  • $150 monthly reimbursement contribution paid monthly towards parking expenses.
  • Receipts must be submitted by the close of business on the 25th of each month.
  • Reimbursements will be paid on the first payroll AFTER reimbursements are submitted each month.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Security Specialist
Information Security Specialist

Novul Solutions • Arlington (TX)

On-site
USD 90,000 - 120,000
10 Paid days off
11 Paid Holidays
401(k) with 3% match
+2
Information Security Specialist
Information Security Specialist

novulsolutions • Arlington (VA)

On-site
USD 95,000 - 130,000
Paid Time Off
Performance bonus
Health Benefits: UNITED HEALTHCARE PPO
Cybersecurity Systems Analyst, Sr.
Cybersecurity Systems Analyst, Sr.

TJ Consulting Group • Coronado (CA)

On-site
USD 120,000 - 170,000
PTO
Holiday Pay
401K with a 4% Match
+13
Information System Security Officer
Information System Security Officer

Base-2 Solutions • Washington

On-site
USD 120,000 - 170,000
Health insurance
401(k) with company match
Paid time off
Security Control Assessor
Security Control Assessor

SAIC • Springfield (VA)

On-site
USD 120,000 - 160,000
Cyber Security Engineer
Cyber Security Engineer

Triglocon • Arlington (VA)

On-site
USD 110,000 - 150,000
Medical, Dental & Vision Coverage
Paid Time Off
Paid Holidays
+3
Junior Security Control Assessor
Junior Security Control Assessor

System One • Bethesda (MD)

Hybrid
USD 100,000 - 115,000
Health insurance
Dental insurance
Vision insurance
+2
TASS (Current Contract) - Security Control Assessor, Senior
TASS (Current Contract) - Security Control Assessor, Senior

Agecareers • Maryland

On-site
USD 95,000 - 105,000
26 Days Paid Leave
401(k) with Match
Health Benefits
+2
Security Assessor (RMF / GRC)
Security Assessor (RMF / GRC)

Digital Global Connectors • McLean (VA)

Hybrid
USD 110,000 - 160,000
Information System Security Officer
Information System Security Officer

Base-2 Solutions • Reston (VA)

On-site
USD 120,000 - 170,000
Referral bonuses up to $10,000
Company-paid health premiums
Company-paid dental premiums
+1