Security Control Assessor

Jobvite, Inc.

Arlington (VA)

Hybrid

USD 110,000 - 145,000

Full time

6 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Security clearance support

Job summary

VMD Corp, now part of Xcelerate Solutions, is seeking a Security Control Assessor to oversee cybersecurity for a program, organization, system, or enclave. You will advise on security/privacy controls and collaborate with system owners to maintain a strong posture.

Responsibilities include risk assessments, control selection, monitoring strategy development, and updating security plans and artifacts. Hybrid Arlington, VA location with required clearances and federal experience.

Qualifications

  • Demonstrated knowledge of cyber legal, regulatory, and policy frameworks (RMF, FedRAMP, NIST SP 800-53/800-171).
  • Experience applying RMF/NIST frameworks to ensure security compliance.
  • Familiarity with security authorization artifacts (SSPs, SARs, POA&Ms) and risk assessments.

Responsibilities

  • Identify security/privacy requirements and system boundaries.
  • Collaborate with System Owner to categorize systems and document results.
  • Identify stakeholders with security/privacy interests across the system lifecycle.
  • Conduct ongoing risk assessments and update plans and milestones.
  • Select controls and document functional descriptions for security implementations.
  • Develop monitoring strategies and coordinate with organizational monitoring efforts.
  • Develop and approve plans to assess controls and document changes.
  • Respond to risk posture from monitoring results and POA&Ms.
  • Update security plans, assessment reports, and remediation plans.
  • Review security status to ensure residual risk remains acceptable.
  • Report security posture to authorizing officials according to monitoring strategy.

Skills

RMF/NIST SP 800-53
FedRAMP
Security Control Assessments
Risk Management
Cybersecurity Frameworks

Education

Bachelor's degree in Cyber-related field

Job description

VMD Corp, now part of Xcelerate Solutions, seeks a Security Control Assessor to be responsible for the cybersecurity of a program, organization, system, or enclave. The Security Control Assessor ensures that the security and privacy posture is maintained for an organizational system and works in close collaboration with the FDIC system owners. The Security Control Assessor serves as an advisor on all matters, technical and otherwise, involving the security and privacy controls for the system and has the knowledge and expertise to manage the security and privacy aspects of an organizational system.

Responsibilities
  • Identify the security and privacy requirements allocated to a system and to the organization, identify the characteristics of a system, contribute to determining the boundary of a system.
  • Collaborate with the System Owner to categorize the system and document the security categorization results as part of system requirements.
  • Identify stakeholders who have a security and/or privacy interest in the development, implementation, operation, or sustainment of a system.
  • Conduct an initial risk assessment of stakeholder assets and update the risk assessment on an ongoing basis.
  • Select the security and privacy controls for a system and document the functional description of the planned control implementations in a security/privacy plan.
  • Develop a strategy for monitoring security and privacy control effectiveness; coordinate the system-level strategy with the organization and mission/business process-level monitoring strategy.
  • Develop, review, and approve a plan to assess the security and privacy controls in a system and the organization.
  • Document changes to planned security and privacy control implementation and establish the configuration baseline for a system.
  • Respond to system risk posture based on the results of ongoing monitoring activities, assessment of risk, and outstanding items in a plan of action and milestones (POA&M).
  • Update a security plan, security assessment report, and plan of action and milestones based on the results of a continuous monitoring process.
  • Review the security and privacy status of a system (including the effectiveness of security and privacy controls) on an ongoing basis to determine whether the risk remains acceptable.
  • Report the security status of a system (including the effectiveness of security and privacy controls) to an authorizing official on an ongoing basis in accordance with the monitoring strategy.
  • Ensure that plans of actions and milestones or remediation plans are in place for vulnerabilities identified during risk assessments, audits, inspections, ensure that security improvement actions are evaluated, validated, and implemented as required.
Experience needed to be successful
  • Demonstrated knowledge in the use of cyber legal, regulatory, and policy, specifically knowledge of federal cybersecurity governance frameworks, i.e., RMF, FedRAMP, and NIST Special Publications such as SP 800-53 and SP 800-171. Development and review of key authorization artifacts such as SSPs, SARs, POA&Ms
  • Demonstrated knowledge of cybersecurity principles, threats, and vulnerabilities, specifically strong knowledge of cybersecurity principles, i.e., confidentiality, integrity, availability, authentication, and risk management.
  • Demonstrated experience in the application of frameworks such as RMF, NIST SP 800-53, and FedRAMP to ensure enterprise-wide security compliance
  • Demonstrated experience of technical systems and tools in a wide range of cyber security defense tools and systems
  • Demonstrated experience of access, architecture, and infrastructure through applied knowledge of authentication, authorization, and access control methods
  • Demonstrated experience in business, operations, and risk management in particular risk management processes using frameworks such as RMF, NIST SP 800-53, and FedRAMP to assess and mitigate vulnerabilities across federal and commercial environments. Development of security documentation, including SSPs, SARs, and POA&Ms
Requirements
  • Experience: 4-6 years of Relevant Cybersecurity Experience - specifically performing security control assessments in a SCA role, including supporting federal clients
  • Education: Bachelors Degree in Cyber-related field (Direct experience or certifications may substitute for the academic credentials)
  • Desired Certifications: Recognized cybersecurity certifications (e.g., CISSP, CISM, CISA, CAP, GIAC, or CompTIA certifications such as Security+ or CASP+)
  • Citizenship: U.S. Citizen
  • Clearance: Public Trust
Location

Location: Arlington, VA (Hybrid). Must reside within the DC Metro area.

VMD provides equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion, gender, sexual orientation, gender identity or expression, national origin, age, disability, genetic information, marital status, amnesty, or status as a covered veteran in accordance with applicable Federal, state and local laws. VMD maintains a drug-free workplace.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Control Assessor
Security Control Assessor

Vmdsystems • Arlington (VA)

Hybrid
USD 110,000 - 150,000
Security Controls Assessor
Security Controls Assessor

ecsfederal • Washington

Hybrid
USD 150,000 - 168,000
Security Controls Assessor — RMF/FedRAMP Expert (Hybrid)
Security Controls Assessor — RMF/FedRAMP Expert (Hybrid)

Vmdsystems • Arlington (VA)

Hybrid
USD 110,000 - 150,000
Security Controls Assessor
Security Controls Assessor

UltraViolet Cyber • Bluemont (VA)

On-site
USD 110,000 - 125,000
401(k) with employer match
Medical, Dental, and Vision Insurance
DTO program
+1
Security Control Assessor
Security Control Assessor

Omniscius Consulting • Arlington (VA)

On-site
USD 120,000 - 180,000
Security Control Assessor
Security Control Assessor

Omniscius • Arlington (VA)

On-site
USD 110,000 - 140,000
Senior Cybersecurity Specialist
Senior Cybersecurity Specialist

Vmdsystems • Maryland

Hybrid
USD 120,000 - 160,000
Hybrid work schedule
Security Control Assessor ? Level II / Journeyman
Security Control Assessor ? Level II / Journeyman

Rividium • Washington

On-site
USD 110,000 - 180,000
Senior Security Controls Assessor
Senior Security Controls Assessor

ecsfederal • Virginia (MN)

Hybrid
USD 160,000 - 190,000
Remote work
Senior Cybersecurity Specialist
Senior Cybersecurity Specialist

VMD Corp • Maryland

On-site
USD 120,000 - 180,000