Security Control Assessor

Peraton

Linthicum (MD)

On-site

USD 120,000 - 180,000

Full time

2 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Peraton in Linthicum, MD is seeking a Security Control Assessor to support a DoD customer. The role involves leading risk assessments, A&A activities, and security plan updates across DoD cloud infrastructure.

The successful candidate will apply NIST and RMF methodologies, review scans, and guide privacy and compliance initiatives while collaborating with a high-performing team in a dynamic cyber operations environment.

Qualifications

  • Bachelor’s or higher with 8+ years experience, or advanced degrees with fewer years.
  • Active TS clearance with SCI eligibility and CompTIA Security+ and IAM III certifications.
  • Knowledge of enterprise cloud environments (JWICS, SIPRNET, NIPRNET, commercial Internet).
  • Experience with NIST, FISMA, HIPAA, and PII governance and RMF processes.

Responsibilities

  • Conduct assessments and facilitate risk mitigation planning.
  • Provide A&A for the ARCYBER cloud infrastructure.
  • Execute a security control assessment plan and update the System Security Plan.
  • Review vulnerability scans and remediation.
  • Implement risk management programs per NIST, FISMA, HIPAA, and PII guidelines.
  • Monitor the privacy landscape for data protection and residency.
  • Assist clients in identifying gaps within privacy programs and designing solutions.
  • Scan, test, and validate systems/networks/applications to obtain/maintain an ATO under NIST/FISMA.

Skills

TS clearance
Cybersecurity
Cloud security
Risk assessment
NIST/FISMA knowledge
Vulnerability assessment
Security certifications
Network security
Analytical skills

Education

Bachelor’s degree in a related field
Master’s degree in a related field
PhD in a related field
4+ years relevant experience in lieu of degree

Tools

eMASS
ACAS
ISC2 CCSP
CISSP
Cloud+
IAM

Job description

Required Qualifications:

  • Bachelor’s degree and 8+ years of experience, or Master’s and 6+ years of experience, or PhD and 3+ years of experience. A degree in one of the following fields of study is highly desired: Information Technology, Computer Science, Cybersecurity, Information Systems, Software Engineering, or Data Science. An additional 4 years of experience or specialized training may be considered in lieu of Bachelor's degree.
  • Active TS clearance with SCI eligibility.
  • Active CompTIA Security+ certification.
  • Active IAM level III certification (such as CISM).
  • Must have knowledge of enterprise solutions across multiple cloud operating environments (JWICS, SIPRNET, NIPRNET, and commercial Internet).
  • Must have eMASS, ACAS, and ISC2 Certified Cloud Computing Professional (CCSP) or CompTIA Cloud+ experience.
  • Must have knowledge in the following areas:
    • Knowledge of computer networking and/or cloud computing concepts and protocols, and network security methodologies.
    • Knowledge of cyber threats and vulnerabilities in a virtualized environment.
    • Knowledge of national and international laws, regulations, policies, and ethics as they relate to cybersecurity.
    • Knowledge of risk management framework processes (e.g., methods for assessing and mitigating risk).
    • Knowledge of specific operational impacts of cybersecurity lapses.
    • Knowledge of industry methods for evaluating, implementing, and disseminating Information Technology (IT) security assessment, monitoring, detection, and remediation tools and procedures using standards-based concepts and capabilities.
    • Knowledge of cyber defense and vulnerability assessment tools, including opensource tools, and their capabilities.
    • Knowledge of cybersecurity principles and organizational requirements (relevant to confidentiality, integrity, availability, authentication, non-repudiation).
    • Knowledge of cybersecurity principles used to manage risks related to the use, processing, storage, and transmission of information or data in a cloud environment.
    • Knowledge of IT and cloud computing security principles and methods (e.g., firewalls, demilitarized zones, encryption).
    • Knowledge of known vulnerabilities from alerts, advisories, errata, and bulletins.
    • Knowledge of network and/or cloud computing environment security architecture concepts including topology, protocols, components, and principles (e.g., application of defense-in-depth).
    • Knowledge of penetration testing principles, tools, and techniques..
    • Knowledge of system and application security threats and vulnerabilities (e.g., buffer overflow, mobile code, cross-site scripting, Procedural Language/Structured Query Language [PL/SQL] and injections, race conditions, covert channel, replay, returnoriented attacks, malicious code).
    • Knowledge of the Security Assessment and Authorization process.
    • Skill in determining how a security and/or cloud computing security system should work (including its resilience and dependability capabilities) and how changes in conditions, operations, or the environment will affect these outcomes.
    • Skill in discerning the protection needs (i.e., security controls) of information systems and networks and those relating to cloud computing.
    • Knowledge of local specialized system requirements (e.g., critical infrastructure systems that may not use standard IT) for safety, performance, and reliability.
    • Knowledge of new and emerging IT and cybersecurity technologies and/or those technologies specific to cloud computing.

Peraton is seeking a Security Control Assessor in our Linthicum, MD office in support of our Department of Defense (DoD) customer as part of a highly talented, highly motivated, and high-performing team. This position offers a unique opportunity to work at the forefront of cyber investigations, digital forensics, cyber threat analysis, and mission support in a dynamic and collaborative environment. The successful candidate will contribute to protecting national security interests by leveraging technical expertise, analytical skills, and innovative problem-solving to address complex cyber challenges. Individuals who are passionate about cybersecurity, committed to excellence, and eager to make a meaningful impact are encouraged to apply.

In this role you will accomplish the following:

  • Conduct assessments and facilitate risk mitigation planning.
  • Provide Assessment and Authorization (A&A) for the ARCYBER cloud infrastructure.
  • Execute a security control assessment plan and update the System Security Plan.
  • Review vulnerability scans and remediation.
  • Implement risk management programs by utilizing NIST, FISMA, HIPAA, and PII -- and document solutions.
  • Monitor the privacy landscape regarding all data (privacy, protection, classification, and residency).
  • Assist clients with identifying gaps within existing privacy programs and designing solutions to help address those challenges.
  • Scan, test, and validate systems/networks/applications to obtain/maintain an ATO under NIST/FISMA guidelines.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Control Assessor SCA TSSCI
Security Control Assessor SCA TSSCI

Tau Six • Sully Square (VA)

On-site
USD 70,000 - 110,000
Security Control Assessor
Security Control Assessor

SAIC • Springfield (VA)

On-site
USD 120,000 - 160,000
Security Control Assessor (SCA) (TS/SCI)
Security Control Assessor (SCA) (TS/SCI)

Tau Six, LLC • Sully Square (VA)

On-site
USD 80,000 - 110,000
Security Control Assessor
Security Control Assessor

System High Corporation • Chantilly (VA)

On-site
USD 120,000 - 160,000
Security Control Assessor – DoD A&A & Cloud
Security Control Assessor – DoD A&A & Cloud

Peraton • Linthicum (MD)

On-site
USD 120,000 - 180,000
Security Control Assessor
Security Control Assessor

Peraton • Alexandria (VA)

On-site
USD 146,000 - 234,000
Medical benefits
401(k) retirement plan
Paid time off
Traveling Security Control Assessor
Traveling Security Control Assessor

Jobtailor • Maryland

On-site
USD 120,000 - 160,000
Security Assessor (RMF / GRC)
Security Assessor (RMF / GRC)

Digital Global Connectors • McLean (VA)

Hybrid
USD 110,000 - 160,000
Traveling DoD Cybersecurity Assessments Specialist
Traveling DoD Cybersecurity Assessments Specialist

Jobtailor • Maryland

On-site
USD 120,000 - 160,000
SCA Lead
SCA Lead

Disruptive Solutions, LLC • Sterling (VA)

Hybrid
USD 150,000 - 190,000