Security Control Assessor

IBSS

Silver Spring (MD)

On-site

USD 80,000 - 110,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical coverage
Dental coverage
Vision coverage
401K match
Tuition reimbursement

Job summary

IBSS is seeking a qualified Security Control Assessor to support NOAA. You will perform FISMA assessments evaluating security controls for high-value assets.

Ideal candidates have 5 years experience with NIST frameworks and relevant cybersecurity certifications. The position includes a competitive benefits package and an inclusive culture.

Qualifications

  • Must be a U.S. Citizen.
  • 5 years of experience with the NIST 800 Series.
  • Experience with FIPS 200, FISMA, and the Privacy Act.

Responsibilities

  • Conduct security and privacy control assessments.
  • Ensure compliance with FISMA and NIST publications.
  • Develop essential security assessment outputs.

Skills

NIST 800 Series knowledge
Risk management principles
Technical writing skills

Education

Cybersecurity certification (e.g., CEH, CISSP)

Job description

Job Title: Security Control Assessor

Location: Silver Spring, MD

Clearance Required: None

Salary Range: $80K - $110K

Application Deadline: June 30, 2026

To apply, please follow these steps:

  • Visit https://ibsscorp.com/careers/
  • Select the position you are interested in
  • Review the job details, then click Apply Now
  • Complete and submit your application
Description

IBSS Corporation is seeking a qualified Security Control Assessor to support Authorization Services for the National Oceanic and Atmospheric Administration (NOAA). In this role, you will perform an independent Federal Information Security Modernization Act (FISMA) assessment to evaluate a Moderate/Moderate/Moderate FISMA system with High Value Asset (HVA) and Privacy overlays. You will be responsible for evaluating security and privacy controls to ensure compliance with Department of Commerce (DOC) and NOAA IT policies, as well as National Institute of Standards and Technology (NIST) requirements. Ultimately, your assessment findings will directly support and inform an Authority to Operate (ATO) recommendation.

Key Responsibilities
  • Conduct full security and privacy control assessments covering 100 percent of the System Security Plan (SSP) identified controls.
  • Ensure all assessment activities comply with FISMA, the Privacy Act, FIPS 200, NIST publications (specifically the NIST 800 Series), and DOC/NOAA cybersecurity mandates.
  • Develop, review, and evaluate essential security assessment outputs, including a Security Assessment Plan (SAP), Security Requirements Traceability Matrix (SRTM), Penetration Testing Report (PTR), Security Assessment Report (SAR), Risk Assessment Report (RAR), and Assessment Findings Report (AFR).
  • Evaluate technical vulnerabilities, vulnerability scan results, and penetration test findings to translate them into actionable business risks. Evaluate Plans of Action and Milestones (POA&M) for completeness and adequacy of closure evidence.
  • Conduct Assessment Results Briefings (ARB) to present findings, vulnerability risks, and ATO recommendations to Authorizing Officials (AO), Co-AOs, System Owners, and Information System Security Officers (ISSO).
Required Skills / Education / Certifications & Qualifications
  • Must be a U.S. Citizen.
  • Must have 5 years of demonstrated experience actively working with the NIST 800 Series.
  • Must have experience working with FIPS 200, FISMA, and the Privacy Act.
  • Must possess a working knowledge of risk management principles and the associated artifacts required by FISMA.
  • Must hold and maintain in good standing at least one of the following DOC‑required professional cybersecurity certifications:
    • EC‑C Certified Ethical Hacker (CEH)
    • GIAC Certified Incident Handler (GCIH)
    • GIAC Systems and Network Auditors (GSNA)
    • ISC2 Certified in Governance Risk and Compliance (CGRC)
    • ISC2 Certified Information System Security Professional (CISSP)
    • ISACA Certified Information System Auditor (CISA)
Desired Skills
  • Experience using the Cyber Security Assessment and Management (CSAM) tool for tracking and reporting assessment packages.
  • Familiarity with Federal Risk and Authorization Management Program (FedRAMP) documentation and evaluating Cloud Service Providers (CSPs) like AWS or Azure.
  • Knowledge of Defense Information Systems Agency (DISA) Security Technical Implementation Guides (STIGs) and analyzing automated vulnerability scanner results.
  • Prior experience handling, marking, and safely transmitting Controlled Unclassified Information (CUI).
  • Strong technical writing and presentation skills required to deliver clear Assessment Results Briefings (ARB) to high‑level agency stakeholders.
  • Ability to demonstrate root cause analysis and troubleshooting skills during independent assessments.
Benefits

IBSS offers a competitive benefits package that includes medical, dental, vision, and prescription drug coverage, paid time off, federal holidays, a matching 401K plan, tuition/professional development reimbursement, and Flex‑Spending (FSA)/Dependent Care Account (DCA) options.

Equal Employment Opportunity

IBSS is an affirmative action and equal opportunity employer. All qualified applicants will be considered for employment without regard to race, color, religion, sex, disability, age, sexual orientation, gender identity, national origin, veteran status, or genetic information. Click https://www.eeoc.gov/poster to see that the EEO is the law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

(590) Information Security Specialist III
(590) Information Security Specialist III

Arlosolutionsllc • Silver Spring (MD)

Hybrid
USD 100,000 - 140,000
DHS Security Control Assessor III
DHS Security Control Assessor III

OneZero Solutions • Washington

On-site
USD 110,000 - 150,000
Qualified Parking Allowance
Security Control Assessor
Security Control Assessor

SAIC • Springfield (VA)

On-site
USD 120,000 - 160,000
Service Desk Support – Level I
Service Desk Support – Level I

IBSS • East Falmouth (MA)

On-site
USD 55,000 - 58,000
Medical coverage
Dental coverage
Vision coverage
+3
Cyber & A&A Security Specialist - Hybrid Remote
Cyber & A&A Security Specialist - Hybrid Remote

ATTAINX INC • Silver Spring (MD)

Hybrid
USD 98,000 - 110,000
Paid vacation
Medical, dental, and vision coverage
Matching 401(k) plan
+1
Junior Security Control Assessor
Junior Security Control Assessor

augustschell • Fort Meade (MD)

Hybrid
USD 70,000 - 90,000
Service Desk Support Level I
Service Desk Support Level I

Creative Solutions Services, LLC • Falmouth (MA)

On-site
USD 55,000 - 58,000
SME Security Control Assessor
SME Security Control Assessor

IMAGINEEER LLC • Arlington (VA)

Hybrid
USD 80,000 - 100,000
Competitive salary
Flexible work from home options
Security Control Assessor
Security Control Assessor

Boston Government Services, LLC (BGS) • United States

Remote
USD 110,000 - 150,000
Health Insurance
Dental Insurance
Vision Insurance
+4
Information System Security Compliance Analyst (Multiple Levels)
Information System Security Compliance Analyst (Multiple Levels)

Noblis • Denver (CO)

On-site
USD 78,900 - 180,525
Health, life, and disability insurance
Retirement plans
Paid leave
+2