Security Control Assessor

SAIC

Springfield (VA)

On-site

USD 120,001 - 160,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

SAIC is seeking a Senior Security Control Assessor (SCA) to support cybersecurity assessments for mission-critical IT systems in Springfield, VA. The role requires working with ISSMs, ISOs, and admins to ensure RMF, NIST 800-53, and A&A compliance, with on-site work in Springfield, VA.

The candidate will perform independent control assessments, review artifacts, lead control implementation reviews, analyze vulnerability data, and prepare SARs and risk summaries for senior stakeholders.

Qualifications

  • Proven ability to conduct independent assessments of security controls.
  • Experience aligning with RMF, NIST SP 800-53 and DoD 8510.01 requirements.
  • Ability to produce Security Assessment Reports and clear recommendations.

Responsibilities

  • Conduct objective assessments to validate security control compliance.
  • Review ABDs, RARs, SSPs, STIGs, and vulnerability results for A&A.
  • Lead control implementation reviews and system-level security assessments.
  • Provide formal authorization recommendations to AO based on findings.
  • Analyze vulnerability scan data and communicate risk posture to stakeholders.
  • Perform continuous monitoring to identify changes affecting security posture.
  • Validate DISA STIGs/CIS Benchmarks across systems and apps.
  • Collaborate with ISSOs, engineers, and stakeholders to remediate risks.
  • Improve processes, tools, and documentation for control assessments.
  • Compile SARs and risk summaries for senior decision-makers.
  • Maintain up-to-date knowledge of threats, frameworks, and best practices.

Skills

Security control assessment
RMF & NIST SP 800-53
Vulnerability assessment
Documentation & SARs

Education

Bachelor's Degree in Cybersecurity/CS/IT

Tools

ACAS/Nessus/Qualys
Windows Server
RHEL (Linux)

Job description

Job ID 2614940

Location Springfield, VA, US

Date Posted 2026-07-24

Category Cyber

Subcategory Cyberspace Ops

Schedule Full-Time

Shift Day Job

Travel Yes - 10% of the time

Minimum Clearance Required Top_Secret

Clearance Level Must Be Able to Obtain TS/SCI with Poly

Potential for Remote Work ORA_ON_SITE

Description

SAIC is seeking a highly skilled and motivated Senior Security Control Assessor (SCA) to support the cybersecurity assessment and compliance needs of mission-critical IT systems for the MAJESTIC Joint Program Office (JPO) Team. The successful candidate will perform independent assessments of security controls to ensure compliance with federal cybersecurity policies, standards, and frameworks, such as the Risk Management Framework (RMF), NIST SP 800-53, and others, to manage and mitigate risks to sensitive and classified systems. This role will require working closely with Information System Security Managers (ISSMs), Information System Owners (ISOs), and system administrators to conduct technical reviews, evaluate security controls, and assist with Authorization and Accreditation (A&A) efforts. This role requires on-site support in Springfield, VA.

Key Responsibilities
  • Conduct independent, objective, and robust assessments of IT systems to validate compliance with security control requirements in alignment withNIST 800-53, RMF, DoD 8510.01, and other applicable federal cybersecurity regulations
  • Review and assessAuthorization Boundary Diagrams (ABDs), Risk Assessment Reports (RARs), Security Plan Packages (SSPs), STIG checklists, vulnerability scan results, POA&Ms, and other security artifacts required for A&A efforts
  • LeadControl Implementation Review and Test (CIRT)procedures and system-level security assessments to evaluate the adequacy of technical, operational, and management security controls
  • Provideformal recommendations on system authorization statusto Authorizing Officials (AOs), based on assessment results, residual risks, and system compliance to applicable policies
  • Analyze and interpretvulnerability scan results(e.g., from ACAS, Nessus, or Qualys) and assist in presenting the organization’s vulnerability management posture to relevant stakeholders
  • Performcontinuous monitoring assessmentsof information systems to identify risks, ensure ongoing compliance, and document changes impacting the security posture of systems
  • Assess and validate security hardening practices using theDISA STIGs or CIS Benchmarksacross systems, applications, and networks
  • Conduct risk analysis and recommend risk mitigation strategies and control adjustments to minimize threats to system operations and data integrity
  • Interface with system engineers, ISSOs, and stakeholders to resolve identified vulnerabilities and ensure timely remediation of risks
  • Provide recommendations to improve current processes, tools, and documentation for security control assessments
  • Compile and present comprehensive reports, includingSecurity Assessment Reports (SARs)and risk assessment summaries, to senior stakeholders for decision-making
  • Maintain up-to-date expertise on cybersecurity threats, technologies, regulatory frameworks, and compliance best practices
Qualifications
Required Qualifications
Certifications (CWF Requirements)
  • Candidates must satisfyCybersecurity Workforce Framework (CWF)ID 612 (Security Control Assessor)requirements, as outlined byNavy COOL This requirement can be met by possessing one or more of the following qualifyingcertifications
  • Certified in Governance Risk and Compliance (CGRC)
  • Certified Information Systems Security Officer (C)ISSO-A)
  • CompTIA Cloud+
  • CompTIA PenTest+
  • CompTIA Security+
  • CompTIA SecurityX (formerly CASP+)
  • Federal IT Security Professional-Auditor-NG (FITSP-A)
  • GIAC Cloud Security Automation (GCSA)
  • GIAC Security Essentials Certification (GSEC)
  • Certified Chief Information Security Officer (CCISO)
  • Certified Information Security Manager (CISM)
  • Certified Information Systems Auditor (CISA)
  • Certified Information Systems Security Professional (CISSP)
  • CompTIA Cybersecurity Analyst (CySA+)
  • GIAC Security Leadership Certification (GSLC)
  • GIAC Systems and Network Auditor (GSNA)
  • Information Systems Security Engineering Professional (ISSEP)
OR This requirement can be met through
  • ABachelor’s Degreein Cybersecurity, Computer Science, IT, or a related field
Experience
  • 5-9 yearsof professional experience managing and supporting enterprise-levelIT environments
Technical Skills
  • Familiarity with IT environments running enterprise systems, such as Windows Server 2019, MS SQL databases, and Linux distributions (RHEL preferred)
  • Knowledge of incident response functions, security architecture, and penetration testing frameworks (e.g., METASPLOIT, Kali Linux)
  • Strong analytical and documentation skills, with the ability to author comprehensive Security Assessment Reports (SARs) and other system artifacts
Preferred Qualifications
  • Familiarity with IT environments running enterprise systems, such as Windows Server 2019, MS SQL databases, and Linux distributions (RHEL preferred)
  • Knowledge of incident response functions, security architecture, and penetration testing frameworks (e.g., METASPLOIT, Kali Linux)
  • Strong analytical and documentation skills, with the ability to author comprehensive Security Assessment Reports (SARs) and other system artifacts
Clearance Requirement
  • ActiveTS/SCIclearance with the ability to obtain and maintain aTS/SCI with Poly
Work Environment and Notes
  • On-Site WorkAll work must be conductedon-sitein Springfield, VA
  • Program ScopeSupports on-premises enterprise IT environments, including virtualized Windows servers, MS SQL Server databases, and networking layers
  • Subcontractor RoleResponsibilities and compensation vary based on the subcontract agreement, with a competitive salary aligned to market rates and role-specific requirements

Target salary range $120,001 - $160,000. The estimate displayed represents the typical salary range for this position based on experience and other factors.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Control Assessor
Security Control Assessor

System High Corporation • Chantilly (VA)

On-site
USD 120,000 - 160,000
Senior Security Controls Assessor (TS/SCI #26-125)
Senior Security Controls Assessor (TS/SCI #26-125)

Strategic Analysis, Inc. • Arlington (VA)

On-site
USD 140,000 - 190,000
Security Control Assessor (SCA)
Security Control Assessor (SCA)

Huntington Ingalls Industries • Springfield (VA)

On-site
Security Control Assessor SCA TSSCI
Security Control Assessor SCA TSSCI

Tau Six • Sully Square (VA)

On-site
USD 70,000 - 110,000
Security Control Assessor (SCA) (TS/SCI)
Security Control Assessor (SCA) (TS/SCI)

Tau Six, LLC • Sully Square (VA)

On-site
USD 80,000 - 110,000
Senior Security Control Assessor: TS/SCI Poly (On-Site)
Senior Security Control Assessor: TS/SCI Poly (On-Site)

SAIC • Springfield (VA)

On-site
USD 120,000 - 160,000
Security Controls Assessor
Security Controls Assessor

Modern Technology Solutions, Inc. (MTSI) • Chantilly (VA)

On-site
USD 100,000 - 130,000
Security Control Assessor Representative
Security Control Assessor Representative

electro soft • Belleville (IL)

On-site
USD 100,000 - 115,000
Security Control Assessor (SCA)
Security Control Assessor (SCA)

Mission Technologies, a division of HII • Springfield (VA)

On-site
USD 85,000 - 135,000
Security Controls Assessor (Pipeline)
Security Controls Assessor (Pipeline)

electro soft • Belleville (IL)

On-site
USD 85,000 - 120,000
Comprehensive benefits
Team-building activities
Growth opportunities