Security Control Assessor

ANALYGENCE

Washington (District of Columbia)

On-site

USD 120,000 - 180,000

Full time

3 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Tharros is seeking a Security Control Assessor to lead independent security control assessments for DHS Intelligence Enterprise systems, both on-premise and cloud. The role covers discovery through ATO/ATC/IATT packages, with responsibility for writing Security Assessment Reports and validating remediation.

You will collaborate with system owners and ISSOs, document evidence of compliance, and prepare A&A artifacts in the GRC tool. The position is on-site in a Government SCIF in Washington, DC.

Qualifications

  • BS degree in Information Technology, Cybersecurity, Information Systems, or Computer Science OR minimum of 6 years' experience in IT or cybersecurity.
  • 3+ years' experience in RMF security control assessment.
  • Active TS/SCI clearance and U.S. citizenship; willing to undergo DHS polygraph.

Responsibilities

  • Conduct discovery and kick-off meetings with project stakeholders for new and re-authorization activities.
  • Assess management, operational, and technical security controls against RMF, NIST, CNSS and IC standards.
  • Conduct vulnerability, configuration, container, and serverless testing across on-premise and cloud environments.
  • Document findings in Security Assessment Reports and ensure alignment with POA&Ms.
  • Validate POA&Ms remediation and document evidence of compliance.
  • Prepare A&A packages in the GRC tool, including risk memoranda and ATO/ATC/IATT letters.
  • Produce System Security Test Reports and A&A portfolio reports.
  • Provide recommendations to mitigate risk and improve the security posture of assigned systems.

Skills

RMF knowledge
NIST SP 800-53A
CNSSI knowledge
Security assessment writing
Independent coordination
Excellent communication

Education

BS degree in IT/Cybersecurity/IS/CS

Tools

Nessus/ACAS
SCAP
Nmap
WebInspect
SonarQube
STIG Viewer

Job description

Tharros supports the Department of Homeland Security (DHS) with cybersecurity services across its Intelligence Enterprise. In support of this mission, we have an immediate opportunity for a Security Control Assessor.

In this role you will lead independent security control assessments of DHS Intelligence Enterprise systems, on-premise and in the cloud, from discovery through a completed authorization package supporting ATO, ATC, and IATT decisions. You will write assessment reports, validate remediation, and work closely with system owners and ISSOs. This position is on-site in a Government SCIF in Washington, DC.

  • Conduct discovery and kick-off meetings with project stakeholders for new and re-authorization activities.
  • Assess management, operational, and technical security controls against NIST, CNSSI, and IC standards.
  • Conduct vulnerability, configuration, container, and serverless testing across on-premise and cloud environments.
  • Document findings in Security Assessment Reports and ensure alignment with POA&Ms.
  • Validate POA&Ms remediation and document evidence of compliance.
  • Prepare A&A packages in the GRC tool, including risk memoranda and ATO/ATC/IATT letters.
  • Produce System Security Test Reports and A&A portfolio reports.
  • Provide recommendations to mitigate risk and improve the security posture of assigned systems.
  • BS degree in Information Technology, Cybersecurity, Information Systems, or Computer Science OR minimum of 6 years' experience in IT or cybersecurity.
  • Minimum of 3 years' experience in RMF security control assessment.
  • Active TS/SCI clearance and U.S. citizenship; willingness to undergo a DHS counterintelligence-scope polygraph.
  • Knowledge of the Risk Management Framework (RMF), NIST SP 800-53A, and CNSSI 1253.
  • Knowledge of the ATO, ATC, and IATT authorization process.
  • Knowledge of POA&Ms management and risk acceptance processes.
  • Skill in using at least two security tools (e.g., Nessus/ACAS, SCAP, Nmap, WebInspect, SonarQube, STIG Viewer).
  • Skill in writing Security Assessment Reports and risk recommendations.
  • Ability to lead an assessment independently and coordinate with system owners.
  • Proficient in Microsoft Office Suite to include Teams or similar workplace chat and videoconferencing tools.
  • Excellent written and oral communications skills.
Desired
  • CGRC (formerly CAP), CompTIA Security+, or CySA+ certification.
  • Cloud authorization experience (AWS or Azure).
  • Experience with RSA Arche r.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Junior Security Control Assessor
Junior Security Control Assessor

ANALYGENCE • Washington

On-site
USD 65,000 - 90,000
Senior Security Control Assessor
Senior Security Control Assessor

ANALYGENCE • Washington

On-site
USD 140,000 - 170,000
Senior Security Control Assessor
Senior Security Control Assessor

Jimmy Jazz • Washington

On-site
USD 120,000 - 150,000
Junior Security Control Assessor
Junior Security Control Assessor

Jimmy Jazz • Washington

On-site
USD 70,000 - 100,000
Security Governance and Policy Analyst
Security Governance and Policy Analyst

ANALYGENCE • Washington

On-site
USD 110,000 - 170,000
RMF Security Control Assessor – TS/SCI, ATO/ATC
RMF Security Control Assessor – TS/SCI, ATO/ATC

ANALYGENCE • Washington

On-site
USD 120,000 - 180,000
Junior Information System Security Officer
Junior Information System Security Officer

ANALYGENCE • Washington

On-site
USD 70,000 - 100,000
IT Security Operations Specialist
IT Security Operations Specialist

ANALYGENCE • Washington

On-site
USD 110,000 - 160,000
Senior Security Controls Assessor (TS/SCI #26-143)
Senior Security Controls Assessor (TS/SCI #26-143)

Strategic Analysis, Inc. • Arlington (VA)

On-site
USD 120,000 - 180,000
Information System Security Officer
Information System Security Officer

ANALYGENCE • Washington

On-site
USD 140,000 - 190,000