Security Control Assessor

Jobs via Dice

Washington (District of Columbia)

On-site

USD 69,923 - 109,975

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Generous salary
Insurance (medical, dental, etc.)
Paid leave
401k plan

Job summary

A leading company in Technical and Program Management Services is seeking a Security Control Assessor to evaluate IT security controls for government clients. The role involves conducting comprehensive assessments, providing expert security advice, and creating Security Assessment Reports to enhance security measures across client systems. Candidates should possess a Bachelor's degree and have a strong grasp of IT security principles and federal regulations.

Qualifications

  • Basic understanding of TCP/IP stack and common networking protocols.
  • Mastery of federal IT security laws such as FISMA and NIST guidelines.
  • Knowledge of Risk Management Framework (RMF) and related audits.

Responsibilities

  • Conduct independent comprehensive assessments of IT security controls.
  • Plan, develop, and conduct security testing and risk assessments.
  • Create Security Assessment Reports for system stakeholders.

Skills

Networking technologies
Windows operating systems
Linux/Unix-based operating systems
IT security principles
Excellent communication skills

Education

Bachelor's Degree in Information Technology

Tools

Active Directory
VMware vSphere

Job description

1 week ago Be among the first 25 applicants

Description:

Business Operational Concepts (BOC) is a recognized leader in providing Technical and Program Management Services, Information Technology, and Support.

BOC has enabled their Government and Commercial clients to achieve their organizational initiatives through the application of high quality, innovative, and cost-effective professional services and solutions. We provide a positive working environment, with opportunities for advancement in our growing Federal sector workforce.

We offer an excellent compensation package which includes a generous salary, insurance (medical, dental, etc.), paid leave, 401k plan and more. We are committed to the diversity we bring to the marketplace and believe customer satisfaction comes first.

JOB SUMMARY:

Business Operational Concepts (BOC) is currently seeking a Security Control Assessor to work with our government client. The selected candidate will conduct independent comprehensive assessments of the management, operational, and technical security controls and control enhancements employed within or inherited by the clients IT system to determine the overall effectiveness of the controls (as defined in NIST SP 800-37 and NIST SP 800-53a).

DUTIES AND RESPONSIBILITIES:

  • Provide expert security advice and recommendations to manage identified risks.
  • Plan, develop, and conduct security testing of management, operational, and technical controls. Analyze and assess results based on risk to clients information systems.
  • Participate in internal and external reviews, inspections, and audits to ensure compliance with federal laws and clients security policy.
  • Conduct risk assessments to identify and mitigate risk to IT systems, facilities, and critical assets.
  • Evaluate and assess network security configurations and recommend corrective actions to mitigate identified deficiencies.
  • Create Security Assessment Reports and deliver test results to system stakeholders. Provide expert security advice and recommendations to manage identified risks.

Requirements:

QUALIFICATIONS:

Required (Minimum) Qualifications Education, Certification, Experience, And Skills

  • Basic level understanding of basic computer and networking technologies
  • TCP/IP stack
  • Windows operating systems
  • Linux/Unix-based operating systems
  • Networking technologies (routing, switching, VLANs, subnets, firewalls)
  • Common networking protocols SSH, SMB, SMTP, FTP/SFTP, HTTP/HTTPS, DNS, etc.
  • Common enterprise technologies Active Directory, Group Policy, VMware vSphere
  • Moderate level understanding of IT security principles, technologies, best practices, and NIST guidance
  • Logical Access Control
  • PKI and other encryption methods
  • DISA STIG Security configuration baselines
  • Auditing
  • Vulnerability discovery and management
  • NIST SP 800-53 rev. 4 control
  • Excellent communications skills. Ability to communicate with senior management and federal client staff both technical and non-technical in a clear and concise manner using proper spelling, punctuation and grammar.
  • Mastery of federal IT security laws such as the Federal Information Security Management Act (FISMA), policies, regulations, requirements, Executive Orders and Presidential Decision Directives such as EO 13556, HSPD12, OMB Memos M-06-16, and M-07-16; NIST 800 series, the federal IT security and incident reporting hierarchy.
  • Knowledge and experience in categorizing systems per current NIST guidelines, defining system boundaries and identifying minimum and supplementary security controls to protect sensitive and critical IT systems.
  • Knowledge and experience with the Risk Management Framework (RMF), Assessment and Authorization (A&A), SSP Development, and conducting audits of security controls.
  • Knowledge and experience protecting the confidentiality, integrity and available of sensitive and critical information systems
  • Knowledge and experience performing network security vulnerability assessments.
  • Knowledge and experience with all areas of the System Development Lifecycle (SDLC) of IT systems.

Preferred Qualifications Education, Certification, Experience, Skills, Knowledge, And Abilities

  • Minimum of 2+ years of experience as a cyber security assessor and/or ISSO
  • Bachelors Degree or higher in information technology or information security-related field
  • Interest in security/hacking culture. Ability to think like an attacker
  • Some proficiency in Cloud Computing Offerings (Cloud Systems, SaaS, IaaS, PaaS).
  • Familiarity with Cloud Service Providers (CSPs) and basic cloud deployment models
  • Certifications of interest:
  • Security+
  • Certified Authorization Professional (CAP)
  • Certified Information Systems Security Professional (CISSP)
  • Certified Information Systems Auditor (CISA)
  • Microsoft Certified Solutions Associate (MCSA)
  • Red Hat Certified System Administrator (RHCSA)
  • Certified Ethical Hacker (CEH)

Seniority level
  • Seniority level
    Entry level
Employment type
  • Employment type
    Full-time
Job function
  • Job function
    Other, Information Technology, and Management
  • Industries
    Software Development

Referrals increase your chances of interviewing at Jobs via Dice by 2x

Get notified about new Security Coordinator jobs in Washington, DC.

Washington, DC $69,923.00-$109,975.00 2 days ago

District of Columbia, United States 1 month ago

District of Columbia, United States 2 months ago

District of Columbia, United States 1 week ago

Personnel Security Specialist – Entry Level (TS/SSBI)

Washington, DC $50,000.00-$100,000.00 3 months ago

Personnel Security Specialist – Mid-Level (TS/SSBI)
Physical and Personnel Security Specialist
Cybersecurity Coordinator (management analyst)
Corporate Security Manager - Washington DC Metro Lead

Arlington, VA $94,400.00-$224,600.00 1 week ago

District of Columbia, United States 3 months ago

Security Supervisor - The Willard InterContinental Washington
Security Professionals – Join the CruxShield Network

Washington, DC $85,000.00-$110,000.00 1 day ago

Professional Security Officer DC (60715)
Security & Event Safety Operations Manager

Washington, DC $75,000.00-$80,000.00 1 month ago

We’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Physical Security Specialist
Physical Security Specialist

Acro Service Corp • Washington

On-site
USD <1,000
Security Management Specialist
Security Management Specialist

Modern Technology Solutions, Inc. (MTSI) • Washington

On-site
USD 45,000 - 101,000
SOC Security Analyst L3
SOC Security Analyst L3

BlueVoyant • College Park (MD)

On-site
USD 100,000 - 130,000
Medical insurance
Vision insurance
401(k)
+1
Cybersecurity Analyst
Cybersecurity Analyst

B/CORE • McLean (VA)

On-site
USD 70,000 - 85,000
Security Operations Coordinator
Security Operations Coordinator

Concentric • United States

Remote
USD 72,000 - 80,000
100% paid medical, dental, and vision premiums for employees
401k with employer match
Paid leave and holidays
+1
Security Service Edge Sales Specialist, DoD & FSI
Security Service Edge Sales Specialist, DoD & FSI

Palo Alto Networks • Great Falls Crossing (VA)

On-site
USD 256,000 - 352,000
FLEXBenefits wellbeing spending account
Mental and financial health resources
Personalized learning opportunities
Security Engineer With Splunk Experience - Remote
Security Engineer With Splunk Experience - Remote

The Dignify Solutions, LLC • Herndon (VA)

Remote
USD 120,000 - 180,000
Workday Security Analyst
Workday Security Analyst

Ascendion • McLean (VA)

On-site
USD 110,000 - 120,000
Medical insurance
Dental insurance
Vision insurance
+3
Security Analyst III
Security Analyst III

First Division Consulting, Inc • Edgewood (MD)

On-site
USD 95,000 - 125,000
Medical insurance
Dental insurance
Vision insurance
+1
SOC Analyst - Top Secret Clearance
SOC Analyst - Top Secret Clearance

Zachary Piper Solutions • Washington

On-site
USD 140,000 - 175,000
Comprehensive Benefits
401K
PTO
+1