Security Control Assessor - Active TS/SCI

MDAEdge

Colorado Springs (CO)

On-site

USD 120,000 - 170,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

MDAEdge seeks an experienced Information System Security professional for multiple DoD-related locations (Colorado Springs, CO; Arlington, VA; Crystal City, VA). The role focuses on assessing security controls, advising stakeholders, and guiding authorization through RMF and JSIG frameworks.

The candidate will prepare SARs/POA&Ms, ensure SDLC compliance, and support AO/DAO in security authorization while maintaining SAP network integration and TS/SCI eligibility responsibilities.

Qualifications

  • Conduct comprehensive assessments of management, operational, and technical security controls for information systems (IS) using RMF and JSIG.
  • Evaluate IS threats, vulnerabilities, and impacts on Confidentiality, Integrity, and Availability to recommend safeguards and corrective actions.
  • Prepare Security Assessment Reports (SAR), initiate Plans of Action and Milestones (POA&M), and provide written recommendations for security authorization to Authorizing Officials (AO/DAO).
  • Advise Information System Owners (ISO), Information Data Owners (IDO), Program Security Officers (PSO), and officials on assessment, authorization, and compliance issues.
  • Review and evaluate authorization packages, proposed changes to operating environments, hardware/software impacts, and Continuous Monitoring Plans.
  • Ensure compliance with sanitization procedures, assist with inspections, security incidents, and all phases of the system development life cycle (SDLC).
  • Perform oversight of IS security program policy, with emphasis on SAP network infrastructure integration.
  • Represent the organization on inspection teams.

Responsibilities

  • Oversee security assessment activities for DoD-grade information systems.
  • Advise stakeholders on risk, compliance, and authorization requirements.
  • Support the preparation and tracking of SARs and POA&Ms.

Skills

Security controls assessment
RMF & JSIG knowledge
ISSO/ISSM experience
Security compliance awareness
Risk assessment & mitigation

Education

Bachelor's degree or equivalent experience (4+ years)

Tools

RMF
JSIG
POA&M
SAR

Job description

Clearance:
Active TS/SCI eligibility required, plus Special Access Program (SAP) access eligibility and willingness for Counterintelligence polygraph
Industry:
Public Sector/Government (DoD/Air Force support)
Job Location:
  • Colorado Springs, CO
  • Arlington, VA
  • Crystal City, VA
Key Responsibilities:
  • Conduct comprehensive assessments of management, operational, and technical security controls for information systems (IS) using Risk Management Framework (RMF) and Joint SAP Implementation Guide (JSIG).
  • Evaluate IS threats, vulnerabilities, and impacts on Confidentiality, Integrity, and Availability to recommend safeguards and corrective actions.
  • Prepare Security Assessment Reports (SAR), initiate Plans of Action and Milestones (POA&M), and provide written recommendations for security authorization to Authorizing Officials (AO/DAO).
  • Advise Information System Owners (ISO), Information Data Owners (IDO), Program Security Officers (PSO), and officials on assessment, authorization, and compliance issues.
  • Review and evaluate authorization packages, proposed changes to operating environments, hardware/software impacts, and Continuous Monitoring Plans.
  • Ensure compliance with sanitization procedures, assist with inspections, security incidents, and all phases of the system development life cycle (SDLC).
  • Perform oversight of IS security program policy, with emphasis on SAP network infrastructure integration.
  • Represent the organization on inspection teams.
Required Qualifications:
  • Bachelor's degree in a related field or equivalent experience (4+ years).
  • 5-7 years of related experience, including at least 3 years in SAP, SCI, or Collateral IS Security with hands-on implementation of relevant regulations.
  • Prior experience as Information Systems Security Officer (ISSO) and/or Information Systems Security Manager (ISSM).
  • Meet DoD Directive 8570.01-M certification requirements for Information Assurance Technician Level III or Information Assurance Manager Level I within 6 months of hire.
  • Native or bilingual proficiency in English.
  • Eligible for TS/SCI and SAP access.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Controls Assessor
Security Controls Assessor

Modern Technology Solutions, Inc. (MTSI) • Chantilly (VA)

On-site
USD 100,000 - 130,000
Security Control Assessor (SCA) I
Security Control Assessor (SCA) I

The Amatriot Group • El Segundo (CA)

On-site
USD 159,000 - 160,000
Security Control Assessor (SCA) II
Security Control Assessor (SCA) II

Modern Technology Solutions, Inc. (MTSI) • Albuquerque (NM)

On-site
USD 90,000 - 140,000
Security Control Assessor II
Security Control Assessor II

General Dynamics - IT • Ogden (UT)

On-site
USD 120,000 - 170,000
Security Control Assessor II
Security Control Assessor II

General Dynamics - IT • Albuquerque (NM)

On-site
USD 120,000 - 150,000
Security Control Assessor (SCA), Level I
Security Control Assessor (SCA), Level I

TAC Integrated Solutions • Arlington (VA)

On-site
USD 90,000 - 120,000
Security Control Assessor I
Security Control Assessor I

P-11 SECURITY • El Segundo (CA)

On-site
USD 120,000 - 180,000
Security Control Assessor (SCA) II
Security Control Assessor (SCA) II

The Amatriot Group • Albuquerque (NM)

On-site
USD 164,000 - 165,000
Security Controls Assessor (SCA)
Security Controls Assessor (SCA)

Modern Technology Solutions, Inc. (MTSI) • Patterson (OH)

On-site
USD 110,000 - 160,000
Security Control Assessor II (SCA II) (TS, w/ SCI Eligibility) -
Security Control Assessor II (SCA II) (TS, w/ SCI Eligibility) -

RedTrace Technologies • Colorado Springs (CO)

On-site
USD 90,000 - 130,000
Competitive salary
401(k) plan
Annual performance bonus
+5