Veteran Firm Seeking a Security Control Assessor II for a Full Time Assignment in Peterson SFB, CO
My name is Stephen Hrutka. I lead a Veteran-Owned management consulting firm in Washington, DC. We specialize in Technical and Cleared Recruiting for the Department of Defense (DoD), the Intelligence Community (IC), and other advanced defense agencies.
At HRUCKUS, we support fellow Veteran-Owned businesses by helping them recruit for positions across organizations such as the VA, SBA, HHS, DARPA, and other leading-edge R&D-focused defense agencies.
We seek to fill a Security Control Assessor II role in Peterson SFB, CO
The ideal candidate is a Colorado Springs resident with an active TS clearance with SCI eligibility, 7 to 9 years of related experience, 4 years of experience in SAP or SCI Information Systems Security, and DoD 8570.01-M IAM Level II certification.
If you’re interested, I'll gladly provide more details about the role and further discuss your qualifications.
Thanks,
www.hruckus.com
Executive Summary
HRUCKUS is looking for an experienced Security Control Assessor II to conduct comprehensive assessments of management, operational, and technical security controls within Information Systems and ensure compliance across Collateral, Sensitive Compartmented Information, and Special Access Program activities.
Position Description
The Security Control Assessor II evaluates Authorization packages, assesses Information System threats and vulnerabilities, initiates Plans of Action and Milestones, and advises stakeholders on Authorization issues based on the Risk Management Framework.
Position Responsibilities
- Perform oversight of the development, implementation and evaluation of IS security program policy; special emphasis placed upon integration of existing SAP network infrastructure
- Perform assessment of ISs, based upon the Risk Management Framework (RMF) methodology in accordance with the Joint Special Access Program (SAP) Implementation Guide (JSIG)
- Advise the Information System Owner (ISO), Information Data Owner (IDO), Program Security Officer (PSO), and the Delegated and or Authorizing Official (DAO AO) on any assessment and authorization issues
- Evaluate Authorization packages and make recommendation to the AO and or DAO for authorization
- Evaluate IS threats and vulnerabilities to determine whether additional safeguards are required
- Advise the Government concerning the impact levels for Confidentiality, Integrity, and Availability for the information on a system
- Ensure security assessments are completed and results documented and prepare the Security Assessment Report (SAR) for the Authorization boundary
- Initiate a Plan of Action and Milestones (POA and M) with identified weaknesses for each Authorization Boundaries assessed, based on findings and recommendations from the SAR
- Evaluate security assessment documentation and provide written recommendations for security authorization to the Government
- Discuss recommendation for authorization and submit the security authorization package to the AO DAO
- Assess proposed changes to Authorization boundaries operating environment and mission needs to determine the continuation to operate.
- Review and concur with all sanitization and clearing procedures in accordance with Government guidance and or policy
- Assist the Government compliance inspections
- Assist the Government with security incidents that relate to cybersecurity and ensure that the proper and corrective measures have been taken
- Ensure organization are addressing and conducting all phases of the system development life cycle (SDLC)
- Evaluate Hardware and Software to determine security impact that it might have on Authorization boundaries
- Evaluate the effectiveness and implementation of Continuous Monitoring Plans
- Represent the customer on inspection teams
Required Qualifications
- 7 to 9 years related experience
- Active TS/SCI clearance
- Minimum of four (4) years of experience in SAP, SCI or Collateral Information Systems (IS) Security and the implementation of regulations identified in the description of duties
- Bachelor’s degree in related discipline or equivalent experience (4 years)
- Prior performance in the role of ISSO, ISSM, or SCA
- Must meet position and certification requirements outlined in DoD Directive 8570.01-M for Information Assurance Manager Level II
- Must be able to regularly lift 50lbs
- Eligibility for access to Special Access Program Information
- Willingness to submit to a Counterintelligence polygraph
Details
Job Title: Security Control Assessor II
Location: Peterson SFB, CO
Clearance Requirement: TS with SCI Eligibility