Security Control Assessor II

HRUCKUS

Colorado Springs (CO)

On-site

USD 110,000 - 150,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

HRUCKUS is seeking an experienced Security Control Assessor II to conduct comprehensive assessments of management, operational, and technical security controls within Information Systems and ensure compliance across Collateral, Sensitive Compartmented Information, and Special Access Program activities.

The candidate will evaluate authorization packages, assess threats, initiate POA&Ms, and advise stakeholders based on RMF/JSIG guidelines.

Qualifications

  • 7 to 9 years related experience.
  • Active TS/SCI clearance.
  • Minimum of four (4) years of experience in SAP, SCI or Collateral Information Systems Security and the implementation of regulations identified in the description of duties.
  • Prior performance in the role of ISSO, ISSM, or SCA.
  • Must meet position and certification requirements outlined in DoD Directive 8570.01-M for Information Assurance Manager Level II.
  • Must be able to regularly lift 50lbs.
  • Eligibility for access to Special Access Program Information.
  • Willingness to submit to a Counterintelligence polygraph.

Responsibilities

  • Perform oversight of the development, implementation and evaluation of IS security program policy; special emphasis placed upon integration of existing SAP network infrastructure.
  • Perform assessment of ISs, based upon the RMF methodology in accordance with the JSIG.
  • Advise the ISO, IDO, PSO, and the DAO AO on assessment and authorization issues.
  • Evaluate Authorization packages and make recommendations to the AO/DAO for authorization.
  • Evaluate IS threats and vulnerabilities to determine additional safeguards required.
  • Advise Government on impact levels for Confidentiality, Integrity, and Availability.
  • Prepare Security Assessment Report (SAR) for the Authorization boundary.
  • Initiate POA&Ms with weaknesses for each boundary assessed.
  • Evaluate security assessment documentation and provide written recommendations for security authorization.
  • Discuss recommendation for authorization and submit the security authorization package to the AO/DAO.
  • Assess changes to Authorization boundaries operating environment and mission needs to determine continuation to operate.
  • Review and concur with sanitization/clearing procedures.
  • Assist Government compliance inspections.
  • Assist Government with cybersecurity incidents and ensure corrective actions.
  • Ensure SDLC phases are addressed.
  • Evaluate hardware/software security impact on boundaries.
  • Evaluate effectiveness of Continuous Monitoring Plans.
  • Represent the customer on inspection teams

Skills

Active TS/SCI clearance
RMF/JSIG knowledge
Security assessment experience
Lifting 50 lbs

Education

Bachelor’s degree

Job description

Veteran Firm Seeking a Security Control Assessor II for a Full Time Assignment in Peterson SFB, CO

My name is Stephen Hrutka. I lead a Veteran-Owned management consulting firm in Washington, DC. We specialize in Technical and Cleared Recruiting for the Department of Defense (DoD), the Intelligence Community (IC), and other advanced defense agencies.

At HRUCKUS, we support fellow Veteran-Owned businesses by helping them recruit for positions across organizations such as the VA, SBA, HHS, DARPA, and other leading-edge R&D-focused defense agencies.

We seek to fill a Security Control Assessor II role in Peterson SFB, CO

The ideal candidate is a Colorado Springs resident with an active TS clearance with SCI eligibility, 7 to 9 years of related experience, 4 years of experience in SAP or SCI Information Systems Security, and DoD 8570.01-M IAM Level II certification.

If you’re interested, I'll gladly provide more details about the role and further discuss your qualifications.

Thanks,

www.hruckus.com

Executive Summary

HRUCKUS is looking for an experienced Security Control Assessor II to conduct comprehensive assessments of management, operational, and technical security controls within Information Systems and ensure compliance across Collateral, Sensitive Compartmented Information, and Special Access Program activities.

Position Description

The Security Control Assessor II evaluates Authorization packages, assesses Information System threats and vulnerabilities, initiates Plans of Action and Milestones, and advises stakeholders on Authorization issues based on the Risk Management Framework.

Position Responsibilities
  • Perform oversight of the development, implementation and evaluation of IS security program policy; special emphasis placed upon integration of existing SAP network infrastructure
  • Perform assessment of ISs, based upon the Risk Management Framework (RMF) methodology in accordance with the Joint Special Access Program (SAP) Implementation Guide (JSIG)
  • Advise the Information System Owner (ISO), Information Data Owner (IDO), Program Security Officer (PSO), and the Delegated and or Authorizing Official (DAO AO) on any assessment and authorization issues
  • Evaluate Authorization packages and make recommendation to the AO and or DAO for authorization
  • Evaluate IS threats and vulnerabilities to determine whether additional safeguards are required
  • Advise the Government concerning the impact levels for Confidentiality, Integrity, and Availability for the information on a system
  • Ensure security assessments are completed and results documented and prepare the Security Assessment Report (SAR) for the Authorization boundary
  • Initiate a Plan of Action and Milestones (POA and M) with identified weaknesses for each Authorization Boundaries assessed, based on findings and recommendations from the SAR
  • Evaluate security assessment documentation and provide written recommendations for security authorization to the Government
  • Discuss recommendation for authorization and submit the security authorization package to the AO DAO
  • Assess proposed changes to Authorization boundaries operating environment and mission needs to determine the continuation to operate.
  • Review and concur with all sanitization and clearing procedures in accordance with Government guidance and or policy
  • Assist the Government compliance inspections
  • Assist the Government with security incidents that relate to cybersecurity and ensure that the proper and corrective measures have been taken
  • Ensure organization are addressing and conducting all phases of the system development life cycle (SDLC)
  • Evaluate Hardware and Software to determine security impact that it might have on Authorization boundaries
  • Evaluate the effectiveness and implementation of Continuous Monitoring Plans
  • Represent the customer on inspection teams
Required Qualifications
  • 7 to 9 years related experience
  • Active TS/SCI clearance
  • Minimum of four (4) years of experience in SAP, SCI or Collateral Information Systems (IS) Security and the implementation of regulations identified in the description of duties
  • Bachelor’s degree in related discipline or equivalent experience (4 years)
  • Prior performance in the role of ISSO, ISSM, or SCA
  • Must meet position and certification requirements outlined in DoD Directive 8570.01-M for Information Assurance Manager Level II
  • Must be able to regularly lift 50lbs
  • Eligibility for access to Special Access Program Information
  • Willingness to submit to a Counterintelligence polygraph
Details

Job Title: Security Control Assessor II

Location: Peterson SFB, CO

Clearance Requirement: TS with SCI Eligibility

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Control Assessor II (SCA II) (TS, w/ SCI Eligibility) -
Security Control Assessor II (SCA II) (TS, w/ SCI Eligibility) -

Redtracetech • Colorado Springs (CO)

On-site
USD 110,000 - 130,000
401(k) plan
Annual performance bonus
Tuition reimbursement
+1
Security Control Assessor II (SCA II) (TS, w/ SCI Eligibility) -
Security Control Assessor II (SCA II) (TS, w/ SCI Eligibility) -

RedTrace Technologies • Colorado Springs (CO)

On-site
USD 90,000 - 130,000
Competitive salary
401(k) plan
Annual performance bonus
+5
Program Security Representative II
Program Security Representative II

HRUCKUS • Colorado Springs (CO)

On-site
USD 93,000 - 110,000
Security Control Assessor II
Security Control Assessor II

General Dynamics - IT • Ogden (UT)

On-site
USD 120,000 - 170,000
Security Control Assessor II
Security Control Assessor II

General Dynamics - IT • Albuquerque (NM)

On-site
USD 120,000 - 150,000
Security Control Assessor II
Security Control Assessor II

Global Resource solution • Albuquerque (NM)

On-site
USD 90,000 - 120,000
Security Control Assessor (SCA) II
Security Control Assessor (SCA) II

Modern Technology Solutions, Inc. (MTSI) • Albuquerque (NM)

On-site
USD 90,000 - 140,000
Security Control Assessor (SCA) II
Security Control Assessor (SCA) II

General Dynamics - IT • Washington

On-site
USD 120,000 - 170,000
401K with company match
Comprehensive health and wellness
Internal mobility and career growth
+3
Security Control Assessor II
Security Control Assessor II

GRS, Inc. • Albuquerque (NM)

On-site
USD <1,000
Security Control Assessor (SCA), Level II
Security Control Assessor (SCA), Level II

TAC Integrated Solutions • Albuquerque (NM)

On-site
USD 95,000 - 125,000