Security Control Assessor, Mid

Quantum Sky

Washington (District of Columbia)

On-site

USD 95,000 - 109,000

Full time

7 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Health/Dental/Vision
401(k) match
Paid Time Off
Parental leave

Job summary

Quantum Sky is seeking a Security Control Assessor (Mid) to support a federal client in Washington, DC. You will evaluate information systems for FISMA/NIST compliance, documenting evidence and communicating risk clearly.

The role involves RMF steps 4–6, producing assessment deliverables and risk analyses. The ideal candidate will have strong analytical skills, attention to detail, and excellent writing and interpersonal abilities to collaborate with system owners and stakeholders.

Qualifications

  • Bachelor's degree plus 4+ years in cybersecurity/GRC within RMF lifecycle.
  • High school diploma with 8 years of experience in a functional area may substitute for a degree.
  • Certifications: CAP/CRISC/ISO 27001/CISM equate to years of experience.
  • Knowledge of FISMA, RMF, SA&A processes and NIST SP 800-53 Rev. 5/800-137.
  • Experience assessing controls, communicating risk, and recommending corrective actions.
  • Strong writing and interpersonal skills for stakeholder collaboration.

Responsibilities

  • Support RMF steps 4–6: assess, authorize, monitor controls.
  • Produce high-quality, subject-system-specific SARs and assessment deliverables.
  • Develop and execute security and privacy assessment plans.
  • Create and maintain test cases for assessment testing.
  • Perform control-level security testing across systems and components.
  • Review vulnerability reports and determine residual risk vs false positives.
  • Document findings with concise, actionable recommendations.
  • Conduct risk analyses per NIST SP 800-30 and client policies and present summaries.

Skills

RMF lifecycle
NIST RMF
FISMA knowledge
Risk analysis
Technical writing
Communication
Collaborate with teams

Education

Bachelor's degree
High school diploma with 8 years experience

Tools

ServiceNow
CSAM

Job description

Description

Quantum Sky is searching for a Security Control Assessor (SCA), Mid to support a federal customer in Washington, DC. The successful candidate will evaluate information systems to ensure compliance with FISMA, NIST, and agency security requirements by conducting thorough security control assessments, documenting objective evidence, and communicating risk in a clear and actionable manner.

The ideal candidate is a detail-oriented cybersecurity professional with exceptional analytical, organizational, and interpersonal skills who can collaborate effectively with technical teams, system owners, and stakeholders while maintaining the highest standards of quality, accuracy, and professionalism throughout the assessment process.

Responsibilities:

  • Support RMF steps 4 –assess, 5 –authorize, step 6 –monitor controls: conducting system security assessments, supporting the system security authorization to operate process, and conducting annual assessments, respectively
  • Produce quality security assessment deliverables, ensuring the content of each deliverable is specific to the subject systems, complete, and accurate
  • Develop and execute a security and privacy assessment plan for each security assessment project
  • Create and maintain test cases for security assessment testing
  • Perform security testing at the control-requirement level for each unique component of each system (e.g., application, web application server, financial systems, database server/instance, operating systems, specialized appliances, network and infrastructure devices, and end-user devices (e.g., mobile phones, laptops, etc.)
  • Conduct technical content review and analysis of technical reports from security vulnerability scan, penetration test, and configuration compliance scan tools with respect to the subject system’s context and environment in order to analyze the findings accurately and completely
  • Analyze security tool reports and determine residual risk or false positives from technical reports and artifacts before assigning findings
  • Document and provide findings and recommendations that are concise, system-specific, and actionable
  • Perform and document client and system-specific risk analysis for each finding identified during each assessment in accordance with NIST SP 800-30, the client’s risk appetite, and the client’s security policies. The results of this risk analysis shall be documented in the Security Assessment Report (SAR) for each assessed FISMA system, and a summary of the assessment results and risk shall be provided in the respective Assessment/Authorization Briefing.
Qualifications

Required:

  • Bachelor's degree and at least four (4) years of experience supporting cybersecurity, information assurance, or Governance, Risk, and Compliance (GRC) activities within the NIST Risk Management Framework (RMF) lifecycle.
    • High school diploma with 8 years of experience in Functional Responsibility area may be substituted for a Bachelor’s Degree
    • PMP, ISO 27001, or CISM certifications equate to 3 years of experience in Functional Responsibility each
    • ITIL, CISSP, or other relevant IT management certifications equate to 2 years of general experience each
  • Thorough knowledge of the Federal Information Security Modernization Act (FISMA), NIST Risk Management Framework (RMF), and Security Assessment and Authorization (SA&A) processes.
  • Demonstrated knowledge of NIST SP 800-53 Rev. 5, NIST SP 800-53A Rev. 5, and NIST SP 800-137.
  • Experience assessing security controls and evaluating the effectiveness of technical, operational, and management safeguards.
  • Ability to assess the severity of identified weaknesses and deficiencies, communicate risk effectively, and recommend appropriate corrective actions.
  • Strong critical thinking, analytical, and problem-solving skills with exceptional attention to detail.
  • Ability to balance security requirements with operational and mission objectives.
  • Excellent technical writing skills, including experience developing assessment reports and documenting security findings.
  • Strong verbal communication and interpersonal skills with the ability to collaborate effectively with technical teams, system owners, and stakeholders.

Desired:

  • Certified Authorization Professional (CAP)
  • Certified in Risk and Information Systems Control (CRISC)
  • Experience with GRC Tools such as ServiceNow, CSAM, etc.

Clearance:

  • US Citizen with Public Trust eligibility required

Location:

  • On-site in DC, minimal remote flexibility
About Quantum Sky

Compensation:

  • Compensation is unique to each candidate and relative to the skills and experience they bring to the position. Salary for this role is between $95,000-$109,000. This does not guarantee a specific salary as compensation is based upon multiple factors such as education, experience, certifications, and other requirements, and may fall outside of the above-stated range.

Benefits:

  • Highlights of our benefits include Health/Dental/Vision, 401(k) match, Paid Time Off, STD/LTD/Life Insurance, Referral Bonuses, professional development reimbursement, and parental leave.

The world the mission operates in is going post-quantum, contested, and machine-speed. Quantum Sky engineers the advantage across cyber, networks, software, and quantum because the mission demands dominance, not parity. We don't follow the map. We draw it.

At Quantum Sky, we believe that success starts with our people. We foster a collaborative, innovative, and mission-driven environment where every team member plays a critical role in shaping the future of technology. Are you ready to join #TeamQuantumSky?

Quantum Sky Engineering LLC is an Equal Opportunity Employer; all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, [sexual orientation, gender identity,] national origin, disability, status as a protected veteran, or any characteristic protected by applicable law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Systems Security Officer (ISSO), Mid
Information Systems Security Officer (ISSO), Mid

Quantum Sky • Washington

On-site
USD 105,000 - 125,000
Health/Dental/Vision
401(k) match
Paid Time Off
+1
Senior Audit Lead
Senior Audit Lead

Quantum Sky • Washington

Hybrid
USD 150,000 - 170,000
Health/Dental/Vision
401(k) match
Paid Time Off
+1
Information Systems Security Officer - Washington DC
Information Systems Security Officer - Washington DC

VetJobs • Washington

On-site
USD 105,000 - 125,000
Health/Dental/Vision
401(k) match
Paid Time Off
Cybersecurity / Information Assurance Lead
Cybersecurity / Information Assurance Lead

Quantum Sky • Arlington (VA)

On-site
USD 140,000 - 175,000
Senior Information Security Analyst
Senior Information Security Analyst

Quantum Sky • Oceanside (CA)

On-site
USD 140,000 - 150,000
Health/Dental/Vision
401(k) match
Paid Time Off
+4
Information Security Analyst - SME
Information Security Analyst - SME

Quantum Sky • Quantico Base (VA)

On-site
USD 155,000 - 165,000
Health/Dental/Vision
401(k) match
Paid Time Off
+1
Cybersecurity DevSecOps Engineer
Cybersecurity DevSecOps Engineer

Quantum Sky • United States

Remote
USD 130,000 - 160,000
Health/Dental/Vision
401(k) match
Paid Time Off
+1
Cybersecurity Analyst - Journeyman
Cybersecurity Analyst - Journeyman

Quantum Sky • Colorado Springs (CO)

On-site
USD 80,000 - 95,000
Health/Dental/Vision
401(k) match
Flexible Time Off
+2
Information Security Analyst - SME
Information Security Analyst - SME

Quantum Sky • Jacksonville (NC)

On-site
USD 155,000 - 165,000
Health/Dental/Vision
401(k) match
Paid Time Off
+4
Information Security Analyst - SME
Information Security Analyst - SME

Quantum Sky • Marine Corps Base Camp Lejeune (NC)

On-site
USD 155,000 - 165,000
Health/Dental/Vision
401(k) match
Paid Time Off
+4