Security Control Assessor Representative (SCA-R)

Age-Solutions

Arlington (VA)

Hybrid

USD 100,000 - 120,000

Full time

26 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

26 Days Paid Leave
Performance Bonuses
401(k) with Match
Health Benefits

Job summary

AGE Solutions is seeking a Security Control Assessor Representative (SCA-R) to provide RMF, A&A support for DoD information systems. You will work with ISSMs, PMOs, system owners, and stakeholders to assess controls, validate configurations, and compile authorization packages.

The role involves performing risk analyses, reviewing STIGs/SRGs, maintaining RMF records, and supporting government reviews. On-site and hybrid work arrangements vary by location, with travel up to 10%.

Qualifications

  • Bachelor's degree in IT or related field.
  • Eight+ years in cybersecurity or network security.
  • 5+ years in C&A/A&A activities.
  • Active DoD Secret clearance with SCI eligibility; Top Secret preferred.
  • Current DoD 8570 IAM Level III certification.
  • Experience with RMF tools such as eMASS, STIG Viewer, Nessus.

Responsibilities

  • Perform cybersecurity assessment and RMF/A&A activities.
  • Coordinate with ISSMs, PMOs, system owners, and stakeholders.
  • Prepare authorization packages and documentation.
  • Lead on-site assessment visits and reporting.
  • Review STIGs/SRGs and NIST controls.

Skills

SCA-R experience
RMF proficiency
NIST SP 800-37
C&A/A&A
DoD clearance
Stakeholder engagement

Education

Bachelor's degree

Tools

eMASS
STIG Viewer
Nessus
ACAS
HBSS/ESS

Job description

Security Control Assessor Representative (SCA-R)
About Us

AGE Solutions is a premier technology and professional services company, providing in-depth consulting, advanced technology solutions, and essential services throughout the U.S. government, defense, and intelligence sectors. Prioritizing innovation and client-focused solutions, we assist major agencies in addressing intricate issues and ensuring a more secure future.

The Security Control Assessor Representative (SCA-R) provides cybersecurity assessment, Risk Management Framework (RMF), and Assessment and Authorization (A&A) support for Department of Defense (DoD) information systems. The SCA-R works with Information System Security Managers (ISSMs), Program Management Offices (PMOs), system owners, technical teams, and Government cybersecurity stakeholders to assess security controls, identify cybersecurity risks, validate system compliance, and support authorization decisions throughout the system lifecycle.

The SCA-R performs independent technical and risk-based assessments using Government-approved processes, databases, and cybersecurity tools and develops complete, accurate, and defensible authorization documentation for Government and Authorizing Official (AO) review.

Responsibilities Include:

  • Use Government-assigned tools and databases to perform weekly updates, maintain system records, track assigned actions, and complete cybersecurity assessment and authorization activities.
  • Coordinate with ISSMs, PMOs, system owners, and technical stakeholders to understand system architectures, security requirements, authorization boundaries, configurations, and system changes.
  • Conduct risk analysis, security control assessment, and authorization activities across applicable RMF steps using approved RE5 tools and processes.
  • Verify system authorization boundaries and validate system security categorizations in accordance with FIPS 199 and applicable DoD requirements.
  • Identify applicable data classifications and conduct system-level cybersecurity risk assessments.
  • Assess threats, vulnerabilities, control deficiencies, and residual risks and compile findings into complete and accurate authorization packages.
  • Evaluate proposed and implemented system changes, determine their potential security and authorization impacts, and provide appropriate status and risk information to the Authorizing Official (AO).
  • Evaluate authorization and change requests, including web-filtering requests, firewall exceptions, ports and protocols, cybersecurity risks, STIG/SRG compliance, and on-site security requirements.
  • Review and validate compliance with applicable Security Technical Implementation Guides (STIGs), Security Requirements Guides (SRGs), security controls, and cybersecurity requirements.
  • Review, validate, and track Plans of Action and Milestones (POA&Ms) and associated cybersecurity deficiencies through resolution.
  • Lead and support on-site assessment visits, including planning, technical assessments, stakeholder coordination, entrance/exit briefings, documentation, findings development, and reporting.
  • Maintain access to and proficiency with required Government cybersecurity databases, vulnerability assessment platforms, endpoint security solutions, scanning tools, and RMF management systems.
  • Attend required Government meetings, technical exchanges, and training to remain current with policies, procedures, tools, and RMF process changes.
  • Complete required assessor, vulnerability scanning, endpoint security, and RMF process training.
  • Support assigned systems throughout their lifecycle in accordance with FISMA, DoD RMF, and applicable cybersecurity requirements.
  • Prepare and submit weekly activity reports documenting completed and ongoing activities, tracking identifiers, assessment status, significant findings, risks, issues, and key updates.

Required Skills, Qualifications and Experience:

  • Education:
    • Bachelor's degree required.
      • A bachelor's in information technology, Cybersecurity, Computer Science, Information Systems, or related technical field is preferred.
  • Overall Experience:
    • Minimum of eight (8) years of experience in a cybersecurity or network security position.
  • A&A Experience:
    • Minimum of five (5) years of experience performing Certification and Accreditation (C&A) and/or Assessment and Authorization (A&A) activities.
  • Security Clearance:
    • Must have a minimum of a current DoD Secret Clearance with the ability to obtain a DoD Top Secret clearance with SCI eligibility. A current DoD Top Secret clearance with SCI eligibility strongly preferred.
  • Certification:
    • Current DoD 8570 IAM Level III certification.
  • Skills:
    • Demonstrated experience serving as a Security Control Assessor Representative (SCA-R) and performing cybersecurity risk analysis and security control validation.
    • Advanced understanding and practical application of the Risk Management Framework (RMF), including NIST SP 800-37, NIST SP 800-53, and CNSSI 1253.
    • Demonstrated experience applying and evaluating Security Technical Implementation Guides (STIGs), Security Requirements Guides (SRGs), Plans of Action and Milestones (POA&Ms), cybersecurity security controls, and industry/DoD cybersecurity best practices.
    • Demonstrated hands-on experience with relevant cybersecurity and RMF tools, including one or more of the following: eMASS, STIG Viewer, Nessus, ACAS, SCAP, and HBSS/Endpoint Security Solutions (ESS).
    • Advanced understanding of multiple cybersecurity technology areas and domains, including network technologies and security, mobility, Windows, UNIX/Linux, cloud environments, cloud-native tools and services, HBSS/Endpoint Security Solutions (ESS), databases, and applications.
    • Strong customer service and stakeholder engagement skills, with the ability to effectively coordinate with Government customers, ISSMs, PMOs, technical teams, system owners, and cybersecurity leadership.
    • Ability to analyze complex technical and cybersecurity information and clearly communicate security risks, vulnerabilities, assessment findings, residual risk, and recommended corrective actions through written documentation and technical briefings.
  • Location and Schedule: This role may be based at one of the following customer locations, with onsite requirements varying by location:
    • Chambersburg, PA: Fully onsite, 5 days per week.
    • Arlington, VA or Fort Meade, MD: Hybrid schedule, 4 days onsite per week with 1 telework day.
  • Travel Requirements:
    • Must be willing and able to support occasional domestic (CONUS) and international (OCONUS) travel, approximately 10% of the time.

The projected salary range for this position is $100,000+ annually. Final compensation will be determined based on factors including years of relevant experience, active security clearance level, certifications, technical skillset, contract requirements, and overall qualifications.

At AGE Solutions, we reward performance, invest in growth, and share success. Our benefits support the whole person, professionally, financially, and personally.

  • 26 Days Paid Leave: Includes vacation, sick, personal time, and holidays. You choose how to use it.
  • Performance Bonuses: Performance bonuses are awarded based on individual contributions and company-wide results, aligning recognition with impact.
  • 401(k) with Match: We match 3% of your contributions with immediate vesting.
  • Financial Protection: Company-paid life insurance up to $300K and options for additional coverage for you and your dependents.
  • Health Benefits: Multiple medical plans, dental, vision, FSA and HSA options to fit your needs.
  • Parental Leave: 15 days of fully paid leave for new parents, because family matters.
  • Military Differential Pay: We bridge the gap for employees on active duty, so they don’t take a financial hit while serving.
  • Professional Growth: Paid training and certifications, tuition reimbursement, and the tools and tech to get the job done right.
  • Shared Success: In the event of a company sale, our CEO has committed to returning 80% of net proceeds to employees. This ensures our team shares in the long term value they help create.

At AGE, you’ll do work that matters, supported by a company that delivers for its people.

Create a Job Alert

Interested in building your career at AGE Solutions? Get future opportunities sent straight to your email.

Accepted file types: pdf, doc, docx, txt, rtf

Enter manually

Accepted file types: pdf, doc, docx, txt, rtf

LinkedIn Profile

Please select your work authorization status from the list below. * Select...

Please select your current security clearance status from the list below. * Select...

What is your desired salary? *

Are you open to relocating for this position? * Select...

Are you willing to travel for this position? *

0%

10%

20%

30%

50%

75%

100%

Have you previously worked directly with AGE Solutions, or do you know anyone currently employed or contracted by AGE? * Select...

If you answered "Yes" to the previous question, please list their name(s) and briefly describe your relationship and/or prior engagement with AGE. If you answered "No" to the previous question, please type "N/A". *

Please select your current CompTIA certifications from the list below.If you do not currently have any CompTIA certifications, please select "None". * Select...

Please select your current ISC2 certifications from the list below. If you do not currently have any ISC2 certifications, please select "None". * Select...

Please select your current ISACA certifications from the list below. If you do not currently have any ISACA certifications, please select "None". * Select...

Please select your current EC-Council certifications from the list below. If you do not currently have any EC-Council certifications, please select "None". * Select...

Please select your current SANS Institute certifications from the list below. If you do not currently have any SANS Institute certifications, please select "None". * Select...

Please select your current OffSec certifications from the list below. If you do not currently have any OffSec certifications, please select "None". * Select...

Please select your current Project Management Institute (PMI) certifications from the list below. If you do not currently have any PMI certifications, please select "None". * Select...

Please select your current Cisco certifications from the list below. If you do not currently have any Cisco certifications, please select "None". * Select...

Please select your current Juniper Networks certifications from the list below. If you do not currently have any Juniper Networks certifications, please select "None". * Select...

Please select your current AWS certifications from the list below. If you do not currently have any AWS certifications, please select "None". * Select...

Please select your current Microsoft certifications from the list below. If you do not currently have any Microsoft certifications, please select "None". * Select...

Please select your current VMware certifications from the list below. If you do not currently have any VMware certifications, please select "None". * Select...

Please select your current Google Cloud certifications from the list below. If you do not currently have any Google Cloud certifications, please select "None". * Select...

Please select your current BICSI certifications from the list below. If you do not currently have any BICSI certifications, please select "None". * Select...

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey.Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiringprocess or thereafter. Any information that you do provide will be recorded and maintained in aconfidential file.

As set forth in AGE Solutions’s Equal Employment Opportunity policy,we do not discriminate on the basis of any protected group status under any applicable law.

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection.As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measurethe effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categoriesis as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Control Assessor Representative (SCA-R)
Security Control Assessor Representative (SCA-R)

AGE Solutions • Arlington (VA), Chambersburg, Fort Meade (MD)

Hybrid
USD 100,000 - 140,000
26 Days Paid Leave
Performance Bonuses
401(k) with Match
+2
Security Control Assessor, Mid Fort Meade, MD
Security Control Assessor, Mid Fort Meade, MD

AGE • Fort Meade (MD), Northern (KY)

Hybrid
USD 63,000 - 77,000
Security Assistant
Security Assistant

Feditc, Llc. • Fort Belvoir (VA), Northern (KY)

Hybrid
USD 42,000 - 64,000
Security Architect, Contract
Security Architect, Contract

66degrees • Chicago (IL)

On-site
USD 83,000 - 124,000
Cloud SCA-R, Mid New Ft. Meade, MD
Cloud SCA-R, Mid New Ft. Meade, MD

AGE • Maryland

Hybrid
USD 90,000 - 120,000
26 Days Paid Leave
Performance Bonuses
401(k) with Match
+6
Cybersecurity Systems Analyst, Intermediate
Cybersecurity Systems Analyst, Intermediate

Feditc, Llc. • Tampa (FL)

Hybrid
USD 90,000 - 140,000
Cybersecurity Threat Hunter
Cybersecurity Threat Hunter

AGE Solutions • Columbus (OH)

On-site
USD 99,000 - 121,000
26 Days Paid Leave
Performance Bonuses
401(k) with Match
+1
Sr. Network/Systems Engineer New Remote, US
Sr. Network/Systems Engineer New Remote, US

AGE • Northern (KY)

Remote
USD 135,000 - 180,000
26 Days Paid Leave
Performance Bonuses
401(k) with Match
+5
Cybersecurity Incident Response & Threat Detection Analyst
Cybersecurity Incident Response & Threat Detection Analyst

AGE Solutions • Columbus (OH)

On-site
USD 110,000 - 140,000
26 Days Paid Leave
Performance Bonuses
401(k) with Match
+5
Geospatial Data Engineer (Senior) New Fort Gordon, GA
Geospatial Data Engineer (Senior) New Fort Gordon, GA

Core One Group • Georgia

On-site
USD 100,000 - 140,000