Security Control Assessor Representative (SCA-R)

Age Solutions

Arlington (VA)

Hybrid

USD 100,000 - 130,000

Full time

3 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

26 Days Paid Leave
Performance Bonuses
401(k) with Match
Financial Protection
Health Benefits
Parental Leave
Military Differential Pay
Professional Growth
Shared Success

Job summary

AGE Solutions is seeking a Security Control Assessor Representative (SCA-R) to support DoD information systems with RMF, A&A, and risk analysis. The role involves coordinating with ISSMs, PMOs, and stakeholders to validate controls and prepare authorization packages.

The position requires DoD clearance, IAM Level III, and 8+ years in cybersecurity, with hybrid onsite work at Arlington, VA or Fort Meade. Training and growth opportunities are provided.

Qualifications

  • Bachelor's degree required; IT/cybersecurity field preferred.
  • Eight plus years in cybersecurity or network security.
  • Five+ years in C&A and/or A&A activities.
  • Current DoD 8570 IAM Level III certification required.
  • Ability to perform risk analysis and security control validation.

Responsibilities

  • Perform cybersecurity assessment and RMF activities using DoD tools.
  • Coordinate with ISSMs, PMOs, system owners, and stakeholders.
  • Develop authorization documentation for AO review.
  • Lead on-site assessment visits and reporting.

Skills

SCA-R
RMF knowledge
A&A experience
DoD 8570 IAM III
NIST SP 800-37/53
STIG/SRG expertise

Education

Bachelor's degree
Information Technology / Cybersecurity degree

Tools

eMASS
STIG Viewer
Nessus

Job description

About Us

AGE Solutions is a premier technology and professional services company, providing in-depth consulting, advanced technology solutions, and essential services throughout the U.S. government, defense, and intelligence sectors. Prioritizing innovation and client-focused solutions, we assist major agencies in addressing intricate issues and ensuring a more secure future.


The Security Control Assessor Representative (SCA-R) provides cybersecurity assessment, Risk Management Framework (RMF), and Assessment and Authorization (A&A) support for Department of Defense (DoD) information systems. The SCA-R works with Information System Security Managers (ISSMs), Program Management Offices (PMOs), system owners, technical teams, and Government cybersecurity stakeholders to assess security controls, identify cybersecurity risks, validate system compliance, and support authorization decisions throughout the system lifecycle.


The SCA-R performs independent technical and risk-based assessments using Government-approved processes, databases, and cybersecurity tools and develops complete, accurate, and defensible authorization documentation for Government and Authorizing Official (AO) review.


Responsibilities Include:



  • Use Government-assigned tools and databases to perform weekly updates, maintain system records, track assigned actions, and complete cybersecurity assessment and authorization activities.

  • Coordinate with ISSMs, PMOs, system owners, and technical stakeholders to understand system architectures, security requirements, authorization boundaries, configurations, and system changes.

  • Conduct risk analysis, security control assessment, and authorization activities across applicable RMF steps using approved RE5 tools and processes.

  • Verify system authorization boundaries and validate system security categorizations in accordance with FIPS 199 and applicable DoD requirements.

  • Identify applicable data classifications and conduct system-level cybersecurity risk assessments.

  • Assess threats, vulnerabilities, control deficiencies, and residual risks and compile findings into complete and accurate authorization packages.

  • Evaluate proposed and implemented system changes, determine their potential security and authorization impacts, and provide appropriate status and risk information to the Authorizing Official (AO).

  • Evaluate authorization and change requests, including web-filtering requests, firewall exceptions, ports and protocols, cybersecurity risks, STIG/SRG compliance, and on-site security requirements.

  • Review and validate compliance with applicable Security Technical Implementation Guides (STIGs), Security Requirements Guides (SRGs), security controls, and cybersecurity requirements.

  • Review, validate, and track Plans of Action and Milestones (POA&Ms) and associated cybersecurity deficiencies through resolution.

  • Lead and support on-site assessment visits, including planning, technical assessments, stakeholder coordination, entrance/exit briefings, documentation, findings development, and reporting.

  • Maintain access to and proficiency with required Government cybersecurity databases, vulnerability assessment platforms, endpoint security solutions, scanning tools, and RMF management systems.

  • Attend required Government meetings, technical exchanges, and training to remain current with policies, procedures, tools, and RMF process changes.

  • Complete required assessor, vulnerability scanning, endpoint security, and RMF process training.

  • Support assigned systems throughout their lifecycle in accordance with FISMA, DoD RMF, and applicable cybersecurity requirements.

  • Prepare and submit weekly activity reports documenting completed and ongoing activities, tracking identifiers, assessment status, significant findings, risks, issues, and key updates.


Required Skills, Qualifications and Experience:



  • Education:

    • Bachelor's degree required.

    • A bachelor's in information technology, Cybersecurity, Computer Science, Information Systems, or related technical field is preferred.



  • Overall Experience:

    • Minimum of eight (8) years of experience in a cybersecurity or network security position.



  • A&A Experience:

    • Minimum of five (5) years of experience performing Certification and Accreditation (C&A) and/or Assessment and Authorization (A&A) activities.



  • Security Clearance:

    • Must have a minimum of a current DoD Secret Clearance with the ability to obtain a DoD Top Secret clearance with SCI eligibility. A current DoD Top Secret clearance with SCI eligibility strongly preferred.



  • Certification:

    • Current DoD 8570 IAM Level III certification.



  • Skills:

    • Demonstrated experience serving as a Security Control Assessor Representative (SCA-R) and performing cybersecurity risk analysis and security control validation.

    • Advanced understanding and practical application of the Risk Management Framework (RMF), including NIST SP 800-37, NIST SP 800-53, and CNSSI 1253.

    • Demonstrated experience applying and evaluating Security Technical Implementation Guides (STIGs), Security Requirements Guides (SRGs), Plans of Action and Milestones (POA&Ms), cybersecurity security controls, and industry/DoD cybersecurity best practices.

    • Demonstrated hands‑on experience with relevant cybersecurity and RMF tools, including one or more of the following: eMASS, STIG Viewer, Nessus, ACAS, SCAP, and HBSS/Endpoint Security Solutions (ESS).

    • Advanced understanding of multiple cybersecurity technology areas and domains, including network technologies and security, mobility, Windows, UNIX/Linux, cloud environments, cloud‑native tools and services, HBSS/Endpoint Security Solutions (ESS), databases, and applications.

    • Strong customer service and stakeholder engagement skills, with the ability to effectively coordinate with Government customers, ISSMs, PMOs, technical teams, system owners, and cybersecurity leadership.

    • Ability to analyze complex technical and cybersecurity information and clearly communicate security risks, vulnerabilities, assessment findings, residual risk, and recommended corrective actions through written documentation and technical briefings.



  • Location and Schedule: This role may be based at one of the following customer locations, with onsite requirements varying by location:

    • Chambersburg, PA: Fully onsite, 5 days per week.

    • Arlington, VA or Fort Meade, MD: Hybrid schedule, 4 days onsite per week with 1 telework day.



  • Travel Requirements:

    • Must be willing and able to support occasional domestic (CONUS) and international (OCONUS) travel, approximately 10% of the time.




The projected salary range for this position is $100,000+ annually. Final compensation will be determined based on factors including years of relevant experience, active security clearance level, certifications, technical skillset, contract requirements, and overall qualifications.


At AGE Solutions, we reward performance, invest in growth, and share success. Our benefits support the whole person, professionally, financially, and personally.



  • 26 Days Paid Leave: Includes vacation, sick, personal time, and holidays. You choose how to use it.

  • Performance Bonuses: Performance bonuses are awarded based on individual contributions and company-wide results, aligning recognition with impact.

  • 401(k) with Match: We match 3% of your contributions with immediate vesting.

  • Financial Protection: Company-paid life insurance up to $300K and options for additional coverage for you and your dependents.

  • Health Benefits: Multiple medical plans, dental, vision, FSA and HSA options to fit your needs.

  • Parental Leave: 15 days of fully paid leave for new parents, because family matters.

  • Military Differential Pay: We bridge the gap for employees on active duty, so they don't take a financial hit while serving.

  • Professional Growth: Paid training and certifications, tuition reimbursement, and the tools and tech to get the job done right.

  • Shared Success: In the event of a company sale, our CEO has committed to returning 80% of net proceeds to employees. This ensures our team shares in the long term value they help create.


At AGE, you'll do work that matters, supported by a company that delivers for its people.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Control Assessor, Mid
Security Control Assessor, Mid

AGE Solutions • United States

Remote
USD 70,000 - 100,000
26 Days Paid Leave
Performance Bonuses
401(k) with Match
+5
Cloud SCA-R, Senior
Cloud SCA-R, Senior

Age Solutions • Fort Meade (MD)

On-site
USD 103,500 - 126,500
26 Days Paid Leave
Performance Bonuses
401(k) with Match
+3
Information System Security Engineer (ISSE)
Information System Security Engineer (ISSE)

Age Solutions • Salem (PA)

On-site
USD 117,000 - 143,000
26 Days Paid Leave
Performance Bonuses
401(k) with Match
+5
TASS (Current Contract) - Security Control Assessor, Senior
TASS (Current Contract) - Security Control Assessor, Senior

Age Solutions • Alexandria (VA)

On-site
USD 95,000 - 105,000
26 Days Paid Leave
Performance Bonuses
401(k) with Match
+6
Information System Security Engineer (ISSE)
Information System Security Engineer (ISSE)

Agecareers • Trenton (MD)

On-site
USD 117,000 - 143,000
26 Days Paid Leave
Performance Bonuses
401(k) with Match
+5
TASS (Current Contract) - Security Control Assessor, Mid
TASS (Current Contract) - Security Control Assessor, Mid

AGE Solutions LLC • Fort Meade (MD)

On-site
USD 63,000 - 77,000
26 Days Paid Leave
Performance Bonuses
401(k) with Match
+6
TASS (Current Contract) - Cybersecurity Engineer – Sr (Cyber Cloud Assessment)
TASS (Current Contract) - Cybersecurity Engineer – Sr (Cyber Cloud Assessment)

AGE Solutions LLC • Fort Meade (MD)

On-site
USD 120,000 - 130,000
26 Days Paid Leave
Performance Bonuses
401(k) with Match
+5
TASS (Current Contract) - Cloud Assessment Lead Cybersecurity Engineer – Sr (Cloud Security Ass[...]
TASS (Current Contract) - Cloud Assessment Lead Cybersecurity Engineer – Sr (Cloud Security Ass[...]

AGE Solutions LLC • Fort Meade (MD)

On-site
USD 115,000 - 130,000
26 Days Paid Leave
Performance Bonuses
401(k) with Match
+3
Cybersecurity Policy Analyst
Cybersecurity Policy Analyst

Age Solutions • Columbus (OH)

On-site
USD 81,000 - 99,000
Paid leave 26 days
Bonuses
401(k) with match
+5
Security Control Assessor, Mid Fort Meade, MD
Security Control Assessor, Mid Fort Meade, MD

AGE • Fort Meade (MD), Northern (KY)

Hybrid
USD 63,000 - 77,000