Security Control Assessor Representative (SCAR)

KBR, Inc

Florida

On-site

USD 120,000 - 170,000

Full time

3 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

401K plan with company match
Medical insurance
Dental insurance
Vision insurance
Life insurance
AD&D
Flexible spending account
Disability insurance
Paid time off
Flexible work schedule

Job summary

KBR is seeking a Security Control Assessor Representative (SCAR) to join our cybersecurity team in the United States. The role focuses on RMF assessments, vulnerability management, and DoD-compliant security controls for complex defense systems.

The SCAR will conduct risk evaluations, develop remediation plans, and oversee independent audits for applications, networks, and cloud services. Travel about 25% is expected to support missions and audits.

Qualifications

  • Experience with RMF and DoD Security Controls.
  • Experience with cybersecurity in the RDT&E community.
  • Proven experience conducting RMF security risk assessments.
  • Familiarity with vulnerability scanning tools.
  • Knowledge of confidentiality, integrity, and availability.
  • IAM III certification per DoD 8140.03.

Responsibilities

  • Conduct in-depth assessments of the management, operations, and technical security controls.
  • Develop a plan to address vulnerabilities and monitor security of network systems.
  • Develop security compliance processes and/or audits for external services (e.g., cloud providers).
  • Review and analyze POAMs, SARs, SAPs.
  • Provide RMF guidance to system engineers and program managers on assessment and risk matters.
  • Review security requirements and configurations for DoD policy compliance.
  • Participate in security assessment meetings with PMs, Cyber Team Lead, and ISSOs.

Skills

RMF experience
DoD cybersecurity
Vulnerability scanning
Risk guidance
Communication
Project management
Stakeholder engagement
IAM III

Education

Bachelor's degree in engineering or IT

Job description

Title: Security Control Assessor Representative (SCAR)

KBR is seeking a Security Control Assessor Representative (SCAR) to join our team.

Why Join Us?

Innovative Projects: KBR’s work is at the forefront of engineering, logistics, operations, science, program management, mission IT and cybersecurity solutions.

Collaborative Environment: Be part of a dynamic team that thrives on collaboration and innovation, fostering a supportive and intellectually stimulating workplace.

Impactful Work: Your contributions will be pivotal in designing and optimizing defense systems that ensure national security and shape the future of space defense.

Applicant Duties
  • Conduct in-depth assessments of the management, operations, and technical security controls.
  • Analyze information and prepare reports describing the vulnerability level of the network/system with specific detail as to what compromises data systems.
  • Develop a plan to address vulnerabilities and continue to monitor the security of network systems.
  • Alongside the TRMC Cybersecurity Team Lead develop and implement cybersecurity independent audit processes for application software/networks/systems and oversee ongoing independent audits to ensure processes and procedures are in compliance with organizational and mandatory cybersecurity requirements and accurately followed by Systems Administrators and other cybersecurity staff when performing their day-to-day activities.
  • Develop security compliance processes and/or audits for external services (e.g., cloud service providers, data centers).
  • Verify that application software/network/system security postures are implemented as stated, document deviations, and recommend required actions to correct those deviations.
  • Perform validation steps, comparing actual results with expected results and analyze the differences to identify impact and risks.
  • Apply confidentiality, integrity, and availability principles.
  • Draft statements of preliminary or residual security risks for system operation.
  • Maintain information systems assurance and accreditation materials.
  • Responsible for identifying, assessing, and managing cybersecurity capabilities and services, providing leadership, team coordination, and subject matter expertise in Assessment and Authorization (A&A) packages and leveraging the A&A process steps as a means for system authorization.
  • Review and analyze Plans of Actions and Milestones (POAMs), Security Assessment Reports (SAR), Security Assessment Plans (SAP).
  • Conduct required vulnerability analysis to support mitigation and residual risk determination.
  • Provide Risk Management Framework guidance and assistance to system engineers and program managers on assessment and risk-related matters and make risk recommendations.
  • Review security requirements, products, configurations, and cybersecurity architectures for compliance with DoD policies.
  • Support a general working knowledge of applicable assessment methods, such as Secure Technical Implementation Guides (STIGs) and automated vulnerability scans and analyze technical test data.
  • Participate in technical interchanges, security impact assessments and security assessment meetings with PMs, Cyber Team Lead, ISSOs/lSSMs and the AO.
Basic Qualifications
  • Subject Matter Expert (SME) with proven experience regarding the Risk Management Framework (RMF) and assessing DoD Security Controls.
  • Experience with Cybersecurity in the RDT&E Community.
  • Proven experience conducting security risk assessments for RMF authorizations.
  • Familiarity with Vulnerability scanning tools and ability to recognize vulnerabilities in information systems and networks.
  • Knowledge of cybersecurity principles and organizational requirements (relevant to confidentiality, integrity, availability, authentication, non-repudiation).
  • Knowledge of cyber threats and vulnerabilities.
  • Knowledge of cloud computing service models Software as a Service (SaaS), Infrastructure as a Service (IaaS), and Platform as a Service (PaaS).
  • Bachelor’s degree in engineering, Computer Science, Information Technology, or relevant field along with work experience in data security.
  • Strong project management, teamwork, and communication skills in addition to intermediate technical knowledge.
  • Ability to adapt to process changes, systems changes, in a fast-paced environment.
  • Ability to interface with senior leadership.
  • Ability to support high visibility or high priority projects.
  • Advanced Certification (IAM III) for SCA per DOD MANUAL 8140.03.
Travel

25% of time.

Basic Compensation

$130,000 - $170,000 (For Maryland, Virginia, DC and California Only)

The offered rate will be based on the selected candidate’s knowledge, skills, abilities and/or experience and in consideration of internal parity.

Additional Compensation

KBR may offer bonuses, commissions, or other forms of compensation to certain job titles or levels, per internal policy or contractual designation.

Additional compensation may be in the form of sign on bonus, relocation benefits, short term incentives, long term incentives, or discretionary payments for exceptional performance.

KBR Benefits
  • 401K plan with company match
  • medical
  • dental
  • vision
  • life insurance
  • AD&D
  • flexible spending account
  • disability
  • paid time off
  • flexible work schedule
Belong, Connect and Grow at KBR

At KBR, we are passionate about our people and our Zero Harm culture. These inform all that we do and are at the heart of our commitment to, and ongoing journey toward being a People First company. That commitment is central to our team of team’s philosophy and fosters an environment where everyone can Belong, Connect and Grow. We Deliver – Together.

KBR is an equal opportunity employer

KBR is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, disability, sex, sexual orientation, gender identity or expression, age, national origin, veteran status, genetic information, union status and/or beliefs, or any other characteristic protected by federal, state, or local law.

KBR — Delivering Solutions, Changing the World

KBR brings together the best and brightest to deliver science, technology and engineering solutions that help governments and companies around the world accomplish their most critical missions and objectives. In everything we do, we are guided by our ONE KBR Values:

  • We Value Our People – We create diverse, inclusive environments in which each person can feel safe, respected and valued, and where everyone has opportunities to grow and reach their full potential.
  • We Deliver – We are uncompromising in our commitment to deliver innovative, high-quality, technology-led solutions for our customers and exceptional, sustainable value for all our stakeholders.
  • We Are People of Integrity – We value honesty, trust, courage, fairness, prudence and tenacity. We believe doing what’s right for the planet, the communities where we work, and our people is good for business.
  • We Empower – We empower our people with a shared purpose, the right tools and the supportive culture they need to be proactive decision-makers, to be adaptive to change, and to succeed.
  • We Are a Team of Teams – We have a will to succeed, but we value the achievements of our team of teams over individual accomplishments. Our collective focus makes us a better, stronger, more effective company.

We have also embedded environmental, social and governance (ESG) principles in every business operation and corporate function. Not only are we committed to operating safely, sustainably and equitably, but we are also committed to using our capabilities and expertise to help our customers accomplish their sustainability goals.

Worldwide Operations

Worldwide, KBR employs a diverse workforce approximately 29,000 people strong, with customers in more than 80 countries and operations in 40 countries. At KBR, We Deliver.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Control Assessor Representative (SCAR)
Security Control Assessor Representative (SCAR)

KBR, Inc • Alexandria (VA)

On-site
USD 130,000 - 170,000
401K plan with company match
medical
dental
+6
Desk Officer
Desk Officer

KBR, Inc • United States

On-site
USD 176,000 - 215,000
401K with company match
Medical insurance
Dental insurance
+7
Cloud Pentester
Cloud Pentester

KBR, Inc • Town of Vienna (WI)

On-site
USD 191,000 - 233,000
401K with company match
Medical, dental, vision insurance
Flexible work schedule
Cloud Pentester
Cloud Pentester

KBR, Inc • Chantilly (VA)

On-site
USD 191,000 - 233,000
401K with company match
Medical insurance
Dental insurance
+7
Senior DevSecOps Cybersecurity Engineer
Senior DevSecOps Cybersecurity Engineer

KBR Careers • Colorado Springs (CO)

Hybrid
USD 149,000 - 186,000
401K plan with company match
Medical and dental benefits
Flexible work schedule
Senior DevSecOps Cybersecurity Engineer
Senior DevSecOps Cybersecurity Engineer

KBR Careers • El Segundo (CA)

Hybrid
USD 149,000 - 186,000
401K with company match
Medical, dental, vision
Flexible work schedule
Testing and Training Associate
Testing and Training Associate

KBR, Inc • Landover (MD), Northern (KY)

Hybrid
USD 75,000 - 130,000
Mid Software Engineer
Mid Software Engineer

KBR, Inc • Colorado Springs (CO), Northern (KY)

Hybrid
USD 116,000 - 174,000
Software Engineer
Software Engineer

KBR, Inc • Springfield (VA), Northern (KY)

Hybrid
USD 110,000 - 115,000
401(k) with company match
Medical, dental, vision
Paid time off
Senior Solution Architect
Senior Solution Architect

KBR Careers • El Segundo (CA)

On-site
USD 207,000 - 311,000
401K plan
Medical coverage
Paid time off