Security Control Assessor (SCA)

Integrity Solutions, Engineering, and Analytics Corporation

Virginia (MN, MD)

On-site

USD 110,000 - 170,000

Full time

3 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

ISEA is seeking an experienced Security Control Assessor to independently validate security postures under RMF, ICD 503 and CNSSI 1253. The role spans cloud, on‑prem, and hybrid environments, delivering risk‑based recommendations to authorizing officials.

Candidates should have 5–10+ years in information assurance or DoD RMF, DoD 8140/8570 certs (CISSP, CISA, CGRC), and familiarity with Xacta, ACAS/Nessus, and STIG Viewer; strong technical writing is essential.

Qualifications

  • 5-10+ years in information assurance, cybersecurity assessment, or IT auditing, RMF focus in DoD/IC.
  • Bachelor’s or Master’s degree in Cybersecurity, CS, IT, or related technical discipline.
  • Active DoD 8140/8570 certifications (IAM III or IAT III): CISSP, CISA, CGRC.
  • Mastery of ICD 503, CNSSI 1253, and NIST SP 800-37/53/53A.
  • Proficiency with Xacta, ACAS/Nessus, SCC, and STIG Viewer.

Responsibilities

  • Plan and conduct security control assessments based on NIST SP 800-53 and CNSSI 1253.
  • Perform hands-on and automated validation of controls; review configurations, logs, access controls, network boundaries.
  • Use vulnerability scanning tools and STIGs to test resilience of cloud, on-premise, and hybrid environments.
  • Evaluate BoE packages (SSP, CONOPS, network diagrams) for accuracy and completeness.
  • Translate vulnerabilities into risk assessments for Authorizing Official (AO) and guide remediation with system teams.
  • Support continuous monitoring through reviews of periodic assessments and vulnerability data.

Skills

RMF
Info Assurance
Cybersecurity

Education

Bachelors/Masters in CS/IT

Tools

Xacta
ACAS/Nessus
SCAP Checker
STIG Viewer

Job description

Job Description:

ISEA is searching for an experienced and motivated Security Control Assessor (SCA) to join our growing team. In this role, you will serve as an independent validator of system security postures within the customer’s agency, conducting comprehensive and independent assessments of information systems to determine the overall effectiveness of implemented security controls and navigating the Risk Management Framework (RMF) under the guidelines of ICD 503 and CNSSI 1253. The ideal candidate possesses the deep technical knowledge required to verify security safeguards as well as the analytical and interpersonal skills to provide risk-based recommendations to authorizing officials.

Responsibilities:
  • Plan and conduct comprehensive security control assessments based on NIST SP 800-53, CNSSI 1253, and customer-specific security requirements.
  • Perform hands-on and automated validation of security controls, including reviewing system configurations, audit logs, access controls, and network boundary defenses.
  • Utilize vulnerability scanning tools, STIGs, and manual verification methods to test the resilience of complex architectures, including cloud, on-premise, and hybrid environments.
  • Critically evaluate Body of Evidence, or BoE, packages, including System Security Plans, CONOPS, and network diagrams, with a focus on accuracy and completeness.
  • Translate complex technical vulnerabilities into actionable risk assessments, providing the Authorizing Official (AO) with a clear picture of the risk associated with system operation.
  • Work closely with ISSMs, System Owners, and engineers, guiding them through the remediation of identified findings.
  • Support the continuous monitoring program by reviewing periodic assessments, system security relevant change requests, and updated vulnerability data.
Qualifications:
  • 5-10+ years’ experience in information assurance, cybersecurity assessment, or IT auditing, with a heavy emphasis on the RMF within the DoD or Intelligence Community.
  • Bachelor’s or Master’s degree in Cybersecurity, Computer Science, Information Technology, or a related technical discipline.
  • Active certifications in accordance with DoD 8140/8570 requirements (IAM Level III or IAT Level III): CISSP, CISA, CGRC (formerly CAP)
  • Mastery of ICD 503, CNSSI 1253, and NIST Special Publications (NIST SP 800-37, 800-53, 800-53A).
  • Proficiency with cybersecurity tools such as Xacta, Assured Compliance Assessment Solution (ACAS/Nessus), SCAP Compliance Checker (SCC), and STIG Viewer.
  • Comprehensive understanding of enterprise networks, cross-domain solutions (CDS), database security, and advanced cloud environments.
  • Strong interpersonal skills and the ability to maintain a strict, independent posture during assessments, while working constructively with system teams.
  • Excellent technical writing skills to produce concise, accurate SARs and executive-level risk briefings.
  • Ability to evaluate non-standard system architectures and determine appropriate compensatory controls when standard controls cannot be met.
Desired Skills:
  • CEH or higher technical testing certifications.
Citizenship/Clearance Requirements:
  • US Citizenship is required.
  • Must be eligible to obtain and maintain a government security clearance.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Controls Assessor (TS/SCI #26-143)
Senior Security Controls Assessor (TS/SCI #26-143)

Strategic Analysis, Inc. • Arlington (VA)

On-site
USD 120,000 - 180,000
Security Control Assessor
Security Control Assessor

Omniscius Consulting • Arlington (VA)

On-site
USD 120,000 - 180,000
Security Control Assessor (SCA) (TS/SCI)
Security Control Assessor (SCA) (TS/SCI)

Tau Six, LLC • Sully Square (VA)

On-site
USD 80,000 - 110,000
Security Control Assessor SCA TSSCI
Security Control Assessor SCA TSSCI

Tau Six • Sully Square (VA)

On-site
USD 70,000 - 110,000
Security Control Assessor
Security Control Assessor

Caliber Systems Inc. • Denver (CO), Northern (KY)

Hybrid
USD 94,000 - 127,000
Security Control Assessor II
Security Control Assessor II

P-11 SECURITY • Virginia (MN)

On-site
USD 90,000 - 130,000
Security Control Assessor II
Security Control Assessor II

P11security • Virginia (MN), Northern (KY)

Hybrid
USD 95,000 - 130,000
Senior Security Control Assessor - RMF & DoD IA Expert
Senior Security Control Assessor - RMF & DoD IA Expert

Integrity Solutions, Engineering, and Analytics Corporation • Virginia (MN)

On-site
USD 110,000 - 170,000
Security Control Assessor
Security Control Assessor

Apavo Corporation • Arlington (VA)

On-site
USD 130,000 - 185,000
Security Controls Assessor
Security Controls Assessor

Modern Technology Solutions, Inc. (MTSI) • Chantilly (VA)

On-site
USD 100,000 - 130,000