Security Control Assessor (SCA) II

Amatriot Group, LLC

Arlington (VA)

On-site

USD 169,000 - 172,000

Full time

3 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Amatriot Group, LLC is actively seeking a Security Control Assessor to perform comprehensive assessments of information system security controls, covering collateral, SCI, and SAP activities. The role emphasizes RMF-based evaluations, control effectiveness, and recommendations for corrective actions to meet security requirements.

Responsibilities include developing security program policy, assessing threats, advising ISO/IDO/PSO/DAO, and ensuring proper documentation such as SARs and POA&Ms.

Qualifications

  • 7–9 years of related experience required.
  • 4+ years of experience in SAP, SCI, or Collateral Information Systems security.
  • Prior performance in ISSO, ISSM, or SCA required.

Responsibilities

  • Lead IS security program policy development and evaluation.
  • Assess IS security controls using RMF and JSIG guidance.
  • Determine vulnerabilities and advise mitigations.
  • Prepare SARs and POA&Ms and coordinate with AO/DAO for authorization.
  • Support compliance inspections and SDLC security activities.

Skills

RMF knowledge
IS security
Security assessment
Policy & compliance
Risk assessment

Tools

JSIG

Job description

Career Opportunities with Amatriot Group, LLC

A great place to work.

Share with friends or Subscribe!

Are you ready for new challenges and new opportunities?

Join our team!

Current job opportunities are posted here as they become available.

Subscribe to our RSS feeds to receive instant updates as new positions become available.

Location: Crystal City, VA
Security Clearance: Active TS/SCI [Required] (Must be able to obtain a CI Poly
Job Type: Full-Time

Target Salary Range*: $169,000-$171,500

*This represents the potential salary range for this position depending on education level, years of experience and/or certifications in addition to other position specific requirements which may impact salary

Position Overview

The Security Control Assessor (SCA) is responsible for conducting comprehensive assessments of the management, operational, and technical security controls employed within or inherited by an information system (IS) to determine the overall effectiveness of those controls. The SCA assesses whether controls are implemented correctly, operating as intended, and producing the desired outcomes with respect to the system's security requirements. The SCA also assesses the severity of identified weaknesses or deficiencies and recommends corrective actions to address vulnerabilities.

Responsibilities cover Collateral, Sensitive Compartmented Information (SCI), and Special Access Program (SAP) activities within the customer's area of responsibility.

Key Responsibilities
Security Program Oversight and Assessment
  • Oversee the development, implementation, and evaluation of IS security program policy, with special emphasis on integrating existing SAP network infrastructure.
  • Assess ISs based on the Risk Management Framework (RMF) methodology in accordance with the Joint Special Access Program (SAP) Implementation Guide (JSIG).
  • Evaluate IS threats and vulnerabilities to determine whether additional safeguards are required.
  • Advise the Government concerning the impact levels for Confidentiality, Integrity, and Availability of information on a system.
  • Evaluate hardware and software to determine the security impact on Authorization boundaries.
  • Evaluate the effectiveness and implementation of Continuous Monitoring Plans.
Authorization and Risk Management
  • Advise the Information System Owner (ISO), Information Data Owner (IDO), Program Security Officer (PSO), and Delegated and/or Authorizing Official (DAO/AO) on assessment and authorization issues.
  • Evaluate Authorization packages and make recommendations to the AO and/or DAO for authorization.
  • Ensure security assessments are completed and results are documented.
  • Prepare the Security Assessment Report (SAR) for the Authorization boundary.
  • Initiate a Plan of Action and Milestones (POA&M) with identified weaknesses for each Authorization boundary assessed, based on findings and recommendations from the SAR.
  • Evaluate security assessment documentation and provide written recommendations for security authorization to the Government.
  • Discuss recommendations for authorization and submit the security authorization package to the AO/DAO.
  • Assess proposed changes to Authorization boundaries, operating environments, and mission needs to determine continuation to operate.
Compliance and Security Operations
  • Review and concur with all sanitization and clearing procedures in accordance with Government guidance and/or policy.
  • Assist with Government compliance inspections.
  • Assist the Government with security incidents related to cybersecurity and ensure proper corrective measures have been taken.
  • Ensure organizations address and conduct all phases of the system development life cycle (SDLC).
  • Represent the customer on inspection teams.
Qualifications
Experience
  • 7–9 years of related experience [Required].
  • 4+ years of experience in SAP, SCI, or Collateral Information Systems (S) security and implementation of regulations identified in the description of duties [Required].
  • Prior performance in the role of ISSO, ISSM, or SCA [Required].
Certifications
  • IAT Level III or IAM Level II [Required].
Clearance
  • Active TS/SCI clearance [Required].
  • Must be willing to obtain a CI Poly [Required].
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Control Assessor II (SCA II) (TS, w/ SCI Eligibility) -
Security Control Assessor II (SCA II) (TS, w/ SCI Eligibility) -

RedTrace Technologies Inc • Colorado Springs (CO)

On-site
USD 110,000 - 130,000
401(k) plan
Annual performance bonus
Tuition reimbursement
+1
Security Control Assessor I
Security Control Assessor I

P-11 SECURITY • Colorado Springs (CO)

On-site
USD 95,000 - 125,000
Security Control Assessor (SCA), Level II
Security Control Assessor (SCA), Level II

TAC Integrated Solutions • Virginia (MN)

On-site
USD 110,000 - 160,000
Security Control Assessor II
Security Control Assessor II

P11security • Virginia (MN), Northern (KY)

Hybrid
USD 95,000 - 130,000
Security Control Assessor II
Security Control Assessor II

P-11 SECURITY • Virginia (MN)

On-site
USD 90,000 - 130,000
Security Control Assessor I
Security Control Assessor I

P-11 Security, Inc. | SBA 8(a) Certified | EDWOSB • Colorado Springs (CO)

On-site
USD 95,000 - 130,000
Security Control Assessor II (SCA II) (TS, w/ SCI Eligibility) -
Security Control Assessor II (SCA II) (TS, w/ SCI Eligibility) -

RedTrace Technologies • Colorado Springs (CO)

On-site
USD 90,000 - 130,000
Competitive salary
401(k) plan
Annual performance bonus
+5
Security Control Assessor I (SCA I) (TS w/ SCI eligibility)
Security Control Assessor I (SCA I) (TS w/ SCI eligibility)

Redtracetech • Colorado Springs (CO)

On-site
USD 150,000 - 165,000
401(k) plan
Annual performance bonus
Health care insurance
+1
Security Control Assessor (SCA) II
Security Control Assessor (SCA) II

Modern Technology Solutions, Inc. (MTSI) • Albuquerque (NM)

On-site
USD 90,000 - 140,000
Security Control Assessor (SCA), Level I
Security Control Assessor (SCA), Level I

TAC Integrated Solutions • Arlington (VA)

On-site
USD 90,000 - 120,000