Security Control Assessor - TS/SCI with Polygraph

General Dynamics Information Technology

Bethesda (MD)

On-site

USD 130,000 - 170,000

Full time

8 days ago
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

401K with company match
Comprehensive health and wellness
Internal mobility support
Professional growth opportunities
Paid education and certifications
Cutting-edge technology exposure

Job summary

General Dynamics Information Technology is seeking a Security Control Assessor to own security assessments, write final reports, defend findings, and drive mitigation strategies on customer sites in Bethesda, MD.

The role requires 6+ years in cybersecurity, SCA experience under ICD 503/CNSSI, RMF/NIST SP 800-53, and TS/SCI with active polygraph. You will assess cloud environments and security controls, with opportunities for growth and professional certifications.

Qualifications

  • Bachelor's Degree required in a related discipline.
  • 6+ years of cybersecurity experience.
  • 3 years of SCA experience under ICD 503/CNSSI 1253 and NIST Cybersecurity Framework/RMF.
  • Experience performing security assessments in cloud environments (AWS, Google, IBM, Azure, Oracle).
  • Active TS/SCI with polygraph clearance.

Responsibilities

  • Write final reports and defend all findings, including risk, mitigations, and references.
  • Report vulnerabilities identified during security assessments.
  • Write RoE, Test Plans, and SOPs for security assessments.
  • Conduct security reviews and technical research to improve defenses.

Skills

Vulnerability assessment
IAM & access management
NIST SP 800-53
IV&V of security controls
Threat research
Report writing
Penetration testing planning
Security frameworks (RMF/CNSSI/NIST)

Education

Bachelor's degree in Cybersecurity / CS / related

Tools

Cloud security assessments (AWS/GCP/IBM/Azure/Oracle)

Job description

A career as a Security Control Assessor at GDIT means owning every opportunity to help support and advance our clients’ missions. At GDIT, cyber security is embedded into every aspect of what we do. We’re constantly evolving our cyber solutions to overcome our clients’ biggest challenges, and you will have the opportunity to develop and grow as these technologies evolve.

HOW A SECURITY CONTROL ASSESSOR WILL MAKE AN IMPACT
  • Skill in conducting vulnerability scans and recognizing vulnerability in security systems (e.g., Cloud Environments) AWS, Google, IBM, Azure, and Oracle.
  • Must meet Department of Defense (DOD) 8570.01-Manual (M) Information Assurances Workforce Improvement Program requirement for Information Assurance Manger (IAM) Level III (CISM, CISSP or Associate GSLC or CCISO).
  • Knowledge of general attack strategies (e.g., MITRE ATT&CK Framework).
  • Knowledge of NISPOM, ICD 503, NIST SP 800-53, ICD 705, and other ICDs as appropriate.
  • Knowledge of Independent Verification & Validation (IV&V) of security controls.
  • Strong writing skills.
  • Knowledge of system and application security threats and vulnerabilities.
  • Knowledge of network access, identity, and access management e.g. public key infrastructure (PKI)
  • Knowledge of network protocols such as Transition Control Protocol/Internet Protocol (TCP/IP), Dynamic Host Configuration, Domain Name System (DNS), and directory Services.
  • Ability to assess the robustness of security systems and designs.
  • Knowledge of cybersecurity principles and organizational requirements (relevant to confidentiality, integrity, availability, authentication, non-repudiation).
  • Write final reports and defend all findings, including risk or vulnerability, mitigation strategies, and references.
  • Report vulnerabilities identified during security assessments.
  • Write penetration testing Rules of Engagement (RoE), Test Plans, and Standard Operating Procedures (SOP).
  • Conducted security reviews and technical research and provided reporting to increase security defense mechanisms.
WHAT YOU’LL NEED TO SUCCEED:
  • Education: Bachelor's Degree (Computer Engineering, Computer Science, Electrical Engineering, Information Systems, Information Technology, Cybersecurity, or a closely related discipline)
  • Required Experience: 6+ yrs
  • Required Technical Skills:
  • Three (3) years of cybersecurity experience with at least one year of experience conducting SCAs under ICD 503/CNSSI 1253 NIST Cybersecurity Framework, Risk Management Framework (RMF), or a similar framework.
  • One full year of SCA experiences within the last three calendar years.
  • One full year supporting cloud environment and experience performing security assessments in a cloud environment (AWS, Google, IBM, Azure, and Oracle).
  • Three years of experience performing security assessments in a cloud computing environment.
  • Security Clearance Level: TS/SCI with active polygraph
  • Location: Bethesda, MD - On Customer Site
GDIT IS YOUR PLACE:
  • 401K with company match
  • Comprehensive health and wellness packages
  • Internal mobility team dedicated to helping you own your career
  • Professional growth opportunities including paid education and certifications
  • Cutting-edge technology you can learn from
  • Rest and recharge with paid vacation and holidays
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Technical Analyst - TS/SCI w/Polygraph
Cyber Technical Analyst - TS/SCI w/Polygraph

General Dynamics Information Technology • Herndon (VA)

On-site
USD 120,000 - 150,000
401K with match
Health benefits
Internal mobility
+3
Cybersecurity Analyst (Risk Management Framework) – TS/SCI w/ Polygraph
Cybersecurity Analyst (Risk Management Framework) – TS/SCI w/ Polygraph

General Dynamics Information Technology • Maryland

On-site
USD 120,000 - 160,000
Comprehensive benefits
401K with company match
Paid time off
Security Control Assessor (SCA) II
Security Control Assessor (SCA) II

General Dynamics Information Technology • Virginia (MN)

On-site
USD 143,000 - 181,000
401K with company match
Health and wellness packages
Internal mobility team
+2
Information Systems Security Manager - TS/SCI with Polygraph
Information Systems Security Manager - TS/SCI with Polygraph

General Dynamics Information Technology • North Dakota

On-site
USD 162,000 - 219,000
401K with company match
Comprehensive health benefits
Professional growth opportunities
+1
IT and Cyber Risk Auditor Principal
IT and Cyber Risk Auditor Principal

General Dynamics Information Technology • La Plata (MD)

On-site
USD 90,000 - 130,000
401K with company match
Paid time off
Wellness packages
Security Control Assessor II
Security Control Assessor II

General Dynamics Information Technology • Bedford (MA)

On-site
USD 143,000 - 181,000
Cybersecurity Support Specialist - TS/SCI with Polygraph
Cybersecurity Support Specialist - TS/SCI with Polygraph

General Dynamics Information Technology • Chantilly (VA)

On-site
USD 60,000 - 80,000
Cyber Security Engineer - TS/SCI with Polygraph
Cyber Security Engineer - TS/SCI with Polygraph

General Dynamics Information Technology • Herndon (VA)

On-site
USD 187,000 - 253,000
401K with company match
Comprehensive health and wellness
Internal mobility team
+3
Information Systems Security Manager (ISSM) - TS/SCI w/Polygraph
Information Systems Security Manager (ISSM) - TS/SCI w/Polygraph

General Dynamics Information Technology • North Dakota

On-site
USD 123,000 - 167,000
401K with company match
Comprehensive health & wellness
Paid education and certifications
+1
Cybersecurity Information Security Assessor
Cybersecurity Information Security Assessor

General Dynamics Information Technology • Chantilly (VA)

Hybrid
USD 128,000 - 173,000