Security Controls Assessor

ECS

Washington (District of Columbia)

Hybrid

USD 150,000 - 168,000

Full time

7 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Everforth ECS in Washington, DC (hybrid) seeks a Security Controls Assessor to perform independent security and privacy control assessments for a federal client. Responsibilities include reviewing SSPs, risk assessments, and ISCPs, and developing test cases and assessment plans in line with NIST RMF and SP 800-53A.

The role requires an active Secret clearance, five years in information security, and experience with RMF 1-6 and A&A processes. Occasional travel is required.

Qualifications

  • Active Secret clearance with eligibility for Top Secret
  • Bachelor's degree in CS / MIS / IT / Eng / InfoSec or related field
  • Minimum five years information security experience
  • Minimum three years supporting security assessment teams, including planning assessments
  • Two years of experience using GRC tools
  • Experience conducting full-scope security control testing across component types
  • Working knowledge of RMF Steps 1-6
  • Strong understanding of NIST SP 800-53, CSF, and related laws
  • Ability to analyze system configurations against NIST SP 800-53
  • Experience developing risk-based documentation
  • Excellent written and verbal communication skills

Responsibilities

  • Review and update information security policies, standards, and procedures per regulations
  • Perform independent security and privacy control assessments for client SA&A
  • Assess existing and new FISMA systems and communicate findings
  • Review A&A packages: SSPs, Risk Assessments, ISCP, IRP, CMP, inventories, diagrams, POA&Ms
  • Develop and maintain test cases for control testing across components
  • Develop and execute security and privacy assessment plans per NIST SP 800-53A
  • Document findings clearly, with actionable recommendations
  • Analyze tool outputs to distinguish residual risk from false positives
  • Travel CONUS and OCONUS for assessments
  • Other duties as assigned

Skills

Active Secret clearance
Bachelor's degree in CS / MIS/IT / Eng
5+ years information security
3+ years security assessments support
2+ years with GRC tools
Full-scope security control testing
RMF Steps 1-6
NIST 800-53 / CSF knowledge
Analyze configurations for NIST
Risk-based documentation
Excellent written & verbal comms

Education

Bachelor's degree in Computer Science, MIS/IT, Engineering, Information Security/Assurance, or related field

Job description

Job Description

ECS is seeking a

Please Note: This position is contingent upon contract award.

ECS seeks a

Job Description

ECS is seeking a Security Controls Assessor to work in our Washington, DC (hybrid) office. Please Note: This position is contingent upon contract award. ECS seeks a Security Controls Assessor to support a full range of cybersecurity services on a long-term, full-time contract with a U.S. Government civilian agency. This position requires mostly CONUS and occasional OCONUS assessments and is available immediately for a qualified candidate with an active security clearance.

Key Responsibilities

  • Review and update information security policies, standards, and procedures in accordance with federal and departmental regulations
  • Perform independent security and privacy control assessments on behalf of the client CSO in support of Security Assessment & Authorization (SA&A)
  • Assess existing and new FISMA systems and subsystems, and communicate findings and potential impacts of identified control weaknesses
  • Review and analyze A&A packages—including System Security Plans (SSP), Risk Assessments, Information System Contingency Plans (ISCP), Backup SOPs, Incident Response Plans (IRP), Configuration Management Plans (CMP), hardware/software inventories, network diagrams, data flows, system change requests, vulnerability scan reports, test reports, and POA&Ms—for completeness, accuracy, and effective control implementation
  • Develop and maintain test cases for control-level security testing across system components (applications, servers, databases, operating systems, network devices, end-user devices, etc.)
  • Develop and execute security and privacy assessment plans in accordance with NIST SP 800-53A, supporting RMF Steps 4-6
  • Document findings and recommendations that are clear, system-specific, and actionable
  • Analyze security tool outputs to distinguish residual risk from false positives prior to finalizing findings
  • CONUS and OCONUS travel to conduct system assessments
  • Other duties as assigned

Salary Range: $150,000-$168,000

General Description Of Benefits

Required Skills

  • Active Secret clearance required with eligibility to get Top Secret clearance
  • Bachelor's degree in Computer Science, MIS/IT, Engineering, Information Security/Assurance, or a related field
  • Minimum five (5) years of information security experience
  • Minimum three (3) years of experience supporting security assessment teams, including planning assessments and serving as a senior team member
  • Two (2) years of experience using GRC tools
  • Demonstrated experience conducting full-scope technical security control testing across component types, including development of security and privacy assessment plans
  • Working knowledge of RMF Steps 1-6
  • Strong understanding of NIST SP 800-53 controls, the NIST Cybersecurity Framework, and applicable information security/privacy laws and regulations
  • Ability to analyze information system configurations and technical specifications against NIST SP 800-53 and related overlays
  • Experience developing risk-based documentation
  • Excellent written and verbal communication skills, with the ability to present control requirements and deficiencies clearly to both technical and non-technical audiences

Desired Skills

  • Assessment and Authorization (A&A) activities, including risk assessments, Security Plans, Security Controls Assessments (SCA), and related documentation
  • Current industry practices for evaluating, implementing, and disseminating IT security assessment, monitoring, detection, and remediation tools
  • Assessing systems hosted in AWS and/or Azure cloud environments
  • Conducting assessments in accordance with OMB, NIST, and FedRAMP policies, procedures, and standards
  • One of the following:
    • CISSP (Certified Information Systems Security Professional)
    • CEH (Certified Ethical Hacker)
    • CRISC (Certified in Risk and Information Systems Control)
    • CISA (Certified Information Systems Auditor)
    • AAIA (Advanced in AI Audits)

ECS Federal LLC is an equal opportunity employer and does not discriminate or allow discrimination on the basis any characteristic protected by law. All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, or local jurisdiction law.

Everforth ECS is the federal segment of Everforth, a $4B global organization with over 10,000 employees. Our nearly 3,500 professionals deliver advanced technology solutions in data and AI, cybersecurity, and enterprise transformation, serving defense, intelligence, and federal civilian agencies.

Our work powers mission-critical outcomes, strengthens technology partnerships, and creates meaningful opportunities for our people. We are defined by a commitment to excellence in delivery, a culture of innovation, and an environment where talent can thrive and grow.

We Value

  • Attracting and developing top talent and high-performing teams
  • Fostering a culture that is engaging, accountable, and mission-driven

Meet the challenge. Make a difference with Everforth ECS!

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Authorizing Official Designated Representative (AODR) Support Analyst
Authorizing Official Designated Representative (AODR) Support Analyst

ECS • Washington

Hybrid
USD 170,000 - 190,000
Information Systems Security Engineer SME
Information Systems Security Engineer SME

ECS • Stafford (VA)

On-site
USD 120,000 - 150,000
Enterprise Vulnerability Assessment Program- AI Focused
Enterprise Vulnerability Assessment Program- AI Focused

ECS • Washington

On-site
USD 160,000 - 205,000
Cyber Assessment & Authorization / Technical Writer
Cyber Assessment & Authorization / Technical Writer

ECS • Falls Church (VA)

On-site
USD 130,000 - 150,000
Sr. Mission Integration Strategist
Sr. Mission Integration Strategist

ECS • Arlington (VA)

On-site
USD 200,000 - 250,000
Sr Forescout Engineer
Sr Forescout Engineer

ECS • Honolulu (HI)

On-site
USD 130,000 - 150,000
Technical Lead
Technical Lead

ECS • Fairfax (VA)

Hybrid
USD 170,000 - 210,000
Senior Cyber Incident Analyst
Senior Cyber Incident Analyst

ECS • Arlington (VA)

On-site
USD 170,000 - 180,000
Sr. Automation SME
Sr. Automation SME

ECS • Arlington (VA)

On-site
USD 160,000 - 195,000
Cyber Ops Delivery Lead
Cyber Ops Delivery Lead

ECS • Arlington (VA)

Hybrid
USD 160,000 - 190,000