Security Controls Assessor

ECS Corporate Services

Washington (District of Columbia)

Hybrid

USD 150,000 - 168,000

Full time

8 days ago
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

ECS Corporate Services is seeking a Security Controls Assessor to our Washington, DC hybrid office. The role supports a long‑term, full‑time contract with a U.S. Government civilian agency, performing risk and control assessments under RMF guidelines.

Applicants must hold an active security clearance and have extensive experience with NIST SP 800‑53, RMF, and federal information security requirements, with travel to CONUS and occasional OCONUS locations expected.

Qualifications

  • Active Secret clearance required with eligibility to obtain Top Secret clearance.
  • Minimum five (5) years of information security experience.
  • Minimum three (3) years of experience supporting security assessment teams, including planning assessments.
  • Two (2) years of experience using GRC tools.
  • Experience conducting full-scope technical security control testing across components.
  • Working knowledge of RMF Steps 1‑6.
  • Strong understanding of NIST SP 800‑53, NIST CSF, and related laws/regulations.
  • Ability to analyze configurations and specifications against NIST controls.
  • Experience developing risk-based documentation.

Responsibilities

  • Review and update information security policies, standards, and procedures per regulations.
  • Perform independent security and privacy control assessments for the client CSO.
  • Assess FISMA systems and communicate findings and impacts of control weaknesses.
  • Review A&A packages including SSP, Risk Assessments, ISCP, CMP, and POA&Ms for completeness.
  • Develop and maintain test cases for control-level testing across system components.
  • Develop and execute security and privacy assessment plans per NIST SP 800‑53A.
  • Document findings and actionable recommendations clearly.
  • Analyze security tool outputs to distinguish residual risk from false positives.
  • CONUS and OCONUS travel to conduct system assessments.

Skills

Security assessment
RMF
NIST SP 800-53
NIST CSF
GRC tools

Education

Bachelor's degree in Computer Science, MIS/IT, Engineering, Information Security/Assurance, or a related field

Tools

GRC tools

Job description

ECS is seeking a Security Controls Assessor to work in our Washington, DC (hybrid) office. Please Note: This position is contingent upon contract award. ECS seeks a Security Controls Assessor to support a full range of cybersecurity services on a long‑term, full‑time contract with a U.S. Government civilian agency. This position requires mostly CONUS and occasional OCONUS assessments and is available immediately for a qualified candidate with an active security clearance.

Key Responsibilities
  • Review and update information security policies, standards, and procedures in accordance with federal and departmental regulations
  • Perform independent security and privacy control assessments on behalf of the client CSO in support of Security Assessment & Authorization (SA&A)
  • Assess existing and new FISMA systems and subsystems, and communicate findings and potential impacts of identified control weaknesses
  • Review and analyze A&A packages-including System Security Plans (SSP), Risk Assessments, Information System Contingency Plans (ISCP), Backup SOPs, Incident Response Plans (IRP), Configuration Management Plans (CMP), hardware/software inventories, network diagrams, data flows, system change requests, vulnerability scan reports, test reports, and POA&Ms-for completeness, accuracy, and effective control implementation
  • Develop and maintain test cases for control‑level security testing across system components (applications, servers, databases, operating systems, network devices, end‑user devices, etc.)
  • Develop and execute security and privacy assessment plans in accordance with NIST SP 800‑53A, supporting RMF Steps 4‑6
  • Document findings and recommendations that are clear, system‑specific, and actionable
  • Analyze security tool outputs to distinguish residual risk from false positives prior to finalizing findings
  • CONUS and OCONUS travel to conduct system assessments
  • Other duties as assigned

Salary Range: $150,000-$168,000

General Description of Benefits
  • Active Secret clearance required with eligibility to get Top Secret clearance
  • Bachelor's degree in Computer Science, MIS/IT, Engineering, Information Security/Assurance, or a related field
  • Minimum five (5) years of information security experience
  • Minimum three (3) years of experience supporting security assessment teams, including planning assessments and serving as a senior team member
  • Two (2) years of experience using GRC tools
  • Demonstrated experience conducting full‑scope technical security control testing across component types, including development of security and privacy assessment plans
  • Working knowledge of RMF Steps 1‑6
  • Strong understanding of NIST SP 800‑53 controls, the NIST Cybersecurity Framework, and applicable information security/privacy laws and regulations
  • Ability to analyze information system configurations and technical specifications against NIST SP 800‑53 and related overlays
  • Experience developing risk‑based documentation
  • Excellent written and verbal communication skills, with the ability to present control requirements and deficiencies clearly to both technical and non‑technical audiences
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Controls Assessor
Security Controls Assessor

ECS • Washington

Hybrid
USD 150,000 - 168,000
Senior Business Analyst
Senior Business Analyst

ECS Corporate Services • Washington

Hybrid
USD 130,000 - 147,000
Security Control Assessor
Security Control Assessor

Caliber Systems Inc. • Denver (CO), Northern (KY)

Hybrid
USD 94,000 - 127,000
Security Control Assessor (SCA)
Security Control Assessor (SCA)

Integrity Solutions, Engineering, and Analytics Corporation • Virginia (MN)

On-site
USD 110,000 - 170,000
Security Control Assessor
Security Control Assessor

Omniscius Consulting • Arlington (VA)

On-site
USD 120,000 - 180,000
Senior Security Controls Assessor – RMF, NIST, SA&A
Senior Security Controls Assessor – RMF, NIST, SA&A

ECS • Washington

Hybrid
USD 150,000 - 168,000
Senior Security Controls Assessor (TS/SCI #26-143)
Senior Security Controls Assessor (TS/SCI #26-143)

Strategic Analysis, Inc. • Arlington (VA)

On-site
USD 120,000 - 180,000
Security Controls Assessor - Senior
Security Controls Assessor - Senior

SMS Data Products Group, Inc. • Springfield (VA)

On-site
USD 123,000 - 136,000
Cybersecurity Specialist
Cybersecurity Specialist

Kaizen Lab Inc. • Charlotte (NC)

On-site
USD 120,000 - 180,000
Security Control Assessor
Security Control Assessor

Apavo Corporation • Arlington (VA)

On-site
USD 130,000 - 185,000