Security Controls Assessor - Senior

Cherokee Federal

Almont (CO)

On-site

USD 150,000 - 155,000

Full time

4 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Cherokee Federal seeks a Senior Security Controls Assessor to conduct RMF-based evaluations of MARAD information systems, including CMA, Initial Authorization, and on-site assessments. You will develop SAPs/SARs, review documentation, and ensure controls meet NIST requirements, collaborating with the ISSM and DOT guidelines.

The role requires a Public Trust clearance or the ability to obtain one, a related IT cybersecurity background, and experience with DOT/NIST processes.

Qualifications

  • Bachelor’s degree in Cybersecurity or IT field; experience can substitute for four years.
  • CISA or equivalent certification preferred.
  • Strong background in security assessments and RMF/NIST guidance.

Responsibilities

  • Assess MARAD systems in one of three states: Initial Authorization, Reauthorization, or CMA.
  • Provide annual assessment support to the NSMV and MARAD CIO programs, including on-site evaluations.
  • Conduct independent assessments following System Authorization processes per DOT guides.
  • Review core documentation to support SAPs and ATO dates.
  • Develop SAPs and SARs compliant with NIST SP 800-53A and SP 800-37.
  • Collaborate with the ISSM and document evidence of control implementation.
  • Enter assessment data into the CSAM database and present findings.

Skills

CISA
AAIA
Public Trust clearance
NIST knowledge

Education

Bachelor’s degree in Cybersecurity
Bachelor’s degree in IT field

Job description

Security Controls Assessor – Senior

This position requires an active Public Trust clearance or the ability to obtain a Public Trust clearance to be considered.

Compensation & Benefits

Pay commensurate with experience. $150,000 - $155,000

Full-time benefits include Medical, Dental, Vision, 401(k), and other possible benefits as provided. Benefits are subject to change with or without notice.

Security Controls Assessor – Senior Responsibilities Include
  • Assess MARAD systems in one of three states: Initial Authorization, Reauthorization, or Continuous Monitoring Assessment (CMA), also known as ongoing authorization. The Independent Assessor must be prepared to support each of these three authorization states.
  • Provide annual assessment support to the NSMV and MARAD CIO programs. NSMV assessment support will involve conducting on-site evaluations at the Philadelphia shipyard and other locations.
  • Conduct independent assessments of specified MARAD information systems following the System Authorization process defined in the current DOT Security Authorization and Continuous Monitoring Performance Guide and associated templates.
  • Review existing information-system core documentation, including privacy requirements and data, to support the development of security assessment plans and schedules supporting Authority to Operate (ATO) dates.
  • Review and establish annual assessment schedules in support of required deliverables and artifacts.
  • Identify noncompliance with security requirements and recommend possible mitigation strategies.
  • Validate the security requirements of information systems.
  • Verify that systems meet applicable security requirements.
  • Conduct independent and comprehensive assessments of management, operational, and technical security controls and control enhancements to determine their overall effectiveness.
  • Execute and analyze network and system assessments to validate appropriate security-control implementation.
  • Develop Security Assessment Plans and Security Assessment Reports compliant with the latest revisions of NIST Special Publication 800-53A, Assessing Security and Privacy Controls in Information Systems and Organizations, and NIST SP 800-37, Risk Management Framework for Information Systems and Organizations.
  • Develop Security Assessment Plans (SAPs) that clearly define the assessment scope, exclusions when necessary, controls being assessed, assessment methods, sampling methods, “determine if” statements, proposed schedules, assessment staff, targeted system endpoints and components, software inventories, processes, and the status of system-specific, hybrid, and inherited controls.
  • Follow the approved SAP when assessing security controls for targeted information systems.
  • Use approved techniques to collect and catalog supporting evidence, including documents, screenshots, scanning reports, and interview notes, to substantiate security-control implementation findings.
  • Develop Security Assessment Reports (SARs) according to the scope and schedule defined in the SAP. The SAR must document assessment findings and include evidence supporting the implementation status of each assessed control.
  • Develop and update qualitative Risk Assessment Reports (RARs) compliant with NIST SP 800-30, Guide for Conducting Risk Assessments.
  • Develop recommendation reports supporting Plan of Action and Milestones (POA&M) development. Reports must document findings and recommend actions and levels of effort for remediation.
  • Develop executive-summary documents and presentations that provide an overview of assessment activities, findings, risks, and mitigation recommendations.
  • Enter assessment data into the Cyber Security Assessment and Management (CSAM) database, DOT’s system of record for ATOs.
  • Provide presentations, reports, evaluations, reviews, meeting minutes, and working papers supporting all assigned tasks, as requested by the Contracting Officer’s Representative (COR).
  • Apply MARAD and DOT Assessment and Authorization guidance and policies to achieve program objectives and improve the overall quality of ATO packages.
  • Collaborate actively with the designated Information Systems Security Manager (ISSM).
  • Perform other job-related duties as assigned.
Security Controls Assessor – Senior Experience, Education, Skills, and Abilities Requested:
  • Bachelor’s degree in Cybersecurity or a related IT field may be substituted for four years of experience.
  • Bachelor’s degree in an IT-related field.
  • Certified Information Systems Auditor (CISA), Advanced in AI Audit (AAIA), or an equivalent certification.
  • Twelve years of related work experience.
  • Prior experience supporting U.S. Navy or Coast Guard maritime cybersecurity assessments.
  • Must possess or be able to obtain a Public Trust clearance.
  • Prior Department of Transportation experience is a plus.
  • Must pass Cherokee Federal’s pre-employment qualifications.
Company Information

Criterion is part of Cherokee Federal, the division of tribally owned federal contracting companies owned by Cherokee Nation Businesses. As a trusted partner for more than 60 federal clients, Cherokee Federal LLCs are focused on building a brighter future, solving complex challenges, and serving the government’s mission with compassion and heart. To learn more about Criterion, visit cherokee-federal.com.

Cherokee Federal is a military-friendly employer. Veterans and active-duty military members transitioning to civilian status are encouraged to apply.

Similar Searchable Job Titles
  • Senior Information Security Assessor
  • RMF Security Controls Assessor
  • Senior Cybersecurity Assessor
  • Information Assurance Assessor
  • ATO/RMF Lead Assessor
Keywords
  • Continuous Monitoring Assessment (CMA)
  • Risk Assessment
  • Security Assessment Plan (SAP)
  • Security Assessment Report (SAR)
  • Federal Cybersecurity
Legal Disclaimer

Cherokee Federal is an equal opportunity employer. Please visit cherokee-federal.com/careers for information regarding our Aff… statement and accommodation requests.

Many of our job openings require access to government buildings or military installations. Candidates must pass Cherokee Federal’s pre-employment qualifications.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Controls Assessor - Senior
Security Controls Assessor - Senior

Cherokee Federal • United States

On-site
USD 120,000 - 180,000
Medical
Dental
Vision
+1
Senior Security Controls Assessor – Public Trust Clearance
Senior Security Controls Assessor – Public Trust Clearance

Cherokee Federal • Almont (CO)

On-site
USD 150,000 - 155,000
Senior Cybersecurity Operations Analyst
Senior Cybersecurity Operations Analyst

Cherokee Federal • United States

On-site
USD 145,000 - 165,000
Information Security Analyst
Information Security Analyst

RiseMe • Washington

On-site
USD 86,000 - 105,000
Medical
Dental
Vision
+1
Senior Cybersecurity Operations Analyst
Senior Cybersecurity Operations Analyst

Cherokee Federal • Almont (CO)

On-site
USD 145,000 - 165,000
Project Lead/Senior Information System Security Specialist
Project Lead/Senior Information System Security Specialist

Cherokee Federal • Almont (CO)

On-site
USD 130,000 - 170,000
Medical insurance
Dental insurance
Vision insurance
+1
Cyber Security Control Assessor
Cyber Security Control Assessor

CACI International • Washington

On-site
USD 87,000 - 182,000
Flexible time off
Learning resources
Comprehensive benefits
Senior Cyber Analyst
Senior Cyber Analyst

Cherokee Federal • Quantico (VA)

On-site
USD 130,000 - 160,000
401(k) match
PTO
Medical insurance
+5
Information Security Analyst
Information Security Analyst

Cherokee Federal • Washington

On-site
USD 95,000 - 110,000
Medical insurance
Dental insurance
Vision insurance
+1
Security Control Assessor
Security Control Assessor

Caliber Systems Inc. • Denver (CO), Northern (KY)

Hybrid
USD 94,000 - 127,000