Security Controls Assessor - Senior

Sms-Data-Products-Group,-Inc

Springfield (VA)

On-site

USD 123,000 - 136,000

Full time

46 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

SMS DATA PRODUCTS GROUP, INC is seeking a Senior Security Controls Assessor and Validator to support the US Coast Guard in Alexandria, VA. You will lead a team, evaluate security controls, and apply RMF, NIST, and A&A processes across federal systems.

The role requires a DoD Secret clearance, extensive SA&A experience, and the ability to coordinate accreditation packages and ongoing assessments. On-site work in VA with federal clients is expected.

Qualifications

  • Active DoD Secret clearance required.
  • BA/BS or equivalent experience.
  • CSSP-AU: CEH/CySA+/CISA/PenTest+/GSNA or CFR within 60 days of hire.
  • DOD 8750 IAT III certifications: CASP+ CE, CCNP Security, CISA, CISSP (or assoc), GCED, GCIH, CCSP.
  • Experience with DoD, DHS or federal security SA&A processes and A&A documentation packages.

Responsibilities

  • Serve as senior member and lead internal resources to meet milestones.
  • Provide guidance, coaching and training to team members.
  • Plan and conduct security authorization reviews of federal systems.
  • Manage and review Accreditation Packages and POA&M remediation.

Skills

Active DoD secret clearance
RMF
NIST SP 800-53
SA&A
POA&M

Education

BA/BS or equivalent experience
DoD 8750 IAT III certifications

Tools

eMASS

Job description

Career Opportunities with SMS DATA PRODUCTS GROUP, INC


A great place to work.


Share with friends or Subscribe!


Are you ready for new challenges and new opportunities?


Join our team!


Current job opportunities are posted here as they become available.


Subscribe to our RSS feeds to receive instant updates as new positions become available.


SMS is seeking a Senior Security Controls Assessor and Validator to join our team supporting the United States Coast Guard in Alexandria, VA. The successful senior level candidate will be responsible for evaluating, testing, and validating the effectiveness of security controls, with a strong emphasis on applying the Risk Management Framework (RMF) and have experience in leading a team of Assessors.


Since 1976, SMS has specialized in modernizing legacy IT and sustaining complex enterprise environments for federal agencies. With the goal of building long-term partnerships with our customers, we invest in our employees by providing the training, tools, and support they need to keep critical missions operational, improve performance, and reduce risk. SMS is headquartered in McLean, Virginia, with offices and on-site operations at customer locations throughout the United States. For additional information on SMS, visit www.sms.com .


Job Responsibilities


  • Serve as senior member and representative of assigned team for meetings and efficiently lead internal resources to meet established milestones and targeted completion dates.

  • Provide guidance, coaching and training to employees of assigned team.

  • Assist in Security Assessment & Authorization Coordination

  • Plan and conduct security authorization reviews of federal systems

  • Manage and review Accreditation Packages

  • Support USCG system accreditation and Ongoing Assessment and Ongoing Authorization processes and activities for assigned systems.

  • Provide SME knowledge of Risk Management Framework (RMF) policy and application, NIST Security Controls, and Control Implementation methodologies for the A&A process.

  • Review and provide guidance on System Security Plan, Security Assessment Report (SAR), and Plans of Action and Milestones and other security documentation

  • Support POA&M remediation activities and the review of POA&M closure documentation.

  • Responsible for assessing and developing authorization packages for technical solutions that may require collaboration with internal expertise and deep analysis of the technical solution.

  • Collaborate and communicates with parties within, and outside, of own job function. May have responsibility for communicating with parties external to the organization (e.g., customers, vendors)

  • Understands and supports Privacy Compliance Activities to include the review of Privacy Impact Analysis (PIA), Privacy Threshold Analysis (PTA), and Statement of Record Notices (SORN).

  • Facilitates and monitors information assurance (IA) processes for new projects, including the development of security authorization packages and the tracking of progress for all Security Control implementations and Plans of Action and Milestones (POA&M).

  • Support and/or development of all Security Authorization artifacts and documentation and assembling of Authorization packages.

  • Responsible for administration and adherence of the Risk Management Plan.

  • Coordinate closely with the Quality Assurance Specialists in identifying and mitigating risk to meet established quality standards.


Required Qualifications


  • Minimum of an active DoD Secret clearance required

  • University Degree (BA/BS) or equivalent experience and minimum 5 years related work experience

  • CSSP-AU: CEH, CySA+, CISA, PenTest+, GSNA, or CFR . Within 60 days of hire.

  • DOD 8750 IAT III certifications: CASP+ CE, CCNP Security, CISA, CISSP (or associate), GCED, GCIH, or CCSP

  • Relevant DOD, DHS or .gov Cyber Security Information Assurance focused experience with specific current hands‑on experience researching, writing, and submitting complete A&A documentation packages for new system authorizations.

  • Well‑developed understanding of Federal Civilian or DHS Security Assessment and Authorization (SA&A) processes.

  • Experience with continuous monitoring/ongoing authorization

  • Intimate understanding of NIST RMF implementation guidance.

  • In‑depth understanding of the relevance of NIST Security Controls and Control Implementation methodologies to the SA&A process.

  • Experience assessing security controls based on cybersecurity principles and tenets. (e.g., NIST SP 800-53, Cybersecurity Framework, etc.).

  • Demonstrated understanding of critical documentation required in Security Authorization (SA) Packages.

  • Ability to understand and support Privacy Compliance Activities to include the development of Privacy Impact Analysis (PIA), Privacy Threshold Analysis (PTA), and Statement of Record Notices (SORN).

  • Experience managing client relationships, including determining client needs/requirements, managing client expectations, and demonstrating commitment to delivering quality results.

  • Experience analyzing strategic guidance for issues requiring clarification and/or additional guidance.

  • Understanding of the basic concepts and issues related to cyber and its organizational impact.

  • Experience as senior or lead member of a team, including experience coaching and providing guidance to less experienced or new team resources, reviewing work products, tracking deadlines, and coverage, reporting, facilitating onboarding / offboarding procedures, etc.

  • Experience with administrative planning activities, to include preparation of functional and specific support plans and preparing and managing correspondence.

  • Understanding of Cloud Services delivery models and how each delivery model influences the Assessment and Authorization process.


Desired Qualifications


  • Well‑developed understanding of Systems Development Lifecycle (SDLC) and ideally the DHS Systems Engineering Lifecycle (SELC) process as it relates to Security Assessment and Authorization (SA&A)

  • Hands on experience with eMASS or similar application


Salary Range

$123,000 - 136,000


SMS is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Controls Assessor - Senior
Security Controls Assessor - Senior

SMS Data Products Group, Inc. • Springfield (VA)

On-site
USD 120,000 - 160,000
Information Assurance Security Analyst
Information Assurance Security Analyst

SMS Data Products Group, Inc. • Del Rio (TX)

On-site
USD 90,000 - 120,000
Information Assurance Security Analyst
Information Assurance Security Analyst

SMS Data Products Group, Inc. • San Antonio (TX)

On-site
USD 85,000 - 120,000
Security Control Assessor
Security Control Assessor

SAIC • Springfield (VA)

On-site
USD 120,000 - 160,000
Information Systems Security Manager ISSM
Information Systems Security Manager ISSM

Kms-Solutions,-LL • Alexandria (VA)

On-site
USD 130,000 - 160,000
Medical insurance
401k / retirement savings plan
Paid time off (PTO)
+3
Information Systems Security Manager ISSM
Information Systems Security Manager ISSM

KMS Solutions, LLC • Alexandria (VA)

Hybrid
USD 130,000 - 160,000
Medical insurance
Dental insurance
Vision insurance
+8
Information Specialist, Mid
Information Specialist, Mid

SMS Data Products Group, Inc. • McLean (VA)

On-site
USD 90,000 - 130,000
IT Security Specialist
IT Security Specialist

Kms-Solutions,-LL • Alexandria (VA)

On-site
USD 110,000 - 140,000
Medical, dental, vision insurance
401k / Retirement plan
Paid time off
+2
Security Control Assessor
Security Control Assessor

System High Corporation • Chantilly (VA)

On-site
USD 120,000 - 160,000
Security Controls Assessor
Security Controls Assessor

ECS • Washington

Hybrid
USD 150,000 - 168,000