Senior Security Controls Assessor

ECS Corporate Services

Fairfax (VA)

On-site

USD 160,000 - 190,000

Full time

8 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

ECS Corporate Services in Fairfax, VA is seeking an experienced Senior Security Assessor to lead and execute Security Assessment and Authorization activities across federal systems.

You will review artifacts (SSPs, SAPs, SARs, NIST SP 800-53, IRS 1075), assess control effectiveness, and present clear remediation guidance to technical and non-technical stakeholders, ensuring compliance with federal regulations and agency requirements.

Qualifications

  • Bachelor's degree or equivalent professional experience in cybersecurity/IT.
  • 7+ years hands-on experience conducting security control assessments and A&A in federal environments.
  • Active Public Trust clearance or ability to obtain one.
  • U.S. Citizenship required.
  • Preferred: CISSP, CISM, CISA certification.
  • Remote but within close proximity to the NCR.
  • Deep knowledge of NIST SP 800-53, NIST RMF, IRS Publication 1075, FedRAMP, OMB, and DHS standards.

Responsibilities

  • Review and maintain SA&A artifacts including IRS 1075 artifacts, SSPs, SAPs, and SARs.
  • Analyze hardware/software inventories, network diagrams and test reports to evaluate control effectiveness and gaps.
  • Develop enterprise-specific guidance to help system owners comply with NIST 800-53 and IRS 1075.
  • Present assessment findings and remediation recommendations to technical and non-technical stakeholders.
  • Review and update information security policies to align with federal regulations.
  • Conduct stakeholder interviews to document procedures and validate control implementations.
  • Analyze federal legislation and guidance to identify required policy updates.
  • Research emerging threats to support policy development and program improvements.
  • Serve as liaison between client personnel and assessment teams for timely issue resolution.
  • Assist in ongoing development of a comprehensive enterprise information security program.

Skills

Federal security compliance
NIST RMF
NIST SP 800-53
IRS Publication 1075
Security control assessments
Clear written communication
Policy development

Education

Bachelor's degree in Cybersecurity/IT/CS or related field

Job description

Position Responsibilities:
  • Support the review, assessment, and maintenance of Security Assessment and Authorization (SA&A) artifacts, including:
    • IRS Publication 1075 artifacts
    • FIPS 199, PTA, PIA
    • NIST SP 800-60 Digital Identity documentation
    • System Security Plans (SSPs)
    • Security Assessment Plans (SAPs) and Security Assessment Reports (SARs)
    • Information System Contingency Plans and Contingency Test Plans
    • Plans of Action & Milestones (POA&Ms)
  • Analyze hardware/software inventories, network diagrams, data flow diagrams, system change requests, vulnerability scan results, and test reports to evaluate control effectiveness and identify gaps.
  • Develop and deliver enterprise-specific implementation guidance to help system owners achieve and maintain compliance with NIST SP 800-53 , IRS Publication 1075, agency-specific control overlays.
  • Present assessment findings, control deficiencies, and remediation recommendations to both technical teams and non-technical stakeholders in a clear, actionable format.
  • Review, update, and maintain information security policies, standards, and procedures to ensure alignment with federal regulations and agency requirements.
  • Conduct stakeholder interviews to document procedures and validate the implementation of security and privacy controls.
  • Analyze federal legislation, OMB mandates, and NIST guidance to identify required policy updates and inform program improvements.
  • Research emerging technologies and threats to support the development of current, effective security and privacy policies, standards, and procedures.
  • Serve as a trusted liaison between client personnel and assessment teams, facilitating clear communication and timely issue resolution.
  • Assist in the development and continuous improvement of a comprehensive enterprise information security and privacy program grounded in the latest laws, regulations, and industry best practices.
Salary Range:

$160,000-190,000

General Description of Benefits
  • Active Public Trust clearance, or the ability to obtain and maintain one.
  • U.S. Citizenship required.
  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field or equivalent professional experience.
  • One of the following certifications or equivalent certifications preferred: Certified Information Systems Security Professional (CISSP) Certified Information Security Manager (CISM) Certified Information Systems Auditor (CISA)
  • 7+ years of hands-on experience conducting security control assessments and supporting Assessment & Authorization (A&A) activities within federal environments.
  • Remote but within close proximity to the NCR.
  • Deep knowledge of NIST SP 800-53, NIST RMF, IRS Publication 1075, FedRAMP, OMB, and DHS compliance standards and requirements.
  • Demonstrated experience planning and leading security control assessments as a senior team member.
  • Proven ability to translate complex technical findings into clear, non-technical language for executive and stakeholder audiences.
  • Strong written and verbal communication skills, with a track record of producing high-quality federal security documentation.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Specialist
Cybersecurity Specialist

Kaizen Lab Inc. • Charlotte (NC)

On-site
USD 120,000 - 180,000
Security Control Assessor
Security Control Assessor

Caliber Systems Inc. • Denver (CO), Northern (KY)

Hybrid
USD 94,000 - 127,000
Security Assessor (RMF / GRC)
Security Assessor (RMF / GRC)

Digital-Global-Connectors • McLean (VA)

Hybrid
USD 120,000 - 155,000
Information Systems Security Engineer SME
Information Systems Security Engineer SME

ECS Corporate Services • Huntsville (AL)

On-site
USD 155,000 - 168,000
SCA Lead
SCA Lead

Disruptive Solutions, LLC • Sterling (VA)

Hybrid
USD 150,000 - 190,000
Information Systems Security Engineer SME
Information Systems Security Engineer SME

ECS Corporate Services • Washington

On-site
USD 155,000 - 170,000
Top Secret clearance eligibility
US citizenship
Senior Security Controls Assessor (TS/SCI #26-143)
Senior Security Controls Assessor (TS/SCI #26-143)

Strategic Analysis, Inc. • Arlington (VA)

On-site
USD 120,000 - 180,000
CyberSecurity Analyst
CyberSecurity Analyst

Pitech Solutions, Inc. • Washington, Northern (KY)

Hybrid
USD 130,000 - 185,000
Information System Security Officer
Information System Security Officer

PlanIT Group, LLC • Reston (VA)

On-site
USD 120,000 - 150,000
Jr Cyber Security Eng
Jr Cyber Security Eng

GovCIO • San Antonio (TX)

On-site
USD 105,000 - 110,000