TS/SCI Security Control Assessor

Insight Global

Denver (CO)

On-site

USD 95,000 - 135,000

Full time

4 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Insight Global is seeking a Security Control Assessor (SCA) to support a federal customer in Denver, CO. The role focuses on independent assessments of security controls to ensure RMF compliance and cybersecurity readiness.

The ideal candidate has extensive RMF, ATO, and accreditation experience, with the ability to advise stakeholders and collaborate with cybersecurity teams across the program lifecycle. On-site support in Denver is required.

Qualifications

  • Hold TS/SCI clearance and a bachelor's degree.
  • Experience with RMF across all phases and ATO processes.
  • Proficient in POA&Ms, risk assessments, and accreditation support.
  • Experience with DoD/IC programs and FedRAMP cloud security.

Responsibilities

  • Conduct independent assessments of security controls per NIST SP 800-37 and RMF.
  • Review and validate accreditation/authorization packages supporting ATO.
  • Plan and execute security authorization reviews for new/existing systems and networks.
  • Evaluate security documentation, assessment results, and risk determinations for acceptable risk.
  • Identify security gaps and provide recommendations to improve posture.
  • Perform technical risk assessments and develop mitigation strategies.
  • Support development and maintenance of cybersecurity metrics, POA&Ms, and continuous monitoring.
  • Review implementation of controls and document deviations from configurations.
  • Participate in risk governance and provide risk mitigation recommendations.
  • Develop and maintain RMF documentation throughout the system lifecycle.
  • Support vulnerability management activities and remediation validation.
  • Assess cloud environments and supporting infrastructure for compliance.
  • Collaborate with technical teams on impact of new systems and interfaces.
  • Provide recommendations to support accreditation decisions and authorizations.

Skills

Strong written and verbal comms
Hands-on RMF experience
Experience briefing findings to leads
Risk-based decision making

Education

Bachelor's degree
IAM Level II or IAT Level II certification
CISSP, CAP, GSLC, CASP+ or equivalent

Tools

eMASS
XACTA
DISA STIG Viewer

Job description

Job Description

Insight Global is seeking a Security Control Assessor (SCA) to support a federal customer in Denver, CO. This individual will be responsible for conducting independent assessments of management, operational, and technical security controls within information systems and networks to ensure compliance with Risk Management Framework (RMF) requirements and overall cybersecurity readiness.

The ideal candidate will have extensive experience supporting Authorization to Operate (ATO) efforts, performing security assessments, developing accreditation documentation, and advising stakeholders on cybersecurity risk management. This position will work closely with cybersecurity, systems engineering, and program leadership teams to evaluate security posture, identify risks, and ensure compliance with federal security standards.

Responsibilities
  • Conduct independent assessments of security controls in accordance with NIST SP 800-37 and the Risk Management Framework (RMF).
  • Review and validate accreditation and authorization packages supporting ATO efforts.
  • Plan and execute security authorization reviews for new and existing systems and networks.
  • Evaluate security documentation, assessment results, and risk determinations to ensure acceptable risk levels.
  • Identify security gaps and provide recommendations to improve system security posture.
  • Perform technical risk assessments and develop mitigation strategies.
  • Support the development and maintenance of cybersecurity metrics, POA&Ms, and continuous monitoring activities.
  • Review and validate implementation of security controls and document any deviations from approved configurations.
  • Participate in risk governance activities and provide recommendations regarding cybersecurity risks and associated mitigations.
  • Develop and maintain RMF documentation throughout the system lifecycle.
  • Support vulnerability management activities and validate remediation plans.
  • Assess cloud environments, external services, and supporting infrastructure for compliance with security requirements.
  • Collaborate with technical teams to evaluate how new systems, interfaces, and technologies impact overall security posture.
  • Provide recommendations to support accreditation decisions and authorization activities.

We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment regardless of their race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or recruiting process, please send a request to HR@insightglobal.com. To learn more about how we collect, keep, and process your private information, please review Insight Global's Workforce Privacy Policy: https://insightglobal.com/workforce-privacy-policy/.

Skills and Requirements
  • TS/SCI Clearance
  • Bachelor's degree
  • IAM Level II or IAT Level II certification (Security+, CAP, CASP+, CISSP, or equivalent).
  • Hands-on experience supporting all phases of the Risk Management Framework (RMF).
  • Strong experience managing and supporting Authorization to Operate (ATO) processes.
  • Experience developing, tracking, and maintaining POA&Ms.
  • Experience performing technical risk assessments and accreditation support activities.
  • Experience with RMF Continuous Monitoring (ConMon) programs.
  • Experience using eMASS, XACTA, or similar RMF management tools.
  • Experience utilizing DISA STIG Viewer and applying STIG requirements.
  • Strong written and verbal communication skills. Experience supporting DoD or Intelligence Community programs.
  • Knowledge of DoDIN architecture and DISA cybersecurity guidance.
  • Familiarity with FedRAMP cloud security requirements.
  • Experience assessing cloud service providers or hybrid-cloud environments.
  • Experience supporting enterprise-level accreditation efforts.
  • CISSP, CAP, GSLC, CASP+, or equivalent advanced cybersecurity certification.
  • Experience briefing technical findings and risk recommendations to leadership.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Assessor (RMF / GRC)
Security Assessor (RMF / GRC)

Digital-Global-Connectors • McLean (VA)

Hybrid
USD 120,000 - 155,000
Security Assessor (RMF / GRC)
Security Assessor (RMF / GRC)

Digital Global Connectors • McLean (VA)

Hybrid
USD 110,000 - 160,000
Security Control Assessor
Security Control Assessor

SAIC • Springfield (VA)

On-site
USD 120,000 - 160,000
TS/SCI Security Control Assessor - RMF & ATO Expert
TS/SCI Security Control Assessor - RMF & ATO Expert

Insight Global • Denver (CO)

On-site
USD 95,000 - 135,000
Security Control Assessor
Security Control Assessor

System High Corporation • Chantilly (VA)

On-site
USD 120,000 - 160,000
Security Control Assessor SCA TSSCI
Security Control Assessor SCA TSSCI

Tau Six • Sully Square (VA)

On-site
USD 70,000 - 110,000
Security Control Assessor (SCA) (TS/SCI)
Security Control Assessor (SCA) (TS/SCI)

Tau Six, LLC • Sully Square (VA)

On-site
USD 80,000 - 110,000
Security Control Assessor
Security Control Assessor

Apavo Corporation • Arlington (VA)

On-site
USD 130,000 - 185,000
Security Controls Assessor (Pipeline)
Security Controls Assessor (Pipeline)

Electrosoft • Belleville (IL)

On-site
USD 90,000 - 120,000
SCA Lead
SCA Lead

Disruptive Solutions, LLC • Sterling (VA)

Hybrid
USD 150,000 - 190,000