Junior Security Control Assessor
$50,000–$60,000 year
HybridFort Meade, Maryland, United States
Job Summary
Conduct cybersecurity assessments, audits, and inspections for DoD organizations by evaluating systems using cyber threat emulation and performance-based testing. Coordinate logistics, test plans, and scope with the SCA Team Lead, then perform vulnerability assessments to capture results and document findings in eMASS. Analyze security gaps to provide mitigation recommendations and validate controls against RMF, STIGs, and DoD policies. Submit risk analysis and assessment results for authorization recommendations while participating in daily review, in-briefs, and out-briefs. This role requires 85% travel to government locations domestically and internationally, an active Secret clearance (with sponsorship to Top Secret/SCI), and DoD 8570 IAT II certification.
Required Qualifications
- Active Secret Clearance
- DoD Top Secret/SCI Clearance
- Interim Top Secret
- DoD 8570 IAT II
- Bachelor's degree in a related area of study
- 0-1 year of experience
- Willingness to train on both technologies and RMF
- Active DoD Top Secret clearance with SCI eligibility
- Active DoD Secret clearance
- IAT Level II certification
- Certification via the ACP IAW the ACP CONOPS
- Certification in a minimum of two (2) technologies
- RMF Control Validation certification
- 85% travel to various government locations
- Domestic and international travel
- Hybrid position with 25% remote support
- CONUS and OCONUS travel
- Active accounts to the tools and systems required to perform risk assessments
- Participation in the in-brief and out-brief of each assessment
- Strong written and verbal communication skills for reporting assessment findings
Desired Qualifications
- CompTIA Cybersecurity Analyst (CySA+)
- CompTIA Security
- EC-Council Certified Network Defense (CND) v3
- Red Hat Certified System Administrator (RHCSA)
- CCNA Security
- Global Industrial Cyber Security Professional (GICSP)
- GIAC Security Essentials (GSEC)
- Systems Security Certified Practitioner (SSCP)
- Familiarity with STIGs (Security Technical Implementation Guides)
- Familiarity with Security Requirement Guides (SRGs)
- Familiarity with Plan of Action and Milestones (POA&Ms)
- Familiarity with cybersecurity best practices
- Understanding of the RMF process
- Understanding of NIST SP 800- 37
- Understanding of NIST SP 800-53
- Understanding of CNSSI 1253
- Familiarity with eMASS
- Familiarity with STIG Viewer
- Familiarity with Nessus
- Familiarity with ACAS
- Familiarity with SCAP
- Familiarity with HBSS
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.