Security Control Assessor
$31,200–$31,200 year
On-siteArlington, Virginia, United States
Job Summary
Conduct comprehensive security control assessments of DoD information systems in accordance with NIST SP 800-53, DoD RMF policies, CNSSI 1253, and the JSIG. Evaluate control implementation, document findings and risks, and communicate government-approved mitigation requirements to system owners and technical stakeholders. Lead the review, preparation, and quality assurance of Authorization to Operate packages and Plans of Action and Milestones. Coordinate with system owners, security personnel, engineers, and government stakeholders throughout the assessment and authorization lifecycle. Provide leadership and technical guidance to assessment teams while resolving complex cybersecurity compliance issues.
Required Qualifications
- Bachelor's degree in cybersecurity, information technology, computer science, information systems, engineering, or a related field
- Eight or more years of professional experience in cybersecurity
- Five or more years of experience supporting Certification and Accreditation or Assessment and Authorization activities
- Expert-level knowledge of the DoD Risk Management Framework
- Strong working knowledge of NIST SP 800-37, NIST SP 800-53, CNSSI 1253, and the JSIG
- Experience conducting security control assessments and evaluating technical, operational, and management controls
- Experience reviewing and preparing ATO packages and supporting documentation
- Experience validating inherited controls and assessing Ports, Protocols, and Services requirements
- Demonstrated leadership experience, including previous experience serving in a lead or senior assessment role
- Strong written and verbal communication skills, with the ability to clearly explain technical findings, risks, and remediation requirements to system owners and government stakeholders
Desired Qualifications
- Experience supporting DoD Special Access Programs or other highly classified environments
- Experience working directly with system owners, ISSOs, ISSMs, security engineers, and Authorizing Official representatives
- Familiarity with security assessment reports, risk assessment reports, system security plans, POA&Ms, and continuous-monitoring documentation
- Experience leading assessment teams or overseeing multiple system authorization efforts
- Strong analytical, documentation-review, and quality-assurance skills
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.