Security Control Assessor Program Lead
1 month ago
Responsibilities
- Manage a team of 4 Security Control Assessors.
- Develop a plan to manage and perform the SA&A activities for all customer information systems.
- Support the transition from NIST Special Publication 800-53, Revision-4 to Revision-5.
- Develop a NIST 800-53 rev5 implementation plan that will bring the customer in compliance with rev5 within 2 years.
- Prepare plans for completing system assessments, continuous monitoring, and security assessments. The contractor shall be responsible for managing resources to meet changing requirements and presenting any impact of resource allocation on current project schedules to the customer.
- The contractor shall assist the customer in planning, documenting, and implementing an efficient and effective SA&A process. Including recommending and documenting process tailoring to provide assessments that are appropriate to the system type (Parent, Child, Major, Minor and Cloud systems) and security impact, maximizing use of common controls, standardization, and other methods to achieve this goal.
- Support the assessment software request by customer end users that may not constitute a system using customers established Desktop Application Checklist (DAC) process. Prepare plans to assess the management, operational, and technical security controls in the information system using methods listed in National Institute of Standards and Technology (NIST) SP 800-53A and additional assessment methods and procedures as required utilizing the GRC solution when appropriate.
- Plans shall include evaluation of contingency plans, configuration management plans, security configuration checklists, and interconnection security agreements for compliance with NIST, and customer guidance.
- Document the security control implementation, as appropriate, in the security plan, providing a functional description of the control implementation (including planned inputs, expected behavior, and expected outputs). Security control documentation shall describe how system-specific, hybrid, and common controls are implemented.
Basic Qualifications:
- At least 3 years' experience as a team lead or manager, with 5 years of related security controls experience.
- Possess experience and working knowledge of preparing security test and evaluation reports, testing and validating security controls are implemented correctly and working as intended.
- Bachelor’s degree in computer science, IT or related discipline
- CISSP or equivalent certification is required (i.e. CISM, CAP, CGRC, etc.)
-
Security Control Assessor
2 weeks ago
Washington, United States Booz Allen Hamilton Full timeJob Number: R0210761Security Control Assessor, MidKey Role:Conduct independent security control testing and assessments of the management, operational, and technical security controls to determine the overall effectiveness of security controls, based on the NIST Risk Management Framework (RMF). Technically assess both major application and general support...
-
Security Control AssessorValidator
4 weeks ago
Washington, United States Information Systems Solutions Full timeSecurity Control Assessor/Validator Information Systems Solutions (ISS) is looking for a Security Control Assessor/Validator supporting the Office of Naval Intelligence. Why Work For ISS? At ISS we pride ourselves on providing an employee-focused and family first environment. Being a small business, we take the time to get to know our employees and have a...
-
Federal Grant Program Assessor
2 days ago
Washington, Washington, D.C., United States Corner Alliance Full timeFederal Grant Program AssessorJob Description:Corner Alliance is a dynamic consulting firm that provides meaningful services to the government. We are seeking a Federal Grant Program Assessor with 6+ years of experience to assess the effectiveness and efficiency of federal grant programs, policies, and organizations.Key Responsibilities:Develop and lead...
-
Cybersecurity Governance Program Director
4 weeks ago
Washington, Washington, D.C., United States Electrosoft Full timeAbout the RoleWe are seeking an experienced Cybersecurity Governance Program Director to lead our team of Security Control Assessors at Electrosoft.Job SummaryThe successful candidate will be responsible for managing a team of 4 Security Control Assessors and developing plans to manage and perform SA&A activities for all customer information systems.Key...
-
Security Controls Specialist
18 hours ago
Washington, Washington, D.C., United States The Swift Group Full timeJob Title: Security Controls SpecialistJob Summary:The Swift Group is seeking a highly skilled Security Controls Specialist to join our team. As a Security Controls Specialist, you will be responsible for conducting verification and validation of security compliance for all information systems, products, and components.Key Responsibilities:Conduct...
-
Security Control Assessor Support Expert
24 hours ago
Washington, Washington, D.C., United States Avint Full timeAbout the Opportunity:Join Avint as an Information Assurance Security Manager and contribute to our team's success in Washington, DC and Tysons Corner, VA. As an expert in security control assessment, you will ensure the effectiveness of IT system controls and guide our team towards compliance with NIST SP 800-37 guidelines.Key Responsibilities:Design and...
-
Expert Disability Assessor for Veterans
4 weeks ago
Washington, Washington, D.C., United States MRG Exams Full timeAt MRG Exams, we are committed to providing exceptional services to our nation's veterans. We are currently seeking a highly skilled Licensed Psychologist to join our team as an Expert Disability Assessor.Company OverviewMRG Exams is a leading provider of Independent Medical Exams for Worker's Compensation, Disability, and the Veterans Administration. With...
-
Washington, Washington, D.C., United States NTT DATA Full timeAbout the RoleWe are seeking a highly skilled Cyber Security Assessment and Authorization Analyst to join our team in Rockville, Maryland. As a Senior Security Control Assessor, you will play a critical role in supporting federal clients obtain authority to operate (ATO) for new and modernized systems.Key ResponsibilitiesSupport assessment and authorization...
-
Information Security Specialist
6 days ago
Washington, Washington, D.C., United States Avint Full timeJob OverviewAvint LLC is seeking a highly skilled Information Security Specialist to join our team in Washington, DC and Tysons Corner, VA. As a Security Control Assessor Support Expert, you will conduct comprehensive assessments of security controls and provide strategic materials for executive management and other stakeholders.Salary: $110,000 - $125,000...
-
Construction Security Lead
4 days ago
Washington, Washington, D.C., United States Control Risks Full timeResponsibilitiesDevelop and Implement Security Strategies: Design and execute a comprehensive security plan to safeguard the company's people and assets.Conduct Security Audits: Conduct initial security audits to identify areas for improvement and understand current roadblocks to success.Review and Improve Security Plans: Review, develop, and improve the...
-
Cloud Security Architect Lead
4 weeks ago
Washington, Washington, D.C., United States Improvix Technologies Full timeAbout Improvix Technologies:We are a technology company focused on delivering innovative solutions to support the Department of State's multi-cloud platforms.Job Summary:We are seeking a highly experienced Cloud Security Architect Lead with an active Secret Clearance to lead our team in supporting the secure deployment of applications and infrastructure...
-
Cloud Security Assessor
7 months ago
Washington, United States Chickasaw Nation Industries, Inc. Full timeIt's fun to work in a company where people truly BELIEVE in what they're doing! We're committed to bringing passion and customer focus to the business. ****** Required DOD Secret or Top-Secret Clearance ******* SUMMARY The Cloud Security Assessor / Information Assurance Analyst provides support to the agency. This position provides advanced...
-
Cyber Security Solutions Architect
7 days ago
Washington, United States SAIC Full timeJob OverviewWe are seeking a highly skilled Cyber Security Solutions Architect to join our team at SAIC in Washington, DC. This is a hybrid remote position that requires regular SIPR network connectivity.About the RoleThis role will support the Secret and Below Releasable Environment (SABRE) program in the Air Force Cloud One Common Computing Environment...
-
Clinical Assessor
6 months ago
Washington, United States Acentra Health Full timeCNSI and Kepro are now Acentra Health! Acentra Health exists to empower better health outcomes through technology, services, and clinical expertise. Our mission is to innovate health solutions that deliver maximum value and impact. Lead the Way is our rallying cry at Acentra Health. Think of it as an open invitation to embrace the company's mission, actively...
-
Cyber Security Program Lead
4 weeks ago
Washington, Washington, D.C., United States GMG Management Consulting Full timeJob OverviewWe are seeking an experienced Cyber Security Program Lead to join our team at GMG Management Consulting. As a key member of our organization, you will play a critical role in leading efforts to protect and secure our cyber infrastructure.
-
Enterprise Security Compliance Specialist
23 hours ago
Washington, Washington, D.C., United States The Swift Group Full timeWe are seeking an experienced professional to conduct verification and validation for security compliance of all information systems, products, and components.Key ResponsibilitiesConduct on-site evaluations and validate security requirementsIdentify and provide recommendations for non-compliance issues and potential mitigationsCoordinate penetration testing...
-
Chief Security Strategist
4 weeks ago
Washington, Washington, D.C., United States Control Risks Full timeJob Overview">Control Risks is seeking a seasoned Senior Security Manager to support a major Energy client for a 6-month contract. This role will act as the client's Security Manager for an onsite construction project in DC, to develop and implement a comprehensive security plan to support the company through the finish of construction into daily...
-
Security Systems Development Lead
2 days ago
Washington, Washington, D.C., United States CPI Security Full timeCPI Security is seeking a results-driven Residential Sales Manager to lead our sales team and drive growth in the residential security market.About the Role:This role offers a unique opportunity to leverage your sales expertise and leadership skills to deliver exceptional results and build a high-performing sales team.Key Responsibilities:Manage the assigned...
-
Cyber Security Risk Management Specialist
4 weeks ago
Washington, United States Control Risks Full timeWe are expanding our cyber security team at Control Risks. Our team provides strategic and technical consulting to clients worldwide, helping them reduce risk, secure their information, and respond effectively to incidents.We seek seasoned professionals with a passion for assisting global businesses in securing their operations and managing cyber risk.**Key...
-
Security Design Strategist
4 days ago
Washington, Washington, D.C., United States Control Risks Full timeJob OverviewWe are seeking a skilled Protective Design Specialist to join our team at Control Risks. This exciting role offers the opportunity to shape the future of security for high-profile individuals and organizations.In this dynamic position, you will combine your security expertise with cutting-edge design principles to create robust protective...