Lead Security Controls Assessor

3 weeks ago


Arlington, United States Tyto Athene, LLC Full time

Tyto Athene is searching for a Lead Security Controls Assessor to support our customer in Arlington, Virginia.


Responsibilities:

  • Support RMF steps 4 - assess, 5 - authorize, step 6 - monitor controls: conducting system security control assessments, supporting the system security authorization to operate process, and conducting annual assessments, respectively
  • Produce quality security assessment deliverables, ensuring the content of each deliverable is specific to the subject systems, are complete, and accurate
  • Develop and execute a security and privacy assessment plan for each security assessment project
  • Create and maintain security assessment test plans
  • Perform security testing at the control-requirement level for each unique component of each system (e.g., application, web application server, financial systems, database server/instance, operating systems, specialized appliances, network and infrastructure devices, and end-user devices (e.g., mobile phones, laptops, etc.)
  • Conduct technical content review and analysis of technical reports from security vulnerability scan, penetration test, and configuration compliance scan tools with respect to the subject system’s context and environment to analyze the findings accurately and completely
  • Analyze security tool reports and determine residual risk or false positives from technical reports and artifacts before assigning findings.
  • Document and provide findings and recommendations that are concise, system-specific, and actionable.
  • Perform and document client and system-specific risk analysis for each finding identified during each assessment in accordance with NIST SP 800-30, the client’s risk appetite, and the client’s security policies. The results of this risk analysis shall be documented in the Security Assessment Report (SAR) for assessed FISMA systems and a summary of the assessment results and risk shall be provided in the respective Assessment/Authorization Briefing.


Required:

  • Bachelor’s degree in Computer Science, Information Technology, or related field
  • 12 years of relevant experience
  • Thorough understanding and knowledge of FISMA and SA&A process
  • Core competencies in Information Assurance, Information System/Network Security, IT Assessment, Risk Management, System Testing and Evaluation, and Vulnerability Assessment
  • Ability to provide an assessment of the severity of weaknesses or deficiencies discovered in the information system and its environment of operation, and the ability to recommend corrective actions to address identified vulnerabilities
  • Knowledge of NIST SP 800-53 (Rev 4 & Rev 5) and NIST 800-137
  • Proficiency in writing technical analysis reports
  • Strong written and oral communication skills
  • Certified Information Systems Security Professional (CISSP) (required)


Desired:

  • Certified Information Security Manager (CISM) (optional but highly recommended)
  • Certified Authorization Professional (CAP), Certified Information Systems Auditor (CISA), Certified in Risk and Information Systems Control (CRISC)
  • Experience with IT ticketing systems (Jira, ServiceNow, Remedy, etc.) and eGRC tools (eMASS, Xacta, etc.)


Clearance: Active TS/SCI clearance required


Certification: DoD 8570 IAM/IAT Level III certification. This will change to a DoD 8140 equivalent once a DISA 8140 policy is released.


Location: This is an on-site role with expectations of being on the client site in Arlington, VA five days a week.



  • Arlington, United States The Newberry Group Inc Full time

    Who We Are... Today's leading government agencies are putting their trust in Newberry Group, and for good reason. Newberry brings strength to our clients, from the inside out through: •client intimacy and superior quality, •presence and accountability in our relationships, and •integrity and innovation at the forefront of everything we do. Newberry...


  • Arlington, United States Saliense Full time

    Who is Saliense? Saliense is a growing Management and Technology Consulting Solutions provider based out of Mclean, VA. We work to solve our clients toughest challenges within the Defense, Civilian, Financial, and Healthcare industries. Our diverse employees support vital missions for government and commercial customers. For more information, visit...


  • Arlington, United States Saliense Full time

    Who is Saliense?Saliense is a growing Management and Technology Consulting Solutions provider based out of Mclean, VA. We work to solve our client’s toughest challenges within the Defense, Civilian, Financial, and Healthcare industries. Our diverse employees support vital missions for government and commercial customers. For more information, visit...


  • Arlington, United States Saliense Full time

    Who is Saliense?Saliense is a growing Management and Technology Consulting Solutions provider based out of Mclean, VA. We work to solve our client’s toughest challenges within the Defense, Civilian, Financial, and Healthcare industries. Our diverse employees support vital missions for government and commercial customers. For more information, visit...


  • Arlington, United States SecuriGence LLC Full time

    Job Title: Security Control Assessor (SCA) Location: Arlington, Virginia Clearance Level: Top Secret Clearance Summary We deliver essential technology services to our customers in support of their missions to sustain the national security and economic interest of our nation. SecuriGence is seeking a talented Security Control Assessor to help contribute to...


  • Arlington, United States Tyto Athene, LLC Full time

    Job Description Tyto Athene is searching for a Senior Security Controls Assessor to support our customer in Arlington, Virginia. Responsibilities:Support RMF steps 4 - assess, 5 - authorize, step 6 - monitor controls: conducting system security assessments, supporting the system security authorization to operate process, and conducting annual assessments,...


  • Arlington, United States Tyto Athene, LLC Full time

    Tyto Athene is searching for a Senior Security Controls Assessor to support our customer in Arlington, Virginia.Responsibilities:Support RMF steps 4 - assess, 5 - authorize, step 6 - monitor controls: conducting system security assessments, supporting the system security authorization to operate process, and conducting annual assessments, respectivelyProduce...


  • Arlington, Virginia, United States Zermount, Inc Full time

    At Zermount, Inc., we are seeking a highly skilled IT Cybersecurity Risk Assessor to join our team. As an integral part of our organization, you will play a critical role in ensuring the security and integrity of our systems and data.About the RoleThe successful candidate will be responsible for conducting thorough risk assessments to identify potential...

  • Intake Assessor

    4 weeks ago


    Arlington, United States Universal Health Services, Inc. Full time

    Responsibilities Who We Are Millwood Hospital (a UHS affiliated hospital) is a 134-bed mental health facility that provides inpatient and outpatient mental health and chemical dependency treatment. Millwood‘s caring, and multidisciplinary staff has successfully provided inpatient and outpatient mental health and chemical dependency care to children,...


  • Arlington, Virginia, United States Johnson Controls Full time

    Job OverviewWe are seeking a skilled Electronic Security Systems Specialist to join our team at Johnson Controls in Arlington. This role involves conducting preventative maintenance, troubleshooting, and commissioning of integrated electronic security systems.Key Responsibilities:Conduct preventative maintenance, troubleshooting, and commissioning of...


  • Arlington, Texas, United States NextGen Security LLC Full time

    At NextGen Security LLC, we are seeking a skilled Senior Technician to join our team. This full-time position offers a competitive salary of $80,000 - $120,000 per year, based on experience.About the RoleThis senior-level role involves overseeing projects in the field, system programming, project activation and commissioning, installation of field devices,...


  • Arlington, Virginia, United States Kratos Defense & Security Solutions Full time

    About the RoleKratos Defense & Security Solutions is a leading provider of advanced technology solutions for national security, defense, and space exploration. We are seeking an experienced Guidance Navigation and Control (GNC) Software Engineer to join our team.Job DescriptionThe successful candidate will be responsible for designing and developing software...


  • Arlington, Virginia, United States Department of Homeland Security Full time

    Job OverviewA secure software engineer position is available at the Department of Homeland Security (DHS) Cybersecurity Service. The successful candidate will contribute to designing, building, and maintaining secure custom software critical to support and safeguard Departmental or Component mission spaces.About UsThe DHS Cybersecurity Service is a dedicated...


  • Arlington, Virginia, United States P-11 Security Inc Full time

    Job DescriptionP-11 Security Inc, a certified Economically-Disadvantaged Women-Owned Small Business (EDWOSB), is seeking a highly skilled Activity Security Representative III to provide multi-disciplined security support to our clients' facilities and organizations. The ideal candidate will possess 5-7 years of related experience and a Bachelor's degree or...


  • Arlington, Virginia, United States Concurrent Technologies Corporation Full time

    At Concurrent Technologies Corporation, we are seeking a seasoned cybersecurity expert to lead our efforts in industrial control systems. This is a critical role that requires exceptional leadership and technical skills.The ideal candidate will serve as the subject matter expert for our defense cybersecurity program, providing technical support and guidance...


  • Arlington Heights, United States Johnson Controls Full time

    Controls Systems Engineer at Johnson Controls summary: As a Controls Systems Engineer, I design and configure sophisticated building control systems for projects, ensuring adherence to project requirements. I am responsible for creating software programs, flow diagrams, and schematics while coordinating with field teams to guarantee efficient and timely...


  • Arlington, United States Credence company Full time

    Information Systems Security ManagerJob Locations US-VA-RosslynID 2024-8250Category OtherType Regular Full-TimeOverviewThe Information Systems Security Manager (ISSM) is responsible for implementing and overseeing cyber hygiene for all refugee operational activities within the Refugee Processing Center (RPC). Reporting directly to the Project Manager and...


  • Arlington, Virginia, United States Zermount, Inc Full time

    About the RoleWe are seeking a highly skilled Compliance Security Specialist to join our team at Zermount, Inc. This is a remote position with occasional on-site work required in Springfield, VA and Arlington, VA.Job SummaryThe Compliance Security Specialist will perform complex risk analyses, ensure systems and technologies satisfy Information Assurance...


  • Arlington Heights, Illinois, United States Johnson Controls Full time

    Job Description:Johnson Controls is seeking an experienced Strategic Sales Director to lead our sales team in driving growth, expanding customer relationships, and increasing bookings across our HVAC and Security lines of business.About the Role:This senior leadership position will be responsible for developing and executing sales strategies, coaching and...


  • Arlington, Virginia, United States Tyto Athene, LLC Full time

    About the OpportunityTyto Athene, LLC is searching for a Senior Security Controls Assessor to support our customer in Arlington, Virginia. This is an exciting opportunity to join a dynamic team and contribute to the success of our client.Key ResponsibilitiesSupport RMF steps 4 - assess, 5 - authorize, step 6 - monitor controls: conducting system security...