Security Control Assessor

2 months ago


Quantico, Virginia, United States U.S. Marine Corps Full time
The Security Control Assessor (SCA)
conducts independent comprehensive assessments of management, operational, and technical security controls and control enhancements employed within or inherited by a system to determine their overall effectiveness across MCCS
. Advises Chief Information Office (CIO), Authorization official (AO) and other stakeholders on risks associated with technology acquisition, maintenance and deployments and provides recommendations for initial or continued operation for the AO's consideration. Collaborates with other technology professionals to include cyber security, operations, cloud, business applications, project management office, etc.

Scope Of Responsibilities
Develop and maintain a comprehensive security assessment and monitoring program in-line with MCCS¿ Mission and business objectives. Manage and approve accreditation packages. Conduct security reviews, identify security gaps and develop a comprehensive risk management plan. Conduct risk analysis (e.g., threats, vulnerabilities, and probability of occurrence) whenever an application or system undergoes a major change. Plan and conduct security authorization reviews and assurance case development for initial installation of systems and networks.
Provides input to the Risk Management Framework (RMF) process activities and related documentation.

Review authorization and assurance documents to confirm that the level of risk is within acceptable limits for each technology solution.

Provide guidance regarding remediation and mitigation of identified vulnerabilities. Review remediation actions based on the findings and recommendations and performs reassessment of remediated controls. Develop security compliance processes and/or audits for external services (e.g., cloud service providers, data centers, etc.). Verify that security configurations are implemented as stated; document deviations and recommend actions to correct those deviations. Participate in Risk Governance process to provide security risks, mitigations, and input on other technical risks.

Determine the level of residual risk based on the overall effectiveness of the security program and provide authorization recommendations to the Authorization Official (AO).

Ensure that plans of actions and milestones (POA&M) or remediation plans are in place for vulnerabilities identified during risk assessments, audits, inspections, etc.

Ensure that security design and cybersecurity development activities are properly documented (providing a functional description of security implementation) and updated as necessary.

Support necessary compliance activities (e.g., ensure that system security configuration guidelines are followed, compliance monitoring occurs). Ensure that all acquisitions, procurements, and outsourcing efforts address information security requirements consistent with organization goals.
Skills and Knowledge

Strong interpersonal and communication skills (verbal and written) with the ability to relate to people at all levels in the organization.

Strong team leadership/collaborative leadership skills.

Ability to function in a collaborative environment, seeking continuous consultation with other analysts and experts¿both internal and external to the organization¿to leverage analytical and technical expertise.

Comfortable managing client relationships, including determining client needs/requirements, managing client expectations, and demonstrating commitment to delivering quality results.
Able to identify cybersecurity and privacy issues that stem from connections with internal and external customers and partner organizations.
Able to relate strategy, business, and technology in the context of organizational dynamics. Understands technology, management, and leadership issues related to organization processes and problem solving.

Able to communicate complex information, concepts, or ideas in a confident and well-organized manner through verbal, written, and/or visual means.

Ability to conduct vulnerability scans and recognize vulnerabilities in security systems.
Ability to dissect a problem and examine the interrelationships between data that may appear unrelated.
Ability to ensure security practices are followed throughout the acquisition process.
Knowledgeable in applying cybersecurity and privacy principles to organizational requirements (relevant to confidentiality, integrity, availability, authentication, non-repudiation).

Knowledgeable in determining how a security system should work (including its resilience and dependability capabilities) and how changes in conditions, operations, or the environment will affect these outcomes.

Able to troubleshoot and diagnose cyber defense infrastructure anomalies and work through resolution.
Proficient in applying cybersecurity and privacy principles to organizational requirements (relevant to confidentiality, integrity, availability, authentication, non-repudiation).

  • Quantico, Virginia, United States USAJobs Full time

    DutiesThe Security Control Assessor (SCA) conducts independent comprehensive assessments of management, operational, and technical security controls and control enhancements employed within or inherited by a system to determine their overall effectiveness across MCCS. Advises Chief Information Office (CIO), Authorization official (AO) and other stakeholders...

  • it specialist

    2 months ago


    Quantico, Virginia, United States U.S. Marine Corps Full time

    You will develop policies and procedures to ensure insider threat and security control assessor associated information systems reliability and accessibility and to prevent and defend against unauthorized access to systems, networks, and data. You will assist in the development of InTP and Security Control Assessor (SCA) systems security contingency plans and...

  • Security Officer

    1 day ago


    Quantico, Virginia, United States Chenega Corporation Full time

    Job SummaryThe Security Officer is responsible for performing access control screening functions of employees and visitors for Chenega Corporation owned or leased facilities. This role does not act in the capacity of a law enforcement officer and has no arrest or apprehension powers.Key ResponsibilitiesRequired to follow all company personnel and safety...


  • Quantico, Virginia, United States JCTM Full time

    Job OverviewThe Opportunity:The Marine Corps Warfighting Laboratory (MCWL) is at the forefront of developing advanced operational concepts and strategies. As the landscape of technology evolves, so does the need for robust security measures. This is where your expertise in security administration can make a significant impact.As a Security Administrator with...


  • Quantico, Virginia, United States Chenega MIOS SBU Full time

    Position Summary The Access Control Officer plays a crucial role in ensuring the safety and security of facilities owned or leased by the organization. This position is dedicated to conducting thorough access control screening for both personnel and visitors. It is important to note that Access Control Officers do not possess law enforcement authority and...


  • Quantico, Virginia, United States Chenega MIOS SBU Full time

    Position Summary The Access Control Officer plays a crucial role in overseeing the access control procedures for personnel and visitors at facilities managed by Chenega MIOS SBU. This position does not entail law enforcement duties and does not include any authority for arrests or detentions. Key ResponsibilitiesAdhere to all organizational policies and...


  • Quantico, Virginia, United States Intrepid Full time

    Being responsible for the screening of visitors with an X-ray machine and a metal detector.Operating access control databases, including the FBI's Phoenix, SOPU Gatekeeper visitor database, Scattered Castles and/or Defense Information System for Security (DISS) verifications as requested.Initiating personnel security background investigations and...


  • Quantico, Virginia, United States TEKsystems Full time

    The **Information Security Specialist** will be tasked with responsibilities related to **Assessment & Authorization (A&A)** to ensure that designated DoD and DoN systems, enclaves, and networks can secure and sustain **Authorization to Operate (ATO)** and **Authorization to Connect (ATC)** certifications. In this capacity, the **Information Security...


  • Quantico, Virginia, United States Chenega MIOS SBU Full time

    Position Summary The Access Control Officer plays a crucial role in overseeing the access screening processes for personnel and visitors at facilities managed by Chenega MIOS SBU. This position does not entail law enforcement duties and does not grant any arrest or apprehension authority. Key ResponsibilitiesAdhere to all organizational policies and safety...


  • Quantico, Virginia, United States The Tatitlek Corporation Full time

    Overview:This job specification outlines the various responsibilities and tasks associated with the role of a Security Officer. It is not intended to encompass every duty that may be performed.SUMMARY:The Security Officer is responsible for upholding regulations and protocols aimed at safeguarding premises from security breaches. This role requires sound...


  • Quantico, Virginia, United States Jacobs Full time

    Your Role:The Cybersecurity Systems Officer will play a crucial role in maintaining the operational security framework for assigned information systems or products. This position entails the daily implementation, supervision, and upkeep of security configurations, practices, and protocols for each product under the officer's responsibility, adhering to...


  • Quantico, Virginia, United States Jacobs Full time

    Your Role:The Cybersecurity Systems Protection Officer will play a crucial role in maintaining the necessary operational security posture for each designated information system or product. This position entails the daily execution, supervision, and upkeep of security configurations, practices, and protocols for each product under the officer's...


  • Quantico, Virginia, United States Obsidian Solutions Group LLC Full time

    Job OverviewLocation: Quantico, VASecurity Clearance: Top Secret with SCI eligibilityObsidian Solutions Group (OSG) is in search of a skilled Joint Aviation Command and Control Analyst to support the External Elements (EXELMS) division of MSTP. This role is pivotal in assisting with the design, planning, and execution of exercises at the MEF/MEB level.The...


  • Quantico, Virginia, United States Amentum Full time

    Job SummaryAmentum is seeking a highly skilled Aircraft Quality Control Inspector to join our team. As a key member of our quality assurance team, you will be responsible for ensuring the highest standards of quality and safety in our aircraft maintenance operations.Key ResponsibilitiesDevelop and implement quality control programs to ensure compliance with...


  • Quantico, Virginia, United States Obsidian Solutions Group LLC Full time

    Obsidian Solutions Group - Aviation Command and Control SpecialistObsidian Solutions Group (OSG) is in search of an Aviation Command and Control Specialist to assist in the design, planning, and execution of military exercises at the MEF/MEB level.Essential QualificationsU.S. Citizenship is requiredSecurity Clearance: Top Secret with SCI...


  • Quantico, Virginia, United States Obsidian Solutions Group LLC Full time

    Obsidian Solutions Group - Aviation Command and Control SpecialistObsidian Solutions Group (OSG) is looking for an Aviation Command and Control Specialist to support exercise design, planning, and execution at the MEF/MEB level.Key QualificationsU.S. Citizenship is requiredMust possess a Top Secret Security Clearance with SCI eligibilityExperience in the...


  • Quantico, Virginia, United States Booz Allen Hamilton Full time

    Position Overview:As a Senior Mobile Security Vulnerability Specialist, you will engage in the critical task of analyzing and fortifying mobile software against potential threats.Key Responsibilities:Conduct reverse engineering, along with both static and dynamic binary assessments, to identify vulnerabilities across various platforms and operating...


  • Quantico, Virginia, United States Amentum Full time

    Support Equipment Quality Control Specialist, Journeyman serves as a coordinator and single point of contact for SE related requirements. Provides advice on technical planning, conducting and reporting of SE in a specific project. Responsible for planning, identifying funding requirements and reporting financial status on all applicable projects. Supports SE...


  • Quantico, Virginia, United States USAJobs Full time

    DutiesThis position is a section supervisor within the Cyber Security and Compliance branch, Information Technology Directorate (MRI), NAF Business and Support Services Division (MR), Manpower and Reserve Affairs Department, Headquarters Marine Corps. Come join a team of professionals in a high energy family oriented setting serving Marines and their...


  • Quantico, Virginia, United States Obsidian Solutions Group LLC Full time

    Senior Joint Aviation C2 AnalystLocation: Quantico, VASecurity Clearance: Top Secret with SCI eligibilityObsidian Solutions Group is in search of a Senior Joint Aviation C2 Analyst to deliver expertise in the design, planning, and execution of exercises at the MEF/MEB level. This role is pivotal in preparing Marine Expeditionary Forces and Brigades for...