Security Control Assessor

3 weeks ago


Fort Meade, United States Athena Technology Group, Inc. Full time
Job DescriptionJob Description

Description/Job Summary

Security Control Assessor - Senior

Job Location: Fort Meade, MD

Position Type: Full Time, 40 hours per week

Athena Technology Group, Inc. is a Service-Disabled Veteran Owned /Small Business (SDVOSB) focused on Information Technology and Communications consulting, system engineering, integration, deployment and operations of stat of the art command and control and information systems that deliver critical network centric solutions to the warfighter. With a proven track record of technical support to our customers, we are looking for innovative industry professionals to join our team. Please contact info@athenatechgrp.com.

JOB DESCRIPTIONS:

Perform Security Control Assessments to determine the extent to which Information System security controls are implemented correctly, operating as intended, and producing the desired outcomes as stated in the DISA Information Assurance Requirements. Conducts independent comprehensive assessments of the management, operational, and technical security controls and control enhancements employed within or inherited by an information technology (IT) system to determine the overall effectiveness of the controls. Follow Assessment and Authorization procedures as defined in NIST 800-37 to complete comprehensive security control assessment and draft formal Security Assessment Reports (SAR) to document finding.

Tasks:

  • Plan and conduct security authorization reviews and assurance case development for initial installation of systems and networks.
  • Review authorization and assurance documents to confirm that the level of risk is within acceptable limits for each software application, system, and network.
  • Verify that application software/network/system security postures are implemented as stated, document deviations, and recommend required actions to correct those deviations.
  • Develop security compliance processes and/or audits for external services (e.g., cloud service providers, data centers).
  • Perform security reviews, identify gaps in security architecture, and develop a security risk management plan.
  • Verify and update security documentation reflecting the application/system security design features.
  • Ensure that plans of actions and milestones or remediation plans are in place for vulnerabilities identified during risk assessments, audits, inspections, etc.
  • Support necessary compliance activities (e.g., ensure that system security configuration guidelines are followed, compliance monitoring occurs).
  • Assess the effectiveness of security controls and assess all the configuration management (change configuration/release management) processes.

Desired skills:

  • Experience with RMF, CNSSI 1253, NIST SP 800-53, ICD 503
  • Experience with Security Technical Implementation Guides (STIGs) and Security Content Automation Protocol (SCAP) Compliance Checker (SCC)
  • Experience with utilizing Telos XACTA tool
  • Applies knowledge of Information Assurance Vulnerability Alerts (IAVAs)
  • Applies experience with compliance and vulnerability scanning tools (Nessus, McAfee ePO)
  • Conducts comprehensive security control assessments levied against a system and documenting the results, including recommendations for correcting any weaknesses or deficiencies in the controls
  • Develops a Security Assessment Report (SAR)
  • Conducts comprehensive reviews of security authorization documents to ensure the appropriate NIST security guidelines were used during the assessments and the selections of security controls are relevant to the confidentiality, integrity, and availability of the system
  • Performs security control assessments on cloud-based systems

Required Experience:

  • 10+ years of relevant experience as a cyber security control assessor or a MS with 5 years
  • Certification Requirements: IAM Level II, CAP or CCSP preferred
  • Education Requirement: B.S. or relevant experience in related field
  • Clearance Requirements: Active TS/SCI

US Citizenship and an active DOD TOP SECRECT/SCI Clearance are required for the position. Salary will be commensurate with experience. ATG is a growing company and there will be opportunities for internal advancement. ATG is an Equal Opportunity Employer.



  • Fort Meade, United States SNVC L.C Full time

    **INFORMATION SYSTEMS SECURITY OFFICER (ISSO) - SENIOR** Location: Fort Meade, MD Clearance: Secret PRIMARY RESPONSIBILITIES Become part of the SNVC team performing duties of ISSO. Responsible for administering, assuring and maintaining a unique communication system network to allow secure communication of critical mission data. Responsible for ensuring...


  • Fort Meade, United States Birchmere Group Full time

    Job DescriptionJob DescriptionSalary: Depends on Experience***You MUST already have a TS/SCI Clearance with a Polygraph to qualify***Delegated Authorizing Official Representative Level 3Responsible for assisting in identifying the overall security requirements for the protection of data, to ensure the implementation of appropriate information security...


  • Fort Meade, United States Birchmere Group Full time

    Job DescriptionJob DescriptionSalary: Depends on Experience***You MUST already have a TS/SCI Clearance with a Polygraph to qualify***Delegated Authorizing Official Representative Level 2Responsible for assisting in identifying the overall security requirements for the protection of data, to ensure the implementation of appropriate information security...


  • Meade, United States National Security Agency (NSA) Full time

    ResponsibilitiesDo you want to be at the forefront of strengthening our National Cybersecurity posture; do you want to do work you can't do anywhere else? Do you want to help chart the course for NSA's innovative Cybersecurity and help prevent future cyber-attacks against the United States? If so, NSA is the place for you Configuration Managers/Configuration...


  • Meade, United States National Security Agency (NSA) Full time

    ResponsibilitiesInformation System Security Professionals at NSA play a vital role in Security Architecture and Engineering, Communication and Network Security, Software Development Security, Security Operations, Identity and Access Management, Asset Security, and Security and Risk Management:Defining information system security requirements and...


  • Fort Meade, United States TechGuard Security Full time

    Job DescriptionJob DescriptionJob Description:Ensures the rigorous application of cybersecurity policies, principles, and practices in the delivery of all Information Technology (IT) and cybersecurity servicesDevelops and designs security solutions to maintain confidentiality, integrity, and availability of information throughout the enterpriseIdentifies,...


  • Fort Meade, United States Gridiron IT Full time

    GridIron IT is seeking a Cyber Security Operations Lead local to the Ft. Meade, MD area. Security Clearance: Secret Clearance PRIMARY RESPONSIBILITIES: •Lead a team of cybersecurity operations personnel consisting of security infrastructure specialists. •Operate and maintain security solutions and related technologies for clients. •Interface with...


  • Fort Meade, United States Gridiron IT Full time

    GridIron IT is seeking a Information Assurance - Systems Security Architect local to the Ft. Meade, MD area. Security Clearance: Secret or Top Secret Clearance PRIMARY RESPONSIBILITIES: •Possess, lead, and apply knowledge for the development of security solutions and architectures for clients. •Evaluate information assurance/security standards and...

  • Security Officer

    2 days ago


    Fort Lauderdale, United States Admiral Security Services Full time

    Overview: Admiral Security Services was established in 1976 and has consistently grown for over four decades. Today, we service hundreds of locations nationally, provide security coverage to millions of square feet of public and private facilities, and are one of the top 10 largest security companies in the United...

  • Cyber Security

    2 weeks ago


    Fort Meade, United States Y-Tech, LLC Full time

    Job DescriptionJob DescriptionCyber Security Assessment and Authorization (A&A) EngineerCyber Security/Information Assurance A&A Engineer is responsible for security processes and implementation supporting a large DoD customer on a new multi-year contract.   Position Overview: The A&A Engineer will perform, review, and conduct technical security...


  • Fort Meade, United States Buffalo Horse Inc Full time

    INFORMATION SECURITY SPECIALISTJOB DESCRIPTIONPosition Title: Information Security Specialist Employment Status: Full-Time, Salaried, Exempt Location: Ft Meade, Maryland Security Requirements: Active TS/SCI government security clearance Preference: Native American Preference, FBIC Veteran Preference POSITION SUMMARY: Buffalo Horse Inc. is seeking an...


  • Fort Meade, United States Birchmere Group Full time

    Job DescriptionJob DescriptionSalary: Depends on Experience***You MUST already have a TS/SCI Clearance with a Polygraph to qualify***IT Security Specialist Level 2Enable planning, coordination, and implementation of the organization’s information security. Identify current organizational security infrastructure, define future program requirements, and...


  • Fort Meade, United States Birchmere Group Full time

    Job DescriptionJob DescriptionSalary: Depends on Experience***You MUST already have a TS/SCI Clearance with a Polygraph to qualify***IT Security Specialist Level 3Enable planning, coordination, and implementation of the organization’s information security. Identify current organizational security infrastructure, define future program requirements, and...


  • Fort Meade, United States By Light Professional IT Services Full time

    Overview The Crestron Control System Programmer will provide daily operational support to the Defense Information Systems Agency (DISA) Headquarters at Ft. Meade, Maryland, with a primary focus on Crestron programming and system integration. Responsibilities Develop, program, and troubleshoot complex Crestron control systems for audio, video, switching,...


  • Fort Meade, United States By Light Professional IT Services Full time

    Overview The Crestron Control System Programmer will provide daily operational support to the Defense Information Systems Agency (DISA) Headquarters at Ft. Meade, Maryland, with a primary focus on Crestron programming and system integration. Responsibilities Develop, program, and troubleshoot complex Crestron control systems for audio, video, switching,...


  • Fort Meade, United States Zavda Technologies Full time

    ** IAES - Information System Security Officer - Senior** **Zavda Technologies, LLC Fort Meade, MD 20755** * Email Job * Share on Facebook * Share on Twitter **Information System Security Officer - Senior** **Clearance:** US Citizen with TS/SCI with Poly **Apply for this position:** Send a Microsoft Word copy of your resume to: HR@zavda.com **Job...


  • Fort Meade, United States Buffalo Horse Inc Full time

    PHYSICAL SECURITY SPECIALISTJOB DESCRIPTIONPosition Title: Physical Security Specialist Employment Status: Full-Time, Salaried, Exempt Location: Ft Meade, Maryland Security Requirements: Active TS/SCI government security clearance Preference: Native American Preference, FBIC Veteran Preference POSITION SUMMARY: Buffalo Horse Inc. is seeking a Physical...


  • Fort Meade, United States Buffalo Horse Inc Full time

    Job DescriptionJob DescriptionPHYSICAL SECURITY SPECIALISTJOB DESCRIPTIONPosition Title: Physical Security SpecialistEmployment Status: Full-Time, Salaried, ExemptLocation: Ft Meade, MarylandSecurity Requirements: Active TS/SCI government security clearancePreference: Native American Preference, FBIC Veteran PreferencePOSITION SUMMARY:Buffalo Horse Inc. is...


  • Fort Meade, United States Hoplite Solutions LLC Full time

    Hoplite Solutions is seeking Information Systems Security Engineers (ISSE) to join us on a contract being awarded in June 2024. The Information Systems Security Engineer will perform, or review, technical security assessments of computing environments to identify points of vulnerability, non-compliance with established Cybersecurity standards and...


  • Fort Meade, United States Hoplite Solutions LLC Full time

    Hoplite Solutions is seeking Information Systems Security Engineers (ISSE) to join us on a contract being awarded in June 2024. The Information Systems Security Engineer will perform, or review, technical security assessments of computing environments to identify points of vulnerability, non-compliance with established Cybersecurity standards and...