Security Control Assessor, Mid

1 week ago


West Mclean, United States Booz Allen Full time $60,400 - $137,000
Security Control Assessor, Mid

Is this your next job Read the full description below to find out, and do not hesitate to make an application.

Key Role:

Conduct independent security control testing and assessments of the management, operational, and technical security controls to determine the overall effectiveness of security controls, based on the NIST Risk Management Framework (RMF). Technically assess both major application and general support system security configurations and implementation using manual and automated test methods. Provide an assessment of the severity of weaknesses or deficiencies discovered in the information system and its environment of operation and recommend corrective actions to address identified vulnerabilities. Develop and review SCA artifacts such as Security Assessment Plan (SAP), Security Assessment Reports (SAR) and System Security Plan (SSP).

Basic Qualifications:

3+ years of experience conducting NIST security control assessments on federal applications and general support systems (GSSs) to ensure compliance with the NIST SP 800-53 Rev. 4 and Rev. 5, NIST 800-37 Rev. 1 and Rev. 2, and agency-specific requirements

Experience assessing Web Application securely via security controls assessment and vulnerability and compliance scanning analysis

Experience assessing the security of cloud environments and cloud-hosted applications based on FedRAMP controls

Knowledge of cybersecurity principles used to manage risks for the use, processing, storage, and transmission of information or data

Knowledge of information technology (IT) security principles and methods such as firewalls, demilitarized zones, or encryption

Ability to obtain and maintain a Public Trust or Suitability/Fitness determination based on client requirements

HS diploma or GED

Security+ Certification

Additional Qualifications:

Experience with cyber governance, risk, and compliance (GRC) tools, and RMF steps 4-6 for federal applications and GSSs

Experience with Xacta a plus

Experience working with Plans of Action and Milestones (POA&Ms), including providing detailed vulnerability summaries and impacts and drafting risk mitigation strategies for identified risk

Experience conducting vulnerability assessments and analysis of vulnerability scan results with Nessus or related vulnerability scanning tools

Knowledge of network security architecture concepts including topology, protocols, components, and principles such as application of defense-in-depth

Knowledge of security principles for Industrial Control Systems (ICS)

Knowledge of security principles for IT infrastructure systems such as PKI, network appliances, intrusion detection and prevention systems, and firewalls

Possession of excellent verbal and written communication skills

Bachelor's degree in Computer Science, Information Technology, or Engineering preferred

CISSP, CISA, CAP, or GSNA certification preferred

Vetting:

Applicants selected will be subject to a government investigation and may need to meet eligibility requirements of the U.S. government client.

Compensation

At Booz Allen, we celebrate your contributions, provide you with opportunities and choices, and support your total well-being. Our offerings include health, life, disability, financial, and retirement benefits, as well as paid leave, professional development, tuition assistance, work-life programs, and dependent care. Our recognition awards program acknowledges employees for exceptional performance and superior demonstration of our values. Full-time and part-time employees working at least 20 hours a week on a regular basis are eligible to participate in Booz Allen’s benefit programs. Individuals that do not meet the threshold are only eligible for select offerings, not inclusive of health benefits. We encourage you to learn more about our total benefits by visiting the Resource page on our Careers site and reviewing Our Employee Benefits page.

Salary at Booz Allen is determined by various factors, including but not limited to location, the individual’s particular combination of education, knowledge, skills, competencies, and experience, as well as contract-specific affordability and organizational requirements. The projected compensation range for this position is $60,400.00 to $137,000.00 (annualized USD). The estimate displayed represents the typical salary range for this position and is just one component of Booz Allen’s total compensation package for employees. This posting will close within 90 days from the Posting Date.

Identity Statement

As part of the application process, you are expected to be on camera during interviews and assessments. We reserve the right to take your picture to verify your identity and prevent fraud.

Work Model
Our people-first culture prioritizes the benefits of flexibility and collaboration, whether that happens in person or remotely.

If this position is listed as remote or hybrid, you’ll periodically work from a Booz Allen or client site facility.
If this position is listed as onsite, you’ll work with colleagues and clients in person, as needed for the specific role.

EEO Commitment

We’re an equal employment opportunity/affirmative action employer that empowers our people to fearlessly drive change – no matter their race, color, ethnicity, religion, sex (including pregnancy, childbirth, lactation, or related medical conditions), national origin, ancestry, age, marital status, sexual orientation, gender identity and expression, disability, veteran status, military or uniformed service member status, genetic information, or any other status protected by applicable federal, state, local, or international law.

  • McLean, United States Maximus Full time

    General information Job Posting Title Security Control Assessor - I Date Friday, June 28, 2024 City Mclean State VA Country United States Working time Full-time Description & Requirements Maximus is seeking a Sr. Cyber Security Program Manager to support our customer out of Colorado Springs, Colorado.*This position is contingent upon award*...

  • Risk Assessor

    1 month ago


    McLean, United States LHH Full time

    Job Description:We are looking for a proactive and detail-oriented Supplier Risk Assessor. The ideal candidate will have experience in risk assessment, audit, and knowledge of SOC 1 and SOC 2 type reports.Key Responsibilities:Assess and analyze risks (technology, privacy security, resiliency, etc.).Evaluate supplier controls and document risk...

  • Risk Assessor

    1 month ago


    McLean, United States LHH Full time

    Job Description:We are looking for a proactive and detail-oriented Supplier Risk Assessor. The ideal candidate will have experience in risk assessment, audit, and knowledge of SOC 1 and SOC 2 type reports.Key Responsibilities:Assess and analyze risks (technology, privacy security, resiliency, etc.).Evaluate supplier controls and document risk...


  • West Point, New York, United States Mount Indie Full time

    Job DescriptionThe Cybersecurity and Server Administrator role at Mount Indie supports the USMA Cybersecurity Branch's mission and strategic direction. This position requires expertise in server configuration, administration, and security in both on-premises and Azure cloud environments.Key ResponsibilitiesAssess server vulnerabilities and provide mitigation...


  • McLean, United States Booz Allen Hamilton Full time

    Job Number: R0210136Project Controls Analyst, Mid The Opportunity: The right mixture of great ideas and attention to detail can create powerful change. In a complex organization, allocating resources to where they can be most effective can be a challenge. That's why we need you, an experienced financial analyst who can help support a team in navigating the...


  • McLean, United States Booz Allen Hamilton Full time

    Security Administrator, Mid Key Role: Perform a wide variety of security administrative duties to support industrial and program security requirements supporting multiple intelligence community (IC) customers. Process security clearance access requests, document reportable information, provide initial security briefings and debriefings, and prepare and...


  • McLean, United States Booz Allen Hamilton Full time

    Industrial Security Specialist, MidKey Role:Maintain responsibility for conducting daily security functions to ensure the protection of firm and government assets in accordance with contract policy and regulations. Provide technical security support to personnel in the areas of base threat analysis, information systems security, communications security...


  • McLean, United States Credence company Full time

    Overview: Credence Management Solutions LLC is looking for experienced ServiceNow Developer(s) to support an upcoming project with our federal customer. The successful candidate(s) should possess the core duties of both Junior and Mid-leveled ServiceNow developer, encompassing various aspects of development, security, collaboration, reporting, and...

  • Security Officer

    4 weeks ago


    McLean, United States Admiral Security Services Full time

    Admiral Security Services was established in 1976 and has consistently grown for over four decades. Today, we service hundreds of locations nationally, provide security coverage to millions of square feet of public and private facilities, and are one of the top 10 largest security companies in the United States.Now is your opportunity to join our...

  • Security Officer

    4 weeks ago


    McLean, United States Admiral Security Services Full time

    Admiral Security Services was established in 1976 and has consistently grown for over four decades. Today, we service hundreds of locations nationally, provide security coverage to millions of square feet of public and private facilities, and are one of the top 10 largest security companies in the United States.Now is your opportunity to join our...


  • McLean, United States Booz Allen Hamilton Full time

    Facilities Manager, MidKey Role:Maintain responsibility for managing day-to-day maintenance operations, including the inspection of living and work spaces to ensure a 100% safe and healthy environment for staff members. Provide regular inspections of safety equipment, including water purification, fire extinguishers, AEDs, and other health and safety...

  • Data Engineer

    4 weeks ago


    McLean, United States Sancorp Consulting LLC Full time

    Job DescriptionJob DescriptionData Engineer (Mid-Level) Position Summary: Position Description: Data Engineer (Mid-Level) Location: Falls Church, Alexandria, Arlington, VA Work Posture: Hybrid with 2-3 days onsite a week Travel: Some travel required Deployment: No Drug screening: Yes Security Clearance: Citizenship: TS clearance and must be able to achieve a...

  • Systems Architect

    4 weeks ago


    McLean, United States Sancorp Consulting LLC Full time

    Job DescriptionJob DescriptionSystems Architect (Mid-Level) Position Summary: Position Description: Systems Architect (Mid-Level) Location: Falls Church, Alexandria, Arlington, VA Work Posture: Hybrid with 2-3 days onsite a week Travel: Some travel required Deployment: No Drug screening: Yes Security Clearance: Citizenship: TS clearance and must be able to...

  • Security Specialist

    6 days ago


    McLean, United States Booz Allen Hamilton Full time

    Job Number: R0211312Industrial Security Specialist, MidKey Role:Maintain responsibility for conducting daily security functions to ensure the protection of firm and government assets in accordance with contract policy and regulations. Provide technical security support to personnel in the areas of base threat analysis, information systems security,...

  • Mid Java Developer

    2 months ago


    McLean, United States Hexaware Technologies Full time

    About the JobWhat Working at Hexaware offers:Hexaware is a dynamic and innovative IT organization committed to delivering cutting-edge solutions to our clients worldwide. We pride ourselves on fostering a collaborative and inclusive work environment where every team member is valued and empowered to succeed.Hexaware provides access to a vast array of tools...


  • McLean, United States Booz Allen Hamilton Full time

    Strategic Communications Specialist, MidThe Opportunity: The key to an organization’s growth is strong stakeholder communication that represents and supports its mission, values, and objectives. As a communications professional, you know how to inform and engage key audiences and help promote an organization’s preferred reputation. We’re looking for an...


  • McLean, United States Booz Allen Hamilton Full time

    ServiceNow Developer, MidThe Opportunity: As a low-code or no-code solution engineer, you know how to harness the latest technologies by developing low-code platforms and creating user-friendly solutions for your clients. We’re looking for an experienced solution engineer like you to support the management of low-code development platforms from vision to...


  • McLean, United States Booz Allen Hamilton Full time

    eMASS and RMF Training and Content DeveloperThe Opportunity:We're looking for a passionate, training and content developer to work with a fast-paced, highly collaborative software development team building and launching capability for Enterprise web-based systems in the Cybersecurity field. We build an Enterprise-web based application automating...


  • McLean, United States Harmonia Holdings Group, LLC Full time

    Harmonia Holdings Group, LLC, an award-winning federal government contractor, has an exciting opportunity for a Information Security Specialist to join our team. Essential Job Functions:Responsibilities include analysis, design, development, testing, data staging, and implementation activities.Responsible for delivering a high-quality application with a...


  • McLean, United States Inadev Full time

    *****MULTIPLE POSITIONS OPEN FOR MID (5+ YEARS OF EXP) AND SENIOR LEVEL (7+ YEARS OF EXP)**********MUST BE LOCATED IN THE DC/MD/VA METROPOLITAN AREA AND BE WILLING TO WORK A HYBRID SCHEDULE (MCLEAN, VA/RESTON, VA) TO BE CONSIDER**********MUST BE OPEN TO QUARTERLY DOMESTIC TRAVEL*****Formed in 2011, Inadev is focused on its founding principle to build...