Security Control Assessor
Save this job and keep your search organized
Create a free account to save jobs, create alerts and return to this listing from your dashboard.
By continuing, you agree to our Terms & Privacy Policy.
DivIHN (pronounced “divine”) is a CMMI ML3-certified Technology and Talent solutions firm. Driven by a unique Purpose, Culture, and Value Delivery Model, we enable meaningful connections between talented professionals and forward-thinking organizations. Since our formation in 2002, organizations across commercial and public sectors have been trusting us to help build their teams with exceptional temporary and permanent talent.
Visit us at to learn more and view our open positions.
Location: Oak Ridge, TN
Duration: 12 Months
- Candidates must currently reside within 50 miles of the client site
- Candidates must have an ACTIVE DOE Q clearance OR an active equivalent clearance that can reciprocate to a Q.
- Client is looking for experienced Security Control Assessors supporting its Cybersecurity Program. These individuals will support RMF/system authorization activities, develop and maintain SSPs and POA&Ms, monitor security posture and vulnerabilities, coordinate remediation, assess the security impact of system changes, support continuous monitoring, and prepare systems for assessments, audits, and Authorizing Official reviews.
- A key deliverable is the delivery of System Security Plans to the client Field Office for Approval to Operate (ATO).
- Please prioritize candidates with hands-on experience taking systems through RMF and ATO processes, particularly candidates who have personally developed or maintained SSPs and POA&Ms.
- Candidates need a firm understanding of NIST SP 800-37 and NIST SP 800-53. CNSSI 1253 experience is a plus. We are looking for genuine system security/authorization experience, not simply general cybersecurity or SOC experience.
- Implements and maintains security controls aligned with approved baselines and organizational requirements.
- Supports system authorization activities, including the development and maintenance of security documentation such as System Security Plans (SSPs) and Plans of Action and Milestones (PO