Security Control Assessor

1 day ago

Oak Ridge, TN, United States DivIHN Integration Inc. Full-time

DivIHN (pronounced “divine”) is a CMMI ML3-certified Technology and Talent solutions firm. Driven by a unique Purpose, Culture, and Value Delivery Model, we enable meaningful connections between talented professionals and forward-thinking organizations. Since our formation in 2002, organizations across commercial and public sectors have been trusting us to help build their teams with exceptional temporary and permanent talent.

Visit us at to learn more and view our open positions.

Please apply or call one of us to learn more

For further inquiries regarding the following opportunity, please contact our Talent Specialist, Abdul at
 
Title: Security Control Assessor
Location: Oak Ridge, TN
Duration: 12 Months
 
Note: 
  • Candidates must currently reside within 50 miles of the client site
  • Candidates must have an ACTIVE DOE Q clearance OR an active equivalent clearance that can reciprocate to a Q.
Only W2 candidates are eligible for this position. Third-party or C2C candidates will not be considered.
 
 
Job Description:
 
Scope:
  • Client is looking for experienced Security Control Assessors supporting its Cybersecurity Program. These individuals will support RMF/system authorization activities, develop and maintain SSPs and POA&Ms, monitor security posture and vulnerabilities, coordinate remediation, assess the security impact of system changes, support continuous monitoring, and prepare systems for assessments, audits, and Authorizing Official reviews.
  • A key deliverable is the delivery of System Security Plans to the client Field Office for Approval to Operate (ATO).
Technical Experience
  • Please prioritize candidates with hands-on experience taking systems through RMF and ATO processes, particularly candidates who have personally developed or maintained SSPs and POA&Ms.
  • Candidates need a firm understanding of NIST SP 800-37 and NIST SP 800-53. CNSSI 1253 experience is a plus. We are looking for genuine system security/authorization experience, not simply general cybersecurity or SOC experience.
Knowledge, Skillset, and Abilities (KSAs)
  • Implements and maintains security controls aligned with approved baselines and organizational requirements.
  • Supports system authorization activities, including the development and maintenance of security documentation such as System Security Plans (SSPs) and Plans of Action and Milestones (PO