Security Controls Specialist

2 days ago


Washington, United States Coalfire Federal Full time
Job Title: Security Controls Assessor

Coalfire Federal is a leading cybersecurity consultancy firm that provides independent and tailored advice, assessments, technical testing, and a full suite of cyber engineering services to Federal agency customers. With an unparalleled client list and deep customer relationships with leading cloud and technology providers, Coalfire Federal is committed to making the world a safer place by solving our clients' toughest security challenges.

Job Summary

We are seeking a highly skilled Security Controls Assessor to support our Federal team. As a Security Controls Assessor, you will facilitate Security Control Assessments (SCAs) and possibly other advanced-level Continuous Monitoring Activities within cloud-based environments.

Key Responsibilities
  • Perform security reviews, identify gaps in security architecture, and develop a Security Assessment Plan and Security Assessment Report.
  • Plan and conduct security authorization reviews and assurance case development for initial installation of systems and networks.
  • Provide input to the Risk Management Framework process activities and related documentation.
  • Provide weekly updates on assessment status.
  • Review authorization and assurance documents to confirm that the level of risk is within acceptable limits for each software application, system, and network.
  • Verify that application software/network/system security postures are implemented as stated, document deviations, and recommend required actions to correct those deviations.
  • Participate in Risk Governance process to provide security risks, mitigations, and input on other technical risk.
  • Ensure that plans of actions and milestones or remediation plans are in place for vulnerabilities identified during risk assessments, audits, inspections, etc.
  • Ensure that security design and cybersecurity development activities are properly documented and updated as necessary.
  • Assess the effectiveness of security controls.
  • Assess all the configuration management (change configuration/release management) processes.
Requirements
  • Computer networking concepts and protocols, and network security methodologies.
  • Risk management processes (e.g., methods for assessing and mitigating risk).
  • Laws, regulations, policies, and ethics as they relate to cybersecurity and privacy.
  • Cybersecurity and privacy principles.
  • Cyber threats and vulnerabilities, including application vulnerabilities.
  • Specific operational impacts of cybersecurity lapses.
  • Authentication, authorization, and access control methods.
  • Applicable business processes and operations of customer organizations.
  • Capabilities and applications of network equipment including routers, switches, bridges, servers, transmission media, and related hardware.
  • Cyber defense and vulnerability assessment tools and their capabilities.
  • Server administration and client operating systems engineering theories, concepts, and methods.
  • System software and organizational design standards, policies, and authorized approaches (e.g., international organization for standardization [iso] guidelines) relating to system design.
  • System life cycle management principles, including software security and usability.
Education and Experience
  • Completed Bachelors degree from an accredited university, preferably in an IT related field.
  • At minimum 5+ years of hands-on work experience with Assessor (SCA) duties; performing systems security assessments, preparing system security documentation, and/or performing security upgrades for live networks, desktop systems, servers, and enterprise data bases leading to successful security authorization of such systems.
Preferred Qualifications
  • Knowledge of GRC tools e.g., Xacta.
  • Knowledge of the NIST Cybersecurity Framework.
  • Cloud and or engineering related certifications.
Why Coalfire Federal?

Our people make Coalfire Federal great. We work together on interesting things and achieve exceptional results. We act as trusted advisors to our customers and are committed to client-focused innovation as well as innovation in the industries that we serve. Coalfire offers our people the chance to grow professionally with colleagues they like and respect while tackling challenges that stretch their minds and expand their skill sets. Regardless of location, you'll experience a company that prioritizes connection and wellbeing and be part of a team where people care about each other and our communities. You'll have opportunities to join employee resource groups, participate in in-person and virtual events, and more. You'll enjoy competitive perks and benefits to support you and your family, like paid parental leave, flexible time off, certification and training reimbursement, digital mental health and wellbeing support memberships, and comprehensive insurance options.

Coalfire is an EEO employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.



  • Washington, United States CONDOR SECURITY CONSULTING INC Full time

    Job DescriptionJob DescriptionThe Quality Control Specialist will be responsible for ensuring the accuracy and completeness of all security-related paperwork and the proper handling and maintenance of weapons. This role is crucial in maintaining the highest standards of security and compliance within our organization. Seeking a candidate with a Minimum of...


  • Washington, United States Insight Global Full time

    Job SummaryWe are seeking a highly skilled Security Control Specialist to join our team at Insight Global. As a Security Control Specialist, you will be responsible for conducting security control assessments of all NIST controls and providing recommendations for corrective actions.Key ResponsibilitiesConduct security control assessments based on a Risk...


  • Washington, United States Securitas Electronic Security Full time

    Job Title: Security Systems SpecialistSecuritas Technology, a leading provider of integrated security solutions, is seeking a skilled Security Systems Specialist to join our team. As a Security Systems Specialist, you will be responsible for providing technical support and maintenance for our security systems, ensuring the highest level of security and...


  • Washington, United States Securitas Electronic Security Full time

    Job Title: Security Systems SpecialistSecuritas Technology, a leading provider of integrated security solutions, is seeking a skilled Security Systems Specialist to join our team. As a Security Systems Specialist, you will be responsible for providing technical support and maintenance for our security systems, ensuring the highest level of security and...


  • Washington, United States Paragon Security Systems Full time

    Job Title: Armed Security SpecialistThis position involves overseeing security operations at a prominent site under the guidance of the Security Manager. The role encompasses a variety of security-related responsibilities.As an armed security specialist, your primary duties will include monitoring and reporting activities at designated locations, ensuring...


  • Washington, Washington, D.C., United States ST2 ManTech Advanced Systems Intl Full time

    Exciting Opportunity at ST2 ManTech Advanced Systems IntlWe are seeking a dedicated and skilled Security Controls Specialist to join our team at ST2 ManTech Advanced Systems Intl. As a leading provider of advanced systems and solutions, we prioritize our employees and offer a dynamic work environment with opportunities for growth and advancement.Key...


  • Washington, United States Securitas Electronic Security Full time

    Job Title: Security Solutions SpecialistSecuritas Technology, a leading provider of integrated security solutions, is seeking a technically skilled individual to fill this role. As a Security Solutions Specialist, you will be responsible for delivering exceptional service to our clients, ensuring the smooth operation of their security systems, and providing...


  • Washington, United States Securitas Electronic Security Full time

    Job Title: Security Solutions SpecialistSecuritas Technology, a leading provider of integrated security solutions, is seeking a technically skilled individual to fill this role. As a Security Solutions Specialist, you will be responsible for delivering exceptional service to our clients, ensuring the smooth operation of their security systems, and providing...


  • Washington, United States Koniag Data Solutions, LLC Full time

    Job SummaryWe are seeking a seasoned Security Control Specialist to conduct comprehensive assessments of management, operational, and technical security controls and control enhancements employed within or inherited by an information technology (IT) system.Key ResponsibilitiesConduct independent comprehensive assessments of IT systems to determine the...


  • Washington, United States Bank of America Full time

    Job Description:At Bank of America, we strive to create a workplace that is inclusive, diverse, and supportive of our teammates' well-being. We believe that our employees are our greatest asset, and we invest heavily in their growth and development.We are seeking an experienced Info Security Controls Sr Specialist to join our Process and Metrics Excellence...


  • Washington, United States Bank of America Full time

    Job Description:At Bank of America, we strive to create a workplace that is inclusive, diverse, and supportive of our teammates' growth and well-being. We are committed to being a great place to work, and we believe that our teammates are our greatest asset.We are seeking an experienced Info Security Controls Sr Specialist to join our Process and Metrics...


  • Washington, United States Govcio LLC Full time

    Job SummaryWe are seeking a highly skilled Senior Security Control Specialist to join our team at GovCIO LLC. As a key member of our security team, you will be responsible for conducting security control assessments and providing recommendations to ensure the security and integrity of our clients' information systems.Key ResponsibilitiesConduct Security...


  • Washington, United States Johnson Controls International plc Full time

    We are seeking an experienced commercial Electronic Security Systems Specialist to join our federal team supporting the NAVSEA Headquarters on the Washington Navy Yard in Washington D.C. At Johnson Controls, we support our nation's most critical facilities, the people who occupy them, and the missions they enable. Johnson Controls Federal Systems (JCFS) is...


  • Washington, United States eXpentor LLC Full time

    Job SummaryeXpentor LLC is seeking a highly skilled Security Control Assessment and Validation Specialist to contribute to the security and integrity of our operations.Key ResponsibilitiesProvide expert-level support to Security Control Assessors/Validators with experience in Navy Authorization and Accreditation (A&A) processes.Collaborate with...


  • Washington, United States Govcio LLC Full time

    Job Title: Security Control AssessorGovCIO is seeking a highly skilled Security Control Assessor to join our team. As a Security Control Assessor, you will be responsible for conducting security control assessments of information systems and their environments of operation.Responsibilities:Conduct security control assessments to identify weaknesses and...


  • Washington, United States General Dynamics Information Technology Full time

    Job SummaryThe Security Control Assessor is a critical role within our organization, responsible for ensuring the effectiveness of our security controls. As a key member of our team, you will conduct comprehensive assessments of our management, operational, and technical security controls to identify areas for improvement.Key ResponsibilitiesConduct thorough...


  • Washington, United States Watermark Risk Management International, LLC Full time

    Job Title: Security Control AssessorWatermark Risk Management International, LLC is seeking a highly skilled Security Control Assessor to join our team. As a Security Control Assessor, you will be responsible for conducting comprehensive assessments of management, operational, and technical security controls to determine their effectiveness in meeting...


  • Washington, United States Bering Straits Native Corporation (BSNC) Full time

    Job Title: Security Control AssessorJob Summary:Bering Straits Native Corporation (BSNC) is seeking a highly skilled Security Control Assessor to join our team. As a Security Control Assessor, you will be responsible for guiding system owners and designated IT security personnel in fulfilling Federal Information Security Management Act (FISMA)...


  • Washington, United States Inter-Con Security Full time

    Position OverviewInter-Con Security is seeking dedicated individuals to assume the pivotal role of a Security Operations Specialist. In this capacity, you will become an integral part of a distinguished team of security professionals tasked with safeguarding some of our nation's most vital assets.Key ResponsibilitiesMonitor and patrol designated areas to...


  • Washington, United States Govcio LLC Full time

    Job SummaryWe are seeking a highly skilled Senior Security Control Specialist to join our team at GovCIO LLC. As a Senior Security Control Specialist, you will be responsible for conducting security control assessments of information systems and their environments of operation.Key ResponsibilitiesConduct Security Control Assessments: Provide an assessment of...