Security Controls Assessor

2 weeks ago


Springfield, Virginia, United States Leidos Full time
Job Summary

Leidos is seeking a highly skilled Security Controls Assessor to support the DHS Cyber Assessments Program. As a key member of our team, you will conduct comprehensive technical assessments to identify security vulnerabilities and weaknesses in information systems and applications, ensuring compliance with DHS policies.

Key Responsibilities:

  • Conduct thorough security assessments to identify vulnerabilities and weaknesses in information systems and applications.
  • Support Security Authorization (SA) and Continuous Monitoring (CM) processes in accordance with the Risk Management Framework (RMF).
  • Develop and maintain a detailed Security Assessment Schedule to ensure the periodic evaluation of systems.
  • Create and maintain technical assessment artifacts, including Security Assessment Reports (SARs) and Security Requirements Traceability Matrix (SRTM).
  • Facilitate the assessment process by leading kick-off meetings, conducting checkpoint reviews, and managing entrance/exit conferences with system stakeholders.
  • Provide recommendations for cybersecurity best practices, tools, and methodologies to enhance system security and mitigate risks.
  • Use and configure vulnerability scanning tools to evaluate system configurations and identify security gaps.
  • Innovate through the development of automated continuous assessment products, including security dashboards and data visualization reports.

Requirements:

  • Bachelor's Degree in Information Technology, Cybersecurity, or a related technical field, and 4+ years of experience, or AS/AA and 6+ years of experience, or HS/GED and 8 years of experience.
  • Experience performing security control assessments in federal government environments.
  • Proficiency in vulnerability scanning tools and reporting using systems like CSAM and IACS.
  • Experience in developing and maintaining cybersecurity documentation, including Standard Operating Procedures (SOPs).
  • Strong communication skills, both written and verbal, for reporting assessment findings and recommendations.
  • Active Public Trust Clearance with eligibility to upgrade to Secret.

Preferred Qualifications:

  • Certified Information Systems Security Professional (CISSP), Certified Authorization Professional (CAP), or similar cybersecurity certifications.
  • Familiarity with DHS cybersecurity guidelines and compliance requirements.
  • Strong knowledge of network architecture, system configurations, and vulnerability management best practices.
  • Experience creating automated assessment reports and dashboards using cybersecurity tools like Axonius and Splunk.
  • Excellent problem-solving and critical-thinking skills for assessing complex IT environments.
  • Proven experience in performing security assessments using RMF and DHS cybersecurity frameworks.
  • Expertise in managing large-scale system evaluations, vulnerability scanning, and risk analysis processes.
  • Strong proficiency with MGMT compliance tools such as IACS and CSAM, and industry-standard assessment tools like Tenable, WebInspect, and Splunk.
  • Demonstrated ability to develop comprehensive technical assessment reports and recommendations for mitigation strategies.
  • A proactive mindset in enhancing security assessment processes and streamlining documentation workflows.
  • Experience conducting kick-off meetings, checkpoint reviews, and final assessments to ensure compliance and drive cybersecurity excellence.
Pay Range:$81,250.00 - $146,875.00

  • Springfield, Virginia, United States Gray Tier Technologies Full time

    Job Title: Security Control AssessorGray Tier Technologies is seeking a highly skilled Security Control Assessor to join our team.Job Summary:We are looking for a seasoned professional with expertise in NIST RMF and CNSS policy frameworks to assess and ensure the security of National Security Systems. The ideal candidate will have a strong background in...


  • Springfield, Virginia, United States Leidos Full time

    Job Title: Security Controls Assessor LeadAt Leidos, we are seeking a highly skilled Security Controls Assessor Lead to join our team. As a key member of our Digital Modernization Sector, you will play a critical role in supporting the DHS Cyber Assessments Program.Job Summary:The Security Controls Assessor Lead will be responsible for conducting...


  • Springfield, Virginia, United States Leidos Full time

    Job Title: National Security Systems Security Controls Assessor LeadAt Leidos, we are seeking a highly skilled National Security Systems Security Controls Assessor Lead to support our DHS Cyber Assessments Program. As a key member of our team, you will be responsible for executing in-depth security control assessments for National Security Systems in...


  • Springfield, Virginia, United States Leidos Full time

    Job SummaryLeidos is seeking a highly skilled Security Controls Assessor Lead to support the DHS Cyber Assessments Program. The successful candidate will conduct comprehensive technical assessments to identify security vulnerabilities and weaknesses in information systems and applications, ensuring compliance with DHS policies.Key ResponsibilitiesConduct...


  • Springfield, Virginia, United States Rividium Inc Full time

    Job Title: Security Control AssessorRiVidium Inc, a leading provider of cybersecurity solutions, is seeking a highly skilled Security Control Assessor to join our team. As a Security Control Assessor, you will be responsible for conducting comprehensive assessments of security controls and control enhancements employed within or inherited by an information...


  • Springfield, Virginia, United States Rividium Inc Full time

    Job Title: Security Control AssessorRiVidium Inc, a leading provider of cybersecurity solutions, is seeking a highly skilled Security Control Assessor to join our team. As a Security Control Assessor, you will be responsible for conducting comprehensive assessments of security controls and control enhancements employed within or inherited by an IT system to...


  • Springfield, Virginia, United States Leidos Full time

    Job Title: Security Controls AssessorLeidos is seeking a highly skilled Security Controls Assessor to support the DHS Cyber Assessments Program. As a key member of our team, you will conduct comprehensive technical assessments to identify security vulnerabilities and weaknesses in information systems and applications, ensuring compliance with DHS...


  • Springfield, Virginia, United States Leidos Full time

    Job Title: National Security Systems Security Controls Assessor LeadAt Leidos, we are committed to delivering innovative solutions that meet the evolving needs of our customers. As a National Security Systems Security Controls Assessor Lead, you will play a critical role in ensuring the security and integrity of our systems.Job Summary:We are seeking a...


  • Springfield, Virginia, United States Rividium Inc Full time

    Job DescriptionRiVidium Inc is seeking a highly skilled Security Control Assessor to join our team. As a Security Control Assessor, you will be responsible for conducting independent comprehensive assessments of the management, operational, and technical security controls employed within or inherited by an information technology (IT) system.Key...


  • Springfield, Virginia, United States MSCCN Full time

    Job SummaryWe are seeking a highly skilled Security Controls Assessor to join our team at Leidos. As a key member of our Digital Modernization Sector, you will play a critical role in supporting the DHS Cyber Assessments Program.Key Responsibilities:Conduct comprehensive technical assessments to identify security vulnerabilities and weaknesses in information...


  • Springfield, Virginia, United States Gray Tier Technologies LLC Full time

    Job Title: NSS Security Control AssessorGray Tier Technologies LLC is seeking a highly skilled Security Control Assessor to support a newly awarded five-year contract. As a key member of our team, you will be responsible for executing in-depth security control assessments (SCAs) for National Security Systems (NSS) in compliance with NIST RMF and CNSS policy,...


  • Springfield, Virginia, United States ManTech Full time

    Secure Our Nation, Ignite Your FutureBecome an integral part of a diverse team at ManTech International Corporation, where our employees come first. As a Cloud ISSO, you'll help protect our national security while working on innovative projects that offer opportunities for advancement.Responsibilities:Draft, review, and update Risk Management Framework (RMF)...


  • Springfield, Virginia, United States ManTech Full time

    Secure Our Nation, Ignite Your FutureAt ManTech International Corporation, we are seeking a highly skilled Cloud ISSO to join our team in the Lorton Location. As a Cloud ISSO, you will play a critical role in ensuring the security and compliance of our cloud-based systems.Responsibilities:Develop and maintain Risk Management Framework (RMF) artifacts to...


  • Springfield, Virginia, United States MSCCN Full time

    Job Title: Security Controls AssessorAt MSCCN, we are committed to delivering innovative solutions through the efforts of our diverse and talented people who are dedicated to our customers' success. We empower our teams, contribute to our communities, and operate sustainably. Our mission, vision, and values guide the way we do business.Job Summary:We are...

  • Security Specialist

    2 weeks ago


    Springfield, Virginia, United States Parsons Corporation Full time

    Job Title: Senior Security SpecialistThis position will be supporting a Government Customer in overseeing security administration, management, and oversight enforcement of sensitive programs activities.Key Responsibilities:Monitor and manage Special Access Programs, SCI security programs, and provide status reports and recommendations for decisions.Develop...

  • Security Specialist

    2 weeks ago


    Springfield, Virginia, United States Parsons Company Full time

    Job Title: Senior Security SpecialistThis is a challenging role that requires a strong background in security administration, management, and oversight. As a Senior Security Specialist, you will be responsible for creating positive, professional, and productive lines of communication with both internal and external customers.Key Responsibilities:Monitor and...

  • Security Specialist

    4 weeks ago


    Springfield, Virginia, United States ManTech Full time

    Secure Our Nation, Ignite Your FutureManTech is seeking a highly motivated and enthusiastic individual to join our team in Alexandria, VA to provide exceptional support to our customer and to begin an exciting and rewarding career within ManTech.Job SummaryThe Security Analyst will provide assistance to the Government security staff in the administration of...

  • Security Specialist

    2 weeks ago


    Springfield, Virginia, United States Parsons Company Full time

    Job Title: Senior Security SpecialistThis is a challenging role that requires a high level of expertise in security administration, management, and oversight. As a Senior Security Specialist, you will be responsible for creating positive, professional, and productive lines of communication with both internal and external customers.Key...


  • Springfield, Virginia, United States Automationtechies Full time

    Job DescriptionA Sr. Automation and Controls Engineer is needed for a large natural gas and power company that provides clean and affordable energy to their customers. The Sr. Automation and Controls Engineer will be responsible for process control systems, communication infrastructure, and information systems to ensure safe and reliable delivery of natural...


  • Springfield, Virginia, United States Parsons Corporation Full time

    This position will be supporting a Government Customer in overseeing security administration, management, and oversight enforcement of sensitive programs activities. As a Senior Security Specialist, you are expected to create positive, professional, and productive lines of communication with both internal and external customers, in addition to delivering the...