Lead Security Control Assessor

6 days ago


Washington, United States Govcio LLC Full time
Job Summary

We are seeking a highly skilled Senior Security Control Specialist to join our team at GovCIO LLC. As a Senior Security Control Specialist, you will be responsible for conducting security control assessments of information systems and their environments of operation.

Key Responsibilities
  • Conduct Security Control Assessments: Provide an assessment of the severity of weaknesses or deficiencies discovered in the information system and its environment of operation, and recommend corrective actions to address identified vulnerabilities.
  • Prepare Security Assessment Reports: Prepare the final security assessment report containing the results and findings from the assessment.
  • Review and Approve Security Documents: Review and approve the IS Security Control Assessment Procedures, the Security Assessment Plan, the System Security Plan (SSP), and the Security Control Traceability Matrix (SCTM).
  • Perform Configuration Management: Perform configuration management of a client central repository for authorization documentation (i.e., Body of Evidence (BOE)), which is maintained using an A&A workflow software application.
  • Review and Compile BOE: Review and compile the BOE (i.e., security control allocations, security control implementations, test results, Security Assessment Reports (SARs), POA&Ms, risk acceptance recommendations, and risk mitigation strategies) to support the recommendation for client risk acceptance authorization decisions.
  • Review SARs and Create POA&Ms: Review SARs, verify test results, and create POA&Ms to document corrective actions with milestone completion dates.
Qualifications
  • Education and Experience: Bachelor's with 5+ years (or commensurate experience) of experience as a Security Control Assessor.
  • Security Control Assessment Experience: Experience conducting security control assessment of all NIST controls.
  • Senior-Level Security Control Assessors: Senior-level security control assessors should have 7 to 10 years of experience.
  • Certifications: At least one of the following certifications: Security+, CAP.
  • Technical Skills: Technical understanding (understanding network diagrams, vulnerability and compliance scans).
  • Document Creation and Maintenance: Experience creating and maintaining various security documents such as the Security Control Plan/Vulnerability Security Review (SCP/VSR), System Backup and Recovery Plans (SBRP) and Plan of Action and Milestone (POA&M) tables.
  • Communication Skills: Excellent Communication skills (written and oral).
  • NIST Security Controls: Thorough knowledge of NIST security controls and required documentation.
  • Risk Management Framework: Conduct security control assessments based on a Risk Management Framework approach.
  • Risk Assessments and Security Assessment Reports: Experience conducting risk assessments and developing security assessment reports.
  • Clearance: Clearance Required: Must possess an active Top Secret Clearance and be able to hold SCI.


  • Washington, United States Insight Global Full time

    Job SummaryWe are seeking a highly skilled Security Control Assessor to join our team at Insight Global. As a Security Control Assessor, you will be responsible for conducting security control assessments of all NIST controls and providing recommendations for corrective actions.Key ResponsibilitiesConduct security control assessments of all NIST controls and...


  • Washington, United States Customer Value Partners Full time $110,000 - $115,000

    Job DescriptionJob DescriptionCVP is seeking a Security Control Assessor Lead to join our growing team. This position will lead a team of seven security control assessors to conduct comprehensive assessments of the management, operational, technical and privacy security controls employed within or inherited by an information system.  The goal is to lead a...


  • Washington, United States Expentor Inc Full time

    Job DescriptionJob DescriptionSecurity Control Assessment and Validation: Provide Security Control Assessors/Validators with experience in Navy Authorization and Accreditation (A&A), including Test and Evaluation (T&E) and Risk Management Framework (RMF) processes.QualificationsIAT Level II/III or IAM Level IIIBachelor's Degree or higher7+ years of...


  • Washington, Washington, D.C., United States Avint Full time

    Position: ISSO Security Control Assessor SupportAvint LLC is in search of a seasoned security expert to fill the role of ISSO Security Control Assessor Support with a valid Top Secret clearance. This position is vital for evaluating and improving security measures for information technology systems.Key Responsibilities:Enhance and optimize project management...


  • Washington, United States Watermark Risk Management International, LLC Full time

    Job SummaryWatermark Risk Management International, LLC is seeking a highly skilled Security Control Assessor II to join our team. As a key member of our organization, you will be responsible for conducting comprehensive assessments of management, operational, and technical security controls to determine their effectiveness.Key ResponsibilitiesSecurity...


  • Washington, Washington, D.C., United States Avint Full time

    Position: ISSO Security Control AssessorAvint LLC is in search of a seasoned security expert to fulfill the role of ISSO Security Control Assessor possessing an active Top Secret clearance. This position is vital for evaluating and strengthening security measures for information technology systems.Key Responsibilities:Enhance and optimize project management...


  • Washington, United States Graham Technologies Full time

    Job DescriptionJob DescriptionJob Overview:Graham Technologies (GTECH) is seeking a Security Control Assessor whose primary duties will be to perform assessments of our customer's application and system controls. You will be happy to know that this is a hybrid position. The work location is Washington, DC. Responsibilities:Develop methods to monitor and...


  • Washington, United States eXpentor LLC Full time

    Job Summary: eXpentor LLC is seeking a highly experienced Security Control Assessor to join our team. As a Security Control Assessor, you will be responsible for providing security control assessment and validation services to our clients.Key Responsibilities:Provide security control assessors/validators with experience in Navy Authorization and...


  • Washington, United States Hummingbirds Innovations Full time

    Job DescriptionJob DescriptionThe ideal candidate has experience performing internal penetration testing, vulnerability assessments and manual exploitation of servers, web applications/services and databases to identify vulnerabilities, misconfigurations, and compliance issues. In addition, the candidate will have extensive experience in performing FISMA...


  • Washington, United States Hummingbirds Innovations Full time

    Job DescriptionJob DescriptionThe ideal candidate has experience performing internal penetration testing, vulnerability assessments and manual exploitation of servers, web applications/services and databases to identify vulnerabilities, misconfigurations, and compliance issues. In addition, the candidate will have extensive experience in performing FISMA...


  • Washington, United States Allen Integrated Solutions Full time

    Job DescriptionJob DescriptionSecurity Control Assessor (SCA), Level 3TS/SCI/POLY RequiredSecurity Control Assessor (SCA) QualificationsA Security Control Assessor (SCA) is a security professional that provides information security Assessment and Authorization (A&A) support throughout a program's lifecycle to Contractor and Government facilities...


  • Washington, United States Tetra Tech Full time

    About the Role:Tetra Tech is seeking a highly skilled Cybersecurity Specialist to join our Cyber Solutions Practice and support a team of Cyber SMEs on a newly awarded contract. This role will make an immediate impact across the Intelligence Community and focus on providing innovative solutions for mission-critical cyber challenges.Responsibilities:Execute...


  • Washington, United States Tetra Tech Full time

    About the Role:Tetra Tech is seeking a highly skilled Cybersecurity Control Assessor to join our Cyber Solutions Practice and support a team of Cyber SMEs on a newly awarded contract. This role will make an immediate impact across the Department of Homeland Security and the Intelligence community, focusing on providing innovative solutions for...


  • Washington, United States Govcio LLC Full time

    Job SummaryWe are seeking a highly skilled Senior Security Control Specialist to join our team at GovCIO LLC. As a key member of our security team, you will be responsible for conducting security control assessments and providing recommendations to ensure the security and integrity of our clients' information systems.Key ResponsibilitiesConduct Security...


  • Washington, United States ShorePoint Full time

    Job DescriptionJob DescriptionSalary: Who we are: ShorePoint is a fast-growing, industry recognized, and award-winning cybersecurity services firm with a focus on high-profile, high-threat, private and public-sector customers who demand experience and proven security models to protect their data. ShorePoint subscribes to a “work hard, play hard”...

  • IT Security Auditor

    6 days ago


    Washington, United States Koniag Data Solutions, LLC Full time

    About the RoleKoniag Data Solutions, LLC, a leading provider of enterprise solutions and professional services, is seeking a highly skilled Security Control Assessor to join our team. As a Security Control Assessor, you will play a critical role in ensuring the security and integrity of our clients' information systems.Key ResponsibilitiesConduct...


  • Washington, United States Maania Consultancy Services Full time

    Job DescriptionJob DescriptionOur federal client is looking for Cyber Risk Assessor. If you are interested, please send me your updated resume along with your expected salary range.Position: Cyber Risk AssessorJob Type: Full-timeLocation: Remote (Local to the DC area – onsite occasionally)Clearance: Active Top Secret ClearanceRequired Skills and...


  • Washington, United States eXpentor LLC Full time

    Job SummaryeXpentor LLC is seeking a highly skilled Security Control Assessment and Validation Specialist to contribute to the security and integrity of our operations.Key ResponsibilitiesProvide expert-level support to Security Control Assessors/Validators with experience in Navy Authorization and Accreditation (A&A) processes.Collaborate with...


  • Washington, Washington, D.C., United States Avint Full time

    Position: ISSO Security Control Evaluation SpecialistAre you a seasoned security expert seeking a rewarding challenge? Avint LLC is on the lookout for an ISSO Security Control Evaluation Specialist with an active Top Secret clearance. This role is essential in enhancing and evaluating security measures for information technology systems.Key...


  • Washington, Washington, D.C., United States ST2 ManTech Advanced Systems Intl Full time

    Job SummaryST2 ManTech Advanced Systems Intl is seeking a highly skilled Security Controls Engineer to join our team. As a Security Controls Engineer, you will be responsible for assessing and implementing security controls to ensure the confidentiality, integrity, and availability of sensitive information.Key ResponsibilitiesAssess and implement security...