Senior Security Control Assessor
7 days ago
Company Overview:
We are a world-class team of professionals who deliver next generation technology and products in robotic and autonomous platforms, ground, soldier, and maritime systems in 50+ locations world-wide. Much of our work contributes to innovative research in the fields of sensor science, signal processing, data fusion, artificial intelligence (AI), machine learning (ML), and augmented reality (AR).
QinetiQ US's dedicated experts in defense, aerospace, security, and related fields all work together to explore new ways of protecting the American Warfighter, Security Forces, and Allies. Being a part of QinetiQ US means being central to the safety and security of the world around us. Partnering with our customers, we help save lives; reduce risks to society; and maintain the global infrastructure on which we all depend.
Why Join QinetiQ US?
If you have the courage to take on a wide variety of complex challenges, then you will experience a unique working environment where innovative teams blend different perspectives, disciplines, and technologies to discover new ways of solving complex problems. In our diverse and inclusive environment, you can be authentic, feel valued, be respected, and realize your full potential. QinetiQ US will support you with workplace flexibility, a commitment to the health and well-being of you and your family and provide opportunities to work with a purpose. We are committed to supporting your success in both your professional and personal lives.
Position Overview:
QinetiQ US is looking for a Senior Security Control Assessor with cloud-based experience to support a dynamic DoD client in the Chantilly, VA area. Candidates are expected to leverage their past experience and knowledge to help deliver superior support to a rapid prototyping office and should have experience in supporting various cloud-based platforms such as Amazon Web Services, Azure, Microsoft Google etc.
Responsibilities:
- Advise the Information System Owner (ISO) concerning the impact levels for Confidentiality, Integrity, and Availability for the information on systems.
- Develop methods to monitor and measure risk, compliance, and assurance efforts.
- Develop specifications to ensure risk, compliance, and assurance efforts conform with security, resilience, and dependability requirements at the software application, system, and network environment level.
- Assess the effectiveness of security controls.
- Perform security reviews, identify gaps in security architecture, and develop a security risk management plan.
- Perform security reviews and identify security gaps in security architecture resulting in recommendations for inclusion in the risk mitigation strategy.
- Perform risk analysis (e.g., threat, vulnerability, and probability of occurrence) whenever an application or system undergoes a major change.
- Plan and conduct security authorization reviews and assurance case development for initial installation of systems and networks.
- Verify that application software/network/system security postures are implemented as stated, document deviations, and recommend required actions to correct those deviations.
- Ensure security assessments are completed for each Information System.
- Initiate a POA&M with identified weaknesses and suspense dates for each IS based on findings and recommendations from the SAR.
- Evaluate security assessment documentation and provide written recommendations for security authorization to the CISO and AO.
- Assess proposed changes to Information Systems, their environment of operation, and mission needs that could affect system authorization.
- Serve as a cybersecurity technical advisor to the CISO and AO under their purview.
- Be integral to the development of the monitoring strategy. The system-level continuous monitoring strategy must conform to all applicable published DoD enterprise-level or DoD Component-level continuous monitoring strategies.
- Determine and document in the SAR a risk level for every noncompliant security control in the system baseline.
- Determine and document in the SAR an aggregate level of risk to the system and identify the key drivers for the assessment. The SCA's risk assessment considers threats, vulnerabilities, and potential impacts as well as existing and planned risk mitigation.
- Develop a continuous monitoring plan specific to the information system.
- Other duties as assigned
Required Qualifications:
- Bachelor's degree required
- 15+ years relevant experience
- DOD 8140 IAM Level II (CAP, CASP, CISM, CISSP, GSLC, CCISO) one of these certifications is required
- Top Secret clearance with SCI eligibility is required #qinetiqclearedjob
Preferred Qualifications:
- Strong knowledge of Risk Management Framework (RMF and continuous monitoring
- Expert knowledge and hands-on experience with FISMA Systems, NIST 800-series guidelines, FIPS, Security Assessment & Authorization (SA&A) requirements and processes, Continuous Monitoring Framework experience and its tools, Plan of Action & Milestones (POA&M) policies, and vulnerability/patch management, risk management, project management, proficient with Microsoft products - Word, Excel, PowerPoint.
- Proficient with vulnerability and scanning tools and well-versed in interpreting risk posture resulting from assessment reports. Experience in project management and tracking, and the Microsoft suite of office products
- Experience in assessing cloud-based security authorizations (FedRamp, AWS & Azure) as well as the NIST control responsibilities
- Strong knowledge of CSAM
- Expert with documenting and or reviewing security materials such as; system security plans (SSP), Security Assessment Report (SAR), Security Assessment Plan (SAP), and other documents per NIST 800 guidelines.
- Experience supporting cloud-based security authorizations (FedRamp, AWS, & Azure)
- Experience creating Security Assessment Plans, Security Assessment Reports, and Executive-level briefings
- Top Secret/SCI with CI Poly preferred
Company EEO Statement:
Accessibility/Accommodation:
If because of a medical condition or disability you need a reasonable accommodation for any part of the employment process, please send an e-mail to or call Opt. 4 and let us know the nature of your request and contact information.
QinetiQ US is an Equal Opportunity employer. All Qualified Applicants will receive equal consideration for employment without regard to race, age, color, religion, creed, sex, sexual orientation, gender identity, national origin, disability, or protected Veteran status.
-
Security Control Assessor
7 days ago
Chantilly, Virginia, United States Lucayan Technology Solutions Full timeChantilly, VA | Full-Time | TS/SCI with Polygraph | OnsiteOverviewLucayan Technology LLC is hiring a Level 3 Security Control Assessor (SCA) to lead the assessment and authorization of government systems. This senior-level role involves managing A&A processes, guiding teams, and providing expert IA support to stakeholders.What You'll DoManage and track...
-
Security Control Assessor
2 weeks ago
Chantilly, Virginia, United States Lucayan Technology Solutions Full time $120,000 - $180,000 per yearChantilly, VA | Full-Time | TS/SCI with Polygraph | Onsite OverviewLucayan Technology LLC is seeking a Level 4 Security Control Assessor (SCA-subject matter expert) to provide enterprise-level IA leadership for national security programs. This role requires deep technical knowledge and the ability to oversee multiple large-scale A&A processes...
-
Senior Security Control Assessor
7 days ago
Chantilly, Virginia, United States QinetiQ US Full timeCompany OverviewWe are a world-class team of professionals who deliver next generation technology and products in robotic and autonomous platforms, ground, soldier, and maritime systems in 50+ locations world-wide. Much of our work contributes to innovative research in the fields of sensor science, signal processing, data fusion, artificial intelligence...
-
Security Control Assessor
2 weeks ago
Chantilly, Virginia, United States Arcfield Full timeOverview:Arcfield was purpose-built to protect the nation and its allies through innovations in digital transformation, space mission engineering and launch assurance, miniaturized sensors and satellites, advanced modeling and simulation, cybersecurity, and conventional and hypersonic missile support. Headquartered in Chantilly, VA with 16 global offices,...
-
Security Control Assessor
2 weeks ago
Chantilly, Virginia, United States Arcfield Full timeOverviewArcfield was purpose-built to protect the nation and its allies through innovations in digital transformation, space mission engineering and launch assurance, miniaturized sensors and satellites, advanced modeling and simulation, cybersecurity, and conventional and hypersonic missile support. Headquartered in Chantilly, VA with 16 global offices,...
-
Senior Government Security
2 weeks ago
Chantilly, Virginia, United States AT&T Full time $69,000 - $109,000 per yearJob Description:This position requires office presence of a minimum of 3 days per week and is only located in the location(s) posted. No relocation is offered.AT&T Public Sector is a trusted provider of secure, IP enabled, cloud-based, network solutions and professional services to the Federal Government. We are dedicated to recruiting, developing and...
-
Information System Security Manager
2 weeks ago
Chantilly, Virginia, United States Kudu Dynamics, LLC Full time $190,000 - $210,000 per yearJob Id: 390# of Openings: 1Job Title: Information System Security Manager (ISSM)Who We Are:Kudu Dynamics is a Leidos owned company, forged out of a decade of experience in computer network operations and staffed with talent who have built, overseen, and enhanced capabilities throughout the entire USG arsenal. Our team of hackers, engineers, makers, and...
-
Senior Security Video Surveillance
2 weeks ago
Chantilly, Virginia, United States GHD Full time $120,000 - $180,000 per yearJob DescriptionHelp us build the future and we'll help you build a rewarding and purposeful career.Our global network is made up of architects, designers, planners, engineers, and environmental scientists all working towards the same goal.Join a team that brings inspirational architecture, landscapes, townscapes and places to our world, and we'll provide you...
-
Senior Security Manager
2 weeks ago
Chantilly, Virginia, United States Leidos Full time $101,000 - $183,300 per yearDescriptionThe Leidos Security Operations is seeking a proven, experienced security professional for a Senior Security Manager, to lead a multi-functional team and manage a portfolio of programs supporting our Mission Solutions Business Area and one of our Intelligence Community (IC) customers. This is an incredible opportunity to apply your leadership and...
-
Senior Program Control Analyst
1 week ago
Chantilly, Virginia, United States Systems Planning and Analysis Full time $60,000 - $150,000 per yearOverviewSystems Planning and Analysis, Inc. (SPA) delivers high-impact, technical solutions to complex national security issues. With over 50 years of business expertise and consistent growth, we are known for continuous innovation for our government customers, in both the US and abroad. Our exceptionally talented team is highly collaborative in spirit and...