O logo

Security Control Assessor

Omniscius ConsultingArlington, VA

Automate your job search with Sonara.

Submit 10x as many applications with less effort than one manual application.1

Reclaim your time by letting our AI handle the grunt work of job searching.

We continuously scan millions of openings to find your top matches.

pay-wall

Overview

Schedule
Full-time
Career level
Senior-level
Remote
On-site

Job Description

  • Job Title: Security Control Assessor  
  • Location: On Site in Arlington, VA  
  • Department: Cyber Security Services  
  • Reports To: Management 
  • FLSA Status: Full Time/Non-exempt  
  • Clearance: Top Secret clearance with the ability to obtain SCI with CI Polygraph

Job Purpose: 

The security control assessor (SCAs) supports a critical, objective role to evaluate the effectiveness of implemented controls in mitigating security risks. The SCA will support a critical mission within the intelligence community. In the role as a SCA, you are expected to use automated scanning tools, manual techniques, and specialized testing methodologies to identify weaknesses and vulnerabilities. The SCA is expected to be a collaborative member of the RMF program of the organization, to provide intelligent input to system security architectures in order to align with RMF principles and guidelines. This includes ensuring to guide the RMF process so that security controls are integrated seamlessly into system designs to provide comprehensive protection against threats and vulnerabilities. 

Duties & Responsibilities: 

The SCA's specific duties include: 

  • Advise the Information System Owner (ISO) concerning the impact levels for Confidentiality, Integrity, and Availability for the information on systems. 
  • Ensure security assessments are completed for each IS. 
  • Initiate a POA&M with identified weaknesses and suspense dates for each IS based on findings and recommendations from the SAR. 
  • Evaluate security assessment documentation and provide written recommendations for security authorization to the CISO and AO. 
  • Assess proposed changes to Information Systems, their environment of operation, and mission needs that could affect system authorization. 
  • Serve as a cybersecurity technical advisor to the CISO and AO under their purview. 
  • Be integral to the development of the monitoring strategy. The system-level continuous monitoring strategy must conform to all applicable published DoD enterprise-level or DoD Component-level continuous monitoring strategies. 
  • Determine and document in the SAR a risk level for every noncompliant security control in the system baseline. 
  • Determine and document in the SAR an aggregate level of risk to the system and identify the key drivers for the assessment. The SCA's risk assessment considers threats, vulnerabilities, and potential impacts as well as existing and planned risk mitigation. 
  • Develop the continuous monitoring plan specific to the information system. 

The SCA is responsible for the RMF deliverables associated with Step 4 of DOD and IC RMF Policies for assigned systems. This includes, but is not limited to:  

  • Security Assessment Plans tailored to specific systems control requirements 
  • Security control assessment input, which includes narratives for the review of controls and artifacts 
  • Security Assessment Reports 
  • ATO recommendations or ATO with Condition Memorandums 
  • Conduct initial remediation actions once a security assessment has been completed to ensure proper hand off to the ISSM and ISSOs.  
  • Assessment of selected controls IAW continuous monitoring strategy 

The SCA is expected to have additional duties as assigned in support of corporate cyber security services. Additional details are reviewed in accordance with company policies.  

Requirements

Required Skills & Experience: 

  • Strong knowledge of Risk Management Framework (RMF) 800-37 and continuous monitoring 800-137 
  • Expert knowledge and hands-on experience with FISMA Systems, NIST 800-series guidelines, FIPS, Security Assessment & Authorization (SA&A) requirements and processes, Continuous Monitoring Framework experience and its tools, Plan of Action & Milestones (POA&M) policies, and vulnerability/patch management, risk management, project management, proficient with Microsoft products - Word, Excel, PowerPoint. 
  • Proficient with vulnerability and scanning tools and well-versed in interpreting risk posture resulting from assessment reports. Experience in project management and tracking, and the Microsoft suite of office products 
  • Experience of assessing cloud-based security authorizations (FedRamp, AWS & Azure) as well as the NIST control responsibilities 
  • Experience with SAP/JSIG 
  • Expert with documenting and or reviewing of security materials such as; system security plans (SSP), Security Assessment Report (SAR), and Security Assessment Plan (SAP), and other documents per NIST 800 guidelines. 
  • Experience supporting cloud-based security authorizations (FedRamp, AWS, & Azure) 
  • Experience creating Security Assessment Plans, Security Assessment Reports, and Executive-level briefings 

Qualifications: 

  • Bachelor's Degree in Computer Science or a related technical discipline  
  • Master's Degree preferred. 
  • Minimum 6-10 years of experience.  
  • Must currently possess an active Top Secret clearance with the ability to obtain SCI with CI Polygraph.
  • DOD 8140 IAM Level II (CAP, CASP, CISM, CISSP, GSLC, CCISO) is required 
  • Systems Security Engineering background preferred.  
  • Effective communication skills to collaborate with cross-functional teams and stakeholders on implementing security measures organization-wide. 
  • Strong analytical skills for identifying system vulnerabilities and documenting control remediation recommendations through collaboration on System Impact Analysis and Documented Risk Acceptance.  
  • Detail-oriented with the ability to manage multiple tasks and prioritize effectively. 
  • Comprehensive knowledge of RMF activities at a senior level (ability to articulate to Executive audiences preferred). 
  • Familiarity with federal regulatory requirements, contractual obligations, and industry standards related to information security. Evaluate adherence to standards such as Privacy, GDPR, and HIPAA 

Powered by JazzHR

Automate your job search with Sonara.

Submit 10x as many applications with less effort than one manual application.

pay-wall

FAQs About Security Control Assessor Jobs at Omniscius Consulting

What is the work location for this position at Omniscius Consulting?
This job at Omniscius Consulting is located in Arlington, VA, according to the details provided by the employer. Some roles may also include multiple work locations depending on the requirement.
What pay range can candidates expect for this role at Omniscius Consulting?
Employer has not shared pay details for this role.
What employment applies to this position at Omniscius Consulting?
Omniscius Consulting lists this role as a Full-time position.
What experience level is required for this role at Omniscius Consulting?
Omniscius Consulting is looking for a candidate with "Senior-level" experience level.
What is the process to apply for this position at Omniscius Consulting?
You can apply for this role at Omniscius Consulting either through Sonara's automated application system, which helps you submit applications 10X faster with minimal effort, or by applying manually using the direct link on the job page.