Talent.com
serp_jobs.error_messages.no_longer_accepting
Senior Security Assurance Controls Manager (Falls Church)

Senior Security Assurance Controls Manager (Falls Church)

ID.meFalls Church, VA, US
job_description.job_card.variable_hours_ago
serp_jobs.job_preview.job_type
  • serp_jobs.job_card.part_time
job_description.job_card.job_description

Senior Security Assurance Controls Manager

ID.me is the next-generation digital identity wallet that simplifies how individuals securely prove their identity online. Consumers can verify their identity with ID.me once and seamlessly login across websites without having to create a new login and verify their identity again. Over 140 million users experience streamlined login and identity verification with ID.me at 20 federal agencies, 44 state government agencies, and 66 healthcare organizations. More than 600 consumer brands use ID.me to verify communities and user segments to honor service and build more authentic relationships. ID.me's technology meets the federal standards for consumer authentication set by the Commerce Department and is approved as a NIST 800-63-3 IAL2 / AAL2 credential service provider by the Kantara Initiative. ID.me is committed to No Identity Left Behind to enable all people to have a secure digital identity.

Role Overview

ID.me is seeking a Senior Security Assurance Controls Manager to lead the development, implementation, and ongoing operation of our internal control program for external security and privacy frameworks including FedRAMP, ISO 27001, and SOC 2.

This role is critical to maintaining the trust of our customers and regulatory stakeholders by ensuring that security and compliance requirements are met across ID.me's rapidly evolving product and infrastructure landscape. You will work cross-functionally with Engineering, Product, Security, GRC, and external auditors to design scalable control strategies, validate control effectiveness, and operationalize continuous monitoring.

Responsibilities

  • Framework Ownership : Serve as the day-to-day owner for one or more frameworks (e.g., FedRAMP, ISO 27001, SOC 2), ensuring alignment between framework requirements and internal controls.
  • Control Lifecycle Management : Collaborate with control owners to design, implement, document, and monitor controls. Define control objectives, implementation guidance, and assurance requirements.
  • Audit & Assessment Readiness : Coordinate internal and external audits by developing audit plans, preparing walkthroughs, and managing evidence collection activities.
  • Continuous Monitoring : Maintain a recurring schedule of control validations based on framework-specific frequency requirements (e.g., FedRAMP ConMon). Track control health and remediation actions.
  • Gap Analysis & Risk Assessments : Lead gap analyses between new framework requirements and existing control coverage. Facilitate Security Impact Assessments (SIAs) to assess compliance implications of changes and identify risks.
  • Compliance Documentation : Manage organizational policies. Ensure up-to-date, reviewer-approved documentation exists for policies, procedures, and implementation statements. Lead annual reviews and updates.
  • Control Remediation & POA&M Management : Partner with control owners to define corrective actions, manage Plans of Action & Milestones (POA&Ms), and track resolution through closure. Propose and coordinate the design of controls to mitigate risks.
  • Stakeholder Engagement : Act as a trusted partner to engineering, product, infrastructure, and customer-facing teams. Provide clear guidance on what controls are required, why, and how to satisfy them.
  • Tooling & Metrics : Support the use of GRC and data pipelines to automate evidence collection, track control status, and generate metrics for reporting.
  • Internal and External : Contribute to executive and board-level reporting, as well as external customer reporting such as through Continuous Monitoring reports.

Basic Qualifications

  • Bachelor's degree in Information Security, Computer Science, Engineering, Risk Management, or related fieldor equivalent practical experience.
  • 710+ years of experience managing and operating security / compliance programs, including at least one of : FedRAMP, ISO 27001, or SOC 2.
  • 35+ years of experience managing third-party audits (e.g., ATO, SOC, ISO certs), including evidence preparation, auditor interface, and corrective actions.
  • Preferred Qualifications

  • Experience leading or contributing to FedRAMP Continuous Monitoring (ConMon) activities or significant change requests (SCR).
  • Proficient in project management : planning, tracking, reporting, and issue resolution.
  • Strong understanding of security control domains (e.g., access control, vulnerability management, encryption, logging, change management).
  • Experience working in cloud-native environments (AWS, GCP preferred).
  • Familiarity with GRC platforms such as LogicGate, ServiceNow GRC, or Archer.
  • Deep understanding of control implementation across cloud-native and DevOps environments.
  • CISSP, CISA, CCSK, or ISO 27001 Lead Auditor certification.
  • Cloud security certifications (e.g., GCP, AWS, etc.) are a plus.
  • Experience working in SaaS or regulated environments (e.g., healthcare, finance, government).
  • The annual base salary listed does not include a company bonus, incentive for sales roles, equity and benefits which will be determined based on experience, skills, education, relevant training, geographic location and role.

    ID.me offers comprehensive medical, dental, vision, health savings account, flexible spending accounts (medical, limited purpose, dependent care, commuter benefit accounts), basic and voluntary life and AD&D insurance, 401(k) with company match, parental leave, ability to participate in unlimited paid time off subject to the terms and conditions of the PTO policy, including 8 company wide holidays, short and long-term disability insurance, accident and critical illness insurance, referral bonus policy, employee assistance program, pet insurance, travel assistant program, wellbeing and childcare discounts, benefit advocates, and a learning and development benefit.

    The above represents the anticipated total rewards package for this job requisition. Final offers may vary from the amount listed based on qualifications, professional experiences, skills, education, relevant training, geographic location, and other job related factors.

    serp_jobs.job_alerts.create_a_job

    Senior Assurance Manager • Falls Church, VA, US

    Job_description.internal_linking.related_jobs
    • serp_jobs.job_card.promoted
    Security Manager

    Security Manager

    Oneida ESC GroupFalls Church, VA, US
    serp_jobs.job_card.full_time
    Navy Bureau of Medicine and Surgery) Schedule : Full-time; Remote work may be available with Government approval Clearance : Must be able to obtain and maintain a security clearance.The Security Mana...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Site Security Manager - CST (QTS / VA / GS)

    Site Security Manager - CST (QTS / VA / GS)

    Clearance JobsManassas, VA, US
    serp_jobs.job_card.full_time
    Construction Surveillance Technician (CST) Site Security Manager.The Construction Surveillance Technician (CST) Site Security Manager is responsible for overseeing the security operations of constr...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    Site Security Manager I

    Site Security Manager I

    gTANGIBLE CorporationWashington, DC, USA
    serp_jobs.job_card.full_time
    serp_jobs.filters_job_card.quick_apply
    TANGIBLE Corporation (gTC), , is a S corporation and a registered Government contractor that provides services and solutions in : . Professional, Administrative, and Management Support.Mission and War...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Program Manager Lead Security Specialist

    Program Manager Lead Security Specialist

    OlgoonikWashington, DC, United States
    serp_jobs.job_card.full_time
    Olgoonik is an Equal Opportunity Employer.The PM Lead Security Specialist's primary duties are to escort, represent the company, and consult with Bureau Security Office (BSO).In addition to normal ...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Security Manager

    Security Manager

    Clearance JobsWashington, DC, US
    serp_jobs.job_card.full_time
    NewGen is seeking a Security Manager to develop and implement security programs to protect personnel, facilities, and information within a military organization. You would be responsible for ensurin...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Junior Security Control Assessor

    Junior Security Control Assessor

    Leidos IncAlexandria, VA, United States
    serp_jobs.job_card.full_time
    Leidos is seeking multiple Junior Security Control Assessors to support our assessment team.These positions can be based out of any of our three locations - Alexandria, VA, Fort Meade, MD, or Chamb...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Safety & Security Manager

    Safety & Security Manager

    Adams and Associates, Inc.Laurel, MD, US
    serp_jobs.job_card.full_time
    ABOUT WOODLAND AND JOB CORPS CENTER.The Woodland Job Corps Center provides students with the opportunity to earn their High School Diploma or Equivalent (GED), and hands-on training in the followin...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    Security Control Assessor I

    Security Control Assessor I

    gTANGIBLE CorporationArlington, VA, USA
    serp_jobs.job_card.full_time
    serp_jobs.filters_job_card.quick_apply
    TANGIBLE Corporation (gTC), , is a S corporation and a registered Government contractor that provides services and solutions in : . Professional, Administrative, and Management Support.Mission and War...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Security Manager

    Security Manager

    Credence Management SolutionsWashington, DC, US
    serp_jobs.job_card.full_time
    Security Management Specialist.Credence supports our clients' mission-critical needs, powered by technology.We provide cutting-edge solutions, including AI / ML, enterprise modernization, and advance...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    Security Contract Manager

    Security Contract Manager

    gTANGIBLE CorporationWashington, DC, USA
    serp_jobs.job_card.full_time
    serp_jobs.filters_job_card.quick_apply
    TANGIBLE Corporation (gTC), , is a S corporation and a registered Government contractor that provides services and solutions in : . Professional, Administrative, and Management Support.Mission and War...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Site Security Manager - CST (QTS / VA / GZ)

    Site Security Manager - CST (QTS / VA / GZ)

    Clearance JobsManassas, VA, US
    serp_jobs.job_card.full_time
    Construction Surveillance Technician (CST) Site Security Manager.The Construction Surveillance Technician (CST) Site Security Manager is responsible for overseeing the security operations of constr...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Fbi Academy Access Control - Guard Ii Sca

    Fbi Academy Access Control - Guard Ii Sca

    Clearance JobsQuantico, VA, US
    serp_jobs.job_card.full_time
    Koniag Technology Solutions, a Koniag Government Services company, is looking for a highly qualified, experienced, and self-motivated individual to perform the duties of an Access and Escort Specia...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Third-Party Risk Assurance Senior

    Third-Party Risk Assurance Senior

    VirtualVocationsRockville, Maryland, United States
    serp_jobs.job_card.full_time
    A company is looking for a Third-Party Risk Assurance Senior.Key Responsibilities Lead and execute SOC 1, SOC 2, and related security readiness and audit engagements Evaluate and test informatio...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_1_day
    Security Manager

    Security Manager

    Armada LtdFalls Church, VA, USA
    serp_jobs.job_card.full_time
    serp_jobs.filters_job_card.quick_apply
    CONTINGENT UPON AWARD • • • • • • • • • • • • • • • • • • • • • • • • • • • • •.Duties & Responsibilities : .Personnel Security Specific Responsibilities : . The Security Manager will provide policy support and technical guidan...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Traveling Security Control Assessor

    Traveling Security Control Assessor

    Leidos IncAlexandria, VA, United States
    serp_jobs.job_card.full_time
    Leidos is seeking multiple Security Control Assessors to support our traveling assessment team.These positions require extensive travel, estimated 85% of the time. Travel may be domestic or internat...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Senior Security Solutions Architect

    Senior Security Solutions Architect

    VirtualVocationsArlington, Virginia, United States
    serp_jobs.job_card.full_time
    A company is looking for a Senior Security Solutions Architect (Zero Trust & Cloud Security).Key Responsibilities Partner with sales teams for business development and technical presales activiti...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    • serp_jobs.job_card.new
    Security Professional - Access Control Specialist

    Security Professional - Access Control Specialist

    Allied UniversalAlexandria, VA, United States
    serp_jobs.job_card.full_time
    Security Professional - Access Control Specialist.Monday, Thursday, Friday, Sunday.Allied Universal, North America's leading security and facility services company, offers rewarding careers that pr...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_hours
    • serp_jobs.job_card.promoted
    • serp_jobs.job_card.new
    Security Management Lead

    Security Management Lead

    Clearance JobsFalls Church, VA, US
    serp_jobs.job_card.full_time
    ANSER) is seeking a Security Management Lead to oversee and coordinate all onsite security activities, policies, and procedures in support of government operations. In this role, you will lead a tea...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_hours
    • serp_jobs.job_card.promoted
    Senior Security Project Manager

    Senior Security Project Manager

    AccentureWashington, DC, United States
    serp_jobs.job_card.full_time
    Infrastructure & Capital Projects - Senior Security Project Manager, ANS.Accenture Infrastructure & Capital Projects.We are reinventing how capital projects are planned, designed, managed and execu...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Senior Director of Managed Security Portfolio

    Senior Director of Managed Security Portfolio

    TNSReston, VA, US
    serp_jobs.job_card.full_time
    An extraordinarily talented group of individuals work together every day to drive TNSs success, from both professional and personal perspectives. The role is accountable for the full end-to-end prod...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days