Lead Senior Security Control Assessor (SCA) (MNSS-02-005)

SecuriGence LLC
Arlington, VA, US
Full-time

Job Description

Job Description

Job Title : Lead Senior Security Control Assessor (SCA)

Location : Arlington, Virginia

Clearance Level : Top Secret Clearance

Summary

We deliver essential technology services to our customers in support of their missions to sustain the national security and economic interest of our nation.

SecuriGence is seeking a talented Senior Security Control Assessor to help contribute to our success. Come help us solve problems with Innovation Through Intelligence.

Duties :

  • Advise the Information System Owner (ISO) concerning the impact levels for Confidentiality, Integrity, and Availability for the information on systems.
  • Ensure security assessments are completed for each IS.
  • Initiate a POA&M with identified weaknesses and suspense dates for each IS based on findings and recommendations from the SAR.
  • Evaluate security assessment documentation and provide written recommendations for security authorization to the CISO and AO.
  • Assess proposed changes to Information Systems, their environment of operation, and mission needs that could affect system authorization.
  • Serve as a cybersecurity technical advisor to the CISO and AO under their purview.
  • Be integral to the development of the monitoring strategy. The system-level continuous monitoring strategy must conform to all applicable published DoD enterprise-level or DoD Component-level continuous monitoring strategies.
  • Determine and document in the SAR a risk level for every noncompliant security control in the system baseline.
  • Determine and document in the SAR an aggregate level of risk to the system and identify the key drivers for the assessment.

The SCA's risk assessment considers threats, vulnerabilities, and potential impacts as well as existing and planned risk mitigation.

Develop the continuous monitoring plan specific to the information system.

Required Skills and Experience :

  • Strong knowledge of Risk Management Framework (RMF) 800-37 and continuous monitoring 800-137
  • Expert knowledge and hands-on experience with FISMA Systems, NIST 800-series guidelines, FIPS, Security Assessment & Authorization (SA&A) requirements and processes, Continuous Monitoring Framework experience and its tools, Plan of Action & Milestones (POA&M) policies, and vulnerability / patch management, risk management, project management, proficient with Microsoft products - Word, Excel, PowerPoint.
  • Proficient with vulnerability and scanning tools and well-versed in interpreting risk posture resulting from assessment reports.

Experience in project management and tracking, and the Microsoft suite of office products

  • Experience of assessing cloud-based security authorizations (FedRamp, AWS & Azure) as well as the NIST control responsibilities
  • Experience with SAP / JSIG
  • Expert with documenting and or reviewing of security materials such as; system security plans (SSP), Security Assessment Report (SAR), and Security Assessment Plan (SAP), and other documents per NIST 800 guidelines.
  • Experience supporting cloud-based security authorizations (FedRamp, AWS, & Azure)
  • Experience creating Security Assessment Plans, Security Assessment Reports, and Executive-level briefings

Qualifications :

  • Bachelor's degree or higher. Can be substituted for Associate's degree with 2+ years of relevant experience or 4 years relevant experience.
  • 5 years relevant experience.
  • DOD 8140 IAM Level II (CAP, CASP, CISM, CISSP, GSLC, CCISO)
  • Top-Secret Clearance with SCI eligibility is required.
  • Performing work onsite is required.

About

SecuriGence LLC (SG) is an agile, Veteran-owned small business headquartered in the Washington, DC metropolitan region. Established in April 2010 we have been supporting the Department of Defense and other United States Civil agencies in Systems Engineering, Software Engineering, Software Development, Cyber Security, and Cloud / Virtualization Management.

SecuriGence provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws.

7 hours ago
Related jobs
Promoted
SecuriGence LLC
Arlington, Virginia

Lead Senior Security Control Assessor (SCA). SecuriGence is seeking a talented Senior Security Control Assessor to help contribute to our success. Expert with documenting and or reviewing of security materials such as; system security plans (SSP), Security Assessment Report (SAR), and Security Asses...

Promoted
Accenture Federal Services
Arlington, Virginia

The Lead SME Platform Architect Senior Manager will re-architect, redesign, and deliver a highly available, high performing IT Infrastructure. Our 13,000+ people are united in a shared purpose to pursue the limitless potential of technology and ingenuity for clients across defense, national security...

Promoted
SOSi
Reston, Virginia

Coordinate with senior leadership and senior intelligence officials on station to ensure CI activities support CI teams, OMT, S2X, and CJ2X and other supported Commands. Coordinate with senior leadership and senior intelligence officials on station to ensure CI activities support CI teams, OMT, S2X,...

Promoted
Accenture Federal Services
Arlington, Virginia

The Lead SME Cloud Architect Senior Manager will ensure Infrastructure is CSP agnostic to enable migration from a single cloud provider (AWS) to a multi-cloud environment (Azure, Google, Salesforce, +). Our 13,000+ people are united in a shared purpose to pursue the limitless potential of technology...

Promoted
Zermount, Inc
Arlington, Virginia

Security Control Assessor Team Lead who will play a vital role in leading multiple teams on large projects. Security Control Assessor Team Lead. A minimum of ten (10) years of IT cybersecurity experience including direct support for the US Government and seven (7) years actin as an ISSO, assessor, o...

Promoted
Leidos Inc
Springfield, Virginia

Leidos has a critical need for a Security Controls Assessor to support the DHS Cyber Assessments Program. Leidos has a critical need for a Security Controls Assessor to support the DHS Cyber Assessments Program. The mission of the DHS Chief Information Security Officer Directorate (DHS CISOD) is to ...

Marathon TS
Arlington, Virginia

Reference : ODID _NIH_SCA(Security Control Assessment) Lead. Role Title SCA(Security Control Assessment) Lead Start Date for assignment // End Date for assignment // of Resources Needed Hours per Week Job Description. Technical Skills: Skill Years/Level of Experience Cyber Risk & Controls P – Interm...

McIntire Solutions
McLean, Virginia

Title: Security Control Assessor Location:   McLean, VA McIntire Solutions is seeking a Security Control Assessor to support our McLean Customer. Required Qualifications Bachelor's Degree (Computer engineering, Computer Science, Electrical Engineering, Information systems, Information Technolog...

VTG
McLean, Virginia

Applies experience with RMF, CNSSI 1253, NIST SP 800-53, and NISPOM Applies experience with Security Technical Implementation Guides (STIGs) and Security Content Automation Protocol (SCAP) Compliance Checker (SCC) Demonstrated experience conducting hands on security testing, analyzing results, docum...

Maximus
Arlington, Virginia

The Security Control Assessor is responsible for conducting a comprehensive assessment of the management, operational, and technical security controls employed within or inherited by an SAP information system to determine the overall effectiveness of the controls (i. Job Posting Title Security Contr...