Security Control Assessor - Senior

ATG
Fort Meade, MD, USA
Full-time

ARCYBER-03 - Security Control Assessor -

Senior

Requisition : 2024-01-014

Description / Job Summary

Security Control Assessor - Senior

Job Location : Fort Meade, MD

Position Type : Full Time, 40 hours per week

Athena Technology Group, Inc. is a Service-Disabled Veteran Owned / Small Business (SDVOSB)

focused on Information Technology and Communications consulting, system engineering,

integration, deployment and operations of stat of the art command and control and information

systems that deliver critical network centric solutions to the warfighter. With a proven track record

of technical support to our customers, we are looking for innovative industry professionals to join

our team. Please contact [email protected].

JOB DESCRIPTIONS :

Perform Security Control Assessments to determine the extent to which Information System

security controls are implemented correctly, operating as intended, and producing the desired

outcomes as stated in the DISA Information Assurance Requirements. Conducts independent

comprehensive assessments of the management, operational, and technical security controls and

control enhancements employed within or inherited by an information technology (IT) system to

determine the overall effectiveness of the controls. Follow Assessment and Authorization

procedures as defined in NIST 800-37 to complete comprehensive security control assessment and

draft formal Security Assessment Reports (SAR) to document finding.

Tasks :

Plan and conduct security authorization reviews and assurance case development for initial

installation of systems and networks.

Review authorization and assurance documents to confirm that the level of risk is within

acceptable limits for each software application, system, and network.

Verify that application software / network / system security postures are implemented as stated,

document deviations, and recommend required actions to correct those deviations.

Develop security compliance processes and / or audits for external services (e.g., cloud

service providers, data centers).

Perform security reviews, identify gaps in security architecture, and develop a security risk

management plan.

Verify and update security documentation reflecting the application / system security design

features.

Ensure that plans of actions and milestones or remediation plans are in place for

vulnerabilities identified during risk assessments, audits, inspections, etc.

Support necessary compliance activities (e.g., ensure that system security configuration

guidelines are followed, compliance monitoring occurs).

Assess the effectiveness of security controls and assess all the configuration management

change configuration / release management) processes.

Desired skills :

Experience with RMF, CNSSI 1253, NIST SP 800-53, ICD 503

Experience with Security Technical Implementation Guides (STIGs) and Security Content

Automation Protocol (SCAP) Compliance Checker (SCC)

Experience with utilizing Telos XACTA tool

Applies knowledge of Information Assurance Vulnerability Alerts (IAVAs)

Applies experience with compliance and vulnerability scanning tools (Nessus, McAfee ePO)

Conducts comprehensive security control assessments levied against a system and

documenting the results, including recommendations for correcting any weaknesses or

deficiencies in the controls

Develops a Security Assessment Report (SAR)

Conducts comprehensive reviews of security authorization documents to ensure the

appropriate NIST security guidelines were used during the assessments and the selections of

security controls are relevant to the confidentiality, integrity, and availability of the system

Performs security control assessments on cloud-based systems

Required Experience :

10+ years of relevant experience as a cyber security control assessor or a MS with 5 years

Certification Requirements : IAM Level II, CAP or CCSP preferred

Education Requirement : B.S. or relevant experience in related field

Clearance Requirements : Active TS / SCI

US Citizenship and an active DOD TOP SECRECT / SCI Clearance are required for the position.

Salary will be commensurate with experience. ATG is a growing company and there will

be opportunities for internal advancement. ATG is an Equal Opportunity Employer.

14 days ago
Related jobs
Promoted
Northrop Grumman
Baltimore, Maryland

Experience with the design of one or more parts of multi-axis pointing and tracking control systems with inertial stabilization * Experience with integration and test of one or more parts of multi-axis pointing and tracking control systems with inertial stabilization * Able to function in a multi-di...

Tulzi Technologies, LLC
Fort Meade, Maryland

Title: Security Controls Assessor (SCA) Senior. Experience in security or system engineering in five or more areas, including: telecommunications concepts, operating systems, databases/DBMS, middleware, applications, web-servers, SANS/Netaps, Active Directory, firewalls, and controlled interfaces. C...

Technology Resource Experts LLC
Linthicum Heights, Maryland

Experience in security or system engineering in five or more areas, including: telecommunications concepts, operating systems, databases/DBMS, middleware, applications, web-servers, SANS/Netaps, Active Directory, firewalls, and controlled interfaces. Conducts verification and validation for security...

Sentar
Columbia, Maryland

Experience in security or system engineering in five or more areas, including: telecommunications concepts, operating systems, databases/DBMS, middleware, applications, web-servers, SANS/Netaps, Active Directory, firewalls, and controlled interfaces. Conducts verification and validation for security...

ATG
Fort Meade, Maryland

Security Control Assessor - Senior. ARCYBER-03 - Security Control Assessor -. Perform security reviews, identify gaps in security architecture, and develop a security risk. Perform Security Control Assessments to determine the extent to which Information System. ...

Chickasaw Nation Industries, Inc.
Fort Meade, Maryland

Security Control Assessor Representative (SCA-R) / Dedicated Team Lead. Has practical analytic skills to evaluate security posture with automated security tool and recommends mitigation and optimizes security posture of IT components. Lead a team to perform certification assessments for assigned pro...

Applied Insight
Fort Meade, Maryland

As the Security Control Assessor, you will conduct verification and validation for security compliance of low and moderately complex information systems, products, and components. Five (5) years' experience in security, systems engineering or system assessment to include recent experience within the...

Acclaim Technical Services
Annapolis Junction, Maryland

Conduct on-site evaluations; Conducts verification and validation for security compliance of low and moderately complex information systems, products, and components; provide identification of non-compliance of security requirements and possible mitigations to requirements that are not in compliance...

Applied Insight
Fort Meade, Maryland

As the Security Control Assessor Level 3 you will Conduct verification and validation for security compliance of low and moderately complex information systems, products, and components. Twelve (12) years' experience in security, systems engineering or system assessment to include recent experience ...

Jacobs
Columbia, Maryland

Security Controls Assessor - Columbia, MD - TS/SCI w/Poly-(CIS00026L). Experience in security or system engineering in five or more areas, including: networking concepts, operating systems, databases/DBMS, middleware, applications, web-servers, data storage, Active Directory, firewalls, and controll...