Enter a job title or keyword

Security Control Accessor


Job Location:

Washington, DC - USA

Monthly Salary: Not provided by the employer
Posted: 1 September 2026 (Yesterday)
Application Deadline: 29 November 2026
Vacancies: 1 Vacancy

Job Summary

Koniag Data Solutions a Koniag Government Services company is seeking an experiencedSecurity Control Assessor (SCA)to support a comprehensive enterprise cybersecurity services program for a federal government client. This position requires the ability to obtain and maintain a Minimum Background Investigation (MBI) or higher PIV credentials and all requisite IT access authorizations prior to performing work. Primary work will be performed at the client site in Washington DC and approved remote/telework locations. We offer competitive compensation and an extraordinary benefits package including health dental and vision insurance 401K with company matching flexible spending accounts paid holidays three weeks paid time off and role serves as a key technical contributor responsible for the independent assessment and evaluation of security and privacy controls across the clients enterprise IT portfoliospanning on-premises cloud-hosted and hybrid systemsin support of the agencys Federal Information Security Modernization Act (FISMA) compliance program Risk Management Framework (RMF) activities and Ongoing Authorization (OA) ideal candidate is a detail-oriented and technically proficient security assessment professional with demonstrated experience conducting NIST SP 800-53 security and privacy controls assessments developing Security Assessment Reports (SARs) supporting Authority to Operate (ATO) activities and executing continuous monitoring assessments across a diverse federal enterprise IT environment. This individual must possess the ability to work independently across complex multi-technology system boundaries and deliver thorough accurate and well-written assessment artifacts that meet rigorous federal documentation Security Control Assessor will serve as an independent technical evaluator responsible for planning executing and reporting on security and privacy controls assessments for assigned systems and services across the clients enterprise IT portfolio. This individual is responsible for assessing the implementation and effectiveness of NIST SP 800-53 security and privacy controls documenting assessment findings in accordance with NIST SP 800-53A methodologies producing high-quality assessment artifacts and supporting the full RMF assessment lifecycle from initial planning through final report delivery and POA&M development. The SCA works closely with ISSOs system owners security engineers and Government stakeholders to ensure assessments are thorough accurate and completed within required responsibilities will include but are not limited to:Security & Privacy Controls AssessmentPlan execute and report on comprehensive security and privacy controls assessments for assigned federal information systems and services including on-premises IaaS PaaS and SaaS implementations in accordance with NIST SP 800-53 Rev 5 NIST SP 800-53A Rev 5 and applicable agency implementation point-in-time full controls assessments annual controls assessments multi-year one-third assessments and Ongoing Authorization (OA) evaluation assessments in accordance with the agencys assessment schedule and applicable implementation and deliver draft Security Assessment Plans (SAPs) no less than ten (10) business days prior to beginning each assessment clearly documenting the assessment scope boundaries sampling strategies test methods and NIST SP 800-53A Determine If Statements (DISs) for all in-scope controls documenting assessment findings to a level of detail sufficient to demonstrate that the implementation of each control objective is validated or not validated avoiding high-level summary statements and ensuring technical depth across all technology types within the system technical controls assessments across all technology types within each system boundary including Windows and UNIX servers network devices (routers switches Cisco F5 load balancers) web applications databases cloud platforms and endpoint systems applying appropriate sampling strategies approved by the Government prior to Government-approved sampling strategies encompassing all asset types within each system boundary typically between ten (10) and twenty (20) percent of applicable assets where appropriate ensuring sampling covers all relevant device types users and identified vulnerabilities and assessment findings to applicable NIST SP 800-53 Rev 5 controls and control families ensuring accurate and complete linkage between technical findings and corresponding control comprehensive draft and final Security Assessment Reports (SARs) within required timelines ensuring reports are comprehensive to the scope identified in the SAP fully aligned to the agencys Governance Risk and Compliance (GRC) tool include visual representation against the NIST Cybersecurity Framework (CSF) and are peer-reviewed for accuracy and grammar prior to draft Plans of Action and Milestones (POA&M) entries for identified control deficiencies typically using the agencys GRC tool delivering draft POA&Ms within thirty (30) calendar days from point-in-time assessment draft Annual Assessment Reports (AARs) per in-scope system within one-hundred-twenty (120) business days from point-in-time annual assessment kickoff and deliver draft summary reports for multi-year assessment efforts no later than sixty (60) business days prior to the end of each Fiscal all Government feedback into assessment artifacts within five (5) business days of receipt of comments delivering finalized deliverables that accurately reflect all Government-provided corrections questions and Authorization (OA) Evaluation SupportConduct Ongoing Authorization (OA) controls assessments for systems approved for OA applying agency-specific OA test procedures that replace traditional NIST SP 800-53A test procedures for OA-approved OA Positive Testing monthly for OA-approved systems using automated or semi-automated techniques to determine whether controls are operating effectively under normal circumstances documenting results in the agency GRC tool in accordance with OA implementation OA Negative Testing annually for OA-approved systems using automated or semi-automated techniques to determine whether controls respond as expected under abnormal circumstances where misuse is injected to attempt to circumvent the control coordinating as necessary with penetration testing purple team in the development and submission of OA Playbooks for Government approval documenting the testing methodology for each OA core control including Test Strategy Test Design Test Execution Results Evaluation and Visualization OA testing comprehensively across all technology types within each target systems boundary including sampling across in-scope devices users and services documenting all test results in detail within the agency GRC tool in accordance with applicable OA implementation all OA Positive and Negative Testing documentation is peer-reviewed for accuracy and grammar prior to submission to the Support & CollaborationCollaborate closely with assigned ISSOs to support their development of in-depth technical and operational knowledge about assigned systems providing assessment expertise technical guidance and documentation support as technical support and expertise to ISSOs in the development and maintenance of all security documentation in the ATO package including System Security Plans (SSPs) Configuration Management Plans (CMPs) Information System Contingency Plans (ISCPs) and other RMF artifacts ensuring documentation aligns with applicable agency implementation procedures and template ISSOs in reviewing and validating system security documentation for technical accuracy completeness and alignment with the system boundary and technology stack providing specific and actionable feedback to improve documentation ISSOs in ensuring control implementation descriptions within SSPs are written to the required level of technical detail clearly explaining how each control is implemented across all technologies within the system boundary using specific naming conventions configurations and operational procedures rather than high-level general in Enterprise Change Control Board (ECCB) activities as needed providing security assessment expertise to support the evaluation of proposed system changes and their potential impact on the systems security posture and ATO & Compliance SupportSupport internal and external audit activities for assigned FISMA systems facilitating meetings and walkthroughs of key cybersecurity capabilities coordinating with system support personnel and supplying auditors with requested artifacts and evidence within required audit artifacts are complete accurate and delivered on time to avoid repeated requests from auditors communicating any issues or problems to the Government immediately upon FISMA continuous monitoring activities including the collection validation and submission of system-level FISMA metrics for assigned systems in alignment with federal CIO metrics requirements and agency reporting in the development and maintenance of automated visualizations and dashboards that reflect the status and effectiveness of security controls for assigned systems providing continuous visibility into the security posture and compliance status of assigned High Value Asset (HVA) assessment activities for designated HVA systems including vulnerability scanning and remediation validation monitoring and analysis of relevant audit logs and identification of connections between HVAs and other in FedRAMP Continuous Monitoring (CONMON) management activities for applicable cloud service provider systems including review of vulnerability penetration testing and ad hoc reporting to ensure vendor actions pose no security risk to the enterprise & ReportingDevelop and maintain all assigned security and privacy assessment documentation in alignment with applicable agency implementation procedures ensuring all documents are complete well-written aligned to agency templates and meet the level of detail specified in agency all assigned documents are updated in the agencys GRC tool and relevant SharePoint repositories in accordance with required timelines and agency and submit all assigned deliverables peer-reviewed for accuracy punctuation and grammar prior to submission ensuring deliverables are delivered on or before agency-defined completion all Government-provided comments edits errors and questions within ten (10) business days of receipt and escalate stakeholder unresponsiveness to the Government POC after ten (10) business days without receiving a required all documentation created under the contract is Government owned properly marked accessible via Section 508 compliant formats as required and not marked with any proprietary or company-restrictive and Experience:Required:Bachelors degree in Computer Science Information Technology Cybersecurity Information Systems or a related field from an accredited college or of 5 years of experience in federal information security with demonstrated hands-on experience conducting NIST SP 800-53 security and privacy controls assessments for federal information experience developing Security Assessment Plans (SAPs) Security Assessment Reports (SARs) Annual Assessment Reports (AARs) and Plans of Action and Milestones (POA&Ms) in accordance with NIST SP 800-53A methodologies and federal RMF conducting technical controls assessments across diverse technology stacks including Windows and UNIX servers network devices web applications databases and cloud platforms (IaaS PaaS SaaS).Experience working with federal agency Governance Risk and Compliance (GRC) tools for documentation management POA&M tracking and continuous monitoring to obtain and maintain a Minimum Background Investigation (MBI) or higher PIV credentials and all requisite IT access authorizations; must be eligible for Top Secret clearance access should such a requirement arise during the period of :CISSP certification or demonstrated equivalent experience and commitment to obtain within 12 months of experience supporting federal civilian agency FISMA compliance programs in a Security Control Assessor or ISSO working on GSA Multiple Award Schedule (MAS) HACS SIN contracts or comparable federal IT cybersecurity contract conducting Ongoing Authorization (OA) assessments using agency-specific positive and negative testing Skills and Competencies:Exceptional written communication skills in English with demonstrated ability to produce clear concise technically thorough and professionally written security assessment artifacts that meet rigorous federal documentation standards including SSPs SAPs SARs AARs and POA& knowledge of NIST SP 800-53 Rev 5 security and privacy control families including the ability to assess all control families across diverse federal information systems and accurately document implementation status at the required level of technical proficiency with NIST SP 800-53A Rev 5 assessment methodologies including development and execution of Determine If Statements (DISs) examination interview and testing assessment methods and objective-based evidence collection and validation ability to conduct technical controls assessments across heterogeneous technology stacks including the ability to assess controls across Windows and UNIX operating systems Cisco and other network devices F5 load balancers web applications SQL and NoSQL databases and cloud service developing and applying Government-approved sampling strategies for large-scale system assessments ensuring sampling encompasses all asset types and is representative of the full system with federal GRC tools for documentation development POA&M management continuous monitoring tracking and assessment results with the NIST Risk Management Framework (RMF) lifecycle including all six RMF stepsCategorize Select Implement Assess Authorize and Monitorand the contractors role in supporting each of FISMA reporting requirements federal CIO metrics and the agency reporting process including CyberScope submission supporting federal audit activities including IG GAO and internal auditor engagements including preparation and delivery of audit artifacts within required with NIST Cybersecurity Framework (CSF) and the ability to represent assessment findings visually against CSF functions in assessment with FedRAMP authorization and continuous monitoring requirements for cloud service providers including review of CSP vulnerability and penetration testing of High Value Asset (HVA) assessment requirements including OMB M-19-03 and CISA HVA 3.0 framework organizational skills with the ability to manage multiple concurrent assessment workstreams meet tight deadlines and maintain accurate and current documentation across a portfolio of assigned with Section 508 accessibility requirements for federal documentation and the ability to produce Section 508 compliant deliverables in Adobe and Microsoft Word formats as Skills and Competencies:Certified Information Systems Security Professional (CISSP) certification or demonstrated commitment to obtain within 12 months of contract Authorization Professional (CAP) / ISC2 Certified in Governance Risk and Compliance (CGRC) certification or equivalent RMF-focused professional Security certification or equivalent foundational cybersecurity conducting Ongoing Authorization (OA) assessments using agency-specific outcome-based positive and negative testing methodologies including coordination with penetration testing purple team resources for negative testing developing OA Playbooks documenting test strategy test design test execution results evaluation and visualization components for OA core with NIST SP 800-37 Rev 2 Risk Management Framework and its practical application within a federal civilian agency of cloud security assessment methodologies for IaaS PaaS and SaaS environments including AWS and Microsoft Azure/M365 security control implementations and assessment with NIST SP 800-207 Zero Trust Architecture and its implications for security control implementation and assessment within a federal enterprise with enterprise vulnerability scanning tools including Tenable Security Center and Nessus sufficient to review and incorporate vulnerability scan data into security control assessments and continuous monitoring with Microsoft Defender suite Microsoft Sentinel and other Microsoft M365 security capabilities sufficient to assess and document relevant security controls within systems leveraging these of NIST SP 800-171 Rev 3 requirements for protecting Controlled Unclassified Information (CUI) in non-federal systems and their relationship to NIST SP 800-53 control with privacy controls assessments including assessment of NIST SP 800-53 privacy control families and documentation of privacy control implementation status within SSPs and with the Factor Analysis of Information Risk (FAIR) methodology as applied to risk quantification activities supporting security assessment findings and POA&M supporting tabletop exercises and functional exercises related to incident response and contingency planning in support of FISMA compliance with the ServiceNow GRC module or equivalent enterprise GRC platform for POA&M tracking continuous monitoring and assessment documentation of NIST SP 800-160 systems security engineering principles as they relate to security architecture review and assessment activities within the secure Equal Employment Opportunity Policy:The company is an equal opportunity employer. The company shall not discriminate against any employee or applicant because of race color religion creed ethnicity sex sexual orientation gender or gender identity (except where gender is a bona fide occupational qualification) national origin or ancestry age disability citizenship military/veteran status marital status genetic information or any other characteristic protected by applicable federal state or local law. We are committed to equal employment opportunity in all decisions related to employment promotion wages benefits and all other privileges terms and conditions of company is dedicated to seeking all qualified applicants. If you require an accommodation to navigate or to apply to a position on our website please contact Heaven Wood via e-mail at or by calling to request accommodations. Koniag Government Services (KGS) is an Alaska Native Owned corporation supporting the values and traditions of our native communities through an agile employee and corporate culture that delivers Enterprise Solutions Professional Services and Operational Management to Federal Government Agencies. As a wholly owned subsidiary of Koniag we apply our proven commercial solutions to a deep knowledge of Defense and Civilian missions to provide forward leaning technical professional and operational solutions. KGS enables successful mission outcomes for our customers through solution-oriented business partnerships and a commitment to exceptional service delivery. We ensure long-term success with a continuous improvement approach while balancing the collective interests of our customers employees and native communities. For more information please visit Opportunity Employer/Veterans/Disabled. Shareholder Preference in accordance with Public Law 88-352

About Company

Company Logo

What We Do Koniag Government Services (KGS) is an Alaska Native Corporation comprised of multiple wholly owned subsidiary companies that deliver Enterprise Solutions, Professional Services, and Operations Management to Federal Government agencies. With an agile employee and corporate ... View more

View Profile View Profile