Security Control Assessor

Novul Solutions


Job Location:

Loudoun County, VA - USA

Monthly Salary: $ 90 - 145000
Experience Required: 5years
Posted on: 5 hours ago
Vacancies: 1 Vacancy

Job Summary

Position Overview

We are seeking an experienced Security Control Assessor to support cybersecurity assessment and authorization activities for Department of Defense information systems. This role is responsible for conducting in-depth security control assessments validating control implementation reviewing system security documentation and supporting the development and maintenance of complete and accurate Authorization to Operate packages.

The ideal candidate will bring extensive experience with the Risk Management Framework NIST security standards DoD cybersecurity policies and the Joint Special Access Program Implementation Guide. The individual must be capable of communicating assessment findings remediation requirements and government-approved mitigation strategies to system owners and technical stakeholders.

Key Responsibilities:
  • Conduct comprehensive security control assessments of DoD information systems in accordance with NIST SP 800-53 DoD RMF policies CNSSI 1253 and the JSIG.
  • Evaluate the implementation and effectiveness of security controls and document assessment findings risks deficiencies and recommended corrective actions.
  • Communicate government-approved mitigation and remediation requirements to system owners cybersecurity personnel and technical stakeholders in support of the RMF process.
  • Apply the cybersecurity principles of confidentiality integrity and availability when evaluating system categorization and impact levels including High Moderate and Low classifications.
  • Validate security controls identified as inherited from hosting environments connected systems enterprise services or other authorized systems.
  • Assess program compliance with security controls associated with registered Ports Protocols and Services including the proper generation retention protection and handling of system log files.
  • Review system security documentation and supporting evidence for accuracy completeness consistency and alignment with applicable cybersecurity requirements.
  • Lead the review preparation and quality assurance of Authorization to Operate packages and related RMF documentation.
  • Identify control gaps weaknesses and areas of noncompliance and provide clear actionable recommendations for remediation.
  • Coordinate with system owners information system security personnel engineers program leadership and government stakeholders throughout the assessment and authorization lifecycle.
  • Support the development review and validation of Plans of Action and Milestones and other risk-management documentation.
  • Provide leadership and technical guidance to assessment teams and support the resolution of complex cybersecurity compliance issues.


Requirements

Required Qualifications:
  • Bachelors degree in cybersecurity information technology computer science information systems engineering or a related field.
  • Eight or more years of professional experience in cybersecurity.
  • Five or more years of experience supporting Certification and Accreditation or Assessment and Authorization activities.
  • Expert-level knowledge of the DoD Risk Management Framework.
  • Strong working knowledge of NIST SP 800-37 NIST SP 800-53 CNSSI 1253 and the JSIG.
  • Experience conducting security control assessments and evaluating technical operational and management controls.
  • Experience reviewing and preparing ATO packages and supporting documentation.
  • Experience validating inherited controls and assessing Ports Protocols and Services requirements.
  • Demonstrated leadership experience including previous experience serving in a lead or senior assessment role.
  • Strong written and verbal communication skills with the ability to clearly explain technical findings risks and remediation requirements to system owners and government stakeholders.
Preferred Qualifications
  • Experience supporting DoD Special Access Programs or other highly classified environments.
  • Experience working directly with system owners ISSOs ISSMs security engineers and Authorizing Official representatives.
  • Familiarity with security assessment reports risk assessment reports system security plans POA&Ms and continuous-monitoring documentation.
  • Experience leading assessment teams or overseeing multiple system authorization efforts.
  • Strong analytical documentation-review and quality-assurance skills.


Benefits

Core Benefits:
  • Paid Time Off PTO):TEN (10) Paid days off & FIVE (5) Floating days off.
  • Holidays: 11 Paid Holidays. Flex time can be utilized instead of holiday time usage.
  • Payroll: Paid Bi-Monthly.
  • 401(k): Partnered with the SECOND LARGEST Retirement plan provider in the U.S. Guaranteed 3% match. Eligibility 21 years of age or older after 3 months of employment
  • Individual or company-wide performance and recognition awards (Quarterly)
Health Benefits:
  • UNITED HEALTHCARE PPO extensive national coverage.
  • INCLUDES: Medical/Dental/Vision/HSA.
  • Eligible on the first of the month immediately after the start date.
  • Submit the enrollment form within 30 days of your start date otherwise you will have to wait until October for the new year enrollment.
Quality of Life Benefits:
  • Training & Career Development Reimbursement of Tuition and training needed to support career development.
  • $150 monthly reimbursement contribution paid monthly towards parking expenses.
  • Receipts must be submitted by the close of business on the 25th of each month.
  • Reimbursements will be paid on the first payroll AFTER reimbursements are submitted each month.
Special Benefits:
  • Performance bonus Project-based
  • Yearly bonus Company based



Required Skills:

Expert knowledge of DoD RMF Assessment and Authorization NIST SP 800-37 NIST SP 800-53 CNSSI 1253 and JSIG requirements. Strong experience conducting security control assessments identifying deficiencies and recommending approved mitigation and remediation actions. Proven ability to review prepare and validate complete ATO packages including SSPs SARs RARs POA&Ms and supporting evidence. Experience validating inherited controls system categorization CIA impact levels and Ports Protocols and Services requirements. Demonstrated leadership and ability to communicate findings risks and corrective actions to system owners technical teams and government stakeholders.


Required Education:

8 years experience in Cybersecurity area5 years Certification and Accreditation/ Assessment and Authorization

Position Overview We are seeking an experienced Security Control Assessor to support cybersecurity assessment and authorization activities for Department of Defense information systems. This role is responsible for conducting in-depth security control assessments validating control implementation re...