Full-Time

Security Control Assessor/Representative

Updated on 8/18/2026

Dark Wolf Solutions

Dark Wolf Solutions

201-500 employees

DevSecOps, security testing, and incident response.

Compensation Overview

$135k - $150k/yr

No H1B Sponsorship

Arlington County, Arlington, VA, USA

Hybrid

Hybrid work opportunities are available.

US Top Secret Clearance Required

Category
IT & Security (1)
Required Skills
LLM
FedRAMP
Pinecone
PyTorch
Postgres
Docker
RAG
CloudFormation
Microservices
AWS
Terraform
LangChain
Penetration Testing
DevOps

Get referred to Dark Wolf Solutions

See people who can refer or advise you

Requirements
  • Active Top Secret security clearance.
  • Current Department of Defense 8570/8140 Information Assurance Manager Level II or Level III certification, such as Security+, CySA+, CISM, CISSP, CCISO, or CAP/CISC.
  • Three to five or more years of experience conducting security control assessments, compliance testing, or Authorization and Accreditation/Risk Management Framework activities for Department of Defense or federal information systems.
  • Solid operational understanding of core Amazon Web Services cloud services, including EC2, S3, IAM, VPCs, Security Groups, and Security Hub, and how security controls function within cloud-native and continuous integration and continuous delivery pipeline environments.
  • Strong working knowledge of NIST SP 800-53 Revision 4/5, NIST SP 800-37 Risk Management Framework, the Department of Defense Cloud Computing Security Requirements Guide, and FedRAMP baselines.
  • Demonstrated experience writing and evaluating core Risk Management Framework artifacts, including System Security Plans, Security Assessment Plans, Security Assessment Reports, and Plans of Action and Milestones.
  • Ability to articulate technical risk clearly to executive stakeholders, Authorizing Officials, and engineering teams.
  • Hands-on experience navigating government governance, risk, and compliance repositories such as eMASS or XACTA.
  • Ability to verify identity and eligibility to work in the United States.
  • Availability to work as a direct, full-time W2 employee rather than through a staffing agency, corporation-to-corporation arrangement, or independent contractor arrangement.
Responsibilities
  • Execute formal Security Control Assessor/Representative duties.
  • Lead security assessment efforts by establishing reusable security playbooks and assessment frameworks for rapid artificial intelligence deployment into enterprise workflows.
  • Evaluate technical control effectiveness across Amazon Web Services cloud infrastructure, DevSecOps pipelines, microservices, containerized workloads, and generative artificial intelligence and large language model application stacks.
  • Partner with cybersecurity engineering and DevSecOps prototyping teams to integrate security controls early in the development lifecycle.
  • Review, author, and maintain assessment packages, including System Security Plans, Security Assessment Plans, Security Assessment Reports, and Plans of Action and Milestones, tailored to rapid prototyping and artificial intelligence systems.
  • Assess technical security risks specific to artificial intelligence and large language model implementations, including application programming interface exposure, vector database access controls, model integration surface area, and software supply chain dependencies.
  • Support continuous monitoring, technical risk evaluations, and cloud architecture reviews across multi-tenant, multi-classification environments.
  • Coordinate with Authorizing Officials, program managers, and engineering leads to deliver decision-ready risk briefings and Authorization to Operate recommendations.
  • Provide technical input and oversight for cybersecurity engineering and penetration testing activities across prototype projects.
Desired Qualifications
  • Hands-on experience mapping security controls to the NIST Artificial Intelligence Risk Management Framework, the OWASP Top 10 for Large Language Model Applications, or Department of Defense Responsible Artificial Intelligence Guidelines.
  • Familiarity with secure design patterns for autonomous artificial intelligence agents, including tool-calling permissions, sandboxing agent execution environments, prompt boundaries, and ReAct or LangGraph architectures.
  • Experience assessing cloud-managed artificial intelligence ecosystems and foundation model platforms such as AWS Bedrock, AWS SageMaker, Hugging Face Enterprise, or self-hosted open-source models.
  • Understanding of data protection, access controls, and boundary security for retrieval-augmented generation pipelines and vector databases such as OpenSearch Vector Engine, Pinecone, Milvus, or PostgreSQL pgvector.
  • Familiarity evaluating risks unique to large language models, including prompt injection, data poisoning, model inversion, insecure output handling, and open-source supply chain vulnerabilities in artificial intelligence libraries such as PyTorch, LangChain, and LlamaIndex.
  • Exposure to large language model guardrail platforms, evaluation frameworks, or artificial intelligence security tools such as Promptfoo, Garak, Giskard, or NeMo Guardrails used to test model robustness and output safety.
  • Experience with continuous Authorization to Operate methodologies, Infrastructure as Code templates such as Terraform and CloudFormation, and container security using AWS EKS/ECS or Docker.
  • Active AWS certifications, such as AWS Certified Security – Specialty or AWS Certified Solutions Architect.
  • Background or familiarity with offensive security and penetration testing.

Dark Wolf Solutions provides DevSecOps agile software development, information operations, penetration testing and incident response, applied research and rapid prototyping, machine learning, and mission support for the Intelligence Community, national security, and Fortune 500 customers. They integrate secure development, security testing, rapid prototyping, ML, and operations support to deliver secure software and cyber capabilities aligned with specific mission needs. They combine deep federal domain expertise with emerging technologies to offer end-to-end capabilities from development to ongoing operations. Their goal is to help security-focused organizations advance their missions while keeping systems secure and resilient.

Company Size

201-500

Company Stage

N/A

Total Funding

N/A

Headquarters

Herndon, Virginia

Founded

2009

Get referred to Dark Wolf Solutions

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • On June 11, 2026, Dark Wolf won a Navy IDIQ worth $178.4 million.
  • On February 2, 2026, the Air Force awarded a $67.2 million cyber contract.
  • January 2026 reorganization added BrickStor products, broadening mission data and ransomware defenses.

What critics are saying

  • GSA MAS option ends September 1, 2026, exposing renewal risk across federal sales.
  • Herndon hiring data shows 28 openings, signaling execution pressure during aggressive contract growth.
  • Dark Wolf depends on DoD sole-source and set-aside vehicles; one protest starves revenue.

What makes Dark Wolf Solutions unique

  • Dark Wolf is sole awardee on Air Force Cyberspace Innovation IDIQ, announced February 2026.
  • Its Platform One marketplace lists seven awardable accelerators, including DARK MASS and Data Den.
  • The company spans GSA MAS, SeaPort-NxG, and Navy IDIQs, deepening federal buying access.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Hybrid Work Options

Growth & Insights and Company News

Headcount

6 month growth

18%

1 year growth

18%

2 year growth

18%
JoBlo.com
Feb 9th, 2024
The Terminal List: Dark Wolf adds Luke Hemsworth to the season's cast

The Terminal List: Dark Wolf adds Luke Hemsworth to the season's cast.

PR Newswire
May 17th, 2022
At-Impact And Dark Wolf Enterprise Toolchain To Support Kessel Run

FALLS CHURCH, Va., May 17, 2022 /PRNewswire/ -- At-Impact, in partnership with Dark Wolf, was awarded the Kessel Run's Enterprise Toolchain contract (Kessel ET), a $41M CIO-SP3 SB award to provide Commercial IT services and the integrated support team needed to enhance Kessel Run's...