Full-Time

Security Control Assessor

Posted on 11/22/2025

KACE

KACE

No salary listed

Reston, VA, USA + 1 more

More locations: Bethesda, MD, USA

In Person

US Top Secret Clearance Required

Category
IT & Security (1)
Requirements
  • Bachelor’s degree in computer engineering, Computer Science, Electrical Engineering, Information Systems, Information Technology, Cybersecurity, or a closely related discipline.
Responsibilities
  • Review, detect, and document gaps and conflicting information within the Body of Evidence presented during validation assessments by Programs and projects via demonstrated understanding of required content and ability to generate a range of security artifacts to include SAR, SSP, Automated Scan Tool Report, POA&M, etc.
  • Conduct architecture and system scanning to detect vulnerabilities and compliance with automated tools, and perform an analysis based on tool reports, to include false positive analysis and compensating controls.
  • Have in-depth understanding of RMF, IV&V methodology and NIST 800-53 revision 4 and ability to perform within Telos Xacta implementation of RMF workflows.
  • Make recommendations to the IC CISO or designee for improving TTPS for better cyber threat protection.
  • Write final reports and defend all findings, including risk or vulnerability, mitigation strategies, and references.
  • Report vulnerabilities identified during security assessments.
  • Write penetration testing Rules of Engagement (ROE), Test Plans, and Standard Operating Procedures (SOP).
  • Conducted security reviews, technical research and provided reporting to increase security defense mechanisms.
Desired Qualifications
  • Four years of additional demonstrated work experience in Security Control Assessor (SCA) and Defensive Cyber Operations (DCO) Testing will be accepted in lieu of a bachelor’s degree.
  • A Master’s degree in an applicable discipline be substituted for three years of demonstrated work experience.
  • One full year of SCA experiences within the last three calendar years.
  • One full year supporting cloud environment and experience performing security assessments in a cloud environment (AWS, Google, IBM, Azure, and Oracle).
  • Must meet Department of Defense (DOD) 8570.01-M baseline certification requirement for Information Assurances Technical (IAT) Level III CASP+CE, CCNP Security, CISA, or CISSP or Associate, GCED, GCIH, or CCSP.
  • Knowledge of Independent Verification & Validation (IV&V) of security controls.
  • Knowledge of general attack strategies (e.g., MITRE ATT&CK Framework).
  • Knowledge of NISPOM, ICD 503, NIST SP 800-53, ICD 705, and other ICDs as appropriate.
  • Ability to assess the robustness of security systems and designs.
  • Three years of experience performing security assessments in a cloud computing environment.
  • Strong writing skills.

Company Size

N/A

Company Stage

N/A

Total Funding

N/A

Headquarters

N/A

Founded

N/A

INACTIVE