Full-Time

Offensive Security Control Assessor Representative

Dark Wolf Solutions

Dark Wolf Solutions

201-500 employees

DevSecOps, security testing, and incident response.

Compensation Overview

$135k - $160k/yr

No H1B Sponsorship

Arlington County, Arlington, VA, USA

Hybrid

Hybrid/remote opportunities are available.

US Citizenship, US Top Secret Clearance Required

Category
Cybersecurity (1)
Required Skills
LLM
FedRAMP
Pinecone
React.js
PyTorch
Postgres
Infrastructure as Code (IaC)
Docker
RAG
CloudFormation
Microservices
AWS
LangGraph
Terraform
REST APIs
LangChain
Penetration Testing
DevOps

Get referred to Dark Wolf Solutions

See people who can refer or advise you

Requirements
  • Active Top Secret security clearance.
  • Current Department of Defense 8570/8140 Information Assurance Manager Level II or Level III certification, such as Security+, CySA+, CISM, CISSP, CCISO, CAP, or CISC.
  • Five to seven or more years of experience conducting security control assessments, compliance testing, or authorization and accreditation/risk management framework activities for Department of Defense or federal information systems.
  • Solid operational understanding of core Amazon Web Services cloud services, including EC2, S3, IAM, VPCs, security groups, and Security Hub, and how security controls function within cloud-native and continuous integration and continuous delivery pipeline environments.
  • Experience with GitLab continuous integration and continuous delivery, including pipeline design, runners, and artifact management, and with Amazon Web Services cloud services including EC2, VPC, IAM, and S3.
  • Strong working knowledge of NIST Special Publication 800-53 Revision 4/5, NIST Special Publication 800-37 risk management framework, the Department of Defense Cloud Computing Security Requirements Guide, and Federal Risk and Authorization Management Program baselines.
  • Demonstrated experience writing and evaluating core risk management framework artifacts, including System Security Plans, Security Assessment Plans, Security Assessment Reports, and Plans of Action and Milestones.
  • Ability to articulate technical risk clearly to executive stakeholders, Authorizing Officials, and engineering teams.
  • Hands-on experience navigating government governance, risk, and compliance repositories such as eMASS or XACTA.
  • U.S. citizenship and employment eligibility verification are required upon hire.
  • Availability for direct, full-time W2 employment.
Responsibilities
  • Execute formal Security Control Assessor/Representative duties.
  • Lead security assessment efforts by establishing reusable security playbooks and assessment frameworks for rapid artificial intelligence deployment into enterprise workflows.
  • Evaluate technical control effectiveness across Amazon Web Services cloud infrastructure, DevSecOps pipelines, microservices, containerized workloads, and generative artificial intelligence and large language model application stacks.
  • Bridge offensive security and development by applying software design best practices.
  • Lead technical exchange meetings and participate in Discovery and Framing workshops with cross-functional teams and stakeholders.
  • Act as the primary subject-matter expert and lead developer for custom offensive tooling, integrating disparate capabilities into a cohesive, mission-ready platform.
  • Review, author, and maintain assessment packages, including System Security Plans, Security Assessment Plans, Security Assessment Reports, and Plans of Action and Milestones, tailored to rapid prototyping and artificial intelligence systems.
  • Assess technical security risks specific to artificial intelligence and large language model implementations, including API exposure, vector database access controls, model integration surface area, and software supply-chain dependencies.
  • Support continuous monitoring, technical risk evaluations, and cloud architecture reviews across multi-tenant, multi-classification environments.
  • Coordinate with Authorizing Officials, program managers, and engineering leads to deliver decision-ready risk briefings and authorization-to-operate recommendations.
  • Provide technical input and oversight for cybersecurity engineering and penetration-testing activities across prototype projects.
Desired Qualifications
  • Hands-on experience mapping security controls to the NIST Artificial Intelligence Risk Management Framework, the OWASP Top 10 for Large Language Model Applications, or Department of Defense Responsible Artificial Intelligence Guidelines.
  • Familiarity with secure design patterns for autonomous artificial intelligence agents, including tool-calling permissions, sandboxing agent execution environments, prompt boundaries, and ReAct or LangGraph architectures.
  • Experience assessing cloud-managed artificial intelligence ecosystems and foundation-model platforms such as Amazon Bedrock, Amazon SageMaker, Hugging Face Enterprise, or self-hosted open-source models.
  • Understanding of data protection, access controls, and boundary security for retrieval-augmented generation pipelines and vector databases such as OpenSearch Vector Engine, Pinecone, Milvus, or PostgreSQL pgvector.
  • Familiarity with large language model risks including prompt injection, data poisoning, model inversion, insecure output handling, and open-source supply-chain vulnerabilities in artificial intelligence libraries such as PyTorch, LangChain, and LlamaIndex.
  • Exposure to large language model guardrail platforms, evaluation frameworks, or artificial intelligence security tools such as Promptfoo, Garak, Giskard, or NeMo Guardrails used to test model robustness and output safety.
  • Experience with continuous authorization-to-operate methodologies, Infrastructure as Code templates such as Terraform and CloudFormation, and container security using Amazon EKS/ECS or Docker.
  • Active Amazon Web Services certifications such as AWS Certified Security—Specialty or AWS Certified Solutions Architect.
  • Background or familiarity with offensive security and penetration testing.

Dark Wolf Solutions provides DevSecOps agile software development, information operations, penetration testing and incident response, applied research and rapid prototyping, machine learning, and mission support for the Intelligence Community, national security, and Fortune 500 customers. They integrate secure development, security testing, rapid prototyping, ML, and operations support to deliver secure software and cyber capabilities aligned with specific mission needs. They combine deep federal domain expertise with emerging technologies to offer end-to-end capabilities from development to ongoing operations. Their goal is to help security-focused organizations advance their missions while keeping systems secure and resilient.

Company Size

201-500

Company Stage

N/A

Total Funding

N/A

Headquarters

Herndon, Virginia

Founded

2009

Get referred to Dark Wolf Solutions

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • February 2026 Air Force awarded Dark Wolf a $67.2 million cyber innovation IDIQ.
  • June 2026 NIWC Pacific added Dark Wolf to a $178.4 million cybersecurity pool.
  • Dark Wolf won a February 2026 Nebula task order for $1.97 million.

What critics are saying

  • Revenue depends on task-order wins inside NIWC Pacific's five-year pool, not automatic spend.
  • One-off SBIR Phase III awards concentrate growth on a few Air Force buyers.
  • A failed cyber accreditation program at Air Force CIO would crush its core business.

What makes Dark Wolf Solutions unique

  • Dark Wolf pairs DevSecOps, cyber, and mission enablement for Defense and Intelligence customers.
  • Its August 2026 GSA MAS HACS listing sells pre-vetted cybersecurity through federal procurement.
  • RackTop-backed secure storage widens its offer beyond services into trusted technology products.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Hybrid Work Options

Growth & Insights and Company News

Headcount

6 month growth

19%

1 year growth

19%

2 year growth

19%
JoBlo.com
Feb 9th, 2024
The Terminal List: Dark Wolf adds Luke Hemsworth to the season's cast

The Terminal List: Dark Wolf adds Luke Hemsworth to the season's cast.

PR Newswire
May 17th, 2022
At-Impact And Dark Wolf Enterprise Toolchain To Support Kessel Run

FALLS CHURCH, Va., May 17, 2022 /PRNewswire/ -- At-Impact, in partnership with Dark Wolf, was awarded the Kessel Run's Enterprise Toolchain contract (Kessel ET), a $41M CIO-SP3 SB award to provide Commercial IT services and the integrated support team needed to enhance Kessel Run's...