Security Control Assessor / IA Specialist

CACI International•Alexandria, VA
•$86,600 - $181,800•Onsite

About The Position

This role involves providing information assurance for digital systems, ensuring adherence to security and compliance standards. The specialist will develop and maintain assessment procedures aligned with NIST guidelines, plan and execute security control assessments using the Risk Management Framework, and validate security control implementation. They will also identify vulnerabilities, prepare Security Assessment Reports (SARs), support the development of information security policies, and ensure compliance with government regulations and cybersecurity frameworks. The position requires providing SME review for system designs and operational procedures, working independently with limited supervision, and coaching junior team members. Effective communication with internal stakeholders and external partners is essential, as is staying current with cybersecurity threats and best practices, and ensuring compliance with security awareness training.

Requirements

  • Working knowledge of NIST SP 800 53 Rev 5 security controls, including control evaluation, validation, and alignment to federal cybersecurity requirements.
  • Hands on experience applying the Risk Management Framework (RMF) Rev 5, including control selection, assessment, documentation, and continuous monitoring.
  • Foundational experience supporting security assessments in cloud environments (AWS, Azure, or similar), including understanding shared responsibility models and reviewing cloud control implementations.
  • Ability to identify security control weaknesses, validate remediation actions, and interpret vulnerability findings within both on prem and cloud systems.
  • Strong understanding of information assurance principles, ATO processes, and compliance frameworks.
  • Minimum of 5 years of relevant professional experience.
  • Bachelor’s degree in a related field or equivalent work experience.
  • Demonstrated analytical ability and experience solving complex technical problems.
  • Excellent communication and collaboration skills, with the ability to influence technical decisions and work independently with minimal supervision.

Nice To Haves

  • Experience leading small technical teams or workgroups.
  • Practical knowledge of project management methodologies.
  • Ability to collaborate across multiple technical specialties to develop integrated solutions.
  • Experience engaging with external stakeholders regarding operational policies and technical procedures.

Responsibilities

  • Provide information assurance for digital systems, ensuring adherence to security and compliance standards.
  • Develop and maintain assessment procedures and methodologies aligned with NIST guidelines and other relevant frameworks.
  • Plan and execute security control assessments as an independent assessor using the Risk Management Framework for various information systems within the organization.
  • Validate security control implementation and provide test results.
  • Provide tailored documentation to support customer security authorization processes.
  • Identify vulnerabilities, weaknesses, and potential risks in information systems and infrastructure.
  • Prepare detailed Security Assessment Reports (SARs) documenting findings and recommendations.
  • Support development and maintenance of information security policies, procedures, and standards.
  • Support compliance with government regulations and external cybersecurity frameworks.
  • Provide SME review and recommendations for system designs, technical solutions, and operational procedures across functional teams.
  • Work independently with limited supervision, managing projects or technical processes as assigned.
  • Coach and review the work of junior team members to support professional development.
  • Communicate effectively with internal stakeholders and external partners such as vendors or customers.
  • Stay current with evolving cybersecurity threats, technologies, and best practices.
  • Ensure compliance with security awareness training and alignment with organizational requirements.

Benefits

  • flexible time off
  • robust learning resources
  • competitive compensation
  • competitive mix of benefits options
  • comprehensive benefits
  • healthcare
  • wellness
  • financial
  • retirement
  • family support
  • continuing education
  • time off benefits
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service