The Security Control Assessor II (SCA II) is responsible for conducting comprehensive assessments of management, operational, and technical security controls for Information Systems (IS). This role determines the effectiveness of controls in meeting security requirements and assesses the severity of identified weaknesses, recommending corrective actions. Responsibilities extend to Collateral, Sensitive Compartmented Information (SCI), and Special Access Program (SAP) activities. The role involves performing oversight of security program policy development and implementation, with a focus on integrating existing SAP network infrastructure. Assessments are conducted using the Risk Management Framework (RMF) methodology, in accordance with the Joint Special Access Program (SAP) Implementation Guide (JSIG). The SCA II advises key stakeholders, including Information System Owners (ISO), Information Data Owners (IDO), Program Security Officers (PSO), and Delegated/Authorizing Officials (DAO/AO) on assessment and authorization matters. They evaluate authorization packages, IS threats, and vulnerabilities, recommending necessary safeguards and advising on the impact levels for Confidentiality, Integrity, and Availability. The position requires ensuring security assessments are completed, documented, and results are reported in a Security Assessment Report (SAR). A Plan of Action and Milestones (POA&M) must be initiated for identified weaknesses. The SCA II also reviews and concurs with sanitization and clearing procedures, assists with compliance inspections and security incidents, ensures adherence to the system development life cycle (SDLC), evaluates hardware and software for security impacts, and assesses the effectiveness of Continuous Monitoring Plans. Additionally, the role involves representing the customer on inspection teams.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Mid Level
Education Level
Associate degree