72-025 – Security Control Assessor (SCA) I

Sandy Mac EvolutionColorado Springs, CO
Onsite

About The Position

Sandy Mac Evolution LLC is seeking a Security Control Assessor (SCA) I to support Department of Defense Special Access Program information systems at Peterson AFB, Colorado. The SCA conducts comprehensive assessments of management, operational, and technical security controls to determine whether controls are implemented correctly, operating as intended, and effectively meeting information-system security requirements. The position also evaluates identified weaknesses and vulnerabilities and provides recommendations for corrective action across Collateral, SCI, and SAP environments.

Requirements

  • 5–7 years of related experience.
  • 3+ years of experience with SAP, SCI, or Collateral Information Systems security and implementation of applicable regulations.
  • Prior performance as an ISSO and ISSM.
  • Active Top Secret clearance required.
  • SCI eligibility required.
  • SAP access eligibility required.
  • Must be willing to undergo a CI Polygraph.
  • DoD 8570.01-M IAM Level I required in lieu of IAT Level III.

Nice To Haves

  • SAP experience.

Responsibilities

  • Oversee development, implementation, and evaluation of information-system security policy.
  • Assess information systems using Risk Management Framework methodology and applicable JSIG requirements.
  • Advise system owners, data owners, Program Security Officers, and Authorizing Officials regarding assessment and authorization matters.
  • Evaluate authorization packages and provide authorization recommendations.
  • Evaluate threats and vulnerabilities to determine whether additional safeguards are required.
  • Advise government personnel regarding confidentiality, integrity, and availability impact levels.
  • Ensure security assessments are completed and results are documented.
  • Prepare Security Assessment Reports for authorization boundaries.
  • Initiate and maintain POA&Ms addressing weaknesses identified during assessments.
  • Evaluate security-assessment documentation and provide written authorization recommendations.
  • Submit security authorization packages to the AO/DAO.
  • Assess proposed changes to authorization boundaries, operating environments, and mission requirements.
  • Review and concur with sanitization and clearing procedures.
  • Support government compliance inspections.
  • Support investigation and remediation of cybersecurity incidents.
  • Ensure information systems address all applicable phases of the system development life cycle.
  • Evaluate hardware and software changes for security impact.
  • Evaluate implementation and effectiveness of continuous-monitoring plans.
  • Represent the customer on inspection teams.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service