The Security Control Assessor (SCA) conducts comprehensive assessments of security controls employed by, or inherited within, information systems to determine their overall effectiveness and compliance with applicable security requirements. The SCA develops and submits the complete Body of Evidence (BoE), including the System Security Plan (SSP), Security Assessment Report (SAR), Plan of Action and Milestones (POA&M), and draft Authorization to Operate (ATO) letter, to the Authorizing Official (AO) or Delegated Authorizing Official (DAO) for review and authorization determination. The SCA serves as a trusted advisor to key stakeholders, including Program Offices, Data Owners, Information System Security Officers (ISSOs), and Authorizing Officials/Delegated Authorizing Officials, providing guidance on system security categorization and determining appropriate confidentiality, integrity, and availability impact levels in accordance with Risk Management Framework (RMF) requirements.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Senior