The Security Control Assessor (SCA) is responsible for conducting comprehensive assessments of management, operational, and technical security controls within Information Systems (IS). This role determines the effectiveness of these controls in meeting security requirements and identifies weaknesses or deficiencies. The SCA will also recommend corrective actions to address identified vulnerabilities. Responsibilities extend to Collateral, Sensitive Compartmented Information (SCI), and Special Access Program (SAP) activities. The role involves performing oversight of IS security program policy development and implementation, with a focus on integrating existing SAP network infrastructure. Assessments will be conducted based on the Risk Management Framework (RMF) methodology, adhering to the Joint Special Access Program (SAP) Implementation Guide (JSIG). The SCA will advise key stakeholders, including the Information System Owner (ISO), Information Data Owner (IDO), Program Security Officer (PSO), and the Delegated and/or Authorizing Official (DAO/AO) on assessment and authorization matters. This includes evaluating authorization packages, assessing IS threats and vulnerabilities, and advising on the impact levels for Confidentiality, Integrity, and Availability. The SCA will ensure security assessments are documented, prepare Security Assessment Reports (SARs), and initiate Plans of Action and Milestones (POA&Ms). They will also evaluate proposed changes to authorization boundaries, review sanitization and clearing procedures, assist with compliance inspections and security incidents, and evaluate hardware and software for security impacts. Additionally, the SCA will evaluate the effectiveness of Continuous Monitoring Plans and represent the customer on inspection teams. Other requirements include the ability to lift 50lbs regularly.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Mid Level