The Security Control Assessor (SCA) I is responsible for conducting comprehensive assessments of management, operational, and technical security controls within information systems (IS). This role determines the effectiveness of these controls in meeting security requirements and identifies weaknesses or deficiencies. The SCA provides recommendations for corrective actions and covers collateral, Sensitive Compartmented Information (SCI), and Special Access Program (SAP) activities. Responsibilities include overseeing security program policies, assessing ISs using the Risk Management Framework (RMF) and Joint Special Access Program (SAP) Implementation Guide (JSIG), advising stakeholders on authorization issues, evaluating authorization packages, assessing threats and vulnerabilities, determining impact levels for confidentiality, integrity, and availability, ensuring security assessments are documented in Security Assessment Reports (SARs), initiating Plans of Action and Milestones (POA&Ms), reviewing security authorization packages, assessing changes to operating environments, concurring with sanitization and clearing procedures, assisting with compliance inspections and security incidents, ensuring adherence to the system development life cycle (SDLC), evaluating hardware and software security impacts, and assessing Continuous Monitoring Plans. The SCA will also represent the customer on inspection teams.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Mid Level