The Security Control Assessor (SCA) will fulfill a variety of cybersecurity functions, including System Administrator, Enterprise Oversight, certification and accreditation, SAP and SCI assessment and authorization (A&A), Platform Information Technology (PIT) assessment and authorization, Information Assurance and Technical Security for AIS, Information Technology (IT) Network Administration & Support, and Information System Security Officer support. The role involves performing IA tasks to ensure the existing DARPA IA program meets National, DoD, and DARPA IA standards, protecting and defending DARPA information and Information Systems (IS) by ensuring confidentiality, integrity, availability, authentication, and non-repudiation. The Senior Cybersecurity Specialist should have experience in participating in DoD Special Access Program Joint Certification and Accreditation, Assessment, and Approval events for DoD Joint cyber ranges and/or jointly accredited SAP information systems. The DARPA systems to be protected handle information from controlled unclassified (CUI) up to Top Secret, including SAP and SCI caveats/compartments. Duties include ensuring system security requirements are addressed throughout DARPA program life cycles, planning and executing A&A events, developing and reviewing A&A packages, conducting quality control of accreditation packages, processing authorization documentation, performing security control assessments, analyzing and recommending actions for DARPA accredited network Configuration Control Board cases, monitoring DARPA accredited networks, providing advice on threats, vulnerabilities, and risk mitigation, conducting certification tests, collaborating with the MSO/ITD on authorization and continuous monitoring of DARPA networks, reviewing and recommending policy changes, evaluating IA products, assessing IT vulnerabilities, developing and maintaining an Information Systems Security Program SOP, ensuring personnel receive necessary training, developing and implementing an information security education program, maintaining a repository for documentation, coordinating inspections, preparing policies for incident response, ensuring corrective actions are taken for incidents/vulnerabilities, assessing changes affecting accreditation, maintaining configuration management, performing system audits, performing and training on secure file transfers, providing technical advice on telecommunications, and reviewing emergency/disaster plans.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Senior