Security Control Assessor

Leidos Holdings Inc.Baltimore, MD
34dOnsite

About The Position

Leidos is seeking a Security Control Assessor (SCA) that is responsible for planning, executing, and documenting security control assessments in accordance with NIST SP 800-53 Revision 5, NIST SP 800-53A Rev. 5, and applicable federal security assessment methodologies. The SCA evaluates the effectiveness of implemented security controls across systems, environments, and organizations to determine compliance, residual risk, and readiness for Authorization to Operate (ATO). If this sounds like a mission you want to be a part of, keep reading! TEAM CULTURE Your passion and values might be a good fit for our teams if you answer "yes" to the following questions: Are you looking for a company that puts employees first, with a focus on career, flexibility, and well-being? Do you enjoy collaborating with colleagues and teammates and believe that the best ideas are fostered in an inclusive environment? Are you searching for a team with a strong sense of ownership, urgency, and drive for daily mission success? Are you comfortable with proactive outward communication and technical leadership? Do you enjoy being a catalyst, solving complex problems, and providing innovative solutions? Do you have the flexibility, creativity, and resilience to pivot the mission for success? Do you have the courage to make tough ethical decisions with pride, transparency, and respect? MENTORSHIP & CAREER GROWTH Our teams are dedicated to supporting new team members in an environment that celebrates knowledge sharing and mentorship. Experienced team members will be assigned to new hires for one-on-one mentoring, collaborative reviews, and coaching on customer engagement to help each new hire successfully onboard and demonstrate their skills. Projects and tasks are assigned in a way that leverages your strengths and will help you further develop your skillset. DAY TO DAY RESPONSIBILITIES Every position we take is more rewarding when you know the why behind it. Know your work makes a difference to support those who need it most. If your passion is enabling life changing service to those around, you this is the place for you. Find you passion in a team environment where all members are valued regardless of contractor or employee status. Find your "Why" with us and take your place in our Leidos Family!! At Leidos, we deliver innovative solutions through the efforts of our diverse and talented people who are dedicated to our customers' success. We empower our teams and contribute to our communities. Everything we do is built on a commitment to do the right thing for our customers, our people, and our community. Our Mission, Vision, and Values guide the way we do business. Every position we take is more rewarding when you know the why behind it. Know your work makes a difference to support those who need it most. If your passion is enabling life changing service to those around, you this is the place for you. Find your passion in a team environment where all members are valued regardless of contractor or employee status. We are excited for you to take your place in our Leidos Family. If you're looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo - because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 - and moving faster than anyone else dares.

Requirements

  • Bachelor's degree in Computer Science, Information Assurance, Cybersecurity, or a related field (or equivalent experience).
  • 4+ years of experience performing security control assessments under NIST RMF or FedRAMP.
  • In-depth knowledge of NIST SP 800-53 Rev. 5, NIST SP 800-53A Rev. 5, and NIST SP 800-37 Rev. 2.
  • Experience using security assessment tools such as Nessus, Splunk, ACAS, OpenVAS, or equivalent.
  • Familiarity with vulnerability management, configuration baselines, and system security documentation (SSP, POA&M, SAR).
  • Strong analytical, documentation, and reporting skills.
  • Ability to communicate technical findings clearly to both technical and non-technical audiences.

Nice To Haves

  • Certifications such as CISSP, CISA, CAP, CEH, or Security+.
  • Experience performing assessments in FedRAMP, DoD RMF, or DHS CDM environments.
  • Knowledge of Zero Trust principles and their alignment with NIST SP 800-207.
  • Must be able to obtain and maintain a Public Trust. Contract requirement. (DO NOT REMOVE)
  • Selected candidate must be willing to work on-site in Woodlawn, MD 5 days a week.

Responsibilities

  • Develop and execute Security Assessment Plans (SAPs) aligned with NIST 800-53A Rev. 5 assessment procedures.
  • Conduct independent security control assessments (SCAs) to validate that implemented controls meet applicable federal and agency security requirements.
  • Perform evidence reviews, interviews, and technical testing (e.g., configuration validation, vulnerability scans, policy reviews).
  • Document findings, weaknesses, and residual risks in Security Assessment Reports (SARs) and provide recommendations for remediation.
  • Assess the implementation and effectiveness of security controls across all NIST control families, including Access Control (AC), Audit and Accountability (AU), Configuration Management (CM), Incident Response (IR), Risk Assessment (RA), and System & Communications Protection (SC).
  • Collaborate with Information System Owners (ISOs), Information System Security Officers (ISSOs), and Authorizing Officials (AOs) to clarify assessment results and risk posture.
  • Map findings to Risk Management Framework (RMF) steps 4 and 5, supporting authorization decisions.
  • Participate in Continuous Monitoring (ConMon) and annual assessment activities for ongoing authorization.
  • Ensure assessment procedures are consistent with NIST, FedRAMP, and agency-specific security requirements.
  • Maintain up-to-date understanding of changes in NIST guidance, FISMA, and Zero Trust Architecture (ZTA) frameworks that impact assessment criteria.

Stand Out From the Crowd

Upload your resume and get instant feedback on how well it matches this job.

Upload and Match Resume

What This Job Offers

Job Type

Full-time

Career Level

Mid Level

Industry

Professional, Scientific, and Technical Services

Number of Employees

11-50 employees

© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service