Security Controls Assessor

Synergy ECPColumbia, MD
Onsite

About The Position

Synergy ECP is seeking a Senior Security Controls Assessor (SCA) to assess the overall security compliance of client information systems. This role involves analyzing security functions for weaknesses and flaws, performing vulnerability assessments, and conducting on-site evaluations. The SCA will be responsible for verifying and validating security compliance, identifying non-compliance issues and mitigations, and coordinating penetration testing. The position requires strong analytical and communication skills, familiarity with various operating systems and network protocols, and an understanding of hacking methodologies and secure network architectures. The SCA will also provide process improvement recommendations and assist the Government in drafting standards and guidelines.

Requirements

  • Twelve years of related work experience
  • A Bachelor’s Degree in Computer Science or IT Engineering may be substituted for four years of experience
  • Experience in security or system engineering in five or more areas, including: telecommunications concepts, operating systems, databases/DBMS, middleware, applications, web-servers, SANS/Netaps, Active Directory, firewalls, and controlled interfaces
  • DoD 8570-1M Change 2 certification
  • TS/SCI Clearance
  • U.S. Citizenship
  • The ability to think ‘out of the box’
  • Strong presentation, report writing and customer interface skills
  • Familiarity with various operations systems such as Microsoft Windows 2000/2003, NT4, XP, various versions of UNIX (AIX, Solaris, HPUX, etc), and Linux
  • Detailed knowledge of TCP/IP and other major protocols (i.e. NetBEUI, NETBIOS, IPX/SPX) and the inherent weaknesses of the protocols
  • Understanding of ‘hacking’ methodology concerning performing a vulnerability assessment
  • The ability to describe a system's avenues of compromise in a network environment and differentiate between various types of network attacks
  • An understanding of a typical secure topology and architecture for a site connected to the Internet (i.e. routers, firewalls, web servers)
  • Understanding of how to read and interpret a network diagram and identify possible security related concerns
  • The ability to keep a robust security skill set current and to work on multiple projects concurrently

Responsibilities

  • Conducts verification and validation for security compliance of all information systems, products, and components
  • Analyzes design specifications, design documentation, configuration practices and procedures, and operational practices and procedures
  • Provides identification of non-compliance of security requirements and possible mitigations to requirements that are not in compliance
  • Conducts on-site evaluations
  • Validates the security requirements of the information system
  • Verifies and validates that the system meets the security requirements
  • Provides vulnerability assessment of the system
  • Coordinates penetration testing
  • Provides a comprehensive verification and validation report (certification report) for the information system
  • Provides process improvement recommendations
  • Assists the Government to draft standards and guidelines for usage
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service