Security Control Assessor Representative (SCAR)

Posted 13 Hours Ago
Be an Early Applicant
Huntsville, AL, USA
In-Office
150K-190K Annually
Entry level
Aerospace
The Role
Assess DoD cybersecurity controls and RMF authorization packages for networks, applications, and cloud services. Identify vulnerabilities, evaluate residual risk, review POA&Ms and security assessment documentation, conduct independent audits, verify security postures, and recommend remediation. Provide RMF guidance to engineers and program managers, maintain accreditation materials, analyze STIG and vulnerability scan results, and coordinate with cybersecurity teams and senior stakeholders.
Summary Generated by Built In

Title:

Security Control Assessor Representative (SCAR)

KBR is seeking a Security Control Assessor Representative (SCAR) to join our team.

Why Join Us?

  • Innovative Projects: KBR’s work is at the forefront of engineering, logistics, operations, science, program management, mission IT and cybersecurity solutions.
  • Collaborative Environment: Be part of a dynamic team that thrives on collaboration and innovation, fostering a supportive and intellectually stimulating workplace.
  • Impactful Work: Your contributions will be pivotal in designing and optimizing defense systems that ensure national security and shape the future of space defense

The selected applicant will provide cybersecurity support to systems and applications for the Test Resource Management Center (TRMC) and the Research, Development, Test and Evaluation (RDT&E) Community. The security controls assessor (SCA) will be responsible for evaluating the security controls within our networks/systems to identify vulnerabilities and recommend actions to correct problems, working with the TRMC Cybersecurity team.

Applicant Duties:

  • Conduct in-depth assessments of the management, operations, and technical security controls.
  • Analyze information and prepare reports describing the vulnerability level of the network/system with specific detail as to what compromises data systems.
  • Develop a plan to address vulnerabilities and continue to monitor the security of network systems.
  • Alongside the TRMC Cybersecurity Team Lead develop and implement cybersecurity independent audit processes for application software/networks/systems and oversee ongoing independent audits to ensure processes and procedures are in compliance with organizational and mandatory cybersecurity requirements and accurately followed by Systems Administrators and other cybersecurity staff when performing their day-to-day activities.
  • Develop security compliance processes and/or audits for external services (e.g., cloud service providers, data centers).
  • Verify that application software/network/system security postures are implemented as stated, document deviations, and recommend required actions to correct those deviations.
  • Perform validation steps, comparing actual results with expected results and analyze the differences to identify impact and risks.
  • Apply confidentiality, integrity, and availability principles.
  • Draft statements of preliminary or residual security risks for system operation
  • Maintain information systems assurance and accreditation materials.
  • Responsible for identifying, assessing, and managing cybersecurity capabilities and services, providing leadership, team coordination, and subject matter expertise in Assessment and Authorization (A&A) packages and leveraging the A&A process steps as a means for system authorization.
  • Review and analyze Plans of Actions and Milestones (POAMs), Security Assessment Reports (SAR), Security Assessment Plans (SAP).
  • Conduct required vulnerability analysis to support mitigation and residual risk determination.
  • Provide Risk Management Framework guidance and assistance to system engineers and program managers on assessment and risk-related matters and make risk recommendations.
  • Review security requirements, products, configurations, and cybersecurity architectures for compliance with DoD policies.
  • Support a general working knowledge of applicable assessment methods, such as Secure Technical Implementation Guides (STIGs) and automated vulnerability scans and analyze technical test data.
  • Participate in technical interchanges, security impact assessments and security assessment meetings with PMs, Cyber Team Lead, ISSOs/lSSMs and the AO

Basic Qualifications:

  • Subject Matter Expert (SME) with proven experience regarding the Risk Management Framework (RMF) and assessing DoD Security Controls.
  • Experience with Cybersecurity in the RDT&E Community
  • Proven experience conducting security risk assessments for RMF authorizations
  • Familiarity with Vulnerability scanning tools and ability to recognize vulnerabilities in information systems and networks.
  • Knowledge of cybersecurity principles and organizational requirements (relevant to confidentiality, integrity, availability, authentication, non-repudiation).
  • Knowledge of cyber threats and vulnerabilities.
  • Knowledge of cloud computing service models Software as a Service (SaaS), Infrastructure as a Service (IaaS), and Platform as a Service (PaaS).
  • Bachelor’s degree in engineering, Computer Science, Information Technology, or relevant field along with work experience in data security.
  • Strong project management, teamwork, and communication skills in addition to intermediate technical knowledge
  • Ability to adapt to process changes, systems changes, in a fast-paced environment.
  • Ability to interface with senior leadership.
  • Ability to support high visibility or high priority projects.
  • Advanced Certification (IAM III) for SCA per DOD MANUAL 8140.03
  • Travel 25% of time
  • Top Secret / SSBI clearance required.

Basic Compensation: $150,000 - $190,000 (For Alabama Only)
The offered rate will be based on the selected candidate’s knowledge, skills, abilities and/or experience and in consideration of internal parity

Additional Compensation:

KBR may offer bonuses, commissions, or other forms of compensation to certain job titles or levels, per internal policy or contractual designation. Additional compensation may be in the form of sign on bonus, relocation benefits, short term incentives, long term incentives, or discretionary payments for exceptional performance.

KBR Benefits

KBR offers a selection of competitive lifestyle benefits which could include 401K plan with company match, medical, dental, vision, life insurance, AD&D, flexible spending account, disability, paid time off, or flexible work schedule. We support career advancement through professional training and development.

Belong, Connect and Grow at KBR
At KBR, we are passionate about our people and our Zero Harm culture.  These inform all that we do and are at the heart of our commitment to, and ongoing journey toward being a People First company.  That commitment is central to our team of team’s philosophy and fosters an environment where everyone can Belong, Connect and Grow. We Deliver – Together. 

KBR is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, disability, sex, sexual orientation, gender identity or expression, age, national origin, veteran status, genetic information, union status and/or beliefs, or any other characteristic protected by federal, state, or local law.

Skills Required

  • Proven subject matter expertise with the Risk Management Framework and assessment of DoD security controls
  • Cybersecurity experience in the Research, Development, Test and Evaluation community
  • Experience conducting security risk assessments for RMF authorizations
  • Familiarity with vulnerability scanning tools and ability to identify information system and network vulnerabilities
  • Knowledge of cybersecurity principles, including confidentiality, integrity, availability, authentication, and non-repudiation
  • Knowledge of cyber threats and vulnerabilities
  • Knowledge of SaaS, IaaS, and PaaS cloud service models
  • Bachelor's degree in engineering, computer science, information technology, or a relevant field, plus work experience in data security
  • Strong project management, teamwork, communication, and intermediate technical skills
  • Ability to adapt to process and system changes in a fast-paced environment
  • Ability to interface with senior leadership
  • Ability to support high-visibility or high-priority projects
  • Advanced IAM III certification for Security Control Assessors under DoD Manual 8140.03
  • Willingness to travel 25% of the time
  • Top Secret / SSBI security clearance

KBR, Inc Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about KBR, Inc and has not been reviewed or approved by KBR, Inc.

  • Healthcare Strength Health coverage includes medical, dental, and vision plans, supplemented by life insurance, mental wellness resources, and a resilience program. Multiple plan options and added wellbeing tools bolster the core offering.
  • Retirement Support Retirement programs feature a 401(k) with employer matching contributions alongside additional savings options. An Employee Stock Purchase Plan complements long‑term financial benefits.
  • Flexible Benefits Work-life programs provide flexible schedules with options for part-time, remote, and “superflex” arrangements coordinated with managers. These flexible arrangements help tailor benefits to role and personal needs.

KBR, Inc Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
Belfast
22,677 Employees

What We Do

KBR, Inc. is an American engineering, procurement, and construction company, formerly a subsidiary of Halliburton.

Similar Jobs

Wipfli Logo Wipfli

Director - Transaction Advisory Services

Cloud • Fintech • Software • Business Intelligence • Consulting • Financial Services
Remote or Hybrid
United States
2900 Employees
142K-212K Annually

Wipfli Logo Wipfli

Audit Manager, Technology Industry

Cloud • Fintech • Software • Business Intelligence • Consulting • Financial Services
Remote or Hybrid
United States
2900 Employees
97K-145K Annually

Wipfli Logo Wipfli

Manager, Accounting Advisory - Manufacturing Industry

Cloud • Fintech • Software • Business Intelligence • Consulting • Financial Services
Remote or Hybrid
United States
2900 Employees
107K-160K Annually

Wipfli Logo Wipfli

Transaction Advisory Services Manager

Cloud • Fintech • Software • Business Intelligence • Consulting • Financial Services
Remote or Hybrid
United States
2900 Employees
117K-158K Annually

Similar Companies Hiring

Red 6 Thumbnail
Aerospace • Hardware • Software • Virtual Reality • Defense
Orlando, Florida
186 Employees
Outpost Space Thumbnail
Aerospace • Defense
US
24 Employees
Revel.io Thumbnail
Aerospace • Hardware • Robotics • Software
US
50 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account