Security Control Assessor (SCA) II

Posted 8 Days Ago
Be an Early Applicant
Arlington, VA, USA
In-Office
169K-172K Annually
Senior level
Information Technology • Professional Services • Cybersecurity • Defense
The Role
Conducts cybersecurity control assessments across Collateral, SCI, and SAP information systems. Evaluates security controls, threats, vulnerabilities, authorization boundaries, continuous monitoring, and RMF compliance. Advises government and system stakeholders on authorization risks, prepares Security Assessment Reports and POA&Ms, supports inspections and incident response, and recommends corrective actions. The role requires extensive SAP/SCI security experience, prior ISSO, ISSM, or SCA performance, IAT Level III or IAM Level II certification, and an active TS/SCI clearance.
Summary Generated by Built In

Location: Crystal City, VA
Security Clearance: Active TS/SCI [Required] (Must be able to obtain a CI Poly
Job Type: Full-Time

Target Salary Range*:$169,000-$171,500

*This represents the potential salary range for this position depending on education level, years of experience and/or certifications in addition to other position specific requirements which may impact salary

Position Overview

The Security Control Assessor (SCA) is responsible for conducting comprehensive assessments of the management, operational, and technical security controls employed within or inherited by an information system (IS) to determine the overall effectiveness of those controls. The SCA assesses whether controls are implemented correctly, operating as intended, and producing the desired outcomes with respect to the system's security requirements. The SCA also assesses the severity of identified weaknesses or deficiencies and recommends corrective actions to address vulnerabilities.

Responsibilities cover Collateral, Sensitive Compartmented Information (SCI), and Special Access Program (SAP) activities within the customer's area of responsibility.

Key ResponsibilitiesSecurity Program Oversight and Assessment
  • Oversee the development, implementation, and evaluation of IS security program policy, with special emphasis on integrating existing SAP network infrastructure.
  • Assess ISs based on the Risk Management Framework (RMF) methodology in accordance with the Joint Special Access Program (SAP) Implementation Guide (JSIG).
  • Evaluate IS threats and vulnerabilities to determine whether additional safeguards are required.
  • Advise the Government concerning the impact levels for Confidentiality, Integrity, and Availability of information on a system.
  • Evaluate hardware and software to determine the security impact on Authorization boundaries.
  • Evaluate the effectiveness and implementation of Continuous Monitoring Plans.
Authorization and Risk Management
  • Advise the Information System Owner (ISO), Information Data Owner (IDO), Program Security Officer (PSO), and Delegated and/or Authorizing Official (DAO/AO) on assessment and authorization issues.
  • Evaluate Authorization packages and make recommendations to the AO and/or DAO for authorization.
  • Ensure security assessments are completed and results are documented.
  • Prepare the Security Assessment Report (SAR) for the Authorization boundary.
  • Initiate a Plan of Action and Milestones (POA&M) with identified weaknesses for each Authorization boundary assessed, based on findings and recommendations from the SAR.
  • Evaluate security assessment documentation and provide written recommendations for security authorization to the Government.
  • Discuss recommendations for authorization and submit the security authorization package to the AO/DAO.
  • Assess proposed changes to Authorization boundaries, operating environments, and mission needs to determine continuation to operate.
Compliance and Security Operations
  • Review and concur with all sanitization and clearing procedures in accordance with Government guidance and/or policy.
  • Assist with Government compliance inspections.
  • Assist the Government with security incidents related to cybersecurity and ensure proper corrective measures have been taken.
  • Ensure organizations address and conduct all phases of the system development life cycle (SDLC).
  • Represent the customer on inspection teams.
QualificationsExperience
  • 7–9 years of related experience [Required].
  • 4+ years of experience in SAP, SCI, or Collateral Information Systems (S) security and implementation of regulations identified in the description of duties [Required].
  • Prior performance in the role of ISSO, ISSM, or SCA [Required].
Certifications
  • IAT Level III or IAM Level II [Required].
Clearance
  • Active TS/SCI clearance [Required].
  • Must be willing to obtain a CI Poly [Required].

Skills Required

  • 7-9 years of related experience
  • 4+ years of experience in SAP, SCI, or Collateral Information Systems security and implementation of applicable regulations
  • Prior experience serving as an ISSO, ISSM, or SCA
  • IAT Level III or IAM Level II certification
  • Active TS/SCI security clearance
  • Ability and willingness to obtain a CI Polygraph
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
200 Employees
Year Founded: 2011

What We Do

The Amatriot Group is a talent solutions firm providing technology expertise to the federal and commercial sectors. With over a decade of experience delivering mission-critical support to the intelligence, defense, and national security sectors, the company specializes in delivering cutting-edge technology solutions by securing top-tier talent to bridge workforce gaps in the most complex and secure environments.

Similar Jobs

Targeted Solutions, LLC Logo Targeted Solutions, LLC

Security Control Assessor II (SCA II)

Professional Services • Consulting • Cybersecurity • Defense
In-Office
Crystal City, VA, USA
5 Employees
In-Office
22202, Arlington, VA, USA
500 Employees
175K-210K Annually

General Dynamics Information Technology Logo General Dynamics Information Technology

Security Control Assessor (SCA) II

Aerospace • Information Technology • Professional Services • Security • Software
In-Office
Arlington, VA, USA
21625 Employees
153K-207K Annually

Similar Companies Hiring

NODA AI Thumbnail
Artificial Intelligence • Information Technology • Software • Cybersecurity
Sydney, AU
54 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees
Outpost Space Thumbnail
Aerospace • Defense
US
24 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account