Security Control Assessor - TS/SCI with Polygraph

Posted Yesterday
Be an Early Applicant
Bethesda, MD, USA
In-Office
149K-201K Annually
Senior level
Aerospace • Information Technology • Professional Services • Security • Software
The Role
Conduct security control assessments for cloud and other systems, documenting risks, test procedures, findings, vulnerabilities, and mitigation recommendations. Develop assessment plans, penetration-testing rules of engagement, SOPs, and final reports. Review security documentation, perform hands-on testing and vulnerability analysis, participate in technical forums, brief management, and advise on cybersecurity improvements. The role requires active TS/SCI clearance with polygraph and onsite work in Bethesda, Maryland.
Summary Generated by Built In

Type of Requisition:

Regular

Clearance Level Must Currently Possess:

Top Secret SCI + Polygraph

Clearance Level Must Be Able to Obtain:

None

Public Trust/Other Required:

None

Job Family:

Cyber and IT Risk Management

Job Qualifications:

Skills:

Cloud: Amazon Web Services (AWS), Cybersecurity, RMF

Certifications:

None

Experience:

6 + years of related experience

US Citizenship Required:

Yes

Job Description:

A career as a Security Control Assessor at GDIT means owning every opportunity to help support and advance our clients’ missions. At GDIT, cyber security is embedded into every aspect of what we do. We’re constantly evolving our cyber solutions to overcome our clients’ biggest challenges, and you will have the opportunity to develop and grow as these technologies evolve.

HOW A SECURITY CONTROL ASSESSOR WILL MAKE AN IMPACT

  • Provide documentation to Customer which describes all identified system risks, planned test procedures taken, and test results 

  • Provide enhancement capabilities and Standard Operating Procedures (SOPs)  to assessment operations for execution and implementation 

  • Maintain accountability to endure integrity and confidentiality of the assessment process 

  • Provide analysis of vulnerabilities and exploitations

  • Review and make recommendations on program-level documentation (e.g., requirements specification, system architecture, design documents, test plans, security plans, etc.) 

  • Develop and document security evaluation test plan and procedures 

  • Assist in researching, evaluating, and developing relevant Information Security policies and guidance 

  • Actively participate in or lead  Technical Exchange Meetings (TEMS)  and application review boards, documenting actions items/results of these events 

  • Brief management, as needed, on the status of action items and/or results of activities 

  • Conduct hands-on security testing, analyze test results, document risk, and recommend countermeasures  

  • Assess and calculate risk based on threats, vulnerabilities, and shortfalls uncovered in testing 

  • Identify mitigating countermeasures to identified threats, vulnerabilities, and shortfalls. 

  • Make recommendations to the IC CISO or designee for improving TTPS for better cyber threat protection.

WHAT YOU’LL NEED TO SUCCEED:

  • Education: Bachelor's Degree (Computer Engineering, Computer Science, Electrical Engineering, Information Systems, Information Technology, Cybersecurity, or a closely related discipline)

  • Required Experience: 6+ yrs

  • Required Technical Skills:

  • Three (3) years of cybersecurity experience with at least one year of experience conducting SCAs under ICD 503/CNSSI 1253 NIST Cybersecurity Framework, Risk Management Framework (RMF), or a similar framework.

  • One full year of SCA experiences within the last three calendar years.

  • One full year supporting cloud environment and experience performing security assessments in a cloud environment (AWS, Google, IBM, Azure, and Oracle).

  • Skill in conducting vulnerability scans and recognizing vulnerability in security systems (e.g., Cloud Environments) AWS, Google, IBM, Azure, and Oracle.

  • Must meet Department of Defense (DOD) 8570.01-Manual (M) Information Assurances Workforce Improvement Program requirement for Information Assurance Manger (IAM) Level III (CISM, CISSP or Associate GSLC or CCISO).

  • Knowledge of general attack strategies (e.g., MITRE ATT&CK Framework).

  • Knowledge of NISPOM, ICD 503, NIST SP 800-53, ICD 705, and other ICDs as appropriate.

  • Knowledge of Independent Verification & Validation (IV&V) of security controls.

  • Three years of experience performing security assessments in a cloud computing environment.

  • Strong writing skills.

  • Knowledge of system and application security threats and vulnerabilities.

  • Knowledge of network access, identity, and access management e.g. public key infrastructure (PKI)

  • Knowledge of network protocols such as Transition Control Protocol/Internet Protocol (TCP/IP), Dynamic Host Configuration, Domain Name System (DNS), and directory Services.

  • Ability to assess the robustness of security systems and designs.

  • Knowledge of cybersecurity principles and organizational requirements (relevant to confidentiality, integrity, availability, authentication, non-repudiation).

  • Write final reports and defend all findings, including risk or vulnerability, mitigation strategies, and references.

  • Report vulnerabilities identified during security assessments.

  • Write penetration testing Rules of Engagement (RoE), Test Plans, and Standard Operating Procedures (SOP).

  • Conducted security reviews and technical research and provided reporting to increase security defense mechanisms.

  • Security Clearance Level: TS/SCI with active polygraph

  • Location: Bethesda, MD - On Customer Site

GDIT IS YOUR PLACE:

  • 401K with company match

  • Comprehensive health and wellness packages

  • Internal mobility team dedicated to helping you own your career

  • Professional growth opportunities including paid education and certifications

  • Cutting-edge technology you can learn from

  • Rest and recharge with paid vacation and holidays

#WeAreGDIT
#JET
#VA_2026Alumn

The likely salary range for this position is $148,750 - $201,250. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.

Scheduled Weekly Hours:

40

Travel Required:

Less than 10%

Telecommuting Options:

Onsite

Work Location:

USA MD Bethesda

Additional Work Locations:

Total Rewards at GDIT:

Our benefits package for all US-based employees includes a variety of medical plan options, some with Health Savings Accounts, dental plan options, a vision plan, and a 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match. To encourage work/life balance, GDIT offers employees full flex work weeks where possible and a variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave. To ensure our employees are able to protect their income, other offerings such as short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available. We regularly review our Total Rewards package to ensure our offerings are competitive and reflect what our employees have told us they value most.

 



Our Identity Verification Process:

As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during virtual interviews. We reserve the right to take your picture to verify your identity and prevent fraud. By proceeding, you authorize the collection, processing, and use of your biometric data for identity verification and security purposes.

About Our Work:

We are GDIT. A global technology and professional services company that delivers technology solutions and mission services to every major agency across the U.S. government, defense and intelligence community. Our 26,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. We operate across 50+ countries worldwide, offering leading mission-ready capabilities in AI, cloud, cyber and software development.

Join our Talent Community to stay up to date on our career opportunities and events at

gdit.com/tc.

Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans

Skills Required

  • Bachelor's degree in computer engineering, computer science, electrical engineering, information systems, information technology, cybersecurity, or a closely related discipline
  • Six or more years of related experience
  • Three years of cybersecurity experience, including at least one year conducting security control assessments under ICD 503, CNSSI 1253, NIST Cybersecurity Framework, RMF, or a similar framework
  • One full year of security control assessor experience within the last three calendar years
  • At least one year supporting cloud environments and performing cloud security assessments
  • Three years of experience performing security assessments in a cloud computing environment
  • Experience conducting vulnerability scans and recognizing vulnerabilities in cloud and other security systems
  • DOD 8570.01-Manual Information Assurance Manager Level III qualification, such as CISM, CISSP, Associate GSLC, or CCISO
  • Knowledge of general attack strategies, including the MITRE ATT&CK Framework
  • Knowledge of NISPOM, ICD 503, NIST SP 800-53, ICD 705, and related intelligence community directives
  • Knowledge of independent verification and validation of security controls
  • Strong writing skills and ability to write and defend final assessment reports
  • Knowledge of system and application security threats and vulnerabilities
  • Knowledge of network access, identity and access management, and PKI
  • Knowledge of TCP/IP, DHCP, DNS, and directory services
  • Ability to assess the robustness of security systems and designs
  • Knowledge of cybersecurity principles and confidentiality, integrity, availability, authentication, and non-repudiation requirements
  • Experience writing penetration-testing rules of engagement, test plans, and SOPs
  • Active Top Secret/SCI clearance with polygraph
  • U.S. citizenship

General Dynamics Information Technology Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about General Dynamics Information Technology and has not been reviewed or approved by General Dynamics Information Technology.

  • Affordable Benefits Pay and benefits are described as good or okay in multiple places, and the overall package is often portrayed as acceptable even when base pay is not viewed as top-tier.
  • Healthcare Strength Medical, dental, and vision plan options are presented as comprehensive, with additional protections like disability and life insurance contributing to a well-rounded health and protection offering.
  • Retirement Support A 401(k) plan with company match is consistently highlighted as part of the total rewards package, supporting longer-term financial planning.

General Dynamics Information Technology Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Falls Church, VA
21,625 Employees

What We Do

We are GDIT. The people supporting some of the most complex government, defense, and intelligence projects across the country. We deliver. Bringing the expertise needed to understand and advance critical missions. We transform. Shifting the ways clients invest in, integrate, and innovate technology solutions. We ensure today is safe and tomorrow is smarter. We are there. On the ground, beside our clients, in the lab, and everywhere in between. Offering the technology transformations, strategy, and mission services needed to get the job done.

Similar Jobs

General Dynamics Information Technology Logo General Dynamics Information Technology

Security Control Assessor - TS/SCI with Polygraph

Aerospace • Information Technology • Professional Services • Security • Software
In-Office
Bethesda, MD, USA
21625 Employees
139K-189K Annually

PNC Bank Logo PNC Bank

Software Engineering Lead - Development Support (Tempus)

Machine Learning • Payments • Security • Software • Financial Services
Remote or Hybrid
USA
55000 Employees
86K-173K Annually

Wipfli Logo Wipfli

Manager, Accounting Advisory - Behavioral Health Industry

Cloud • Fintech • Software • Business Intelligence • Consulting • Financial Services
Remote or Hybrid
United States
2900 Employees
107K-160K Annually

CrowdStrike Logo CrowdStrike

Sr. Competitive Intelligence Analyst, Exposure Management (Remote)

Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Remote or Hybrid
5 Locations
11000 Employees
145K-225K Annually

Similar Companies Hiring

Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Revel.io Thumbnail
Aerospace • Hardware • Robotics • Software
US
50 Employees
Blee Thumbnail
Artificial Intelligence • Marketing Tech • Software • Productivity
US
15 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account