Security Control Assessor

Posted Yesterday
Be an Early Applicant
St. Louis, MO, USA
In-Office
Entry level
Information Technology • Other
The Role
Conducts independent assessments of management, operational, and technical security controls for IT systems and networks. Plans authorization reviews, evaluates security documentation and risk, identifies architecture gaps, supports Risk Management Framework activities, verifies control implementation, manages remediation plans, and ensures cybersecurity requirements and compliance processes are properly documented and maintained. Requires a bachelor’s degree, TS/SCI clearance, and an approved DoD 8140 certification.
Summary Generated by Built In
Overview

Amyx is seeking to hire a Security Control Assessor-Intermediate to support our Cybersecurity Division/NGA Defender in the NCW St Louis, MO area. Conducts independent comprehensive assessments of the management, operational, and technical security controls and control enhancements employed within or inherited by an information technology (IT) system to determine the overall effectiveness of the controls (as defined in NIST 800-37).

Responsibilities
  • Plan and conduct security authorization reviews and assurance case development for initial installation of systems and networks.
  • Review authorization and assurance documents to confirm that the level of risk is within acceptable limits for each software application, system, and network.
  • Verify that application software/network/system security postures are implemented as stated, document deviations, and recommend required actions to correct those deviations.
  • Develop security compliance processes and/or audits for external services (e.g., cloud service providers, data centers).
  • Establish acceptable limits for the software application, network, or system. Manage Accreditation Packages (e.g., ISO/IEC 15026-2).
  • Perform security reviews, identify gaps in security architecture, and develop a security risk management plan.
  • Perform security reviews and identify security gaps in security architecture resulting in recommendations for inclusion in the risk mitigation strategy.
  • Perform risk analysis (e.g., threat, vulnerability, and probability of occurrence) whenever an application or system undergoes a major change.
  • Provide input to the Risk Management Framework process activities and related documentation (e.g., system life-cycle support plans, concept of operations, operational procedures, and maintenance training materials).
  • Verify and update security documentation reflecting the application/system security design features.
  • Participate in Risk Governance process to provide security risks, mitigations, and input on other technical risk.
  • Ensure that plans of actions and milestones or remediation plans are in place for vulnerabilities identified during risk assessments, audits, inspections, etc.
  • Assure successful implementation and functionality of security requirements and appropriate information technology (IT) policies and procedures that are consistent with the organization's mission and goals.
  • Define and document how the implementation of a new system or new interfaces between systems impacts the security posture of the current environment.
  • Ensure that security design and cybersecurity development activities are properly documented (providing a functional description of security implementation) and updated as necessary.
  • Support necessary compliance activities (e.g., ensure that system security configuration guidelines are followed, compliance monitoring occurs).
  • Ensure that all acquisitions, procurements, and outsourcing efforts address information security requirements consistent with organization goals.
  • Assess the effectiveness of security controls.
  • Assess all the configuration management (change configuration/release management) processes.
  • Must have the ability to communicate accurate information
Qualifications
  • Bachelor degree or higher from an accredited college or university (Recommend an accredited Computer Science, Cyber Security, Information Technology, Software Engineering, Information Systems, or Computer Engineering degree; or a degree in a Mathematics or Engineering field.)
  • Clearance: TS/SCI
  • 8140 Certification: CAP or CASP+ or Cloud+ or CYSA+ or PenTest+.

Benefits include:

  • Medical, Dental, and Vision Plans (PPO & HSA options available)
  • Flexible Spending Accounts (Health Care & Dependent Care FSA)
  • Health Savings Account (HSA)
  • 401(k) with matching contributions
  • Roth
  • Qualified Transportation Expense with matching contributions
  • Short Term Disability
  • Long Term Disability
  • Life and Accidental Death & Dismemberment
  • Basic & Voluntary Life Insurance
  • Wellness Program
  • PTO
  • 11 Holidays
  • Professional Development Reimbursement


Please contact [email protected] with any questions!


Amyx is proud to be an Equal Opportunity Employer.  All qualified candidates will be considered without regard to race, color, religion, national origin, age, disability, sexual orientation, gender identity, status as a protected veteran, or any other characteristic protected by law. Amyx is a VEVRAA federal contractor and we request priority referral of veterans.

Physical DemandsEmployee needs to be able to sit at a workstation for extended periods; use hand(s) to handle or feel objects, tools, or controls; reach with hands and arms; talk and hear. Most positions require ability to work on desktop or laptop computer for extended periods of time reading, reviewing/analyzing information, and providing recommendations, summaries and/or reports in written format. Must be able to effectively communicate with others verbally and in writing. Employee may be required to occasionally lift and/or move moderate amounts of weight, typically less than 20 pounds. Regular and predictable attendance is essential.

Skills Required

  • Bachelor’s degree or higher from an accredited college or university
  • Top Secret/Sensitive Compartmented Information (TS/SCI) security clearance
  • One of the following 8140 certifications: CAP, CASP+, Cloud+, CySA+, or PenTest+
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Reston, VA
501 Employees
Year Founded: 1999

What We Do

At Amyx, our mission is to exceed our customer's expectations on every contract, to provide an environment that encourages, recognizes and rewards the extraordinary contributions of our employees, and to advance and support the communities in which we work and live. Amyx. is a management and technical solutions provider and a "trusted partner"​ to our Federal Government clients on programs of national importance. We understand that successful programs require superior performance and a level of trust achieved through genuine rapport with the customer. Award-winning results have propelled Amyx to become one of the fastest growing businesses in the Washington Region. Amyx's service offerings include: - Program Management and Acquisition Support - Systems Engineering and Implementation - Enterprise Architecture - Business Process Transformation Amyx is also a Microsoft Certified Partner and a recognized leader in leveraging Microsoft platforms, applications, and associated information systems. Amyx currently qualifies as a Small Business under all NAICS codes that use either the new $7 Million and $25 Million SBA thresholds. We also hold a Top Secret Facility clearance. Amyx services can be easily retained by using the General Services Administration (GSA) IT and MOBIS schedule contracts, Government Wide Acquisition Contracts (GWACs), Indefinite Delivery/Indefinite Quantity (ID/IQ contracts), and Blanket Purchase Agreements (BPAs).

Similar Jobs

Wipfli Logo Wipfli

Director - Transaction Advisory Services

Cloud • Fintech • Software • Business Intelligence • Consulting • Financial Services
Remote or Hybrid
United States
2900 Employees
142K-212K Annually

Wipfli Logo Wipfli

Audit Manager, Technology Industry

Cloud • Fintech • Software • Business Intelligence • Consulting • Financial Services
Remote or Hybrid
United States
2900 Employees
97K-145K Annually

Wipfli Logo Wipfli

Manager, Accounting Advisory - Manufacturing Industry

Cloud • Fintech • Software • Business Intelligence • Consulting • Financial Services
Remote or Hybrid
United States
2900 Employees
107K-160K Annually

Wipfli Logo Wipfli

Senior Auditor - Construction and Real Estate Industry

Cloud • Fintech • Software • Business Intelligence • Consulting • Financial Services
Remote or Hybrid
Clayton, MO, USA
2900 Employees

Similar Companies Hiring

Rosendin Thumbnail
Other • Manufacturing
San Jose, CA
6219 Employees
OmniCable Thumbnail
Other
Houston, Texas
815 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account