89 security control assessor jobs at 47 companies in United States

3mo
Save
Mark Applied
Hide
SAP Security Control Assessor
Reston, Virginia, United States
OnsiteFull Time
Pueo Business Solutions
Pueo Business Solutions: Providing cybersecurity, IT, and business intelligence to government agencies.
12+ YOE12 years cybersecurity experience (or equivalent), 2 years as a Security Control Assessor, bachelor’s degree in a technical discipline, DoD 8570/IAT Level III certifications (examples: CASP+ CE, CCNP Security, CISA, CISSP, GCIH, CCSP), TS/SCI clearance required.
Public Key Infrastructure (PKI)
2w
Save
Mark Applied
Hide
Security Control Assessor
Colorado Springs, Colorado, United States
$100k-$105k/yr OnsiteFull Time
FEDITC
FEDITC: Provides IT, cybersecurity, and engineering services to federal agencies.
1+ YOEUS citizen with active Top-Secret/SCI clearance, AS in IT, Security+ CE required, 1–3 years RMF/security control assessment experience, strong analytical and communication skills.
Risk Management Framework (RMF), Security Technical Implementation Guides (STIGs), Evaluated/Approved Products List (E/APL)
2w
Save
Mark Applied
Hide
Security Control Assessor
Colorado Springs, Colorado, United States
$90k-$102k/yr OnsiteFull Time
ITI Solutions
ITI Solutions: Provides professional, technical, and engineering services for government defense.
5+ YOE5+ years implementing and assessing RMF security controls, BS in IT-related field, Security+ CE required, Top Secret clearance with TS/SCI eligibility, strong analytical and communication skills.
3mo
Save
Mark Applied
Hide
Senior Security Control Assessor
Alexandria, Virginia, United States
$130k-$150k/yr OnsiteFull Time
Technology Security Associates
Technology Security Associates: Provides specialized engineering and security services for defense programs.
10+ YOESenior security control assessor with RMF experience, active Top Secret clearance with SAP/SAR and SCI eligibility; 10+ years of DoD cybersecurity assessments; bachelor’s degree.
RMF, DoD_SECURITY_STANDARDS, NIST_SP_800-53, Security_Assessment_Tools
2w
Save
Mark Applied
Hide
Security Control Assessor II
Ogden, Utah, United States
$130k-$176k/yr OnsiteFull Time
GDIT
GDITNYSE: GD: Delivers IT and mission services to government agencies.
7+ YOEPerform comprehensive RMF-based security control assessments for Collateral/SCI/SAP systems, produce SARs/POA&Ms, and advise on authorization and remediation.
Risk Management Framework (RMF), Joint Special Access Program Implementation Guide (JSIG)
15h
Save
Mark Applied
Hide
Security Control Assessor
Springfield, Virginia, United States
OnsiteFull Time
SAIC
SAICNASDAQ: SAIC: Provides government and defense clients with technology and engineering services.
5+ YOEMust meet CWF ID 612 requirements via listed cyber certifications or bachelor’s in related field; 5+ years enterprise IT experience; strong assessment, documentation, and security analysis skills; active TS/SCI with ability to obtain TS/SCI with Poly.
Windows Server 2019, Microsoft SQL Server, RHEL, METASPLOIT, Kali Linux, ACAS, Nessus, Qualys, DISA STIGs, CIS Benchmarks, NIST SP 800-53, RMF, DoD 8510.01
2w
Save
Mark Applied
Hide
Security Control Assessor II
Ogden, Utah, United States
$130k-$176k/yr OnsiteFull Time
General Dynamics Information TechnologyNYSE: GD: Provides mission-critical IT services to government and defense organizations.
7+ YOE7+ years experience assessing information system security controls using RMF/JSIG for Collateral/SCI/SAP environments; ISSO/ISSM experience, ability to produce SARs and POA&Ms, and lift 50 lbs.
Risk Management Framework (RMF), Joint Special Access Program (JSIG), SDLC
23h
Save
Mark Applied
Hide
Senior Security Control Assessor
Crystal City, Virginia, United States
$85k-$135k/yr OnsiteFull Time
Serco
SercoLondon Stock Exchange: SRP: Provides professional outsourcing services to governments worldwide.
10+ YOEU.S. citizen with active TS/SCI clearance, minimum 10 years relevant cybersecurity/RMF/security control assessment experience, SAP knowledge, strong technical writing and stakeholder coordination; Master’s+10yrs or Bachelor’s+14yrs.
Risk Management Framework (RMF), SAP
1mo
Save
Mark Applied
Hide
Security Control Assessor (SCA)
Springfield, Virginia, United States
$103k-$150k/yr OnsiteFull Time
HII
HIINYSE: HII: Builds naval ships and provides global defense technology solutions.
4+ YOEActive TS/SCI clearance, 4+ years assessing or validating security controls on enterprise systems, RMF experience, familiarity with Windows/RHEL/Active Directory/ACAS/ServiceNow CAM, strong technical writing and communication, DoD 8140/CSWF 612-Intermediate or willingness to obtain.
Windows, RHEL, Active Directory, ACAS, AV, ServiceNow CAM, Risk Management Framework (RMF)
1mo
Save
Mark Applied
Hide
Security Control Assessor - C
Washington, D.C., District of Columbia, United States
OnsiteFull Time
Telos
TelosNASDAQ: TLS: Provides cyber, cloud, and enterprise security solutions for government and commercial clients.
5+ YOEActive DoD Top Secret clearance with SCI eligibility, US citizenship, 5+ years assessing NIST 800-53/CNSS 1253 controls, RMF (NIST 800-37) experience, STIG/ACAS/HBSS/Xacta 360 familiarity, Security Assessment Plan/Report writing, and strong communication skills.
STIG, ACAS, HBSS, Xacta 360, NIST 800-53, CNSS 1253, NIST 800-37, Risk Management Framework (RMF)
15h
Save
Mark Applied
Hide
Security Control Assessor
Springfield, Virginia, United States
$120k-$160k/yr OnsiteFull Time
SAIC
SAICNYSE: SAIC: Provides engineering, IT, and mission support services to government.
5+ YOEMeets CWF 612 requirements via listed certifications or a Bachelor's in related field; 5+ years enterprise IT/cybersecurity experience; familiarity with RMF/NIST, vulnerability assessment, STIG/CIS hardening, and strong reporting skills.
Risk Management Framework (RMF), NIST SP 800-53, DoD 8510.01, ACAS, Nessus, Qualys, DISA STIGs, CIS Benchmarks, Windows Server 2019, MS SQL, RHEL, METASPLOIT, Kali Linux
1mo
Save
Mark Applied
Hide
Security Control Assessor
Chantilly, Virginia, United States
OnsiteContract
System High
System High: Provides specialized security engineering and protection for national security missions.
12+ YOEMinimum 12 years IT/cybersecurity/A&A experience; DoD 8140.01 IAT Level III or IAM Level III certification (e.g., CISSP, CISM, GSLC, CASP+ CE); hands-on experience with systems integration, enterprise networks, cloud/Platform IT architectures; SAP/SCI experience preferred; active Top-Secret clearance with SCI and SAP eligibility; ability to travel ...
ACAS, Nessus, STIG, Risk Management Framework (RMF), Cross Domain Solutions (CDS)
4d
Save
Mark Applied
Hide
Security Control Assessor
Arlington, Virginia, United States
OnsiteFull Time
Novul Solutions
Novul Solutions: Providing cybersecurity, software engineering, and IT solutions for government.
8+ YOE8+ years cybersecurity experience with 5+ years A&A or RMF support; bachelor\u0002s degree in related field; expert knowledge of DoD RMF, NIST SP 800-37/53, CNSSI 1253, JSIG; strong communication and leadership.
Risk Management Framework, NIST SP 800-37, NIST SP 800-53, CNSSI 1253, JSIG
2d
Save
Mark Applied
Hide
CYB - Security Control Assessor (19927)
Oak Ridge, Tennessee, United States
OnsiteFull Time
Consolidated Nuclear Security
Consolidated Nuclear Security: Operates nuclear security facilities for the U.S. government.
3+ YOEConduct NIST-based security control assessments; prepare assessment reports, gap analyses, and POA&Ms; bachelor's degree in related field; experience with NIST RMF and assessment procedures; security certification preferred.
NIST SP 800-53A, NIST SP 800-53, NIST RMF, NIST SP 800-82, NIST SP 800-161, FedRAMP
2d
Save
Mark Applied
Hide
Junior Security Control Assessor
Fort Meade, Maryland, United States
$50k-$60k/yr FieldFull Time
Newberry Group
Newberry Group: Provides cybersecurity and IT consulting services for government agencies.
0+ YOEDoD IAT II (or obtain within 90 days), active or sponsorable Secret clearance with Top Secret/SCI preferred, 0–1 years experience, certifications (e.g., CySA+, Security+, CND, RHCSA, CCNA Security, GICSP, GSEC, SSCP), familiarity with RMF, STIGs, eMASS, and vulnerability tools.
eMASS, STIG Viewer, Nessus, ACAS, SCAP, HBSS
1w
Save
Mark Applied
Hide
Security Control Assessor I
El Segundo, California, United States
OnsiteFull Time
P-11 Security
P-11 Security: Provides security and technology services for defense industry clients
5+ YOE5+ years related experience with 3+ years in SAP/SCI/collateral IS security, prior ISSO/ISSM experience, DoD 8570 certification within 6 months, Top-Secret/SCI clearance, ability to lift 50lbs.
Risk Management Framework (RMF), Joint Special Access Program (JSIG), Plan of Action and Milestones (POA&M), Security Assessment Report (SAR), System Development Life Cycle (SDLC)
4d
Save
Mark Applied
Hide
Security Control Assessor II
Albuquerque, New Mexico, United States
OnsiteFull Time
Global Resource Solutions
Global Resource Solutions: Provides security and intelligence services to US government agencies.
10+ YOE10+ years experience assessing IS security using RMF/JAFAN, Top Secret/SCI clearance, willingness for polygraph, bachelor's degree or equivalent, DoD 8570 IA level 3 compliance within 6 months, travel and lifting ability.
Risk Management Framework (RMF), JAFAN 6/3, Microsoft Word, Microsoft PowerPoint, Microsoft Excel
3mo
Save
Mark Applied
Hide
IT Security Control Assessor
McLean or Tysons Corner
OnsiteFull Time
Guidehouse
Guidehouse: Provides management and technology consulting services to diverse organizations.
3+ YOEBachelor’s degree in computer science or related field; 3+ years cybersecurity; ability to obtain SECRET clearance; experience with FISMA/RMF and NIST; security tool knowledge.
Nessus, Splunk, ACAS, FedRAMP
1w
Save
Mark Applied
Hide
Security Control Assessor (SCA)
Washington, District of Columbia, United States
$160k-$172k/yr OnsiteFull Time
KBR
KBRNYSE: KBR: Provides engineering, technology, and professional services for global markets.
7+ YOEMaster's or equivalent,7+ years cybersecurity experience in DoD classified environments,SAP/SCI experience,3+ years ISSM or senior lead experience,RMF/JSIG/ICD 503/NIST 800-53 familiarity,DoD 8570/8140 IAT Level III or IAM II/III,TS/SCI w/SAP eligibility.
JSIG, RMF (DoDI 8510.01), ICD 503, NIST 800-53
1mo
Save
Mark Applied
Hide
Junior Security Control Assessor
Fort Meade, Maryland, United States
HybridFull Time
August Schell
August Schell: Cybersecurity and data engineering services for federal agencies.
3+ YOEActive Secret clearance (willing to upgrade to TS/SCI), DoD 8570 IAT-II, bachelor\u0002s (IT preferred), 3 years DoD/Federal IT experience, experience in 3+ tech areas, familiarity with STIGs, RMF, eMASS and vulnerability tools.
STIG Viewer, eMASS, Nessus, ACAS, SCAP, HBSS, RMF, SQL, Oracle, Windows, Unix