The Security Control Assessor (SCA) conducts comprehensive assessments of security controls employed by, or inherited within, information systems to determine their overall effectiveness and compliance with applicable security requirements. The SCA develops and submits the complete Body of Evidence (BoE), including the System Security Plan (SSP), Security Assessment Report (SAR), Plan of Action and Milestones (POA&M), and draft Authorization to Operate (ATO) letter, to the Authorizing Official (AO) or Delegated Authorizing Official (DAO) for review and authorization determination.
The SCA serves as a trusted advisor to key stakeholders, including Program Offices, Data Owners, Information System Security Officers (ISSOs), and Authorizing Officials/Delegated Authorizing Officials, providing guidance on system security categorization and determining appropriate confidentiality, integrity, and availability impact levels in accordance with Risk Management Framework (RMF) requirements.
Knowledge, Skills and Abilities
-
Excellent interpersonal, verbal, and written communication skills, with experience collaborating across mixed technical teams and engaging diverse stakeholders.
-
Expert-level experience reviewing, analyzing, and interpreting compliance and vulnerability assessment results from tools such as Xacta, STIG Viewer, ACAS, Prisma, Splunk, Trellix (HBSS), and other vulnerability scanners.
-
Ability to lead or support security projects and initiatives, manage competing priorities, and contribute effectively in a team-oriented environment.
Required Qualifications:
-
Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or a related field. A Bachelor’s degree may be substituted with an additional four (4) years of directly related experience, for a total of sixteen (16) years of relevant experience.
-
Twelve (12) years of experience supporting cybersecurity, Information Assurance, Risk Management Framework (RMF), and Assessment & Authorization (A&A) activities.
-
Obtain and maintain an IAT Level III certification in accordance with DoD 8570.01-M and DoD Directive 8140 Cyberspace Workforce Management requirements.
-
Acceptable certifications include: CompTIA Advanced Security Practitioner (CASP+ CE), Cisco Certified Network Professional Security (CCNP Security), Certified Information Systems Auditor (CISA), Certified Information Systems Security Professional (CISSP) or CISSP Associate, GIAC Certified Enterprise Defender (GCED), GIAC Certified Incident Handler (GCIH), and Certified Cloud Security Professional (CCSP).
Clearance:
-
Hold a Top Secret Security Clearance with SCI eligibility. Ability to Pass CI Poly.
Pueo is an equal employment opportunity employer and affirmative action employer. All interested individuals will receive consideration and will not be discriminated against on the basis of race, color, religion, sex, national origin, disability, age, sexual orientation, gender identity, genetic information, or protected veteran status. Pueo takes affirmative action in support of its policy to advance diversity and inclusion of individuals who are minorities, women, protected veterans, and individuals with disabilities.