Security Control Assessor

Washington, DC, US • Posted 60+ days ago • Updated 8 hours ago
Full Time
On-site
Company Branding Image
Fitment

Dice Job Match Score™

🔢 Crunching numbers...

Job Details

Skills

  • FIPS
  • Management
  • Risk Assessment
  • Standard Operating Procedure
  • Presentations
  • Evaluation
  • Interviewing
  • Test Management
  • IT Security
  • Configuration Management
  • Regulatory Compliance
  • Testing
  • STIG
  • Security Analysis
  • Information Assurance
  • SAR
  • Documentation
  • IT Risk Management
  • Computer Science
  • Information Technology
  • Security QA
  • NIST SP 800 Series
  • Security Controls
  • Program Management
  • Policies and Procedures
  • Continuous Monitoring
  • Risk Management
  • PASS
  • Customer Engagement
  • Cloud Computing
  • Communication
  • Collaboration
  • Work Ethic
  • Accountability
  • Organizational Skills
  • Attention To Detail
  • Analytical Skill
  • Critical Thinking
  • Problem Solving
  • Conflict Resolution
  • Microsoft Office
  • Microsoft Excel
  • Microsoft Outlook
  • CISSP
  • CISM
  • Security+
  • CISA
  • Military
  • Law
  • Insurance

Summary

Evolver is looking for a Security Control Assessor to join our team supporting our federal client in Washington, DC. This position requires on-site 5 days/week at our federal client's HQ located in Washington, DC.

The Security Control Assessor is responsible for providing independent security control testing to the client for 20 FIPS Moderate and Low systems. Duties include conducting security control assessments through interviews, examination, and/or testing for all applicable management, operational, and technical controls, including analyzing findings and results and validating test results/ reports. Duties also include developing Security Control Assessment Plans, Risk Assessment Reports, and ATO Memos, as well as developing and maintaining testing policies and related Standard Operating Procedures (SOPs). The Security Control Assessor is also responsible for documenting and presenting the results of the Security Test & Evaluation (ST&E) to government stakeholders including System Owners, ISSOs, the CISO and Authorizing Official. Responsibilities also include reviewing artifacts and providing recommendations on POA&M closures.

Responsibilities
  • Conduct security testing in accordance with NIST SP 800-53-A.
  • Develop Security Controls Assessment Plans, including:
    • Interviewing, examining, and/or testing management, operational, and technical controls.
    • Gathering evidence for tested controls.
    • Summarizing testing results, highlighting high/moderate risk items and compliance percentages.
    • Documenting results within the Security Controls Assessment Plan.
    • Analyzing and summarizing scan results, utilizing scans provided by the cloud environment.
  • Assist in updating the client's IT Security Program policies and procedures.
  • Provide timely reminders to Agency ISSOs to support Continuous Monitoring efforts.
  • Assist in launching the client's Configuration Management program, including compliance testing and guidance on implementing DISA's Security Technical Implementation Guides (STIGs).
  • Produce Security Assessment Reports (SAR) using the Agency's Information Assurance tool.
  • Evaluate the risk of SAR findings from security testing and summarize them into Plan of Action and Milestone (POA&M) tracking documentation.
  • Track the progress of the IT Risk Management program through POA&M updates and/or data submission to the Agency's Office of Risk Management.
  • Review supporting artifacts, evaluate remediation of risk, and recommend POA&M closure


Basic Qualifications

  • Bachelor's degree in computer science, Information Technology, or a related field.
  • 4 years of experience in conducting security testing in accordance with NIST SP 800-53A.
  • 4 years of experience creating POA&Ms in the CSAM tool.
  • 2 years of experience with NIST SP 800-53-A and security control assessment methodologies.
  • 2 years of experience with security program management, including policy and procedure development, Continuous Monitoring, and risk management.
  • with the ablity to pass a comprehensive background check.
  • 2 years of previous client-engagement experience.


Preferred Qualifications
  • Strong analytical skills and ability to quantify and analyze test findings.
  • Knowledge of security tools and techniques, including scanning tools.
  • Understanding of cloud environments and related security implications.
  • Excellent communication (verbal and written) and collaboration skills, with the ability to work effectively with security staff and Agency ISSOs.
  • Impeccable work ethic, the ability to make sound decisions, and a commitment to integrity and accountability.
  • Excellent organizational skills and attention to detail.
  • Strong analytical, critical thinking, and problem-solving skills.
  • Ability to function well in a high-paced and at times stressful environment.
  • Ability to prioritize tasks.
  • Proficient with Microsoft Office Suite; specifically, Excel, Word, and Outlook a must.
  • One or more of the following certifications preferred: CISSP, CAP, CISM, Security+, CASP, CISA.


Evolver Federal is an equal opportunity employer and welcomes all job seekers. It is the policy of Evolver Federal not to discriminate based on race, color, ancestry, religion, gender, age, national origin, gender identity or expression, sexual orientation, genetic factors, pregnancy, physical or mental disability, military/veteran status, or any other factor protected by law.

Actual salary will depend on factors such as skills, qualifications, experience, market and work location. Evolver Federal offers competitive benefits, including health, dental and vision insurance, 401(k), flexible spending account, and paid leave (including PTO and parental leave) in accordance with our applicable plans and policies.
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 10516943
  • Position Id: 3931663
  • Posted 30+ days ago

Company Info

About Evolver Federal

Evolver LLC, a Converged Security Solutions (CSS) company, is a technology company serving government and commercial customers by addressing client challenges in the present and transitioning clients to the future through innovative IT transformation and cybersecurity services and solutions. Founded in 2000, Evolver delivers services and solutions that improve security, promote innovation, and maximize operational efficiency.

Headquartered in Reston, Virginia, Evolver has grown to nearly 600 employees, and continues to expand our information technology services customer base in both the government and commercial markets.

Evolver Federal was forged from decades of combined expertise from Evolver, LLC and the former Solutions By Design II, LLC. With an unwavering commitment to serving our government clients, Evolver Federal stands as the pinnacle of innovation, security, and transformative technology solutions.

At Evolver Federal, our core mission is clear: to empower government entities with unparalleled cybersecurity measures, optimize infrastructure operations, deliver comprehensive end-user support, pioneer cutting-edge application development, leverage cloud services for enhanced efficiency, and drive transformative IT solutions.

About_Company_OneAbout_Company_Two
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

Washington, District of Columbia

Today

Full-time

Washington, District of Columbia

Today

Full-time

Springfield, Virginia

Today

Full-time

Search all similar jobs