Hiring.Camp

Security Control Assessor (SCA) (TS/SCI)

Tau Six

·

Apr 19, 2025

Location
Chantilly, VA, US
Type
Full-time
Department
Security
Clearance
Required
Source
Breezy HR

Description

Join a fast growing agile small company that delivers cutting edge cybersecurity and system integration services to the US National Security market. We are seeking a motivated self-starter with experience in secure information systems to join a team of security professionals and help defend national security systems.

Tau Six, an agile small company delivering cutting edge cybersecurity and systems integration services to the US National Security market, has an immediate need for a Cybersecurity Security Control Assessor (SCA) for a Department of Defense customer. This high-profile contract will assist the DoD with the oversight and management of information technology projects in support of critical Defense priorities. The ideal candidate will bring excellent cybersecurity and information assurance knowledge to the program coupled with strong communication skills.

Your excellent technical skills will assist in identifying risk to systems across a broad spectrum of technologies and processes. Your responsibilities will also include elements of physical and environmental protection, incident handling, and security training and awareness. In close coordination with the rest of the security team, you will play an active role in identifying risk and defending the enterprise. Candidates must possess thorough understanding of Windows & Linux operating systems, cloud technology, contemporary networking, and cybersecurity tools, techniques, and tactics.

Clearance Required: U.S. Government Top Secret / SCI

Responsibilities:

The Security Control Assessor (SCA) will conduct and document a comprehensive assessment of the management, operational, and technical security controls employed within or inherited by an information system. Determine the overall control effectiveness through documentation review, inspections, testing and interviews. Provide an assessment of the severity of weakness or deficiencies and recommend corrective actions to address identified vulnerabilities. Provide initial mitigation of Cybersecurity incidents, support incident investigations, and closure of the incident. Provide assessment of proposed technology (hardware, software, and firmware) for Cybersecurity vulnerabilities.

General activities:

  • Improves operations by conducting functional and systems analyses and recommending changes in policies and procedures.
  • Scrutinizes builds of secure infrastructure to ensure best practices are followed in using the latest networking, virtualization, automation, and configuration management tools.
  • Works with the customer to identify and implement security requirements, security best practices, and security controls.
  • Partners with the customer to develop and implement strategic security initiatives
  • Assist in security investigations and responses as necessary
  • Provide cyber security technical expertise and analysis for new technologies and configurations.

Specific assessment of security controls and organizational requirements shall include:

  • Assessment Package Feedback which focuses on the documentation submitted to support the various steps of Risk Management Framework (RMF).
  • Security Assessment Report which focuses on the assessment of an information system in support of the authorization determination. Shall provide a draft report
  • Periodic Cybersecurity Assessment Report or Security Compliance Report which focuses on the assessment of a Cybersecurity program at a location.
  • Cybersecurity Incident Reports which focus on documenting Cybersecurity incidents.
  • Technical Assessment of Hardware, Software, or Firmware. Shall document the technical assessment addressing Cybersecurity vulnerabilities
  • Shall develop an annual compilation of findings and observations based upon the Security Assessment Reports and Periodic Cybersecurity Assessment Reports or Security Compliance Reports based upon fiscal year assessments.

Position Qualifications:

  • Shall have 4 or more years of experience in the validation of security configuration of operating systems.
  • Shall have 2 or more years of experience applying Risk Management Framework (RMF) as described in the National Institute of Standards and Technology Special Publications.
  • Candidates must have extensive experience with risk assessment technologies including analyses of the adequacy of implemented security features across a broad range of technologies.
  • Must have extensive experience conducting security testing and providing accreditation recommendations to decision authorities.
  • A background and experience with NIST SP800-53, CNSSI 1253, DCID 6/3, JSIG, and/or ICD 503. Knowledge of current authorization practices, particularly within the DoD and IC is a must.
  • Must have extensive direct experience with the policies, processes, and methodologies in the application of the Risk Management Framework.
  • Must have demonstrated knowledge of host and network access control and auditing technologies and methods.
  • Must have an understanding of incident response, configuration management, and defense in depth best practices.

Desired Qualifications:

  • Strongly desired experience with application of the Defense Information Systems Agency (DISA) Security Technical Implementation Guides.
  • Operating System/Computing Environment certificate for Windows Server 2012 or newer UNIX (Linux (Red Hat), Solaris).
  • Experience with vulnerability scanners.
  • Experience with assessing security relevant applications.
  • Experience as a System Administrator, Information System Security Manager, or Information System Security Officer.
  • Experience applying the requirements of the DoD Joint Special Access Program Implementation Guide (JSIG) to information systems or Cybersecurity programs.
  • Experience with Cross Domain Solutions (CDS)

Education Desired:

  • Bachelor’s Degree/Master’s Degree in a technology-related discipline

Skills

LinuxCybersecurityRisk ManagementCompliance

Similar Jobs

30

Security Control Assessor

Apavo Corporation · Arlington, VA

3 days ago

Security Control Assessor

M9Solutions · Alexandria, VA - Secret clearance required · Onsite

5 days ago

Security Control Assessor

Peraton · Alexandria, VA, US

2 weeks ago

Security Control Assessor

BEAT · SAN ANTONIO, TX

11 months ago

Security Control Assessor

G-Force Solutions Inc · Arlington, VA

1+ year ago

Security Control Assessor

Netizen

1+ year ago

Security Control Assessor Apprentice

Citadel Pacific · Tamuning

6 days ago

Cyber Security Security Control Assessor

Lawrence Livermore National Laboratory · Livermore, CA, United States · Hybrid

1 week ago

Offensive Security Control Assessor Security Control Assessor Representative

Darkwolfsolutions · Washington DC Metro Area +1 · Remote, Hybrid

1 week ago

Security Control Assessor (SCA) II

GDIT · USA VA Arlington - Customer Proprietary (VAC473), United States of America

2 weeks ago

Security Control Assessor (SCA) II

Gdit · USA VA Arlington - Customer Proprietary (VAC473), United States of America

2 weeks ago

Senior Cybersecurity SME/Security Control Assessor

Qinetiqus · Chantilly, VA, US

3 weeks ago

Security Control Assessor/Representatives

Darkwolfsolutions · Washington DC Metro Area +1 · Remote, Hybrid

3 weeks ago

Security Control Assessor II (SCA II) (TS, w/ SCI Eligibility) -

RedTrace Technologies Inc · Peterson SFB, Colorado Springs, CO

4 weeks ago

Junior Security Control Assessor

The Newberry Group · Ft. Meade, MD · Remote, Hybrid

1 month ago

Security Control Assessor / ISSE Support- Federal Health

rockITdata · Arlington, VA · Remote

1 month ago

Security Control Assessor II

GDIT · USA NM Albuquerque - Customer Proprietary (NMC027), United States of America

1 month ago

Security Control Assessor II

Gdit · USA NM Albuquerque - Customer Proprietary (NMC027), United States of America

1 month ago

Sr Security Control Assessor Representative

KBR Careers · USA, Eglin AFB, 8th Special Forces Way, Florida, United States of America · Onsite

1 month ago

Security Control Assessor (SCA) II

Modern Technology Solutions Inc · Albuquerque, NM,US, US · Onsite

1 month ago

Security Control Assessor (SCA)

KBR Careers · USA, Washington, 8th & I Streets SE, District of Columbia, United States of America

1 month ago

Security Control Assessor II

Gdit · USA UT Ogden - Customer Proprietary (UTC016), United States of America

1 month ago

Security Control Assessor II

GDIT · USA UT Ogden - Customer Proprietary (UTC016), United States of America

1 month ago

Security Control Assessor (SCA) II - West Lake, TX area

Gdit · USA TX West Lake - Customer Proprietary (TXC166), United States of America

1 month ago

Security Control Assessor (SCA) II - West Lake, TX area

GDIT · USA TX West Lake - Customer Proprietary (TXC166), United States of America

1 month ago

Cyber Security Control Assessor

Caci · 398 NATIONAL HARBOR MD, United States of America · Onsite

2 months ago

IT Security Control Assessor

Guidehouse is · GH Office: Tysons Corner, VA (Headquarters), United States of America

4 months ago

TASS (Current Contract) - Security Control Assessor, Senior

Agecareers · Alexandria, Virginia, United States, Chambersburg, Pennsylvania, United States, Fort Meade, Maryland, United States +3

11 months ago

IA Security Administrator | Security Control Assessor

3500 Square · Remote, US +1 · Remote

1+ year ago

(178) Senior Security Control Assessor

Arlosolutionsllc · Hybrid · Hybrid

1+ year ago
Security Control Assessor (SCA) (TS/SCI) at Tau Six | Hiring.Camp