Skip to main content
Tallo logoTallo logo

Find Jobs

Find Jobs Near You – Available Work in Your Location

Skip to job details

Back to Results

Apply for this opportunity

To apply for this job, you'll continue to an external website or email application.

FileImport - Booz Allen Hamilton | ClearanceJobs.com

Security Control Assessor, Lead

Review key factors to help you decide if the role fits your goals.
Pay Growth
?
out of 5
Not enough data
Not enough info to score pay or growth
Job Security
?
out of 5
Not enough data
Calculating job security score...
Total Score
53
out of 100
Average of individual scores

Were these scores useful?

Job Description

Security Control Assessor, Lead

Job Number:
R0249483
Security Control Assessor, LeadThe Opportunity:

The Lead Security Control Assessor directs the SCA workstream and provides independent cybersecurity assessment leadership for CDAO systems and environments to the ISSM. The Lead SCA owns assessment strategy, quality standards, stakeholder coordination, risk adjudication, and final review of Security Assessment Plans (SAPs) and Security Assessment Reports (SARs). The position advises technical leadership and Authorizing Official (AO) stakeholders on control effectiveness, authorization readiness, and residual cybersecurity risk. In this role you will be responsible for developing and governing the assessment approach, schedule, evidence standards, test procedures, and quality-control framework for the SCA team.

What You'll Work On:

Provide eMASS administration, analyze

STIG, SCAP, ACAS

findings, POA&Ms, architecture, inherited controls, compensating controls, and technical evidence. Work with the project ISSM to understand customer cybersecurity RMF requirements applicable to the systems in their respective environments. Lead independent security control assessments in accordance with DoD

RMF, NIST

guidance, applicable DoD cybersecurity policy, and organizational assessment procedures. Brief findings and risk recommendations to the

ISSM, AO

representative, and AO-level stakeholders. Develop all system applicable RMF Body of Evidence (BOE) documentation ensuring accuracy, relevance, and completion to meet requirements and input BOE documentation into AO approved databases such as eMASS or AO specific SharePoint site. Review and approve SAPs and SARs for technical accuracy, evidence sufficiency, traceability, consistency, and defensibility before stakeholder delivery. Coordinate with system owners, ISSMs and ISSOs, cybersecurity engineers, administrators, developers, program leadership, control providers, and AO representatives. Review system boundaries, data flows, external interfaces, interconnections, inherited controls, common-control dependencies, and significant changes. Oversee assessment execution for ATO, reauthorization, annual assessment, significant-change assessment, and continuous monitoring activities. Brief assessment status, systemic risks, unresolved findings, remediation priorities, and authorization recommendations to senior stakeholders. Mentor assessors, calibrate assessment judgments, and ensure independence and objectivity across the assessment lifecycle. Develop and maintain strong relationships with stakeholders across the organization

You Have:

8+ years of experience with cybersecurity including substantial DoD or federal RMF, security assessment, security engineering, or authorization Experience with eMASS, analyzing

STIG, SCAP, ACAS

findings, POA&Ms, architecture, inherited controls, compensating controls, and technical evidence Experience leading security control assessments and producing or approving SSPs, SAPs, SARs, POA&Ms, risk assessments, and authorization packages Experience with administration of Windows, Linux, AWS Cloud, and containerization systems and software configuration Experience with technical writing, facilitation, quality-assurance, team leadership, and stakeholder-management capabilities Knowledge of

NIST SP 800-53, NIST SP

800-37, DoD RMF, STIGs, vulnerability management, and security-control assessment methodology Ability to evaluate complex enterprises, cloud, hybrid, containerized, data, and AI-enabled architectures and communicate risks at the AO and executive levels Ability to lead, organize, and complete various cybersecurity testing events ...For full information see follow application link. Commitment to Non-Discrimination - All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran, or any other status protected by applicable federal, state, local, or international law.

Benefits

  • Dental Insurance