Job Description
Zachary Piper Solutions is seeking a Senior Security Control Assessor to support a high-visibility National Security contract in Arlington, VA (100% onsite) . The Senior SCA will bring advanced cybersecurity assessment experience, deep knowledge of DoD RMF and NIST frameworks, and the ability to deliver independent risk determinations supporting cutting-edge AI/ML and data-driven mission systems. The Senior SCA will play a critical role in evaluating system security posture, advising Authorizing Officials, and ensuring compliance while articulating real-world risk across complex enterprise environments. Responsibilities of the Senior Security Control Assessor Representative include:
Lead Risk Assessments:
Provide independent, authoritative risk determinations and recommendations to the Authorizing Official for Authority to Operate decisions Conduct Security Assessments:
Develop Security Assessment Plans, execute control assessments, and produce Security Assessment Reports Drive RMF Execution:
Apply DoD RMF methodologies to identify baselines, evaluate controls, and assess system security posture Qualifications of the Senior Security Control Assessor include: 10+ years of cybersecurity experience, including senior-level risk management, assessment, or GRC roles Familiarity with DevSecOps, CI/CD pipelines, and automated security controls Hands-on experience with GRC tools such as eMASS, Xacta, or similar platforms Experience evaluating STIGs, Cloud Compliance Guides, and FedRAMP requirements Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related field (Master's preferred or equivalent experience) Active TS/SCI Clearance Active IAT/IAM II
Certification Compensation for the Senior Security Control Assessor include: Salary Range:
$150,000 - $160,000 depending on experience Full Benefits Package:
PTO, Paid Holidays, Medical, Dental, Vision, 401K, Tuition Reimbursement, Sick leave as required by law #LI-RL1 #LI-ONSITE SEO
Keywords:
Senior Security Control Assessor, SCAR, RMF, DoD RMF, A&A, Authorization to Operate, ATO, cybersecurity, GRC, eMASS, Xacta, NIST, FedRAMP, STIGs, cloud security, AWS, Azure, GCP, DevSecOps, CI/CD, risk assessment, POA&M, SAR, SAP, TS clearance, SCI eligible, Arlington VA, onsite cybersecurity jobs, federal cybersecurity, security architecture, enterprise security, AI/ML systems, defense technology