Skip to main content
Tallo logoTallo logo

Find Jobs

Find Jobs Near You – Available Work in Your Location

Skip to job details

Back to Results

Apply for this opportunity

To apply for this job, you'll continue to an external website or email application.

Crest Security Assurance

DCMA Security Control Assessor

Career Insights for Cyber Security Specialist / Technician

See where this job fits in the broader career landscape. Knowing your career path helps you see what's possible from here.

Scorecard

Based on Virginia data

Review key factors to help you decide if this role fits your goals. How is this calculated?

Were these scores useful?

What they do

A Cyber Security Specialist or Technician works on monitoring, controlling, and maintaining systems that protect the security of large databases, including databases with customer information and patient files. May work on examination of client computer systems, identification of weak points in security, development and implementation of new systems, and monitoring and response to security issues.

$126,138 / year median in Virginia

+2% projected growth

Explore Career

Job Description

Support the Defense Contract Management Agency (DCMA) Cybersecurity Support Services (CSS) contract by independently assessing security controls for classified and unclassified information systems. Plan and execute security control assessments in accordance with DoDI 8510.01, the DoD Risk Management Framework (RMF), NIST SP 800-53, and NIST SP 800-53A, and provide objective evidence and risk-based recommendations to support authorization decisions and continuous monitoring.
Responsibilities:
Develop and execute Security Assessment Plans (SAPs), including assessment scope, methodology, procedures, schedules, and evidence requirements, in coordination with system owners, Information System Security Officers (ISSOs), Information System Security Managers (ISSMs), and Authorizing Official staff. Assess implemented technical, operational, and management security controls through documentation review, interviews, observation, testing, and analysis of artifacts such as vulnerability scan results, Security Technical Implementation Guide (STIG) checklists, configuration baselines, and continuous monitoring records. Document assessment results, findings, and residual risk in Security Assessment Reports (SARs), Security Control Assessment Reports (SCARs), Risk Assessment Reports (RARs), and related RMF artifacts; validate that findings are accurate, traceable, and supported by sufficient evidence. Review Plans of Action and Milestones (POA&Ms) and remediation evidence, evaluate proposed mitigations, and perform closure validation or follow-up testing to confirm that identified weaknesses have been effectively addressed. Maintain assessment results, control status, evidence, and authorization documentation in the Enterprise Mission Assurance Support Service (eMASS); track assessment activities and provide status, risk, and performance metrics to DCMA leadership.
Requirements:
Active Secret security clearance At least 5-7 years of related cybersecurity, RMF, security control assessment, or information assurance experience DoD IAM III required certification(s) (one of the following):
CISM CISSP
(or Associate) GSLC CCISO