Security Control Assessor

Open 19d

Position Overview

A Cybersecurity Subject Matter Expert provides expert-level cybersecurity analysis, engineering, and assessment services for complex, multi-domain systems. This role acts as a senior technical advisor and Security Control Assessor (SCA), specializing in integrating security throughout the system lifecycle, translating technical risks into mission-impact statements, and guiding the implementation of advanced security architectures.

Principal Duties and Responsibilities:

  • Provides strategic cybersecurity guidance and participates in technical reviews (e.g., SRR, PDR, CDR) to ensure security is integrated from the initial design phase and throughout the system development lifecycle.
  • Executes the Risk Management Framework (RMF) process, providing risk determinations and recommendations to the Authorizing Official (AO).
  • As a Security Control Assessor (SCA), executes the Risk Management Framework (RMF) process across Federal, DoD, and IC policies. Provides continuous risk determinations and actionable recommendations directly to the Authorizing Official (AO).
  • Conducts deep technical validation of security controls by reviewing vulnerability scans (e.g., ACAS/Nessus), STIG checklists, and penetration test reports to correlate findings with operational mission risk.
  • Evaluates the security performance, integrity, and residual risk of diverse and complex architectures, including Platform Information Technology (PIT), cloud environments, communication networks, and satellite control systems.
  • Guides the adoption and implementation of DoD Zero Trust principles and provides specialized expertise in the design and evaluation of Cross Domain Solutions (CDS).
  • Functions as a technical liaison between engineering teams, program leadership, and external government and industry partners.