Job Description35-003 - Security Control Assessor (SCA) IILocation: Kirtland AFB, NM
Salary: $162,937.41
Position Type: Full-Time
Security Clearance: Active Top Secret/SCI Clearance RequiredEligibility for Special Access Program AccessMust Be Willing to Undergo a Counterintelligence Polygraph
Position OverviewSandy Mac Evolution LLC is seeking an experienced
Security Control Assessor (SCA) II to support Department of Defense Special Access Program environments at Kirtland Air Force Base, New Mexico.
The selected candidate will conduct comprehensive assessments of the management, operational, and technical security controls implemented within or inherited by classified Information Systems. The SCA II will determine whether security controls are properly implemented, operating as intended, and producing the required security outcomes for the system and its operating environment.
This position will also evaluate the severity of identified weaknesses and deficiencies, recommend corrective actions, and provide security authorization guidance to government stakeholders. Responsibilities will support Collateral, Sensitive Compartmented Information, and Special Access Program activities within the customer's area of responsibility.
Key Responsibilities- Provide oversight for the development, implementation, and evaluation of Information System security policies and programs, with particular emphasis on integrating existing SAP network infrastructure.
- Conduct security control assessments using the Risk Management Framework methodology and the Joint Special Access Program Implementation Guide.
- Assess management, operational, and technical security controls to determine whether they are implemented correctly, operating as intended, and meeting established security requirements.
- Advise Information System Owners, Information Data Owners, Program Security Officers, Delegated Authorizing Officials, and Authorizing Officials regarding assessment and authorization matters.
- Review and evaluate authorization packages and provide recommendations to the Authorizing Official or Delegated Authorizing Official.
- Evaluate Information System threats, risks, and vulnerabilities to determine whether additional safeguards or corrective actions are required.
- Advise government personnel regarding appropriate confidentiality, integrity, and availability impact levels for information processed by classified systems.
- Ensure security assessments are completed, documented, and maintained in accordance with applicable government requirements.
- Prepare Security Assessment Reports for assigned authorization boundaries.
- Develop and initiate Plans of Action and Milestones for identified weaknesses based on findings and recommendations documented in Security Assessment Reports.
- Evaluate assessment documentation and provide written recommendations regarding system authorization.
- Present authorization recommendations and submit completed security authorization packages to the appropriate Authorizing Official.
- Assess proposed changes to authorization boundaries, operating environments, system configurations, and mission requirements to determine whether continued authorization to operate is appropriate.
- Review and concur with media sanitization, clearing, and disposal procedures in accordance with government policy and guidance.
- Support government compliance reviews, audits, and inspections.
- Assist with cybersecurity incident response activities and verify that appropriate corrective and preventive measures have been implemented.
- Ensure organizations address cybersecurity requirements throughout all phases of the System Development Life Cycle.
- Evaluate hardware and software changes to determine their potential security impact on authorization boundaries.
- Evaluate the effectiveness and implementation of Continuous Monitoring Plans.
- Represent the customer as a member of inspection and assessment teams.
- Identify security control deficiencies and recommend practical remediation strategies.
- Maintain accurate assessment records, supporting evidence, findings, and authorization documentation.
Required Qualifications- Seven to nine years of directly related cybersecurity, Information Assurance, Information System security, or security assessment experience.
- Minimum of four years of experience supporting SAP, SCI, or Collateral Information Systems and implementing applicable cybersecurity regulations and policies.
- Previous experience performing in the role of an Information System Security Officer, Information System Security Manager, or Security Control Assessor.
- Demonstrated experience conducting security control assessments and evaluating authorization packages.
- Working knowledge of the Risk Management Framework and Joint Special Access Program Implementation Guide.
- Experience preparing Security Assessment Reports, Plans of Action and Milestones, and authorization recommendations.
- Knowledge of classified Information System security requirements, cybersecurity incident response, continuous monitoring, and the System Development Life Cycle.
- Ability to assess technical and nontechnical security controls and clearly communicate findings to government leadership and system stakeholders.
- Ability to regularly lift up to 50 pounds.
Education- Bachelor's degree in cybersecurity, information technology, computer science, information systems, or a related discipline.
- Four additional years of directly related professional experience may be accepted in lieu of a bachelor's degree.
Certification RequirementsCandidates must meet the applicable position and certification requirements established under DoD Directive 8570.01-M within six months of hire.
Qualifying certification requirements include:
- Information Assurance Technician Level III, or
- Information Assurance Manager Level II in lieu of IAT Level III.
Security Requirements- Active Top Secret clearance with Sensitive Compartmented Information eligibility is required at the time of application.
- Eligibility for access to Special Access Program information.
- Ability and willingness to submit to a Counterintelligence polygraph.
- Ability to maintain TS/SCI eligibility, SAP access, and all required security certifications throughout employment.
- U.S. citizenship is required due to the classified nature of the work.
Preferred Qualifications- Extensive experience supporting Department of Defense SAP environments.
- Previous experience working directly with Authorizing Officials, Delegated Authorizing Officials, Program Security Officers, and Information System Owners.
- Experience participating in government inspections, compliance reviews, and authorization activities.
- Strong technical writing skills and experience developing formal cybersecurity assessment documentation.
Work EnvironmentThis position operates within a highly secure Department of Defense environment and may require work involving classified systems, secure facilities, specialized equipment, inspections, and coordination with government cybersecurity and program security personnel.