OverviewThe Sea, Land, Air Analysis Group’s mission is to deliver objective analyses, plans and strategies to US Navy, US Marine Corps, US Air Force, other DoD, and Australian Defence Force clients to support technology development, acquisition, delivery and sustainment decisions. The group provides the core of SPA thought leadership on Undersea Strategy, Software Development and Cost Estimating, with additional benchmark capabilities in AI/ML & Decision Analytics, Modeling and Simulation, and Future Force Assessments.
SPA has an immediate need for a Security Controls Assessor (SCA).#FC #Dice
Responsibilities
The Security Controls Assessor (SCA) is responsible for conducting a comprehensive assessment of the management, operational, and technical security controls employed within or inherited by an Information System (IS) to determine the overall effectiveness of the controls. SCAs also provide an assessment of the severity of weaknesses or deficiencies discovered in the IS and its environment of operation and recommend corrective actions to address identified vulnerabilities. Responsibilities will cover Collateral, Sensitive Compartmented Information (SCI) and Special Access Program (SAP) activities within the customer’s area of responsibility.
Responsibilities include conducting IS assessments in accordance with the Risk Management Framework (RMF) and Joint Special Access Program Implementation Guide (JSIG), advising key stakeholders on assessment and authorization matters, and evaluating authorization packages for recommendation to the Authorizing Official. The role encompasses identifying and analyzing threats and vulnerabilities, ensuring proper documentation of security assessments, preparing Security Assessment Reports (SARs), and initiating Plans of Action and Milestones (POA&Ms). The candidate will review sanitization procedures, support Government compliance inspections and cybersecurity incident responses, and assess the security impact of hardware, software, and environmental or mission changes. Additionally, the position requires evaluating Continuous Monitoring Plans and providing clear, actionable recommendations to support secure and compliant system operations.
Qualifications
Required Qualifications:
- Master's Degree in related field
- 7 years of relevant experience
- 2 years of experience in SAP, SCI or Collateral Information Systems Security and implementation of regulations identified in the duty descriptions
- Prior performance in the role of ISSO (or System, Network administrator) and ISSM
- Must meet position and certification requirements outlined in DoD Directive 8570.01-M for Information Assurance Technician Level III or Information Assurance Manager Level II
- Active TS/SCI and the ability to maintain it throughout employment
Desired Qualifications:
- 9 years of related experience
Pay Range InformationAt SPA, we strive to deliver a robust total compensation package that will attract and retain top talent. Elements of the compensation package include competitive base pay and variable compensation opportunities. SPA provides eligible employees with an opportunity to enroll in a variety of benefit programs, generally including health insurance, flexible spending accounts, health savings accounts, retirement savings plans, life and disability insurance programs, and a number of programs that provide for both paid and unpaid time away from work. The specific programs and options available to any given employee may vary depending on eligibility factors such as geographic location, date of hire, etc. Please note that the salary information shown below is a general guideline only. Salaries are commensurate with experience and qualifications, as well as market and business considerations. Washington, DC, Pay Transparency Salary range: USD $160,000.00/Yr. - USD $180,000.00/Yr.