Location: Bethesda, MD (mostly remote, occasional onsite required)
Work schedule: 40 hrs/week
Compensation: $100,000-$115,000/year
Target start: by
end of August 2026 Clearance / Public Trust: Public Trust eligibility (Tier 2/3) required
About the roleWe're hiring a
Junior Security Control Assessor to support independent security control assessments across the system authorization lifecycle. You'll work under a senior assessor and help evaluate security control implementation, validate evidence, and document results in alignment with
NIST Risk Management Framework (RMF) and
NIST SP 800-53 Rev. 5, using
JCAM practices.
This is a great fit for someone who enjoys cybersecurity compliance, evidence-based assessments, and strong technical writing-without being the person who authors the entire authorization package.
What you'll do - Support independent Security Control Assessments (SCAs) across the authorization lifecycle
- Review and validate security authorization documentation (SSP, SAP, SAR, POA&M, contingency plans, and supporting artifacts)
- Assess security control implementation through documentation review, interviews, and technical validation
- Help evaluate cloud security packages and inherited controls (as applicable)
- Document findings, recommendations, and remediation activities clearly and professionally
- Assist with evidence validation and remediation tracking
- Partner with system owners and ISSOs while maintaining assessor independence
Required qualifications - Education: Bachelor's in Cybersecurity, IT, Computer Science, Information Systems (or similar)
- OR 4 additional years of relevant experience in lieu of a degree
- Experience: 3-5 years supporting cybersecurity, information assurance, RMF, security assessments, compliance, or IT operations
- Working knowledge of:
- NIST RMF (800-37) and NIST SP 800-53 Rev. 5
- JCAM methodology
- Experience reviewing security documentation and assessment evidence/artifacts
- Strong analytical skills and technical writing ability
Preferred (nice to have) - Experience with eMASS or similar GRC platforms
- Familiarity with FedRAMP, cloud security concepts, C-SCRM, and related federal security frameworks
- Experience supporting independent audits/assessments (e.g., external review organizations)
Tools/tech exposure (helpful) - JCAM
- Tenable
- CrowdStrike
- Splunk / Splunk Enterprise
- AWS
- Python (plus)
Certifications (preferred, not all required) - ISC2 CC or CGRC
- CompTIA Security+, CySA+, PenTest+, CASP+
- CEH
- Microsoft SC-900