Mid-Level Security Control Assessor

System One Holdings, LLC

$140K *
Healthcare
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Cybersecurity, IT, Computer Science, or related field, or equivalent experience.
  • 10+ years' experience in federal cybersecurity and information assurance programs.
  • Proven experience in leading independent Security Control Assessments.
  • Expertise in assessing security control testing and documentation per NIST standards.
  • Experience reviewing FedRAMP authorization packages and conducting regulatory assessments.

Responsibilities

  • Serve as technical authority for security assessments following NIST standards.
  • Lead planning and execution of Security Control Assessments throughout the authorization lifecycle.
  • Review authorization packages including SSPs, SADs, and SARs for completeness and accuracy.
  • Assess implementation and effectiveness of security controls via documentation reviews.
  • Document findings and support continuous cybersecurity improvements.
  • Provide risk-based recommendations while maintaining assessment independence.
  • Mentor junior assessors and enhance assessment methodologies.

Benefits

  • Health and welfare benefits options including medical, dental, and vision coverage.
  • Spending accounts and life insurance plans available.
  • Participation in a 401(k) plan.
Full Job Description
Job Title: Mid-Level Security Control Assessor
Location: Bethesda, Maryland
Type: Direct Hire
Salary: $140,000 range annually, plus benefits
Work Model: Hybrid - onsite and remote
Hours: 40.0/week
Security Clearance: Public Trust

Work expected to begin on or about August 30, 2026

System One IT has a direct hire opening for a mid-level Security Control Assessor to support a National Healthcare agency. This is a remote position day-to-day with infrequent on-site visits in Bethesda, MD.
This position supports a federal end customer and requires US citizenship with eligibility to pass a Public Trust clearance. (Current Public Trust clearance highly desired). This role is currently in the bid process and is expected to be awarded in early August, with work to begin on or about August 30, 2026, if awarded.

Responsibilities

  • Serve as the technical authority for independent security assessments in accordance with NIST standards and agency policies.
  • Lead planning, execution, and validation of Security Control Assessments throughout the authorization lifecycle.
  • Review and validate authorization packages, including SSPs, SAPs, SARs, POA&Ms, and supporting evidence.
  • Assess the implementation and effectiveness of security controls through documentation reviews, interviews, and technical validation.
  • Review FedRAMP cloud packages and inherited controls as applicable.
  • Document findings, recommendations, and remediation activities.
  • Support cybersecurity audits and continuous improvement initiatives.
  • Provide risk-based recommendations to the Authorizing Official while maintaining assessment independence.
  • Mentor junior assessors and improve assessment methodologies.


Requirements
  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or related discipline, or four (4) additional years of relevant experience.
  • Ten (10) or more years of progressive experience supporting federal cybersecurity, RMF, Security Control Assessment, or information assurance programs.
  • Significant experience leading independent Security Control Assessments and validating RMF authorization packages.
  • Experience conducting security control testing, evidence validation, and developing SARs per NIST SP 800-37, NIST SP 800-53 Rev. 5, and JCAM.
  • Experience supporting federal civilian agencies is highly desirable.
  • Experience reviewing FedRAMP authorization packages and supporting OIG, GAO, or independent assessments.
  • Strong knowledge of federal cybersecurity assessment principles, excellent analytical and technical writing skills, and effective communication skills.


System One not only serves as a valued partner for our clients, but we offer eligible employees health and welfare benefits coverage options including medical, dental, vision, spending accounts, life insurance, voluntary plans, as well as participation in a 401(k) plan.

#M-MM1
#LI-MM1
Ref: #856-Baltimore-S1

Similar Jobs

More Jobs at System One Holdings, LLC

More Healthcare Jobs

Find similar Mid-Level Security Control Assessor jobs: