Koniag Government Services

Security Control Accessor

Koniag Government Services$100K — $120K *
Education, Government & Non-Profit
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Computer Science, IT, Cybersecurity, or related field.
  • 5+ years in federal information security with NIST SP 800-53 assessments.
  • Proven experience developing Security Assessment Plans and Reports per NIST standards.
  • Hands-on assessment experience across diverse IT environments including cloud and on-premises systems.
  • Familiarity with federal agency GRC tools for documentation and monitoring activities.
  • Ability to obtain a Minimum Background Investigation (MBI) and PIV credentials; eligibility for Top Secret clearance preferred.

Responsibilities

  • Plan, execute, and report on assessments of security and privacy controls for federal systems.
  • Conduct various types of controls assessments based on agency schedules and requirements.
  • Prepare draft Security Assessment Plans, outlining assessment scope and methodologies.
  • Execute and document detailed assessments using NIST SP 800-53A methodologies.
  • Produce comprehensive Security Assessment Reports that meet federal documentation standards.
  • Collaborate with ISSOs and stakeholders to support security documentation and assessment activities.

Benefits

  • Health, dental, and vision insurance coverage.
  • 401K with company matching contributions.
  • Flexible spending accounts available.
  • Three weeks of paid time off annually.
  • Paid holidays and additional leave options.
Full Job Description
Koniag Data Solutions, a Koniag Government Services company, is seeking an experienced Security Control Assessor (SCA) to support a comprehensive enterprise cybersecurity services program for a federal government client.

This position requires the ability to obtain and maintain a Minimum Background Investigation (MBI) or higher, PIV credentials, and all requisite IT access authorizations prior to performing work. Primary work will be performed at the client site in Washington DC and approved remote/telework locations.

We offer competitive compensation and an extraordinary benefits package including health, dental and vision insurance, 401K with company matching, flexible spending accounts, paid holidays, three weeks paid time off, and more.

This role serves as a key technical contributor responsible for the independent assessment and evaluation of security and privacy controls across the client's enterprise IT portfolio-spanning on-premises, cloud-hosted, and hybrid systems-in support of the agency's Federal Information Security Modernization Act (FISMA) compliance program, Risk Management Framework (RMF) activities, and Ongoing Authorization (OA) initiatives.

The ideal candidate is a detail-oriented and technically proficient security assessment professional with demonstrated experience conducting NIST SP 800-53 security and privacy controls assessments, developing Security Assessment Reports (SARs), supporting Authority to Operate (ATO) activities, and executing continuous monitoring assessments across a diverse federal enterprise IT environment. This individual must possess the ability to work independently across complex, multi-technology system boundaries and deliver thorough, accurate, and well-written assessment artifacts that meet rigorous federal documentation standards.

The Security Control Assessor will serve as an independent technical evaluator responsible for planning, executing, and reporting on security and privacy controls assessments for assigned systems and services across the client's enterprise IT portfolio. This individual is responsible for assessing the implementation and effectiveness of NIST SP 800-53 security and privacy controls, documenting assessment findings in accordance with NIST SP 800-53A methodologies, producing high-quality assessment artifacts, and supporting the full RMF assessment lifecycle from initial planning through final report delivery and POA&M development. The SCA works closely with ISSOs, system owners, security engineers, and Government stakeholders to ensure assessments are thorough, accurate, and completed within required timelines.

Principal responsibilities will include but are not limited to:

Security & Privacy Controls Assessment
  • Plan, execute, and report on comprehensive security and privacy controls assessments for assigned federal information systems and services, including on-premises, IaaS, PaaS, and SaaS implementations, in accordance with NIST SP 800-53 Rev 5, NIST SP 800-53A Rev 5, and applicable agency implementation procedures.
  • Conduct point-in-time full controls assessments, annual controls assessments, multi-year one-third assessments, and Ongoing Authorization (OA) evaluation assessments in accordance with the agency's assessment schedule and applicable implementation procedures.
  • Develop and deliver draft Security Assessment Plans (SAPs) no less than ten (10) business days prior to beginning each assessment, clearly documenting the assessment scope, boundaries, sampling strategies, test methods, and schedule.
  • Execute NIST SP 800-53A Determine If Statements (DISs) for all in-scope controls, documenting assessment findings to a level of detail sufficient to demonstrate that the implementation of each control objective is validated or not validated, avoiding high-level summary statements and ensuring technical depth across all technology types within the system boundary.
  • Conduct technical controls assessments across all technology types within each system boundary, including Windows and UNIX servers, network devices (routers, switches, Cisco, F5 load balancers), web applications, databases, cloud platforms, and endpoint systems, applying appropriate sampling strategies approved by the Government prior to implementation.
  • Develop Government-approved sampling strategies encompassing all asset types within each system boundary, typically between ten (10) and twenty (20) percent of applicable assets where appropriate, ensuring sampling covers all relevant device types, users, and services.
  • Map identified vulnerabilities and assessment findings to applicable NIST SP 800-53 Rev 5 controls and control families, ensuring accurate and complete linkage between technical findings and corresponding control deficiencies.
  • Produce comprehensive draft and final Security Assessment Reports (SARs) within required timelines, ensuring reports are comprehensive to the scope identified in the SAP, fully aligned to the agency's Governance, Risk, and Compliance (GRC) tool, include visual representation against the NIST Cybersecurity Framework (CSF), and are peer-reviewed for accuracy and grammar prior to submission.
  • Develop draft Plans of Action and Milestones (POA&M) entries for identified control deficiencies, typically using the agency's GRC tool, delivering draft POA&Ms within thirty (30) calendar days from point-in-time assessment kickoff.
  • Develop draft Annual Assessment Reports (AARs) per in-scope system within one-hundred-twenty (120) business days from point-in-time annual assessment kickoff, and deliver draft summary reports for multi-year assessment efforts no later than sixty (60) business days prior to the end of each Fiscal Year.
  • Incorporate all Government feedback into assessment artifacts within five (5) business days of receipt of comments, delivering finalized deliverables that accurately reflect all Government-provided corrections, questions, and recommendations.

Ongoing Authorization (OA) Evaluation Support
  • Conduct Ongoing Authorization (OA) controls assessments for systems approved for OA, applying agency-specific OA test procedures that replace traditional NIST SP 800-53A test procedures for OA-approved systems.
  • Execute OA Positive Testing monthly for OA-approved systems, using automated or semi-automated techniques to determine whether controls are operating effectively under normal circumstances, documenting results in the agency GRC tool in accordance with OA implementation procedures.
  • Execute OA Negative Testing annually for OA-approved systems, using automated or semi-automated techniques to determine whether controls respond as expected under abnormal circumstances where misuse is injected to attempt to circumvent the control, coordinating as necessary with penetration testing purple team resources.
  • Assist in the development and submission of OA Playbooks for Government approval, documenting the testing methodology for each OA core control including Test Strategy, Test Design, Test Execution, Results Evaluation, and Visualization components.
  • Conduct OA testing comprehensively across all technology types within each target system's boundary, including sampling across in-scope devices, users, and services, documenting all test results in detail within the agency GRC tool in accordance with applicable OA implementation procedures.
  • Ensure all OA Positive and Negative Testing documentation is peer-reviewed for accuracy and grammar prior to submission to the Government.

ISSO Support & Collaboration
  • Collaborate closely with assigned ISSOs to support their development of in-depth technical and operational knowledge about assigned systems, providing assessment expertise, technical guidance, and documentation support as needed.
  • Provide technical support and expertise to ISSOs in the development and maintenance of all security documentation in the ATO package, including System Security Plans (SSPs), Configuration Management Plans (CMPs), Information System Contingency Plans (ISCPs), and other RMF artifacts, ensuring documentation aligns with applicable agency implementation procedures and template requirements.
  • Support ISSOs in reviewing and validating system security documentation for technical accuracy, completeness, and alignment with the system boundary and technology stack, providing specific and actionable feedback to improve documentation quality.
  • Assist ISSOs in ensuring control implementation descriptions within SSPs are written to the required level of technical detail, clearly explaining how each control is implemented across all technologies within the system boundary using specific naming conventions, configurations, and operational procedures rather than high-level general statements.
  • Participate in Enterprise Change Control Board (ECCB) activities as needed, providing security assessment expertise to support the evaluation of proposed system changes and their potential impact on the system's security posture and ATO status.

Audit & Compliance Support
  • Support internal and external audit activities for assigned FISMA systems, facilitating meetings and walkthroughs of key cybersecurity capabilities, coordinating with system support personnel, and supplying auditors with requested artifacts and evidence within required timeframes.
  • Ensure audit artifacts are complete, accurate, and delivered on time to avoid repeated requests from auditors, communicating any issues or problems to the Government immediately upon discovery.
  • Support FISMA continuous monitoring activities, including the collection, validation, and submission of system-level FISMA metrics for assigned systems in alignment with federal CIO metrics requirements and agency reporting schedules.
  • Assist in the development and maintenance of automated visualizations and dashboards that reflect the status and effectiveness of security controls for assigned systems, providing continuous visibility into the security posture and compliance status of assigned systems.
  • Support High Value Asset (HVA) assessment activities for designated HVA systems, including vulnerability scanning and remediation validation, monitoring and analysis of relevant audit logs, and identification of connections between HVAs and other systems.
  • Assist in FedRAMP Continuous Monitoring (CONMON) management activities for applicable cloud service provider systems, including review of vulnerability, penetration testing, and ad hoc reporting to ensure vendor actions pose no security risk to the enterprise environment.

Documentation & Reporting
  • Develop and maintain all assigned security and privacy assessment documentation in alignment with applicable agency implementation procedures, ensuring all documents are complete, well-written, aligned to agency templates, and meet the level of detail specified in agency procedures.
  • Ensure all assigned documents are updated in the agency's GRC tool and relevant SharePoint repositories in accordance with required timelines and agency standards.
  • Prepare and submit all assigned deliverables peer-reviewed for accuracy, punctuation, and grammar prior to submission, ensuring deliverables are delivered on or before agency-defined completion dates.
  • Address all Government-provided comments, edits, errors, and questions within ten (10) business days of receipt, and escalate stakeholder unresponsiveness to the Government POC after ten (10) business days without receiving a required response.
  • Ensure all documentation created under the contract is Government owned, properly marked, accessible via Section 508 compliant formats as required, and not marked with any proprietary or company-restrictive language.


Education and Experience:

Required:
  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Information Systems, or a related field from an accredited college or university.
  • Minimum of 5 years of experience in federal information security, with demonstrated hands-on experience conducting NIST SP 800-53 security and privacy controls assessments for federal information systems.
  • Demonstrated experience developing Security Assessment Plans (SAPs), Security Assessment Reports (SARs), Annual Assessment Reports (AARs), and Plans of Action and Milestones (POA&Ms) in accordance with NIST SP 800-53A methodologies and federal RMF requirements.
  • Experience conducting technical controls assessments across diverse technology stacks, including Windows and UNIX servers, network devices, web applications, databases, and cloud platforms (IaaS, PaaS, SaaS).
  • Experience working with federal agency Governance, Risk, and Compliance (GRC) tools for documentation management, POA&M tracking, and continuous monitoring activities.
  • Ability to obtain and maintain a Minimum Background Investigation (MBI) or higher, PIV credentials, and all requisite IT access authorizations; must be eligible for Top Secret clearance access should such a requirement arise during the period of performance.

Preferred:
  • CISSP certification or demonstrated equivalent experience and commitment to obtain within 12 months of award.
  • Prior experience supporting federal civilian agency FISMA compliance programs in a Security Control Assessor or ISSO capacity.
  • Experience working on GSA Multiple Award Schedule (MAS) HACS SIN contracts or comparable federal IT cybersecurity contract vehicles.
  • Experience conducting Ongoing Authorization (OA) assessments using agency-specific positive and negative testing methodologies.


Required Skills and Competencies:
  • Exceptional written communication skills in English with demonstrated ability to produce clear, concise, technically thorough, and professionally written security assessment artifacts that meet rigorous federal documentation standards, including SSPs, SAPs, SARs, AARs, and POA&Ms.
  • Deep knowledge of NIST SP 800-53 Rev 5 security and privacy control families, including the ability to assess all control families across diverse federal information systems and accurately document implementation status at the required level of technical detail.
  • Strong proficiency with NIST SP 800-53A Rev 5 assessment methodologies, including development and execution of Determine If Statements (DISs), examination, interview, and testing assessment methods, and objective-based evidence collection and validation

About Koniag Government Services

Koniag Government Services Careers

Join the dynamic team at Koniag Government Services, a leader in providing innovative solutions to government clients. This esteemed company offers a plethora of job opportunities that pave the way for professional growth and career advancement in a diverse and inclusive environment.

Explore Career Opportunities

Koniag Government Services is actively hiring and offers a range of positions that cater to various skills and experiences. Whether you're a seasoned professional or a recent graduate, Koniag Government Services provides a platform to enhance your career through meaningful work in a supportive culture.

Innovation and Leadership

At the forefront of innovation, Koniag Government Services encourages its team to lead with creativity and strategic thinking. The company is committed to leadership development and diversity training, ensuring that all team members have the opportunity to excel and contribute to industry-leading projects.

Professional Growth and Development

Koniag Government Services is dedicated to the professional development of its employees. With comprehensive benefits, competitive employment packages, and opportunities for advancement, the company supports its team in achieving their career goals. Networking within the company and industry is encouraged, fostering a community of learning and mutual growth.

Internship Programs

For those starting their career journey, Koniag Government Services offers internship programs that provide real-world experience and a pathway to full-time employment. Interns gain valuable industry knowledge and develop essential skills under the guidance of experienced mentors.

Commitment to Diversity and Inclusion

Diversity is at the core of Koniag Government Services' values. The company is committed to creating an inclusive environment where diverse voices are heard and valued. Diversity training is integral, equipping the team with the tools to thrive in a multicultural setting.

Applying for a Position

To apply for a position at Koniag Government Services, candidates should prepare a resume that highlights relevant experience and skills. The interview process is designed to assess fit both for the role and the company culture, ensuring alignment with the team’s values and objectives.

Stay Connected with Koniag Government Services Careers

Explore the various job opportunities and embark on a path of professional growth and innovation. Koniag Government Services is not just a workplace but a community where careers flourish in an environment of respect, integrity, and continuous learning.

Search Koniag Government Services Jobs

Discover the exciting career opportunities available at Koniag Government Services. Search for open positions that match your skills and interests, and join a team that values curiosity, creativity, and collaboration.

Keep Up to Date

Stay informed with the latest career tips, industry insights, and company updates directly from Koniag Government Services. Engage with content that can transform your professional journey and lead to rewarding opportunities.

Job Alert Emails

Personalize your subscription to receive job alerts and insider tips tailored to your preferences from Koniag Government Services. See what exciting and rewarding opportunities await in the field of government services.
Learn more about Koniag Government Services
Size
501 employees
Industry

Similar Jobs

More Jobs at Koniag Government Services

More Education, Government & Non-Profit Jobs

  • Deputy Building Official
    $80K — $150K + gloucester county government offers an excellent benefit package *
    Gloucester County
    Gloucester, VA 23061 (Gloucester County)
  • Deputy Assessor
    $80K — $150K + gloucester county government offers an excellent benefit package *
    Gloucester County
    Gloucester, VA 23061 (Gloucester County)
  • Civil Engineer II
    $80K — $150K + gloucester county government offers an excellent benefit package *
    Gloucester County
    Gloucester, VA 23061 (Gloucester County)
  • Accounting Manager
    $80K — $100K + gloucester county government offers an excellent benefit package *
    Gloucester County
    Gloucester, VA 23061 (Gloucester County)
  • Manager, Clinical Business Development
    $115K — $120K *
    Columbia University Irving Medical Center
    New York, NY 10032 (New York County)

Find similar Security Control Accessor jobs: