SAIC

Security Control Assessor

SAIC$120K — $160K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5-9 years of experience in enterprise IT environments
  • Bachelor's degree in Cybersecurity, Computer Science, IT, or related field
  • Active TS/SCI clearance with ability to obtain TS/SCI with Poly
  • Certifications meeting Cybersecurity Workforce Framework ID 612 requirements
  • Strong analytical and documentation skills for creating Security Assessment Reports

Responsibilities

  • Conduct independent assessments of IT systems for security compliance
  • Review Authorization Boundary Diagrams and risk assessment documentation
  • Lead security control assessments and implementation reviews
  • Provide recommendations on system authorization status based on assessment findings
  • Analyze vulnerability scan results and present findings
  • Perform continuous monitoring assessments for risk identification
  • Compile comprehensive reports for senior stakeholders

Benefits

  • On-site work location in Springfield, VA
  • Opportunity to support mission-critical IT systems
  • Engagement with advanced cybersecurity frameworks
  • Possibility for professional growth in assessment and compliance roles
  • Participation in a dynamic and collaborative team environment
Full Job Description
Job Description

Description

SAIC is seeking a highly skilled and motivatedSenior Security Control Assessor (SCA)to support the cybersecurity assessment and compliance needs of mission-critical IT systems for theMAJESTIC Joint Program Office (JPO) Team.The successful candidate will perform independent assessments of security controls to ensure compliance with federal cybersecurity policies, standards, and frameworks, such as the Risk Management Framework (RMF), NIST SP 800-53, and others, to manage and mitigate risks to sensitive and classified systems.

This role will require working closely with Information System Security Managers (ISSMs), Information System Owners (ISOs), and system administrators to conduct technical reviews, evaluate security controls, and assist with Authorization and Accreditation (A&A) efforts. This role requireson-site support in Springfield, VA.

Key Responsibilities:
  • Conduct independent, objective, and robust assessments of IT systems to validate compliance with security control requirements in alignment withNIST 800-53, RMF, DoD 8510.01, and other applicable federal cybersecurity regulations.
  • Review and assessAuthorization Boundary Diagrams (ABDs), Risk Assessment Reports (RARs), Security Plan Packages (SSPs), STIG checklists, vulnerability scan results, POA&Ms, and other security artifacts required for A&A efforts.
  • LeadControl Implementation Review and Test (CIRT)procedures and system-level security assessments to evaluate the adequacy of technical, operational, and management security controls.
  • Provideformal recommendations on system authorization statusto Authorizing Officials (AOs), based on assessment results, residual risks, and system compliance to applicable policies.
  • Analyze and interpretvulnerability scan results(e.g., from ACAS, Nessus, or Qualys) and assist in presenting the organization's vulnerability management posture to relevant stakeholders.
  • Performcontinuous monitoring assessmentsof information systems to identify risks, ensure ongoing compliance, and document changes impacting the security posture of systems.
  • Assess and validate security hardening practices using theDISA STIGs or CIS Benchmarksacross systems, applications, and networks.
  • Conduct risk analysis and recommend risk mitigation strategies and control adjustments to minimize threats to system operations and data integrity.
  • Interface with system engineers, ISSOs, and stakeholders to resolve identified vulnerabilities and ensure timely remediation of risks.
  • Provide recommendations to improve current processes, tools, and documentation for security control assessments.
  • Compile and present comprehensive reports, includingSecurity Assessment Reports (SARs)and risk assessment summaries, to senior stakeholders for decision-making.
  • Maintain up-to-date expertise on cybersecurity threats, technologies, regulatory frameworks, and compliance best practices.

Qualifications

Required Qualifications:

Certifications (CWF Requirements):
  • Candidates must satisfyCybersecurity Workforce Framework (CWF)ID 612 (Security Control Assessor)requirements, as outlined byNavy COOL.
    This requirement can be met by possessing one or more of the following qualifyingcertifications:
  • Certified in Governance Risk and Compliance (CGRC)
  • Certified Information Systems Security Officer (C)ISSO-A)
  • CompTIA Cloud+
  • CompTIA PenTest+
  • CompTIA Security+
  • CompTIA SecurityX (formerly CASP+)
  • Federal IT Security Professional-Auditor-NG (FITSP-A)
  • GIAC Cloud Security Automation (GCSA)
  • GIAC Security Essentials Certification (GSEC)
  • Certified Chief Information Security Officer (CCISO)
  • Certified Information Security Manager (CISM)
  • Certified Information Systems Auditor (CISA)
  • Certified Information Systems Security Professional (CISSP)
  • CompTIA Cybersecurity Analyst (CySA+)
  • GIAC Security Leadership Certification (GSLC)
  • GIAC Systems and Network Auditor (GSNA)
  • Information Systems Security Engineering Professional (ISSEP)

    OR This requirement can be met through:
  • ABachelor's Degreein Cybersecurity, Computer Science, IT, or a related field.

    Experience:
  • 5-9 yearsof professional experience managing and supporting enterprise-levelIT environments.

    Technical Skills:
  • Familiarity with IT environments running enterprise systems, such as Windows Server 2019, MS SQL databases, and Linux distributions (RHEL preferred).
  • Knowledge of incident response functions, security architecture, and penetration testing frameworks (e.g., METASPLOIT, Kali Linux).
  • Strong analytical and documentation skills, with the ability to author comprehensive Security Assessment Reports (SARs) and other system artifacts.

    Preferred Qualifications:
  • Familiarity with IT environments running enterprise systems, such as Windows Server 2019, MS SQL databases, and Linux distributions (RHEL preferred).
  • Knowledge of incident response functions, security architecture, and penetration testing frameworks (e.g., METASPLOIT, Kali Linux).
  • Strong analytical and documentation skills, with the ability to author comprehensive Security Assessment Reports (SARs) and other system artifacts.

    Clearance Requirement:
  • ActiveTS/SCIclearance with the ability to obtain and maintain aTS/SCI with Poly.

    Work Environment and Notes:
  • On-Site Work:All work must be conductedon-sitein Springfield, VA.
  • Program Scope:Supports on-premises enterprise IT environments, including virtualized Windows servers, MS SQL Server databases, and networking layers.
  • Subcontractor Role:Responsibilities and compensation vary based on the subcontract agreement, with a competitive salary aligned to market rates and role-specific requirements.

Target salary range: $120,001 - $160,000. The estimate displayed represents the typical salary range for this position based on experience and other factors.

Overview

SAIC accepts applications on an ongoing basis and there is no deadline.

About SAIC

Science Applications International Corporation (SAIC) is a technology integrator in the technical, engineering, intelligence, and enterprise information technology markets. SAIC has approximately 26,000 employees and operates in more than 70 countries. The company was founded in 1969 and is headquartered in Reston, Virginia. SAIC provides services to the U.S. government, including the Department of Defense, the intelligence community, and civilian agencies. The company also serves commercial customers in the healthcare, energy, and financial services sectors.
Learn more about SAIC
Size
26,000 employees
Market Cap
$6 billion
Industry
Net Income
$206 million
Founded
1969
5 Year Trend
+10.7%
Revenue
$6.8 billion
NASDAQ

Similar Jobs

More Jobs at SAIC

More Information Technology Jobs

Find similar Security Control Assessor jobs: