ECS

Security Controls Assessor

ECS$150K — $168K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Active Secret clearance required, with eligibility to obtain Top Secret clearance
  • Bachelor's degree in Computer Science, MIS/IT, Engineering, Information Security/Assurance, or a related field
  • Minimum of 5 years in information security
  • At least 3 years of experience supporting security assessment teams
  • 2 years of experience using GRC tools
  • Strong understanding of NIST SP 800-53 and applicable information security laws

Responsibilities

  • Review and update security policies and procedures for compliance
  • Perform independent security and privacy audits for the client
  • Assess FISMA systems and report on control weaknesses
  • Analyze and verify completeness of authorization packages
  • Develop and execute security assessment test cases
  • Document actionable findings and recommendations
  • Conduct security assessments that require occasional travel

Benefits

  • Hybrid work environment in Washington, DC
  • Opportunity to work on a long-term contract with a U.S. Government agency
  • Support for CONUS and OCONUS travel
  • Access to advanced security assessment tools and methodologies
Full Job Description
ECS is seeking a Security Controls Assessor to work in our Washington, DC (hybrid) office. Please Note: This position is contingent upon contract award.

ECS seeks a Security Controls Assessor to support a full range of cybersecurity services on a long-term, full-time contract with a U.S. Government civilian agency. This position requires mostly CONUS and occasional OCONUS assessments and is available immediately for a qualified candidate with an active security clearance.

Key Responsibilities
  • Review and update information security policies, standards, and procedures in accordance with federal and departmental regulations
  • Perform independent security and privacy control assessments on behalf of the client CSO in support of Security Assessment & Authorization (SA&A)
  • Assess existing and new FISMA systems and subsystems, and communicate findings and potential impacts of identified control weaknesses
  • Review and analyze A&A packages-including System Security Plans (SSP), Risk Assessments, Information System Contingency Plans (ISCP), Backup SOPs, Incident Response Plans (IRP), Configuration Management Plans (CMP), hardware/software inventories, network diagrams, data flows, system change requests, vulnerability scan reports, test reports, and POA&Ms-for completeness, accuracy, and effective control implementation
  • Develop and maintain test cases for control-level security testing across system components (applications, servers, databases, operating systems, network devices, end-user devices, etc.)
  • Develop and execute security and privacy assessment plans in accordance with NIST SP 800-53A, supporting RMF Steps 4-6
  • Document findings and recommendations that are clear, system-specific, and actionable
  • Analyze security tool outputs to distinguish residual risk from false positives prior to finalizing findings
  • CONUS and OCONUS travel to conduct system assessments
  • Other duties as assigned

Salary Range: $150,000-$168,000

General Description of Benefits

  • Active Secret clearance required with eligibility to get Top Secret clearance
  • Bachelor's degree in Computer Science, MIS/IT, Engineering, Information Security/Assurance, or a related field
  • Minimum five (5) years of information security experience
  • Minimum three (3) years of experience supporting security assessment teams, including planning assessments and serving as a senior team member
  • Two (2) years of experience using GRC tools
  • Demonstrated experience conducting full-scope technical security control testing across component types, including development of security and privacy assessment plans
  • Working knowledge of RMF Steps 1-6
  • Strong understanding of NIST SP 800-53 controls, the NIST Cybersecurity Framework, and applicable information security/privacy laws and regulations
  • Ability to analyze information system configurations and technical specifications against NIST SP 800-53 and related overlays
  • Experience developing risk-based documentation
  • Excellent written and verbal communication skills, with the ability to present control requirements and deficiencies clearly to both technical and non-technical audiences

About ECS

ECS is a leading provider of digital solutions and services to the federal government. The company was founded in 2001 by Roy Kapani and has since grown to become a trusted partner to a wide range of government agencies. ECS offers a broad range of services, including cloud computing, cybersecurity, and artificial intelligence. The company has been recognized for its innovative solutions and has won numerous awards, including the AWS Public Sector Partner of the Year award.
Learn more about ECS
Size
2,000 employees
Industry

Similar Jobs

More Jobs at ECS

  • ECS
    Enterprise Technical Writer
    $130K — $147K *
    Washington, DC 20011 (District Of Columbia County)
    Information Technology
    In-Person
  • ECS
    Senior Operations Manager
    $160K — $210K *
    Fort George G Meade, MD 20755 (Anne Arundel County)
    Aerospace & Defense
    In-Person
  • ECS
    Motion GEOINT Analyst
    $75K — $105K *
    Springfield, VA 22153 (Fairfax County)
    Aerospace & Defense
    In-Person
  • ECS
    ISO Coordinator
    $75K — $130K *
    Remote
    Education, Government & Non-Profit
    Remote in Virginia, US
  • ECS
    Senior Cloud Engineer
    $170K — $210K *
    Fort George G Meade, MD 20755 (Anne Arundel County)
    Technical Services
    In-Person

More Information Technology Jobs

Find similar Security Controls Assessor jobs: