Security Controls Assessor (Pipeline)

Electrosoft

$80K — $110K *
Aerospace & Defense
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Active IAM-III certification (e.g., CISSP, CISM) required.
  • 5 years of related experience preferred.
  • Active DoD Secret security clearance necessary.
  • BA/BS degree from an accredited university required.
  • In-depth knowledge of DoD RMF tool eMASS needed.
  • Strong written and verbal communication skills essential.
  • Ability to engage effectively with senior leadership.

Responsibilities

  • Assess and recommend security controls for mission assurance on USTRANCOM terrains.
  • Provide subject matter expert support for RMF activities.
  • Analyze technical artifacts and give risk analysis recommendations.
  • Triaging various security control documentation and requests.
  • Document non-compliant submissions for Government SCA approval.
  • Review and assess cybersecurity controls for adequacy.
  • Perform Independent Verification and Validation within eMASS.

Benefits

  • Work on critical defense projects for the DoD.
  • Opportunity to impact over 52 Programs of Record.
  • Support mission critical security assessments.
  • Work with a skilled team of professionals in a specialized field.
  • Possibility of career growth in a prestigious government contracting environment.
Full Job Description
Job Description Electrosoft is seeking a Security Control Assessor - Representative (SCA-R) to support our DoD customer at Scott Air Force Base, IL. The SCA-R will independently assess the adequacy and compliance of security controls applied to the agency on behalf of the Government SCA and Authorizing Official (AO). SCA-R personnel will assist Government personnel with the overall responsibility to conduct independent comprehensive assessments of the management, operational, privacy and technical security controls and controls enhancements employed within or inherited by an IT system to determine the overall effectives of the controls for more than 52 Programs of Record in use across the Enterprise. The SCA-R will collect, provide, and maintain current documentation on authorization processes and procedures. Duties & Responsibilities: 3 Assess, identify, and provide to the Government, for AO approval, a listing of recommended enterprise security controls/enhancements that provide mission assurance for cyber USTRANCOM terrain systems supporting USTRANSCOM's mission. 3 Provide SME support for RMF activities within and/or outside Enterprise Mission Assurance Support Service (eMASS) or other tool as designated by the Government. 3 Provide technical and operational analyses of supporting artifacts and provide risk analysis recommendations to the SCA. 3 Perform triage of authorization, POA&M, System Security Plan, System Categorization, and risk acceptance requests using the Govt RMF Artifact Quality Rubric. 3 Identify non-compliant submissions, document in the Package Return Report (PRR), and submit to the Government SCA for approval and signature. 3 Review security artifacts provided by program offices or other organizations and assess both technical and functional adequacy of cybersecurity/Information Assurance (IA) controls 3 Perform the Independent Verification and Validation (IV&V) role within eMASS on NIPRNet and SIPRNet, verifying that controls are in-place, operating as intended, producing desired outcomes, and providing feedback to submitters on non-compliant security controls, adequacy of artifacts, and POA&M items, and provide the required PRR as needed. 3 Compile Authorization Official package to include risk assessment, required artifacts, and required approval documents to support risk recommendations to the AO in accordance with Government guidance. 3 Review and coordinate RMF packages such as categorizations, security plans and POA&Ms for signature by approved authorities as designated by the Government and IAW suspense assigned by the Government. 3 Manage eMASS user accounts (i.e., add, delete, and assign/update roles) for the customers instance of eMASS per Government direction. 3 Track status of checklists and packages from submission through approval or disapproval decision by the AO. Qualifications/Certifications: 3 Requires Active IAM-III certification (e.g. CISSP, CISM) 3 Minimum of 5 years of related experience 3 Requires Active DoD Secret security clearance 3 BA/BS degree from an accredited university 3 Thorough understanding and experience with DoD RMF tool eMASS 3 Excellent written and verbal communication skills, demonstrating the ability to present material to senior DoD and non-DoD officials. 3 Able to communicate effectively with senior leaders and customers to clearly present technical approaches and findings. 3 Demonstrated knowledge and understanding of the DoD mission 3 Experience with Ports, Protocols, Services Management (PPSM) is desired

Similar Jobs

More Jobs at Electrosoft

More Aerospace & Defense Jobs

Find similar Security Controls Assessor (Pipeline) jobs: