Arlo Solutions (Arlo) is an information technology consulting services company that specializes in delivering technology solutions. Our reputation reflects the high quality of the talented Arlo Solutions team and the consultants working in partnership with our customers. Our mission is to understand and meet the needs of both our customers and consultants by delivering quality, value-added solutions. The Department of Defense’s (DoD) Chief Digital and Artificial Intelligence Office (CDAO) is at the forefront of supporting the DoD with the adoption of innovative technologies such as data, analytics, and artificial intelligence to help accelerate predictions, forecasts, and interpretations for both strategic and tactical decisions across the enterprise.
Senior Security Control Assessor
Location
United States
Posted
2 days ago
Salary
Not specified
No structured requirement data.
Job Description
Role Description
The Department of Defense’s (DoW) Office of the Undersecretary of War for Research and Engineering (OUSW (R&E)) is at the forefront of supporting the DoW with the adoption of innovative technologies such as data, analytics, and artificial intelligence to help accelerate predictions, forecasts, and interpretations for both strategic and tactical decisions across the enterprise. The Security Control Assessor (SCA) plays a pivotal role in comprehensively understanding the cybersecurity posture of a given capability within OUSW (R&E). SCAs must go beyond a mere compliance focus on controls to articulate the inherent risks of systems.
Success in this position requires expertise in statutory guidance such as:
- NIST 800 series
- DoW 8500.01
- DoW 8140.03
- ISO 27001
- COBIT
- DoW RMF
- Operation Vulcan Logic (OVL)
The Senior SCA provides authoritative risk determinations and recommendations critical for the Authorizing Official (AO) to grant an Authority to Operate (ATO). Their assessments integrate technical rigor with regulatory compliance, ensuring a robust security posture and informing strategic decision-making.
Work Location: Full time remote. Candidates in the Washington DC Metropolitan preferred. Travel requirements will vary with location, however, expect approximately 10% to 25%.
Clearance: Top Secret with SCI eligibility
Qualifications
- Strong background in information security systems management (ISSM), risk management, and governance, risk and compliance (GRC).
- Strong client focus and commitment to continuous improvement.
- Ability to proactively network and establish relationships.
- Experience supporting and assessing risks within a CI/CD DevSecOps environment.
- Expansive knowledge with integrating IaaS, PaaS, and SaaS offerings into government cloud environments (e.g., AWS, AZURE & GCP).
- Experience assessing STIGs, Cloud Compliance Guides, and System Mission Owner responsibilities within Government Cloud Environments.
- Expert understanding of NIST 800 series guidelines, DoW 8500.01, DoW 8140.03, ISO 27001, COBIT, DoW RMF, OVL, and current cybersecurity best practices.
- Excellent communication/presentation skills briefing senior military and government civilian leadership.
- Experienced with writing policies, guides, procedures.
- Experience in hands-on with eMASS, Xacta and/or other GRC tools.
- Experience with Federal and FedRamp A&A Processes.
- Experienced and comfortable advising at the Senior Executive Service (SES) level of customers.
Requirements
- Must have an active Top-Secret Clearance SCI eligible.
- Bachelor’s degree in computer science/information technology, or other related degree fields (master’s degree is preferred or at least 10 years of related experience).
- At least 10+ years of cybersecurity experience including a senior technical or management role; Project or Program Management experience a plus.
- At least one IAT/IAM or equivalent security certifications (e.g., CISSP, CCSP, CISM, CISA, or CASP).
Company Description
We are proud to be an Affirmative Action and Equal Opportunity Employer and as such, we evaluate qualified candidates in full consideration without regard to race, color, religion, sex, sexual orientation, gender identity, marital status, national origin, age, disability status, protected veteran status, and any other protected status.
Job Requirements
- Strong background in information security systems management (ISSM), risk management, and governance, risk and compliance (GRC).
- Strong client focus and commitment to continuous improvement.
- Ability to proactively network and establish relationships.
- Experience supporting and assessing risks within a CI/CD DevSecOps environment.
- Expansive knowledge with integrating IaaS, PaaS, and SaaS offerings into government cloud environments (e.g., AWS, AZURE & GCP).
- Experience assessing STIGs, Cloud Compliance Guides, and System Mission Owner responsibilities within Government Cloud Environments.
- Expert understanding of NIST 800 series guidelines, DoW 8500.01, DoW 8140.03, ISO 27001, COBIT, DoW RMF, OVL, and current cybersecurity best practices.
- Excellent communication/presentation skills briefing senior military and government civilian leadership.
- Experienced with writing policies, guides, procedures.
- Experience in hands-on with eMASS, Xacta and/or other GRC tools.
- Experience with Federal and FedRamp A&A Processes.
- Experienced and comfortable advising at the Senior Executive Service (SES) level of customers.
- Must have an active Top-Secret Clearance SCI eligible.
- Bachelor’s degree in computer science/information technology, or other related degree fields (master’s degree is preferred or at least 10 years of related experience).
- At least 10+ years of cybersecurity experience including a senior technical or management role; Project or Program Management experience a plus.
- At least one IAT/IAM or equivalent security certifications (e.g., CISSP, CCSP, CISM, CISA, or CASP).
Related Guides
Related Categories
Related Job Pages
More Security Analyst Jobs
Senior Investigator, Aetna SIU (Must reside in Ohio)
CVS HealthBringing our heart to every moment of your health.
The Senior Investigator conducts high-level, complex investigations into suspected healthcare fraud and abuse, often involving sensitive, high-profile, or national scope cases within Medicaid lines of business. This role involves researching, documenting case activity, facilitating recovery of lost funds, and providing guidance and training to less experienced investigators.
Cybersecurity Analyst supporting NASA’s enterprise business solutions
Threat Analyst, Machine Learning
CrowdStrikeCrowdStrike has redefined security with the world’s most advanced cloud-native platform that protects and enables the people, processes and technologies that drive modern enterprise. Tested and proven, the world's largest organizations trust CrowdStrike to stop breaches with unparalleled protection against the most sophisticated cyberattacks. The CrowdStrike culture has been built upon our Core Values since the day we began. We are Fanatical About the Customer, Relentlessly Focused on Innovation and believe that our Limitless Passion drives Unlimited Potential for every CrowdStriker. As a purpose-built remote-first company, we believe cultivating a connected culture for every employee, no matter where they are in the world, is a key ingredient in building a high-performing, diverse team. We don’t have a mission statement. We’re on a mission—to stop breaches. Ready to join a mission that matters?
At CrowdStrike we’re on a mission - to stop breaches. Our groundbreaking technology, services delivery, and intelligence gathering together with our innovations in machine learning and behavioral-based detection, allow our customers to not only defend themselves, but do so in a...
Lead Cybersecurity Analyst - Incident Response
TargetWorking at Target means helping all families discover the joy of everyday life. We bring that vision to life through our values and culture. A role within Roundel is an opportunity to be part of a strategic priority business for Target. Roundel is Target’s entry into the media business, built on the principles of first-party data, brand-safe environments, and proof that our marketing programs drive business results for our clients. We operate with the ethos of trust and transparency, and that media works best when it works in everyone’s best interest. Roundel is here to drive business growth for our clients and redefine “value” in the industry by solving core industry challenges.
JOIN TARGET CYBERSECURITY AS A LEAD CYBERSECURITY ANALYST - CSIRT (INCIDENT RESPONSE) As a Lead Cybersecurity Analyst on CSIRT, you will assist with leading the team as you assess information security events and incidents across the Target environment. In this role, you will: Col...