Lead Security Control Assessor
Location
United States
Posted
4 days ago
Salary
Not specified
Seniority
Lead
No structured requirement data.
Job Description
Role Description
We have an opening for a full-time Security Control Assessor to join our talented, dynamic team in support of the Department of Veterans Affairs. As a Security Control Assessor, you will be trusted to support the delivery of our cybersecurity solutions and services. In this role, you will be a part of a security control assessment team working on the tasks outlined below. Veterans are encouraged to apply.
Responsibilities:
- Lead a small team in coordinating and conducting security control assessment activities, stakeholder interviews, and report generation.
- Conduct independent comprehensive assessments of the management, operational, and technical security controls and control enhancements employed within or inherited by an information technology (IT) system to determine the overall effectiveness of the controls (as defined in NIST SP 800-37).
- Plan and conduct security authorization reviews and assurance case development for initial installation of systems and networks.
- Review authorization and assurance documents to confirm that the level of risk is within acceptable limits for each software application, system, and network.
- Verify that application software/network/system security postures are implemented as stated, document deviations, and recommend required actions to correct those deviations.
- Develop security compliance processes and/or audits for external services (e.g., cloud service providers, data centers).
- Perform security reviews and identify security gaps in security architecture resulting in recommendations for inclusion in the risk mitigation strategy.
- Perform risk analysis (e.g., threat, vulnerability, and probability of occurrence) whenever an application or system undergoes a major change.
- Provide input to the Risk Management Framework process activities and related documentation (e.g., system life-cycle support plans, concept of operations, operational procedures, and maintenance training materials).
Qualifications
- Bachelor's degree in computer science, electronics engineering or other engineering or technical discipline is required, and will accept relevant experience in lieu of degree.
- 2+ years hands-on experience with Cybersecurity policy, risk management, or security and privacy control assessments.
- Knowledge of cybersecurity and privacy principles and organizational requirements (relevant to confidentiality, integrity, availability, authentication, non-repudiation).
- Knowledge of system and application security threats and vulnerabilities.
- Knowledge of Personally Identifiable Information (PII), Payment Card Industry (PCI), and Personal Health Information (PHI) data security standards.
Requirements
- Experience with security control assessments within the VA using the NIST Risk Management Framework (RMF) is a plus.
- Certifications such as SCA and CISA are a plus.
- Exceptional written and verbal communication skills.
- Strong planning, organizational, and time management skills.
- Exceptional analytical and conceptual thinking skills.
- Ability to work collaboratively with a team of peers.
Benefits
- Traditional and HSA-eligible medical insurance plans.
- 100% employer-paid dental and vision insurance options.
- 100% employer-sponsored STD, LTD, and life insurance.
- 5% 401(k) company matching.
- Flexible schedules and teleworking options.
- Paid holidays and PTO Accrual Plans.
- Paid Parental Leave.
- Professional development and career growth opportunities.
- Team and company-wide events, recognition, and appreciation.
Job Requirements
- Bachelor's degree in computer science, electronics engineering or other engineering or technical discipline is required, and will accept relevant experience in lieu of degree.
- 2+ years hands-on experience with Cybersecurity policy, risk management, or security and privacy control assessments.
- Knowledge of cybersecurity and privacy principles and organizational requirements (relevant to confidentiality, integrity, availability, authentication, non-repudiation).
- Knowledge of system and application security threats and vulnerabilities.
- Knowledge of Personally Identifiable Information (PII), Payment Card Industry (PCI), and Personal Health Information (PHI) data security standards.
- Experience with security control assessments within the VA using the NIST Risk Management Framework (RMF) is a plus.
- Certifications such as SCA and CISA are a plus.
- Exceptional written and verbal communication skills.
- Strong planning, organizational, and time management skills.
- Exceptional analytical and conceptual thinking skills.
- Ability to work collaboratively with a team of peers.
Benefits
- Traditional and HSA-eligible medical insurance plans.
- 100% employer-paid dental and vision insurance options.
- 100% employer-sponsored STD, LTD, and life insurance.
- 5% 401(k) company matching.
- Flexible schedules and teleworking options.
- Paid holidays and PTO Accrual Plans.
- Paid Parental Leave.
- Professional development and career growth opportunities.
- Team and company-wide events, recognition, and appreciation.
Related Guides
Related Categories
Related Job Pages
More Security Analyst Jobs
RIT Co-op: Information Security - Governance, Risk, & Compliance
Rochester Regional HealthFor All You Are, We're Here for It.
The participant will gain exposure and experience in the healthcare field, covering governance, risk, and compliance areas within Information Security. Responsibilities include providing work experience directly related to the student's course of study through active engagement and meaningful activities.
The analyst will support cybersecurity compliance activities across NCATS systems, assisting with the implementation and documentation of NIST SP 800-53 security and privacy controls and maintaining compliance documentation for system authorization packages. Duties also include providing guidance to personnel, supporting security control mapping, and assisting with various RMF artifacts like SSPs and POA&Ms.
As a member of the Information Security team, the Cybersecurity Analyst intern is responsible for supporting SecOps efforts to protect the company from intrusions, malware, threat actors, and other forms of cyber attacks. The cybersecurity analyst intern will also be involved in ...
Cyber Information Assurance Specialist
JobgetherWe use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best! Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time. #LI-CL1 We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
This role is a critical part of a team supporting naval surface fleet maintenance, modernization, and sustainment initiatives. You will help ensure the security, compliance, and operational integrity of information systems while collaborating with a geographically dispersed team ...


