Job Title: Security Control Assessor (2 openings)
Location: McLean, VA AND Bethesda, MD
Clearance: TS/SCI w/ CI Poly
Key Responsibilities:
- Security Controls Assessment: Identify and mitigate system and user-level attack vulnerabilities.
- Frameworks & Standards: Apply RMF, CNSSI 1253, NIST SP 800-53, NISPOM, STIGs, and SCAP.
- Security Testing: Conduct hands-on security testing, analyze results, document risks, and recommend countermeasures.
- Risk Assessment: Develop reports based on security plans and stakeholder interviews, ensuring compliance with information assurance policies.
- Threat Analysis: Provide analysis and recommendations based on identified security vulnerabilities.
- Security Evaluation: Develop and document test plans and procedures, focusing on cloud-based systems and applications.
- Operational Technology Security: Secure OT systems (SCADA, DCS, PLCs, PACSs) per NIST SP 800-82 guidelines, including risk-based assessments and mitigation strategies.
Skills & Experience:
- Bachelor's Degree and applicable information security/cybersecurity experience (Experience may be substituted for a Degree).
- Experience with RMF, ICD 503, CNSSI 1253, NIST SP 800-53, or a similar framework.
- Experience performing vulnerability scans and/or security control assessments in AWS, IBM, Google, Azure, or Oracle Cloud environment.