SonicJobs Logo
Left arrow iconBack to search

Security Controls Assessor

ECS Tech Inc
Posted 7 hours ago, valid for 20 days
Location

Washington, DC, US

Salary

$150,000 - $168,000 per year

Contract type

Full Time

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.

ECS is seeking a Security Controls Assessor to work in our Washington, DC (hybrid) office.  Please Note: This position is contingent upon contract award.

 

ECS seeks a Security Controls Assessor to support a full range of cybersecurity services on a long-term, full-time contract with a U.S. Government civilian agency. This position requires mostly CONUS and occasional OCONUS assessments and is available immediately for a qualified candidate with an active security clearance.

 

Key Responsibilities

  • Review and update information security policies, standards, and procedures in accordance with federal and departmental regulations
  • Perform independent security and privacy control assessments on behalf of the client CSO in support of Security Assessment & Authorization (SA&A)
  • Assess existing and new FISMA systems and subsystems, and communicate findings and potential impacts of identified control weaknesses
  • Review and analyze A&A packages—including System Security Plans (SSP), Risk Assessments, Information System Contingency Plans (ISCP), Backup SOPs, Incident Response Plans (IRP), Configuration Management Plans (CMP), hardware/software inventories, network diagrams, data flows, system change requests, vulnerability scan reports, test reports, and POA&Ms—for completeness, accuracy, and effective control implementation
  • Develop and maintain test cases for control-level security testing across system components (applications, servers, databases, operating systems, network devices, end-user devices, etc.)
  • Develop and execute security and privacy assessment plans in accordance with NIST SP 800-53A, supporting RMF Steps 4–6
  • Document findings and recommendations that are clear, system-specific, and actionable
  • Analyze security tool outputs to distinguish residual risk from false positives prior to finalizing findings
  • CONUS and OCONUS travel to conduct system assessments
  • Other duties as assigned

Salary Range: $150,000-$168,000

General Description of Benefits

Qualifications
  • Active Secret clearance required with eligibility to get Top Secret clearance
  • Bachelor's degree in Computer Science, MIS/IT, Engineering, Information Security/Assurance, or a related field
  • Minimum five (5) years of information security experience
  • Minimum three (3) years of experience supporting security assessment teams, including planning assessments and serving as a senior team member
  • Two (2) years of experience using GRC tools
  • Demonstrated experience conducting full-scope technical security control testing across component types, including development of security and privacy assessment plans
  • Working knowledge of RMF Steps 1-6
  • Strong understanding of NIST SP 800-53 controls, the NIST Cybersecurity Framework, and applicable information security/privacy laws and regulations
  • Ability to analyze information system configurations and technical specifications against NIST SP 800-53 and related overlays
  • Experience developing risk-based documentation
  • Excellent written and verbal communication skills, with the ability to present control requirements and deficiencies clearly to both technical and non-technical audiences



Learn more about this Employer on their Career Site

Apply now in a few quick clicks

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.