ECS is seeking a Security Controls Assessor to work in our Washington, DC (hybrid) office. Please Note: This position is contingent upon contract award.
Â
ECS seeks a Security Controls Assessor to support a full range of cybersecurity services on a long-term, full-time contract with a U.S. Government civilian agency. This position requires mostly CONUS and occasional OCONUS assessments and is available immediately for a qualified candidate with an active security clearance.
Â
Key Responsibilities
- Review and update information security policies, standards, and procedures in accordance with federal and departmental regulations
- Perform independent security and privacy control assessments on behalf of the client CSO in support of Security Assessment & Authorization (SA&A)
- Assess existing and new FISMA systems and subsystems, and communicate findings and potential impacts of identified control weaknesses
- Review and analyze A&A packages—including System Security Plans (SSP), Risk Assessments, Information System Contingency Plans (ISCP), Backup SOPs, Incident Response Plans (IRP), Configuration Management Plans (CMP), hardware/software inventories, network diagrams, data flows, system change requests, vulnerability scan reports, test reports, and POA&Ms—for completeness, accuracy, and effective control implementation
- Develop and maintain test cases for control-level security testing across system components (applications, servers, databases, operating systems, network devices, end-user devices, etc.)
- Develop and execute security and privacy assessment plans in accordance with NIST SP 800-53A, supporting RMF Steps 4–6
- Document findings and recommendations that are clear, system-specific, and actionable
- Analyze security tool outputs to distinguish residual risk from false positives prior to finalizing findings
- CONUS and OCONUS travel to conduct system assessments
- Other duties as assigned
Salary Range: $150,000-$168,000
General Description of Benefits
- Active Secret clearance required with eligibility to get Top Secret clearance
- Bachelor's degree in Computer Science, MIS/IT, Engineering, Information Security/Assurance, or a related field
- Minimum five (5) years of information security experience
- Minimum three (3) years of experience supporting security assessment teams, including planning assessments and serving as a senior team member
- Two (2) years of experience using GRC tools
- Demonstrated experience conducting full-scope technical security control testing across component types, including development of security and privacy assessment plans
- Working knowledge of RMF Steps 1-6
- Strong understanding of NIST SP 800-53 controls, the NIST Cybersecurity Framework, and applicable information security/privacy laws and regulations
- Ability to analyze information system configurations and technical specifications against NIST SP 800-53 and related overlays
- Experience developing risk-based documentation
- Excellent written and verbal communication skills, with the ability to present control requirements and deficiencies clearly to both technical and non-technical audiences
Learn more about this Employer on their Career Site
