Jobs
>
Reston

    Security Control Assessor - Reston, United States - CACI International Inc.

    Default job background
    Technology / Internet
    Description
    Security Control Assessor (SCA)


    Job Category:
    Information Technology


    Time Type:
    Full time


    Minimum Clearance Required to Start:
    TS/SCI with Polygraph


    Employee Type:
    Regular


    Percentage of Travel Required:
    None


    Type of Travel:
    None

    *

    CACI is seeking a Security Control Assessor (SCA) to join our team of talented Cybersecurity professionals in Reston, VA.

    You will evaluate Government customer systems and other security standards and publications as well as Government customer defined security guidelines and regulations.

    You will also determine the extent to which the assigned security controls are implemented correctly; operating as intended; and producing the desired outcome with respect to meeting the regulatory and or statutory security requirements for National Security Systems.

    Invent your future and make a lasting impact at CACI

    Duties include but are not limited to:

    • Evaluate Government customer systems against NIST SP 800 53/53A R4, 30, 37 and 39, RMF and other security standards and publications as well as Government customer defined security guidelines and regulations utilizing the customer assessment tracking system.
    • Conduct a comprehensive assessment of the management, operational, and technical security controls employed within or inherited by complex and diverse information systems to determine the overall effectiveness of the control implementation.
    • Function as an independent and unbiased advocate who provides evidence to validate the trustworthiness of the system for the designated Authorizing Official (AO).
    • Conduct hands-on security control testing, analyze Body of Evidence (BoE) documentation and test results, document risk and recommend countermeasures.
    • Provide an assessment of the severity of weakness or deficiencies discovered in the information system and its environment of operation and recommend corrective actions to address identified vulnerabilities.
    • Conduct hands-on security testing leveraging commercial tools and custom developed scripts and procedures.
    • Execute vulnerability/compliance assessment tools and evaluate results for systems undergoing security assessment.
    • Participate in joint test teams with other customer organizations and or Government Agencies to complete security assessment and adjudication.
    • Coordinate with other program elements conducting security testing.
    • Actively participate in or lead technical exchange meetings and application review boards, documenting actions items/results of these events.
    • Brief management, as needed, on the status of action items and/or results of activities.
    • Prepare security assessment reports containing the results and findings form the assigned security control assessments.
    • Provide documentation to the customer which describes all identified system risks, planned test procedures taken and test results.
    • Provide enhancement capabilities and SOPs to assessment operations for execution and implementation.
    • Responsible for implementing and applying technologies, processes, and practices designed to protect networks, devices, programs, and data from malicious attack, damage, or unauthorized access.
    • Investigates network device and information security incidents to determine extent of compromise to national security information and automated information systems.

    Required Certifications:

    • TS/SCI with Polygraph (active / in-scope)
    • Bachelor's Degree
    • 4+ years of relative experience. Additional experience may be considered in lieu of a degree
    • Familiarity with conducting security assessment in support of accreditation and or authorization (A&A) decisions.
    • Familiarity with National Institute of Standards and Technology (NIST) Cybersecurity Framework and National Institute of Standards and Technology (NIST) Risk Management Framework (RMF) requirements.
    • Familiarity with National Institute of Standards and Technology (NIST) Special Publication (SP and or 800-53A Revision 4 as well as 800-30, 37 and 39.
    • Familiarity with the Committee on National Security Systems (CNSS) Instruction No. 1253.
    • Knowledge of Federal laws, regulations, policies, and ethics as they relate to cybersecurity.
    • Knowledge of cyber defense and vulnerability assessment tools, including open source tools, and their capabilities.
    • Knowledge of cybersecurity principles and organizational requirements (relevant to confidentiality, integrity, availability, authentication, non-repudiation).
    • Knowledge of cybersecurity principles used to manage risks related to the use, processing, storage, and transmission of information or data.

    Desired Qualifications:

    • CompTIA Security+
    • GIAC Security Essentials (GSEC)
    • Certified Information Systems Security Professional (CISSP)
    • Knowledge of cyber threats and known vulnerabilities from alerts, advisories, errata, and bulletins.
    • Knowledge of computer networking concepts and protocols, and network security methodologies.
    • Knowledge of network security architecture concepts including topology, protocols, components, and principles (e.g., application of defense-in-depth).
    • Knowledge of system and application security threats and vulnerabilities (e.g., buffer overflow, mobile code, cross-site scripting, Procedural Language/Structured Query Language [PL/SQL] and injections, race conditions, covert channel, replay, return-oriented attacks, malicious code).
    • Skill in discerning the protection needs (i.e., security controls) of information systems and other computing environments.

    What we can offer you:


    At CACI, our philosophy of employee development and advancement rests on a cultural foundation of providing unlimited and equal opportunity for growth, recognition, and rewards.

    We provide the environment, support and responsive, available management to nurture and stretch your abilities.

    We also offer a career mobility program to make it easy to build a dynamic career at CACI and offer flexible work schedule arrangements to support work/life balance.


    • CACI has been named one of Fortune magazine's World's Most Admired Companies for 2022
    • CACI also has more than 20 Communities of Practice to share and gain skills and knowledge regarding various technologies and topics including SAP, Salesforce, Agile Development, and many more. The associated Learning Academies provide training and certifications to gain additional skills and build your brand.
    • We offer competitive benefits and learning and development opportunities
    • We are mission-oriented and ever vigilant in aligning our solutions with the nation's highest priorities
    • With over 25,000 employees worldwide, CACI has been named a Best Place to Work by the Washington Post
    • For over 55 years, the principles of CACI's unique, character-based culture have been the driving force behind our success

    Company Overview:
    CACI is an Equal Opportunity/Affirmative Action Employer.

    All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, status as a protected veteran, or any other protected characteristic.


    Pay Range:

    There are a host of factors that can influence final salary including, but not limited to, geographic location, Federal Government contract labor categories and contract wage rates, relevant prior work experience, specific skills and competencies, education, and certifications.

    Our employees value the flexibility at CACI that allows them to balance quality work and their personal lives. We offer competitive compensation, benefits and learning and development opportunities. Our broad and competitive mix of benefits options is designed to support and protect employees and their families.

    At CACI, you will receive comprehensive benefits such as; healthcare, wellness, financial, retirement, family support, continuing education, and time off benefits.

    Learn more here

    The proposed salary range for this position is:
    $109,800 - $241,600


  • Zachary Piper Solutions Reston, United States

    Zachary Piper Solutions is seeking FedRAMP Security Controls Assessor for a long-term, remote opportunity headquartered in Reston, Virginia. The Sr. FedRAMP Assessor will facilitate and support Security Controls Assessments and high-level Continuous Monitoring Activities in c ...


  • Parsons Chantilly, United States

    In a world of possibilities, pursue one with endless opportunities. Imagine Next · When it comes to what you want in your career, if you can imagine it, you can do it at Parsons. Imagine a career working with intelligent, diverse people sharing a common quest. Imagine a workplace ...


  • Syneren Technologies Corporation Vienna, United States

    **Job Title**: Telecom Security Control Assessor (Remote/Hybrid) · Syneren is seeking an experienced Telecom Security Control Assessor. · **Responsibilities**: · - 10+ years of experience in Information Security. · - 5+ years of experience with security control assessment methodo ...


  • System High Corporation Arlington, United States

    **Position Overview** · The Security Control Assessor must fulfill a variety of cybersecurity functions, to include: System Administrator, Enterprise Oversight, certification and accreditation, SAP and SCI assessment and authorization (A&A), Platform Information Technology (PIT) ...


  • Modern Technology Solutions, Inc. Washington, United States

    Own Your Future. · Modern Technology Solutions, Inc. (MTSI) is seeking a **Security Control Assessor (SCA) II** to join our team. · **Why is MTSI known as a Great Place to Work?** · - ** Interesting Work**: Our co-workers support some of the most important and critical programs t ...


  • Zachary Piper Solutions Reston, United States

    Zachary Piper Solutions is seeking FedRAMP Security Controls Assessor for a long-term, remote opportunity headquartered in Reston, Virginia. The Sr. FedRAMP Assessor will facilitate and support Security Controls Assessments and high-level Continuous Monitoring Activities in c ...


  • GDH Reston, United States

    : This candidate will be performing security control assessments for existing system security plans, evaluation of new technologies meeting baseline security requirements. Experience in on-prem and cloud environments. This is a day shift position working Monday-Friday. Some weeke ...


  • Maximus Services, LLC Arlington, United States

    **Description & Requirements** · Maximus is searching for a Security Control Assessor (SCA) to join a DoD program in Arlington, VA. · The Security Control Assessor is responsible for conducting a comprehensive assessment of the management, operational, and technical security cont ...


  • General Dynamics Information Technology Bethesda, United States

    Type of Requisition: · Regular · Clearance Level Must Currently Possess: · Top Secret SCI + Polygraph · Clearance Level Must Be Able to Obtain: · Top Secret SCI + Polygraph · Suitability: · Public Trust/Other Required: · None · Job Family: · Cyber Security · Job Qualifications: · ...


  • Zermount Inc Arlington, United States

    **Security Control Assessor Team Lead**: · **MILITARY FRIENDLY & PREFERRED - HOH SPONSOR**: · **Summary** · Zermount Inc. is seeking a Security Control Assessor Team Lead who will play a vital role in leading multiple teams on large projects. The System Security Assessment Team L ...


  • Excel Technologies Herndon, United States

    Job Description · Job DescriptionSalary: · Security Control Assessor · This is a Remote, Work-From-Home Position · Full Job Description · The Security Control Assessor (SCA) will be part of a team responsible for providing independent assessments of security control complianc ...


  • Booz Allen Hamilton Herndon, United States

    Everyone is trying to harness the cloud, but not everyone knows how to secure it. As a Cloud Security Assessor, you know how to assess and implement requirements that ensure the safety of information systems and protect them against intentional or Security, Assessor, Control, Clo ...


  • Allen Integrated Solutions Chantilly, United States

    Job Description · Job DescriptionTop Secret SCI w/Polygraph Required · Security Control Assessor (SCA), Level 2 · Chantilly, VA · Security Control Assessor (SCA) Qualifications · A Security Control Assessor (SCA) is a security professional that provides information security Asses ...


  • ZP Group Reston, United States

    Zachary Piper Solutions is seeking FedRAMP Security Controls Assessor for a long-term, remote opportunity in Reston, Virginia. The Sr. FedRAMP Assessor will facilitate and support Security Controls Assessments and high-level Continuous Monitoring Activities in cloud-based environ ...


  • ZP Group Reston, United States

    Zachary Piper Solutions is seeking a Lead Security Controls Assessor for a remote opportunity based out of Reston, Virginia. The Lead Security Controls Assessor will lead, facilitate and support Security Controls Assessments and high-level Continuous Monitoring Activities in clou ...


  • Bering Straits Native Corporation (BSNC) Washington, United States

    Overview: · **SUMMARY** · Bering Global Solutions, LLC, a subsidiary of Bering Straits Native Corporation is currently seeking a qualified Security Control Assessor, Lead for a government client in Washington, DC. The selected individual will guide system owners, designated IT se ...


  • Guidehouse Reston, United States

    Job Family: · Cyber Consulting · Travel Required: · Up to 10% · Clearance Required: · Active Top Secret SCI (TS/SCI) · What You Will Do: · Guidehouse has an opportunity for a cleared Security Controls Assessor (SCA) Lead to leverage their understanding of IC/DOD Risk Management F ...


  • Goldbelt, Inc. Washington, United States

    Overview: · Goldbelt Hawk designs, develops, and implements comprehensive solutions for problem spaces, including computer security, scalable architectures, advanced analytics, artificial intelligence, and network/data center operations. Specializing in local and enterprise-level ...


  • General Dynamics Information Technology McLean, United States

    REQ#: RQ173502 Public Trust: None Requisition Type: Regular Your Impact Own your opportunity to serve as a critical component of our nation's safety and security. Make an impact by using your expertise to protect our country from threats. Job Description Seize your opportunity to ...


  • Leidos Suitland, United States

    **Description** · Leidos National Security Sector has a dynamic opportunity for a **Security Controls Assessor/Assessment and Authorization Specialist** to work at our customer site at the National Maritime Intelligence Center in Suitland, MD (all work is performed on site). · ** ...