Government Careers
  • Security Control Assessor - Placement

  • Apex Systems
  • Alexandria, Virginia 22350 United States View Map
Security Control Assessor

We are seeking a skilled and detail-oriented Security Control Assessor. The successful candidate will be responsible for evaluating, testing, and validating the effectiveness of security controls within information systems and networks, with a strong emphasis on applying the Risk Management Framework (RMF). This role requires a strong background in RMF execution, documentation for Assessment and Authorization (A&A), vulnerability analysis, and remediation validation.

Key Responsibilities

  • Provide tailored documentation to support security authorizations.
  • Serve as an independent assessor for Risk Management Framework Steps 0 to 7.
  • Plan and execute security control assessments for various information systems.
  • Develop and maintain assessment procedures and methodologies aligned with NIST guidelines.
  • Analyze and evaluate the effectiveness of implemented security controls, identify vulnerabilities, and prepare detailed Security Assessment Reports (SARs).
  • Perform vulnerability scanning and compliance operations, including analysis of scans and STIG implementations.
  • Create and manage artifacts such as System Security Plans (SSPs) and Plans of Action and Milestones (POA&Ms).
  • Collaborate with system owners and Information System Security Officers (ISSOs) throughout the assessment and authorization process.
  • Assess and validate security controls in cloud-based technology environments.

Required Qualifications

Experience: 5+ years of relevant experience in a Security Control Assessor role.

Education & Certifications:

  • Bachelor's degree or equivalent years of relevant experience.
  • A current DoD 8570 IAT II certification is required (e.g., CCNA Security, CySA+, GICSP, GSEC, Security+ CE, CND, or SSCP).

Technical Skills & Knowledge:

  • Hands-on experience with eMASS or similar Information Assurance tools.
  • Proficient understanding of all steps of the RMF process and NIST implementation guidance.
  • Experience with vulnerability analysis, STIG implementation, access controls, and remediation validation.
  • Knowledge of relevant security standards such as NIST SP 800-series (e.g., 800-53, 800-53A, 800-137) and others.
  • Demonstrated documentation and communication skills for interacting with stakeholders and creating authorization artifacts.
  • Experience assessing and validating controls within any cloud-based technology.

Preferred Qualifications:

  • A well-developed understanding of the Systems Development Lifecycle (SDLC).
  • Relevant Cybersecurity and Information Assurance experience with specific hands-on involvement in writing and submitting complete documentation packages for new system authorizations.
Security Control Assessor

We are seeking a skilled and detail-oriented Security Control Assessor. The successful candidate will be responsible for evaluating, testing, and validating the effectiveness of security controls within information systems and networks, with a strong emphasis on applying the Risk Management Framework (RMF). This role requires a strong background in RMF execution, documentation for Assessment and Authorization (A&A), vulnerability analysis, and remediation validation.

Key Responsibilities

  • Provide tailored documentation to support security authorizations.
  • Serve as an independent assessor for Risk Management Framework Steps 0 to 7.
  • Plan and execute security control assessments for various information systems.
  • Develop and maintain assessment procedures and methodologies aligned with NIST guidelines.
  • Analyze and evaluate the effectiveness of implemented security controls, identify vulnerabilities, and prepare detailed Security Assessment Reports (SARs).
  • Perform vulnerability scanning and compliance operations, including analysis of scans and STIG implementations.
  • Create and manage artifacts such as System Security Plans (SSPs) and Plans of Action and Milestones (POA&Ms).
  • Collaborate with system owners and Information System Security Officers (ISSOs) throughout the assessment and authorization process.
  • Assess and validate security controls in cloud-based technology environments.

Required Qualifications

Experience: 5+ years of relevant experience in a Security Control Assessor role.

Education & Certifications:

  • Bachelor's degree or equivalent years of relevant experience.
  • A current DoD 8570 IAT II certification is required (e.g., CCNA Security, CySA+, GICSP, GSEC, Security+ CE, CND, or SSCP).

Technical Skills & Knowledge:

  • Hands-on experience with eMASS or similar Information Assurance tools.
  • Proficient understanding of all steps of the RMF process and NIST implementation guidance.
  • Experience with vulnerability analysis, STIG implementation, access controls, and remediation validation.
  • Knowledge of relevant security standards such as NIST SP 800-series (e.g., 800-53, 800-53A, 800-137) and others.
  • Demonstrated documentation and communication skills for interacting with stakeholders and creating authorization artifacts.
  • Experience assessing and validating controls within any cloud-based technology.

Preferred Qualifications:

  • A well-developed understanding of the Systems Development Lifecycle (SDLC).
  • Relevant Cybersecurity and Information Assurance experience with specific hands-on involvement in writing and submitting complete documentation packages for new system authorizations.
Government Careers

Government Careers

Government jobs offer stability, competitive benefits, and the chance to make a meaningful impact on your community and country.

Whether you’re starting your career or seeking new opportunities, these roles provide pathways for growth, security, and service.

Explore positions across a wide range of fields and take the first step toward a rewarding future in public service.

Show more

MORE JOBS