Security Control Assessor Job at MKS2 Technologies, Springfield, VA

bmx2aFhSSE5XcGFrMkpYYTJ1T2JFZUdT
  • MKS2 Technologies
  • Springfield, VA

Job Description

Security Control Assessor

Overview

We are a rapidly growing, energetic, and win-focused enterprise supporting the Federal government, military, and civilian agencies. We are an organization committed to growth and shared success for all stakeholders; we are customer-driven, mission-focused, and operate with integrity and trust in all relationships.

We have a great opportunity for a Security Control Assessor in Springfield, VA. The position is required to be onsite and requires the ability to travel.

Responsibilities

The Security Control Assessor (SCA) will conduct and document a comprehensive assessment of the management, operational, and technical security controls employed within or inherited by an information system. Determine the overall control effectiveness through documentation review, inspections, testing, and interviews. Provide an assessment of the severity of weakness or deficiencies and recommend corrective actions to address identified vulnerabilities.

Provide initial mitigation of Cybersecurity incidents, support incident investigations, and closure of the incidents. Provide assessment of proposed technology (hardware, software, and firmware) for Cybersecurity vulnerabilities.

Assessment of security controls and organizational requirements shall include:

  • Assessment Package Feedback which focuses on the documentation submitted to support the various steps of Risk Management Framework (RMF). Recommend a format for this document for government approval.
  • Security Assessment Report which focuses on the assessment of an information system in support of the authorization determination. Shall provide a draft report using the government provided template; may recommend format changes for government consideration.
  • Periodic Cybersecurity Assessment Report or Security Compliance Report which focuses on the assessment of a Cybersecurity program at a location. Shall provide a draft report using the government provided template; may recommend format changes for government consideration.
  • Cybersecurity Incident Reports which focus on documenting Cybersecurity incidents. Shall provide a draft report using the government provided template; may recommend format changes for government consideration.
  • Technical Assessment of Hardware, Software, or Firmware. Shall document the technical assessment addressing Cybersecurity vulnerabilities via a government agreed format, such as a Help Desk ticket application, electronic mail, memorandum, etc.
  • Shall develop an annual compilation of findings and observations based upon the Security Assessment Reports and Periodic Cybersecurity Assessment Reports or Security Compliance Reports based upon fiscal year assessments. The format shall be recommended for government approval. The compilation shall be void of system names, system identification numbers, government or contractor locations, and individual names.
  • Draft and/or preliminary documents shall be presented in one of the following electronic formats: Microsoft Office version 2007 compatible (.docx, .xlsx, or .pptx) or the standard Portable Document Format (PDF) format. Final and/or approved format shall be determined by the government; may recommend additional formats.
  • Incumbent travel requirements are approximately 30% annually to support critical business needs.

Qualifications

  • Shall have 4 or more years of experience in the validation of security configuration of operating systems.
  • Shall have 2 or more years of experience applying Risk Management Framework (RMF) as described in the National Institute of Standards and Technology Special Publications.
  • Shall meet the Cyber IT/Cybersecurity Workforce (CSWF) Security Control Assessor (612); Intermediate Level for SECNAV M-5239.2 compliance. (See Navy Cool Website)

Travel Requirements:

Travel approximately 30% annually.

Education:

  • Bachelor’s Degree in Information Technology, Cybersecurity, Computer Science, Information Systems, Data Science, or Software Engineering from an ABET accredited or NCAE designated institution, OR

Certification:

  • Certified in Governance Risk and Compliance (CGRC); or
  • CompTIA Security+ ce; or
  • CompTIA Cloud +; or
  • CompTIA PenTest +; or
  • CompTIA SecurityX (formerly CASP+)

Desired Qualifications:

  • Strongly desired experience with application of the Defense Information Systems Agency (DISA) Security Technical Implementation Guides.
  • Operating System/Computing Environment certificate for Windows Server 2012 or newer UNIX (Linux (Red Hat), Solaris).
  • Experience with vulnerability scanners.
  • Experience with Cloud technologies.
  • Documented (certificate) RMF training provided by the Intelligence Community or DoD SAP community.
  • Experience with assessing security relevant applications.
  • Experience as a System Administrator, Information System Security Manager, or Information System Security Officer.
  • Experience applying the requirements of the DoD Joint Special Access Program Implementation Guide (JSIG) to information systems or Cybersecurity programs.
  • A cyber credential at the Master proficiency level for specialty area Securely Provision - Risk Management as outlined in SECNAV M-5239.2.
  • Experience with Cross Domain Solutions (CDS).

This position will require U.S. citizenship and an active DoD Top Secret clearance. Candidate must be willing to obtain and pass a Counterintelligence (CI) Polygraph.

Job Tags

Work at office,

Similar Jobs

TBG | The Bachrach Group

Cash Posting- Physician Billing Job at TBG | The Bachrach Group

Title: Cash Posting / Physician Billing Location: Melville, NY Department: Revenue Cycle Salary: $26-28/hour Job Summary Responsible for accurately posting and reconciling payments for physician billing accounts. Ensures payments from insurance carriers...

Froedtert Health

Primary Care Physician Job at Froedtert Health

 ...includes 10 hospitals, nearly 2,000 physicians and over 45 health centers...  ...to provide excellent patient care. Explore Froedtert Health and...  ...recruiting a part time Primary Care (Fam Med or Med/Peds) Physician...  ...in Primary Care, Family Medicine, or Med/Peds Will consider... 

Lutheran Sunset Ministries

Scheduler - Every Other Weekend Job at Lutheran Sunset Ministries

 ...Ministries in Clifton, TX is hiring for a Scheduler for every other weekend (part-time). Responsibilities & Essential Job Functions ~...  ...~ Must possess leadership ability and the willingness to work harmoniously with other personnel ~ Communicatewith the medical... 

Walsh Employment

Senior Graphic Designer Job at Walsh Employment

 ...Senior Graphic Designer Location: Highland Park, IL Salary: $80-85K plus excellent benefits package Our client is seeking a highly creative and proactive Senior Graphic Designer to join their dynamic in-house creative team. This is an excellent opportunity... 

Guthrie

Unit Clerk/Care Partner - Nursing Unit ICU/CCU - Full Time Job at Guthrie

 ...clerical duties, communication and reception duties on assigned nursing units. In addition, employee works with other members of the...  ...Education, License & Cert: High School Grad or Equivalent Experience: No experience required. Essential Functions:...