Demo

Security Control Assessor

ECS Federal, LLC
Fairfax, VA Full Time
POSTED ON 3/1/2025
AVAILABLE BEFORE 4/25/2025

ECS is seeking a Project Manager to work remotely.

  • Review and update existing information security policy, standards, and procedures based on federal and departmental regulations.
  • Perform independent security and privacy control assessments on behalf of the client CSO in support of Security Assessment & Authorization (SA&A).
  • Conduct assessments of existing and new FISMA systems, including subsystems in the respective system boundary, and communicate the results and potential implications of identified control weaknesses.
  • Reviews and analyze, Assessment & Authorization (A&A) packages to include System Security Plans (SSP), Risk Assessments, Information System Contingency Plans (ISCP), Back-up Standard Operating Procedures (SOP), Incident Response Plans (IRP), Configuration Management Plans, (CMP), Hardware/Software lists, Network Diagrams, Data Flows, System Change Requests/Proposals, Vulnerability scan reports, test reports, and Plan of Actions & Milestones (POA&Ms) for completeness, accuracy, and document effectiveness of controls, plans and procedures implementation.
  • Create and maintain test cases for security assessment testing and perform security testing at the control-requirement level for each unique component of each system (e.g., application, web application server, financial systems, database server/instance, operating systems, specialized appliances, network and infrastructure devices, and end-user devices (e.g., mobile phones, laptops, etc.).
  • Develop and execute a security and privacy assessment plan in accordance with NIST SP 800-53A, as amended, requirements, for each security assessment project. SA&A activities shall include support for RMF steps 4-6
  • Document and provide findings and recommendations that are concise, system-specific, and actionable.
  • Analyze security tool reports and determine residual risk or false positives from technical reports and artifacts before assigning findings.

Salary Range: $90,000 - $110,000

General Description of Benefits

Requirements:
  • Strong written and verbal communication skills.
  • Strong communication ability across all levels of management.
  • Experience in planning assessments and a collaborative member with a team of security control assessors
  • Three (3) years' experience supporting security assessment teams is required.
  • Experience in presenting control requirements and deficiencies to both technical and non-technical audiences.
  • Experience performing detailed, full-scope technical security control testing for each of the component types, including development of security and privacy assessment plans is required.
  • Ability to analyze information system configurations and technical specifications against NIST SP 800-53 and other overlays
  • Possesses a strong understanding of the NIST Special Publication 800-53 security and privacy controls, the NIST Cybersecurity Framework and other information security and privacy laws and regulations.
  • Experience with development and writing of risk-based documentation.
Certifications/Licenses:
  • Bachelor's degree or higher in Computer Science's, MIS/IT, Engineering, Information Security/IA, or related discipline to work requirement.
  • Five (5) or more years of Information Security experience required.
  • Two (2) years of experience with the use of eGRC tools.
  • One of the following certifications preferred: Certified Information Systems Security Professional (CISSP), Certified Ethical Hacker (CEH), Certified Risk and Information Systems Control (CRISC), or Certified Information Security Auditor (CISA).


Req Benefits:
https://ecstech.com/careers/benefits/">https://ecstech.com/careers/benefits/

Salary : $90,000 - $110,000

If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Security Control Assessor?

Sign up to receive alerts about other jobs on the Security Control Assessor career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$91,971 - $119,923
Income Estimation: 
$114,980 - $148,259
Income Estimation: 
$87,093 - $107,335
Income Estimation: 
$111,725 - $147,313
Income Estimation: 
$112,673 - $137,290
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$112,673 - $137,290
Income Estimation: 
$139,945 - $168,577
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$152,549 - $188,894
Income Estimation: 
$194,072 - $240,547
Income Estimation: 
$135,994 - $168,063
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$70,462 - $84,818
Income Estimation: 
$77,991 - $108,747
Income Estimation: 
$87,093 - $107,335
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at ECS Federal, LLC

ECS Federal, LLC
Hired Organization Address Memphis, TN Full Time
ECS is seeking a Qlik Sense Developer to work in our Memphis, TN office. Hands on experience in Qlik Sense development, ...
ECS Federal, LLC
Hired Organization Address Fairfax, VA Full Time
ECS is seeking an ARPA-H Travel Specialist to work in our remote office. Please Note: This position is contingent upon [...
ECS Federal, LLC
Hired Organization Address Vandenberg AFB, CA Full Time
ECS is seeking a GitOps Manager to work in our Vandenberg Space Force Base, CA office. Please Note: This position is con...
ECS Federal, LLC
Hired Organization Address Albuquerque, NM Full Time
ECS is seeking a Service Desk Technician to work in our Albuquerque, NM office. The Service Desk Technician role plays a...

Not the job you're looking for? Here are some other Security Control Assessor jobs in the Fairfax, VA area that may be a better fit.

Security Control Assessor

Govcio LLC, Washington, DC

Security Control Assessor

LightFeather, Washington, DC

AI Assistant is available now!

Feel free to start your new journey!