Demo

SECURITY CONTROL ASSESSOR (SCA)

Navy Exchange Service Command
Virginia, VA Full Time
POSTED ON 3/22/2025 CLOSED ON 4/9/2025

What are the responsibilities and job description for the SECURITY CONTROL ASSESSOR (SCA) position at Navy Exchange Service Command?

Job Details

The Security Control Assessor SCA oversees NEXCOM NAF IT cybersecurity risk assessment process which determines aggregate cybersecurity risk in support of an Authorization.

Duties and Responsibilities:


Responsibilities include:

Provides NEXCOM cybersecurity support, by performing full package analysis of all IT systems, as defined by the Navy Risk Management Framework (RMF) guide.

Assists in the development of risk assessment requirements and participates in the execution of RMF assessment processes for authorization of systems to the Navy Exchange enterprise network to include ensuring that system hardware and software adheres to security standards that minimize risk to the Navy Exchange enterprise from cyber security threats based on the POA&M and other supporting documentation.

Participates in the development and maintenance of Navy Exchange cyber defense architectures, processes, standards, specifications, cyber threat profiles and enterprise risk assessments.

Independently and impartially assess and quantify aggregate cybersecurity risk using metrics consistent with DON guidance for both inherent system residual risks and system accessibility related risks in support of the Risk Management Program (RMP).

Produce the risk determination using the security assessment plan (SAP) and make a recommendation regarding system authorization.

Provides review and analysis of FedRAMP, PCI, and other third party package authorizations for reciprocity and use within the NEXCOM organization.

Provide initial concurrence on the SAP, ensuring all appropriate security controls will be assessed for compliance.

Support NEXCOM's NAF IT continuous monitoring requirements. Determines and documents compliance with the assigned security controls.

Actively work with the Cybersecurity Compliance Assessor and Validator, and program management office to provide support and guidance throughout the RMF cybersecurity assessment and lifecycle.

Represent the system during DoD and DON Cybersecurity inspections, while responding to information requests and addressing identified findings.

Provides RMF/RMP Subject Matter Expert (SME) guidance. Provide guidance on the following:
o Understanding of the RMF/RMP risk assessment process
o Knowledge of implementation and applicability of security controls
o Use of appropriate test procedures and tools and mitigation measures
o Understanding of policies and their effects on the risk of a system.
o Review and assessment of individual vulnerabilities in the POA&M

Keeps supervisors up to date on all assignments.

Performs other related duties as assigned.

SECNAV M 5239.2, DoN, Information Assurance (IA) Workforce Manual requires incumbents of this position to possess and maintain current, two types of certifications as follows:

IA Certification: Certified Information Security Manager (CISM), Certified Information Systems Security Professional (CISSP), CompTIA Advanced Security Practitioner (CASP ), GIAC Security Leadership Certification (GSLC)

Technical Certification: Operating System/Computing Environment (OS/CE) certificate of training as dictated by Supervisor and approved by Command Cyber IT/CSWF PM.

Candidate is also required to sign a Privileged Access Agreement.

Candidates without the required certification may be placed into this job but must obtain the required certification within 6 months of appointment; failure to obtain this requirement will result in termination of employment.

A total of 8 years of experience, consisting of the following:


GENERAL EXPERIENCE: 3 years' experience in security, technical or investigative work which demonstrated the ability and aptitudes required to perform technical, managerial or analytical work involving management information systems.

OR

SUBSTITUTION OF EXPERIENCE FOR EDUCATION: One year of related academic study above the high school level may be substituted for 9 months of experience up to a maximum of a 4 year bachelor's degree in IT security or computer information systems for 3 years of general experience.

AND

SPECIALIZED EXPERIENCE: 5 years of demonstrated experience in at least two of the following:
Risk management validation
IT security compliance and reporting;
Technical risk analysis;
Authorization and accreditation

And experience in the performance of:
System Security Assurance: ensuring that entire systems meet security requirements, function securely, and undergo comprehensive testing for overall security assurance.
Security Assessments: conducting security assessments and developing Security Assessment Plans (SAPs).
Technical Understanding: interpreting network diagrams, vulnerability scans, and compliance scans.
Security Documentation: creating and maintaining various security documents, including Security Assessment Plans.
Risk Management Framework: conducting security control assessments following a Risk Management Framework approach, along with conducting risk assessments and developing security assessment reports.

And in depth knowledge of:
NIST 800 53, risk mitigation strategies for computer operating systems, networks, or cloud services, and security controls and compliance frameworks.

This position is designated in accordance with SECNAV M 5510.30 and will require a favorable Single Scope Background Investigation (SSBI). Candidates must be eligible for and obtain a Top Secret Clearance, within 6 months of appointment. Failure to obtain will result in termination.
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
Inventory Control Specialist with Security Clearance
T2C-Global -
Virginia, VA
CMMC Assessor
Jobot -
Virginia, VA
Installation Technician II - Security/ Access Control
Unlimited Technology, Inc. -
Virginia, VA

If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a SECURITY CONTROL ASSESSOR (SCA)?

Sign up to receive alerts about other jobs on the SECURITY CONTROL ASSESSOR (SCA) career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$139,945 - $168,577
Income Estimation: 
$164,835 - $201,088
Income Estimation: 
$135,994 - $168,063
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$111,725 - $147,313
Income Estimation: 
$139,945 - $168,577
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$152,549 - $188,894
Income Estimation: 
$194,072 - $240,547
Income Estimation: 
$135,994 - $168,063
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$77,991 - $108,747
Income Estimation: 
$111,725 - $147,313
Income Estimation: 
$112,673 - $137,290
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$123,246 - $161,441
Income Estimation: 
$152,549 - $188,894
Income Estimation: 
$135,994 - $168,063
Income Estimation: 
$161,209 - $233,553

Sign up to receive alerts about other jobs with skills like those required for the SECURITY CONTROL ASSESSOR (SCA).

Click the checkbox next to the jobs that you are interested in.

  • SAP Asap Methodology Skill

    • Income Estimation: $152,066 - $200,383
    • Income Estimation: $160,866 - $213,122
  • Business Analytics Skill

    • Income Estimation: $105,524 - $145,118
    • Income Estimation: $107,442 - $160,602
This job has expired.
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at Navy Exchange Service Command

Navy Exchange Service Command
Hired Organization Address Gulfport, MS Full Time
ASSET PROTECTION / SAFETY INVEST Job Number : 2400040Q Primary Location United States-Mississippi-Gulfport Organization ...
Navy Exchange Service Command
Hired Organization Address Annapolis, MD Full Time
Job Summary Regularly performs the full range and scope of housekeeping services at a Navy Gateway Inn and Suites and or...
Navy Exchange Service Command
Hired Organization Address Virginia, VA Full Time
Job Summary Responsible for executing a range of clerical tasks, including processing equipment requests, purchase order...
Navy Exchange Service Command
Hired Organization Address Groton, CT Full Time
Job Summary Serves as first point of contact with guests at a Navy Gateway Inn and Suites and or Navy Lodge property and...

Not the job you're looking for? Here are some other SECURITY CONTROL ASSESSOR (SCA) jobs in the Virginia, VA area that may be a better fit.

Installation Technician II - Security/ Access Control

Integrated Security Technologies, Inc., Virginia, VA

TRAFFIC CONTROL SECURITY GUARD (FT & PT)

Good Guard Security, Ocean, MD

AI Assistant is available now!

Feel free to start your new journey!