Security Control Assessor Active TS SCI
Posted
Clearance: Active TS/SCI eligibility required, plus Special Access Program (SAP) access eligibility and willingness for Counterintelligence polygraph Industry: Public Sector/Government (DoD/Air Force support) Key Responsibilities:
- Conduct comprehensive assessments of management, operational, and technical security controls for information systems (IS) using Risk Management Framework (RMF) and Joint SAP Implementation Guide (JSIG).
- Evaluate IS threats, vulnerabilities, and impacts on Confidentiality, Integrity, and Availability to recommend safeguards and corrective actions.
- Prepare Security Assessment Reports (SAR), initiate Plans of Action and Milestones (POA&M), and provide written recommendations for security authorization to Authorizing Officials (AO/DAO).
- Advise Information System Owners (ISO), Information Data Owners (IDO), Program Security Officers (PSO), and officials on assessment, authorization, and compliance issues.
- Review and evaluate authorization packages, proposed changes to operating environments, hardware/software impacts, and Continuous Monitoring Plans.
- Ensure compliance with sanitization procedures, assist with inspections, security incidents, and all phases of the system development life cycle (SDLC).
- Perform oversight of IS security program policy, with emphasis on SAP network infrastructure integration.
- Represent the organization on inspection teams.
- Bachelor's degree in a related field or equivalent experience (4+ years).
- 5-7 years of related experience, including at least 3 years in SAP, SCI, or Collateral IS Security with hands-on implementation of relevant regulations.
- Prior experience as Information Systems Security Officer (ISSO) and/or Information Systems Security Manager (ISSM).
- Meet DoD Directive 8570.01-M certification requirements for Information Assurance Technician Level III or Information Assurance Manager Level I within 6 months of hire.
- Native or bilingual proficiency in English.
- Eligible for TS/SCI and SAP access.
