Senior Security Control Assessor jobs in United States
cer-icon
Apply on Employer Site
company-logo

SkyePoint Decisions, Inc. · 1 month ago

Senior Security Control Assessor

SkyePoint Decisions, Inc. is a leading IT service provider specializing in Cybersecurity Architecture and Engineering. The Senior Security Control Assessor will conduct comprehensive assessments of security controls to ensure compliance with regulations and standards, while balancing mission goals with security requirements.

AnalyticsAppsArtificial Intelligence (AI)Cyber SecurityInformation TechnologyIT InfrastructureMachine LearningSecurity
badNo H1BnoteU.S. Citizen Onlynote

Responsibilities

Perform security reviews to identify architectural gaps and provide recommendations for risk mitigation
Conduct risk analyses (e.g., threats, vulnerabilities, probability of occurrence) during significant system/application changes
Plan and execute security authorization reviews, assurance case development, and audits for system installations and networks
Provide input to the Risk Management Framework (RMF) and related documentation, including lifecycle support plans, CONOPS, and operational procedures
Review authorization packages and assurance documents to confirm risk levels are acceptable for systems, applications, and networks
Verify that system, network, and application security postures are implemented as designed, documenting deviations and recommending corrective actions
Perform security reviews to identify architectural gaps and provide recommendations for risk mitigation
Assess the effectiveness of implemented security controls across management, operational, and technical areas
Support compliance activities by ensuring security configuration guidelines and standards are followed
Evaluate configuration management and release processes for security impacts
Define/document how new systems or interfaces affect the organization’s current security posture
Develop security compliance processes and perform audits of external services (e.g., CSPs, data centers)
Ensure Plans of Action & Milestones (POA&Ms) and remediation plans are established for vulnerabilities
Participate in Risk Governance processes by presenting risks, mitigations, and technical assessments
Support acquisition and procurement efforts to ensure information security requirements are integrated
Produce reports, briefings, and technical documentation reflecting assessment results and recommendations

Qualification

NIST SP 800-53Risk Management FrameworkSecurity Assessment & AuthorizationVulnerability scanningCISSPCISMSecurity architecture reviewCompliance frameworksCybersecurity lawsTechnical documentationAnalytical skillsCommunication skillsCollaboration skillsProblem-solving skills

Required

Must be able to obtain a High Risk/Public Trust Security Clearance
7+ years of relevant IT/cybersecurity experience
Certification in one of the following: A+, Net+, or Security+
Degree in a technical/cyber-related field (or equivalent experience/certifications)
Proficiency in assessing security controls against standards (e.g., NIST SP 800-53, CIS CSC, Cybersecurity Framework)
Strong skills in vulnerability scanning, penetration testing principles, and interpreting results
Ability to conduct risk, impact, and compliance assessments
Skill in technical documentation, briefings, and audit reporting
Proficiency in security architecture review and system design evaluation
Knowledge of secure coding principles and application security (e.g., OWASP Top 10)
Experience applying confidentiality, integrity, availability, authenticity, and non-repudiation principles to systems and networks
Familiarity with compliance frameworks and security assessment tools
Strong analytical, technical writing, and communication skills are essential
Knowledge of Risk Management Framework (RMF) and Security Assessment & Authorization (SA&A) processes
Knowledge of security architecture concepts, enterprise reference models, and assessment methodologies
Knowledge of network security protocols, models, and configurations (including defense-in-depth)
Working knowledge of government compliance standards and assessment processes
Knowledge of cyber threats, vulnerabilities, and operational impacts of lapses
Knowledge of information security principles and methods (e.g., encryption, access control, PKI)
Knowledge of applicable laws, directives, and compliance requirements (e.g., NIST SP 800-161, FISMA, FedRAMP)
Knowledge of system and application security threats (e.g., injection flaws, cross-site scripting, buffer overflow)
Knowledge of IT supply chain security and risk management practices
Knowledge of cyber defense and vulnerability assessment tools
Working knowledge of IRS Safeguards
Must be a U.S. citizen

Preferred

Active Secret or Top Secret security clearance
CISSP or CISM
Ability to evaluate and synthesize risk assessment data into actionable findings
Ability to clearly communicate technical and risk information to technical and non-technical audiences
Ability to assess vulnerabilities and recommend corrective actions
Ability to apply judgment in ambiguous or evolving situations
Ability to interpret and apply relevant cybersecurity laws, regulations, and policies
Ability to collaborate across teams and work effectively with external service providers
Ability to design, conduct, and evaluate test plans, assessments, and compliance audits
Ability to lead complex assessments, provide strategic recommendations, and advise leadership on enterprise-wide security control effectiveness

Benefits

Several insurance options including HMO and High Deductible plans with Health Savings Accounts [HSAs]
Flex Spending Accounts [FSAs]
Full Dental Plans
ST/LT Disability
Life Insurance
Floating federal holiday options
401k matched
Certificate Incentive Program
PTO
Vision

Company

SkyePoint Decisions, Inc.

twittertwittertwitter
company-logo
SkyePoint Decisions is a leading Cybersecurity Architecture and Engineering, Critical Infrastructure and Operations, and Applications Development and Maintenance IT service provider headquartered in Dulles, Virginia.

Funding

Current Stage
Growth Stage

Leadership Team

leader-logo
Bo Kimbrough
Founder & CEO
linkedin
leader-logo
Jason Weaver
Chief Technology Officer
linkedin
Company data provided by crunchbase