Coalfire · 1 month ago
Security Controls Assessor (SCA)
Coalfire Federal is a leading cybersecurity consultancy firm that provides tailored advice and assessments to Federal agency customers. They are looking for a Security Controls Assessor (SCA) to support their Federal team in the DMV area, responsible for developing and implementing security standards, evaluating security programs, and ensuring the security of information systems.
Information Technology & Services
Responsibilities
Determines enterprise information assurance and security standards
Develops and implements information assurance/security standards and procedures
Coordinates, develops, and evaluates security programs for an organization
Recommends information assurance/security solutions to support customers’ requirements
Identifies, reports, and resolves security violations
Supports customers at the highest levels in the development and implementation of doctrine and policies
Applies know-how to government and commercial common user systems, as well as to dedicated special purpose systems requiring specialized security features and procedures
Provides integration and implementation of the computer system security solution
Analyzes general information assurance-related technical problems and provides basic engineering and technical support in solving these problems
Ensures that all information systems are functional and secure
Qualification
Required
Completed Bachelor's degree from an accredited university, preferably in an IT related field
Ability to obtain a clearance or a Public Trust
One or more of the following: CISSP, CISM, or equivalent senior industry recognized cybersecurity certification
5 to 10 years of hands-on work experience with Assessor (SCA) duties; performing systems security assessments, preparing system security documentation, and/or performing security upgrades for live networks, desktop systems, servers, and enterprise data bases leading to successful security authorization of such systems
Computer networking concepts and protocols, and network security methodologies
Risk management processes (e.g., methods for assessing and mitigating risk)
Laws, regulations, policies, and ethics as they relate to cybersecurity and privacy
Cybersecurity and privacy principles
Cyber threats and vulnerabilities, including application vulnerabilities
Specific operational impacts of cybersecurity lapses
Authentication, authorization, and access control methods
Applicable business processes and operations of customer organizations
Capabilities and applications of network equipment including routers, switches, bridges, servers, transmission media, and related hardware
Cyber defense and vulnerability assessment tools and their capabilities
Server administration and client operating systems engineering theories, concepts, and methods
System software and organizational design standards, policies, and authorized approaches (e.g., international organization for standardization [iso] guidelines) relating to system design
System life cycle management principles, including software security and usability
Preferred
Local candidates with the availability to go on site on a hybrid basis are highly preferred
Ability to obtain a clearance or a Public Trust is preferred, however all clearance levels and non-cleared applicants will also be considered
Benefits
Paid parental leave
Flexible time off
Certification and training reimbursement
Digital mental health and wellbeing support memberships
Comprehensive insurance options
Company
Coalfire
Coalfire is the premier Cybersecurity and Compliance Services leader for the tech, healthcare, and finance industries.
H1B Sponsorship
Coalfire has a track record of offering H1B sponsorships. Please note that this does not
guarantee sponsorship for this specific role. Below presents additional info for your
reference. (Data Powered by US Department of Labor)
Distribution of Different Job Fields Receiving Sponsorship
Represents job field similar to this job
Trends of Total Sponsorships
2025 (3)
2024 (4)
2023 (3)
2022 (6)
2021 (2)
2020 (4)
Funding
Current Stage
Late StageCompany data provided by crunchbase