
Security Control Assessor (SCA)
- Charlottesville, VA
- Permanent
- Full-time
Responsibilities
- Lead and perform compliance reviews of computer security plans, perform risk assessments, and validate and perform security test evaluations and audits.
- Analyze and define security requirements for information protection for enterprise systems and networks.
- Assist in the development of security policies.
- Analyze the sensitivity of the information and perform vulnerability and risk assessments based on defined sensitivity and information flow.
- Responsible for auditing the most complex new and existing information systems applications to ensure that appropriate controls exist, that processing is efficient and accurate, and that information systems procedures are compliant with corporate standards.
- Other duties as assigned.
- Bachelor’s Degree in Computer Science, Information Security, or a related field; a Master’s Degree in a related field is preferred.
- 10+ years of experience in protected information environments (i.e., SIPR, SAP, JWICS, etc.)
- IAM Level III certification (CISM, CISSP (or associate), GSLC, or CCISO) in accordance with DoD 8570.01-M/8140.03
- Active TS/SCI clearance
- Detailed knowledge of and experience with ICD 503 and the government's assessment and authorization process
- Experience working within eMASS
- Current knowledge of cloud-computing technologies and security as they relate to Infrastructure-as-a-Service (IaaS), Platform-as-a-Service (PaaS), and Software-as-a-Service (SaaS)
- Thorough knowledge of information security principles, practices, and technologies
- Familiarity with security frameworks and regulations such as NIST, FISMA, and HIPAA.
- Excellent problem-solving and critical-thinking skills
- Strong communication and interpersonal skills to collaborate effectively with various stakeholders