Security Control Assessor Representative (SCAR) – Cyber Ops V

Aleut Federal

  • United States Air Force Academy, CO
  • $130,000-150,000 per year
  • Permanent
  • Full-time
  • 23 hours ago
Description :At Aleut Federal, we believe the company and its mission is just as important as the job you are applying for. Aleut Federal is an Alaskan Native-owned enterprise whose purpose is to support our “Shareholders,” the Unangax, the indigenous people of the Aleutian Islands of Alaska. People are at the core of everything we do. We support our Shareholders by providing excellent service and quality results to our clients and the various branches of the federal government. We engage in local markets, so community service is embedded in our process.Our culture nurtures the strength of our workforce through mentorship and coaching, providing opportunities for growth and competitive benefits. We support and encourage diversity, inclusion, and accountability at every level.The Aleut Federal motto is “We are One” because we truly believe that with one heart, one mind, and one purpose, we can accomplish our mission and be an organization anyone would be proud to be a part of.POSITION SUMMARYAleut is seeking a Security Control Assessor Representative (SCAR) to work with the United States Air Force Academy (USAFA) RMF team. This position requires personnel to work on-site at USAFA in Colorado Springs, CO.*** POSITION HIRING CONTINGENT ON CONTRACT AWARD ***ESSENTIAL JOB FUNCTIONS
  • Serve as an independent assessor responsible for evaluating the effectiveness of implemented security controls across USAFA information systems in accordance with NIST SP 800-53A Rev. 5 and DoD RMF standards.
  • Develop and maintain Security Assessment Plans (SAPs) for each assigned system, including assessment scope, testing schedule, security tools, control evaluation methods, and designated assessor personnel.
  • Draft and coordinate Rules of Engagement (ROE) documents for penetration testing and vulnerability scanning activities to ensure alignment with mission requirements and operational constraints.
  • Conduct or oversee security control assessments for management, operational, and technical controls, leveraging interviews, evidence review, technical validation, and security testing.
  • Document assessment results and risk impacts in the Security Assessment Report (SAR), providing a clear summary of control effectiveness, risk posture, and any residual vulnerabilities.
  • Support SAR preparation activities including:
  • Vulnerability assessments and validation
  • Security categorization reviews
  • System Security Plan (SSP) analysis
  • Risk issue resolution and remediation status reporting
  • Preparation of SAR briefings, findings presentations, and meeting support materials
  • Provide independent contributions to the Authorization to Operate (ATO) process by delivering the SAR, risk determinations, and supporting documentation for inclusion in the final ATO package.
  • Generate draft Plan of Action and Milestones (POA&M) entries based on control deficiencies and observations documented during assessments, excluding any actions already remediated by the implementation team.
  • Prepare a Residual Risk Statement with a recommendation for risk acceptance or mitigation, which feeds into the Authorizing Official's risk decision process and the Risk Acceptance Recommendation Report.
  • Determine and document the risk impact of unmitigated vulnerabilities on organizational operations, mission capabilities, and other dependent systems or stakeholders.
  • Contribute to the assembly of the overall security authorization package, ensuring completeness and readiness for AO review.
  • Participate in and support continuous monitoring efforts, including annual control re-assessment activities, targeted testing of inherited or system-specific controls, and the documentation of monitoring results in accordance with NIST SP 800-137.
  • Maintain strict independence from the ISSM, ISSO, and ISSE functions to preserve objectivity, while collaborating professionally with system owners and stakeholders to clarify findings and recommended remediation paths.
WORK ENVIRONMENT
  • This is an onsite position that requires work to be performed onsite in Colorado Springs, CO.
  • Indoor office working conditions.
PHYSICAL DEMANDS
  • Must be able to sit or stand for prolonged periods.
  • Must be able to perform repetitive keyboard tasks and associated motions for prolonged periods.
  • Must be able to carry up to 10 pounds.
SALARY RANGE
  • $130,000 -- $150,000 (annual) depending on qualifications
*We will be accepting applications for this position until 09/26/2025 at 11:59 PM EST*REQUIERMENTS:
  • CERTIFICATION: CISM or CISSO or CPTE or CySA+ or FITSP-A or GCSA or CISA or CISSP or CISSP-ISSEP or GSLC or GSNA.
  • REQUIED EDUCATION: Bachelor of Science degree in Information Technology, Cybersecurity, Data Science, Information Systems, or Computer Science, from an Accreditation Board for Engineering and Technology (ABET) accredited or Certified Association Executive (CAE) designated institution.
  • EXPERIENCE: At least ten years of relevant experience acting as a Security Control Assessor Representative preferably in the United States Air Force or DoD space. Must have knowledge of NIST SP 800-53A Rev. 5, SP 800-37, SP 800-137, FIPS 199, FIPS 200, risk analysis and documentation, ATO package structure.
  • SECURITY CLEARANCE: Must hold an active Secret security clearance
Aleut offers the following benefits to eligible employees:
  • Health insurance
  • Dental/Vision insurance
  • Paid Time Off
  • Short- and Long-Term Disability
  • Life insurance
  • 401k and match
At Aleut, our culture thrives on diversity, inclusion, and collaboration. Integrating diverse perspectives opens up new possibilities, fosters innovation, and fully harnesses our team's potential. We are committed to creating an environment where every employee feels valued, included, and inspired to grow and find purpose. Join us and be part of a culture that celebrates differences and belonging for everyone, without regard to race, color, religion or belief, national, social, or ethnic origin, sex, pregnancy, marital status, age, physical, mental, or sensory disability, sexual orientation, gender identity and/or expression, or past or present military service. We welcome everyone as they are!#CJ#AMSBehaviors : Team Player: Works well as a member of a group
Loyal: Shows firm and constant support to a cause
Enthusiastic: Shows intense and eager enjoyment and interest
Detail Oriented: Capable of carrying out a given task with all details necessary to get the task done well
Dedicated: Devoted to a task or purpose with loyalty or integrityMotivation : Ability to Make an Impact: Inspired to perform well by the ability to contribute to the success of a project or the organizationEducation : BachelorsExperience : 10 years: At least ten years of relevant experience acting as a Security Control Assessor Representative preferably in the United States Air Force or DoD space. Must have knowledge of NIST SP 800-53A Rev. 5, SP 800-37, SP 800-137, FIPS 199, FIPS 200, risk analysis and documentation, ATO package structure.

Aleut Federal