Security Control Assessor; SME), Level III
Listed on 2026-09-04
-
IT/Tech
Cybersecurity, Information Security & Data Protection
We are an employee-centric company that truly values our team members and the contributions they make to our customers and the missions they support. We pride ourselves on being forward-leaning thinkers and on building teams that are, and continue to be, technically proficient across a broad range of cyber mission areas. One Zero full-time employees receive a highly competitive benefits package, including health, dental, vision, and life insurance, a 401(k) with company matching, paid time off and holidays, an employee referral program, and educational assistance.
Additional details are available on our website:
Position Title :
Security Control Assessor (SME), Level III
Location
:
USCG Surface Forces Logistics Center, 2401 Hawkins Point Road, Baltimore, MD 21226. Work may also be performed at the SFLC satellite offices at 707 East Ordnance Road, approximately one mile from the primary site, and at other sites as determined necessary by the Contracting Officer's Representative (COR).
Clearance
:
- No security clearance required. This position does not involve access to classified information or classified IT systems.
- S. citizenship is required in accordance with HSAR Alternate I.
The Security Control Assessor (SCA) provides independent security control assessment and authorization support to the USCG SFLC Business Operations Division in support of Surface Domain Operational Technology (OT) and Platform IT systems. The role is the assessment authority on the team: it evaluates whether security and privacy controls are implemented correctly, operating as intended, and producing the intended outcome, and it provides the evidence the Authorizing Official relies on to make risk decisions.
This is the senior assessment position on the task order and is distinct from the ISSO roles, which own and maintain the authorization packages. The SCA assesses; the ISSOs prepare and sustain. The position is expected to operate with a high degree of independence and to advise the OT Security Manager (ISSM) directly.
Key Responsibilities- Support the OT Security Manager (ISSM) and staff in establishing and maintaining the programs, procedures, and policies that protect Government Sensitive But Unclassified (SBU) information.
- Perform independent assessments of SFLC Operational Technology to verify that applicable security and privacy controls are implemented correctly, operating as intended, and producing the desired outcome.
- Provide security assessment and authorization consultation services to the ISSM, on site.
- Review existing policies, procedures, and guidelines for compliance with DHS, USCG, and DoD cybersecurity policy; draft or revise SFLC policy documentation for ISSM review, approval, and organizational implementation.
- Assist in preparing RMF security authorization documentation for submission to the Authorizing Official (AO).
- Maintain security assessment information and supporting documentation within Government-designated systems and repositories.
- Create and validate SFLC security assessment and authorization accounts within Government-designated systems and tools.
- Update and maintain assessment and authorization status within Government-designated tracking systems and databases.
- Upload, track, and update Plans of Action and Milestones (POA&Ms); recommend POA&Ms updates based on assessment results and maintain traceability from identified vulnerabilities through to the applicable POA&Ms.
- Conduct vulnerability scans of SFLC OT, networks, devices, and associated components using Government-approved tools.
- Provide assistance to system administrators in remediating vulnerabilities identified through scanning.
- Provide vulnerability and risk management support in conjunction with assessment and authorization activities.
- Maintain the enterprise tracking log for electronic spillage activities in accordance with Government policy.
- Support the destruction of removable media generated during assessment activities in accordance with Government procedures.
- Support cybersecurity strategic planning and continuous monitoring activities, evaluating enterprise services through assessment of priorities and risk.
- Provide bi-weekly…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).