Junior Security Control Assessor
Listed on 2026-07-27
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Location: Bethesda, MD (mostly remote, occasional onsite required)
Work schedule: 40 hrs/week
Compensation: $100,000–$115,000/year
Target start: by end of August 2026
Clearance / Public Trust: Public Trust eligibility (Tier 2/3) required
We’re hiring a Junior Security Control Assessor to support independent security control assessments across the system authorization lifecycle. You’ll work under a senior assessor and help evaluate security control implementation, validate evidence, and document results in alignment with NIST Risk Management Framework (RMF) and NIST SP 800-53 Rev. 5, using JCAM practices.
This is a great fit for someone who enjoys cybersecurity compliance, evidence-based assessments, and strong technical writing—without being the person who authors the entire authorization package.
What you’ll do- Support independent Security Control Assessments (SCAs) across the authorization lifecycle
- Review and validate security authorization documentation (SSP, SAP, SAR, POA&M, contingency plans, and supporting artifacts)
- Assess security control implementation through documentation review, interviews, and technical validation
- Help evaluate cloud security packages and inherited controls (as applicable)
- Document findings, recommendations, and remediation activities clearly and professionally
- Assist with evidence validation and remediation tracking
- Partner with system owners and ISSOs while maintaining assessor independence
- Education: Bachelor’s in Cybersecurity, IT, Computer Science, Information Systems (or similar)
- OR 4 additional years of relevant experience in lieu of a degree
- Experience: 3–5 years supporting cybersecurity, information assurance, RMF, security assessments, compliance, or IT operations
- Working knowledge of:
- NIST RMF (800-37) and NIST SP 800-53 Rev. 5
- JCAM methodology
- Experience reviewing security documentation and assessment evidence/artifacts
- Strong analytical skills and technical writing ability
- Experience with eMASS or similar GRC platforms
- Familiarity with FedRAMP
, cloud security concepts, C-SCRM, and related federal security frameworks - Experience supporting independent audits/assessments (e.g., external review organizations)
- JCAM
- Tenable
- Crowd Strike
- Splunk / Splunk Enterprise
- AWS
- Python (plus)
- ISC2 CC or CGRC
- CompTIA Security+, CySA+, Pen Test+, CASP+
- CEH
- Microsoft SC-900
System One, and its subsidiaries including Joulé and Mountain Ltd., are leaders in delivering outsourced services and workforce solutions across North America. We help clients get work done more efficiently and economically, without compromising quality. System One not only serves as a valued partner for our clients, but we offer eligible employees health and welfare benefits coverage options including medical, dental, vision, spending accounts, life insurance, voluntary plans, as well as participation in a 401(k) plan.
System One is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, age, national origin, disability, family care or medical leave status, genetic information, veteran status, marital status, or any other characteristic protected by applicable federal, state, or local law.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).