Security Control Assessor/Representatives
Listed on 2026-08-05
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Dark Wolf Solutions is seeking Security Control Assessor/Representatives (SCA/Rs) tolead security control assessments across high-priority projects. Working at the intersection ofcybersecurity engineering, cloud architecture, and Dev Sec Ops prototyping, you will evaluate security controls for cutting-edge AI/LLM technologies across multiple classification levels. This position is ideal for a pragmatic cloud assessor or SCAR who excels in fast-paced Dev Sec Ops environments , understands AWS cloud security, and is eager to shape the cybersecurity postureof next-generation DoD AI capabilities.
This position will be based out of Arlington, VA with hybrid/remote opportunities.
Additional responsibilities include:
Key Responsibilities
- Execute formal SCA/R duties.
- Lead security assessment efforts, establishing reusable security playbooks and assessment frameworks for rapid AI deployment into enterprise workflows.
- Evaluate technical control effectiveness across AWS cloud infrastructure, Dev Sec Ops pipelines, microservices, containerized workloads, and GenAI/LLM application stacks.
- Partner directly with cybersecurity engineering and Dev Sec Ops prototyping teams to integrate security controls early in the development lifecycle.
- Review, author, and maintain assessment packages-Including System Security Plans (SSPs), Security Assessment Plans (SAPs), Security Assessment Reports (SARs), and POA&Ms—tailored to rapid prototyping and AI systems.
- Assess technical security risks specific to AI/LLM implementations, such as API exposure, vector database access controls, model integration surface area, and software supply chain dependencies.
- Support continuous monitoring (Con Mon), technical risk evaluations, and cloud architecture reviews across multi-tenant, multi-classification environments.
- Coordinate with Authorizing Officials (AOs), program managers, and engineering leads to deliver decision-ready risk briefings and ATO recommendations.
- Provide technical input and oversight for cybersecurity engineering and penetration testing activities across prototype projects.
Required Qualifications
- Active Top Secret security clearance
- Current DoD 8570/8140 IAM Level II or Level III certification (e.g., Security+, CySA+, CISM, CISSP, CCISO, CAP/CISC)
- 3-5+ years of experience conducting security control assessments, compliance testing, or A&A/RMF activities for DoD or federal information systems
- Solid operational understanding of core AWS cloud services (EC2, S3, IAM, VPCs, Security Groups, Security Hub) and how security controls function within cloud-native and CI/CD pipeline environments.
- Strong working knowledge of NIST SP 800-53 (Rev. 4/5), NIST SP 800-37 (RMF), DoD Cloud Computing SRG, and FedRAMP baselines.
- Demonstrated experience writing and evaluating core RMF artifacts (SSPs, SAPs, SARs, POA&Ms)
- Exceptional written and verbal communication skills, with the ability to articulate technical risk clearly to executive stakeholders, Authorizing Officials, and engineering teams.
- Hands-on experience navigating government GRC repositories, such as eMASS or XACTA.
Desired Qualifications
- Hands-on experience mapping security controls to the NIST AI Risk Management Framework (AI RMF), the OWASP Top 10 for LLM Applications, or the DoD Responsible AI (RAI) Guidelines.
- Familiarity evaluating secure design patterns for autonomous AI Agents (e.g., tool-calling permissions, sandboxing agent execution environments, prompt boundaries, and ReAct/Lang Graph architectures).
- Experience assessing cloud-managed AI ecosystems and foundation model platforms (e.g., AWS Bedrock, AWS Sage Maker, Hugging Face Enterprise, or self-hosted open-source models).
- Understanding of data protection, access controls, and boundary security for RAG pipelines and vector databases (e.g., Open Search Vector Engine, Pinecone, Milvus, or PostgreSQL pgvector).
- Familiarity evaluating risks unique to LLMs—including prompt injection, data poisoning, model inversion, insecure output handling, and open-source supply chain vulnerabilities in AI libraries (PyTorch, Lang Chain, Llama Index).
- Exposure to LLM guardrail platforms, evaluation frameworks, or AI security tools (e.g., Promptfoo,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).