Security Control Assessor; SCA II
Listed on 2026-07-29
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Kirtland Afb, United States | Posted on 07/21/2026
Sandy Mac Evolution LLC is a Veteran-Owned company dedicated to connecting top talent with meaningful opportunities.
Job Description35-003 – Security Control Assessor (SCA) II
Location: Kirtland AFB, NM
Position Type: Full-Time
Security Clearance: Active Top Secret/SCI Clearance Required | Eligibility for Special Access Program Access | Must Be Willing to Undergo a Counterintelligence Polygraph
Position OverviewSandy Mac Evolution LLC is seeking an experienced Security Control Assessor (SCA) II to support Department of Defense Special Access Program environments at Kirtland Air Force Base, New Mexico.
The selected candidate will conduct comprehensive assessments of the management, operational, and technical security controls implemented within or inherited by classified Information Systems. The SCA II will determine whether security controls are properly implemented, operating as intended, and producing the required security outcomes for the system and its operating environment.
This position will also evaluate the severity of identified weaknesses and deficiencies, recommend corrective actions, and provide security authorization guidance to government stakeholders. Responsibilities will support Collateral, Sensitive Compartmented Information, and Special Access Program activities within the customer’s area of responsibility.
Key ResponsibilitiesProvide oversight for the development, implementation, and evaluation of Information System security policies and programs, with particular emphasis on integrating existing SAP network infrastructure.
Conduct security control assessments using the Risk Management Framework methodology and the Joint Special Access Program Implementation Guide.
Assess management, operational, and technical security controls to determine whether they are implemented correctly, operating as intended, and meeting established security requirements.
Advise Information System Owners, Information Data Owners, Program Security Officers, Delegated Authorizing Officials, and Authorizing Officials regarding assessment and authorization matters.
Review and evaluate authorization packages and provide recommendations to the Authorizing Official or Delegated Authorizing Official.
Evaluate Information System threats, risks, and vulnerabilities to determine whether additional safeguards or corrective actions are required.
Advise government personnel regarding appropriate confidentiality, integrity, and availability impact levels for information processed by classified systems.
Ensure security assessments are completed, documented, and maintained in accordance with applicable government requirements.
Prepare Security Assessment Reports for assigned authorization boundaries.
Develop and initiate Plans of Action and Milestones for identified weaknesses based on findings and recommendations documented in Security Assessment Reports.
Evaluate assessment documentation and provide written recommendations regarding system authorization.
Present authorization recommendations and submit completed security authorization packages to the appropriate Authorizing Official.
Assess proposed changes to authorization boundaries, operating environments, system configurations, and mission requirements to determine whether continued authorization to operate is appropriate.
Review and concur with media sanitization, clearing, and disposal procedures in accordance with government policy and guidance.
Support government compliance reviews, audits, and inspections.
Assist with cybersecurity incident response activities and verify that appropriate corrective and preventive measures have been implemented.
Ensure organizations address cybersecurity requirements throughout all phases of the System Development Life Cycle.
Evaluate hardware and software changes to determine their potential security impact on authorization boundaries.
Evaluate the effectiveness and implementation of Continuous Monitoring Plans.
Represent the customer as a member of inspection and assessment teams.
Identify security control deficiencies and recommend practical…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).