Security Control Assessor; SCA
Listed on 2026-07-20
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Los Angeles, United States | Posted on 07/16/2026
Sandy Mac Evolution LLC is a Veteran-Owned company dedicated to connecting top talent with meaningful opportunities.
Job Description13-004 – Security Control Assessor (SCA) I
Position Type: Full-Time
Security Clearance: Active TS/SCI Required
Additional Access: Eligibility for Special Access Program Information | Willingness to Submit to a Counterintelligence Polygraph
Position OverviewSandy Mac Evolution LLC is seeking a highly qualified Security Control Assessor (SCA) I to support Department of Defense classified information systems at Los Angeles Air Force Base, California.
The selected candidate will conduct comprehensive assessments of management, operational, and technical security controls employed within or inherited by information systems. These assessments will determine whether security controls are implemented correctly, operating as intended, and producing the required security outcomes.
The SCA will identify weaknesses and deficiencies, evaluate their severity, recommend corrective actions, and support authorization decisions for systems operating within Collateral, Sensitive Compartmented Information, and Special Access Program environments.
Key ResponsibilitiesConduct independent security control assessments using the Risk Management Framework methodology and the Joint Special Access Program Implementation Guide.
Provide oversight of the development, implementation, and evaluation of information system security policies and programs.
Support the integration and assessment of existing SAP network infrastructure.
Assess management, operational, and technical security controls to determine their effectiveness and compliance with applicable security requirements.
Advise Information System Owners, Information Data Owners, Program Security Officers, Delegated Authorizing Officials, and Authorizing Officials regarding assessment and authorization matters.
Review and evaluate system authorization packages and provide recommendations to the Authorizing Official or Delegated Authorizing Official.
Evaluate information system threats and vulnerabilities to determine whether additional safeguards or mitigating controls are required.
Advise Government stakeholders regarding Confidentiality, Integrity, and Availability impact levels for information processed by classified systems.
Ensure security assessments are completed, properly documented, and maintained in accordance with applicable Government policies and guidance.
Prepare Security Assessment Reports for assigned authorization boundaries.
Develop and initiate Plans of Action and Milestones based on weaknesses identified during security assessments.
Review security assessment documentation and provide written recommendations regarding system authorization.
Present authorization recommendations and submit completed security authorization packages to the appropriate Authorizing Official.
Evaluate proposed changes to authorization boundaries, operating environments, system configurations, and mission requirements to determine whether continued operation remains appropriate.
Review and concur with sanitization and media-clearing procedures in accordance with Government policy and guidance.
Support Government security compliance reviews and inspections.
Assist with cybersecurity incident response activities and verify that appropriate corrective measures have been implemented.
Ensure organizations address information security requirements throughout all phases of the System Development Life Cycle.
Evaluate proposed hardware and software changes to determine their potential security impact on authorization boundaries.
Assess the effectiveness and implementation of Continuous Monitoring Plans.
Represent the customer as a member of security inspection and assessment teams.
Perform additional cybersecurity, assessment, and authorization duties as required.
Required QualificationsFive to seven years of related cybersecurity, information assurance, or information system security experience.
Minimum of three years of experience supporting SAP, SCI, or Collateral Information Systems…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).