Security Assessor; RMF/GRC)
Listed on 2026-08-30
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Security Assessor (RMF / GRC)
Location:
Bethesda, MD (Hybrid; On-site as Required)
Clearance:
Tier 2 Public Trust (Required)
Employment Type:
Full-Time
Digital Global Connectors (DGC) is seeking an experienced Security Assessor (RMF / GRC) to support a Federal information security program. The Security Assessor is responsible for planning, conducting, documenting, and reporting comprehensive security control assessments that evaluate the effectiveness of administrative, technical, and operational safeguards protecting enterprise information systems.
This position performs Security Control Assessments (SCAs), validates implementation of NIST security controls, supports Authorization to Operate (ATO) activities, identifies cybersecurity risks, and develops recommendations to improve organizational security posture. The Security Assessor collaborates closely with ISSOs, Security Engineers, System Owners, Security Architects, Program Managers, and Government stakeholders to ensure systems meet Federal cybersecurity and compliance requirements.
The successful candidate will possess extensive experience performing Risk Management Framework (RMF) assessments, evaluating security controls, and producing assessment documentation that supports system authorization and continuous monitoring.
Essential Duties and Responsibilities Security Control Assessments- Plan and conduct Security Control Assessments (SCAs) for enterprise information systems.
- Evaluate implementation of administrative, technical, and operational security controls.
- Assess the effectiveness of security controls using interviews, technical testing, documentation reviews, and observation.
- Validate implementation of corrective actions.
- Identify security deficiencies and associated risks.
- Develop risk-based recommendations for remediation.
- Support all phases of the Risk Management Framework (RMF).
- Assess implementation of NIST SP 800-53 security controls.
- Support Authorization to Operate (ATO), Authorization to Test (ATT), and reauthorization activities.
- Review System Security Plans (SSPs), Security Assessment Plans (SAPs), Security Assessment Reports (SARs), and Plans of Action and Milestones (POA&Ms).
- Validate remediation of assessment findings.
Support continuous monitoring activities throughout the system lifecycle.
- Evaluate compliance with applicable Federal cybersecurity requirements, organizational policies, and security standards.
- Assess cybersecurity governance processes.
- Perform risk analyses supporting executive decision-making.
- Identify compliance gaps and recommend corrective actions.
- Assist organizations in improving overall cybersecurity maturity.
- Support enterprise GRC initiatives and reporting.
- Review system configurations for compliance with approved security baselines.
- Evaluate identity and access management controls.
- Assess cloud security implementations.
- Validate vulnerability remediation activities.
- Review audit logging, incident response, contingency planning, and configuration management practices.
- Assess secure implementation of enterprise cybersecurity technologies.
Review and evaluate:
- System Security Plans (SSPs)
- Security Assessment Plans (SAPs)
- Security Assessment Reports (SARs)
- Plans of Action and Milestones (POA&Ms)
- Configuration Management Plans
- Contingency Plans
- Incident Response Plans
- Privacy Documentation
- Continuous Monitoring Strategies
- Security Architecture Documentation
Ensure documentation is complete, accurate, and compliant with applicable Federal standards.
Assessment ReportingDevelop and maintain:
- Security Assessment Plans
- Security Assessment Reports
- Executive Assessment Summaries
- Risk Assessments
- POA&M Recommendations
- Continuous Monitoring Reports
- Compliance Assessments
- Control Implementation Analyses
- Technical Findings Reports
- Standard Operating Procedures
Prepare clear, accurate, and actionable reports suitable for both technical and executive audiences.
Collaboration- Coordinate with ISSOs, Security Engineers, Security Architects, System Owners, Program Managers, Cloud Engineers, SOC personnel, and Government stakeholders.
- Participate in assessment planning meetings and technical working groups.
- Provide assessment briefings to leadership.
- Support remediation planning and validation activities.
- Assist organizations in preparing for audits and authorization reviews.
- Monitor updates to Federal cybersecurity policies, standards, and assessment methodologies.
- Recommend improvements to assessment processes and governance practices.
- Support automation of assessment and compliance activities where appropriate.
- Share assessment best practices across project teams.
- Maintain professional certifications and technical expertise.
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Information Systems, Engineering, or a related discipline.
- Minimum five (5) years of experience performing…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).