Security Control Assessor
Listed on 2026-02-16
-
IT/Tech
Cybersecurity, Information Security
The Opportunity
As a systems security and network security engineer, you will identify the appropriate tools, systems, and applications needed to assess vulnerabilities and recommend the best solution and security strategy.
Job InformationJob Number: R0233273
Security Control Assessor
On our team, you’ll assess a variety of network and security devices and applications in accordance with NIST 800-53 and NIST 800-37 standards. You’ll use your curiosity for technology and market trends to further research and develop security solutions. Using your knowledge and experience you’ll assess security threats and implement infrastructure controls. In this role, you’ll have impact on the mission by supporting accreditation and authorization packages for both new and existing systems.
With mentoring, challenging hands‑on problem‑solving, and opportunities to learn new tools and skills, we focus on growing as a team to make the best solutions for our customers.
- Develop relationships quickly and easily with other teams, communicating the complexities of security with a wide variety of audiences, including senior management.
- Implement infrastructure and cybersecurity controls, including enhanced detection and vulnerability capabilities and improved event correlation in large enterprises.
- Perform risk and vulnerability assessments in network, system, and application areas.
- Leverage big data analytics and traditional security event types to identify advanced threats or indicators of compromise.
- 5+ years of experience in information assurance
- Experience utilizing NIST 800-53 security controls and with NIST 800-37 Risk Management Framework (RMF) requirements
- Experience supporting system authorization activities, including the development and maintenance of security documentation such as System Security Plans (SSPs) and Plans of Action and Milestones (POA&Ms)
- Experience monitoring system security posture and identifying risks, vulnerabilities, and compliance gaps
- Experience tracking and managing POA&Ms and coordinating remediation activities with system stakeholders
- Experience assessing the security impact of system changes and supporting configuration and change management processes
- Experience preparing systems for security assessments, audits, and Authorizing Official reviews
- Ability to support continuous monitoring activities, including vulnerability management and security reporting, and serve as a security liaison between system teams, cybersecurity operations, and governance bodies
- Top Secret clearance
- Bachelor’s degree
- Experience with operational technology and industrial control systems
- Master’s degree in Information Systems
- CompTIA Advanced Security Practitioner (CASP) or Certified Information Systems Security Professional (CISSP) Certification
Applicants selected will be subject to a security investigation and may need to meet eligibility requirements for access to classified information;
Top Secret clearance is required.
At Booz Allen, we celebrate your contributions, provide you with opportunities and choices, and support your total well‑being. Our offerings include health, life, disability, financial, and retirement benefits, as well as paid leave, professional development, tuition assistance, work‑life programs, and dependent care. Our recognition awards program acknowledges employees for exceptional performance and superior demonstration of our values. Full‑time and part‑time employees working at least 20 hours a week on a regular basis are eligible to participate in Booz Allen’s benefit programs.
Individuals that do not meet the threshold are only eligible for select offerings, not inclusive of health benefits. We encourage you to learn more about our total benefits by visiting the Resource page on our Careers site and reviewing Our Employee Benefits page. Salary at Booz Allen is determined by various factors, including but not limited to location, the individual’s particular combination of education, knowledge, skills, competencies, and experience, as well as contract‑specific affordability and organizational requirements.
The projected…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).