×
Register Here to Apply for Jobs or Post Jobs. X

CDS Security Control Assessor

Job in Reston, Fairfax County, Virginia, 20191, USA
Listing for: Pueo Business Solutions
Full Time position
Listed on 2026-07-01
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection, IT Consultant
Job Description & How to Apply Below

Cross Domain Solutions Security Control Assessor

Pueo is known for bringing the best talent and unique tools to every opportunity. Pueo's Parliament (aka workforce) is composed of professionals who are seeking the opportunity to work in a business organization that thrives on career development and independence. In support of mission and professional growth, our Parliament has supported the development of multiple patents, proprietary tools, and applications as well as trademarked processes.

Our organization emphasizes career development across multiple career environments (at the members own pace) and ensures those who contribute broadly are properly rewarded. Pueo has four career environments where every member of the parliament can participate. Each environment has opportunities available for all levels. Opportunities are framed by an employee's desires and capabilities, and we ensure challenges, growth, and unique experiences are available for employees at all levels.

Our Career Environments (Program, Functional, Service, and Leadership) provide numerous opportunities for employees to invest in their personal growth and those things that offer fulfillment. We invest in helping our members create and execute their career development plans. Our Pods (small teams of 5 or less) are comprised of personnel with similar skillsets to ensure mentorship, understanding, and peer support.

Overview

The Cross Domain Solutions (CDS) SCA conducts a comprehensive assessment of the security controls employed within or inherited by a CDS Information System (IS) to determine their overall effectiveness, and submits the Body of Evidence (BoE), composed of the System Security Plan (SSP), Security Assessment Report (SAR), Plan of Action and Milestones (POA&M), and draft Authorization to Operate (ATO) Letter, to the Authorizing Official (AO) or Delegated Authorizing Official (DAO) for review and authorization decision.

The SCA also advises key stakeholders, such as the Program Office, Data Owner and Authorizing Official/Delegated Authorizing Official concerning the security categorization and impact levels for confidentiality, integrity, and availability for the information on a CDS system.

  • Support the Assessment and Authorization (A&A) Risk Management Framework process for all client managed systems, networks, and enclaves (all security domains); ensure validity and accuracy review of all associated documentation; support remote sites when required.
  • Advise ISSOs on categorization and selection of security controls (RMF steps 1 and
    2) and conduct Technical Exchange Meetings (TEMs) where they collaborate with other security professionals.
  • Communicate finding impacts through presentations and written deliverables.
  • Stay up to date with the latest trends and technologies related to IC policy to continuously refine security inspection protocols.
Required Qualifications
  • Expert knowledge and hands-on experience with RMF, NIST 800-series guidelines, FIPS, Security Assessment & Authorization (SA&A) requirements and processes, Continuous Monitoring Framework experience and its tools, Plan of Action & Milestones (POA&M) policies, and vulnerability/patch management.
  • Expert with documenting and or reviewing of security materials such as; system security plans (SSP), Security Assessment Report (SAR), and Security Assessment Plan (SAP), and other documents per NIST 800 guidelines. Knowledge is Cross Domain Solutions to included but not limited to:
  • Evaluating the security controls of systems that handle the transfer of information between different security domains or levels of classification. Their technical functions encompass a range of tasks aimed at ensuring the integrity, confidentiality, and availability of data across disparate domains. Here are the technical functions typically associated with this role:
  • CDS Architecture Review:
    Conduct in-depth reviews of cross domain solutions architecture to understand the design, components, and data flows between different security domains. Evaluate the effectiveness of data isolation mechanisms, data filtering techniques, and boundary protection controls.
  • Security Policy Analysis:
    Analyze security policies, guidelines, and regulations governing the transfer of information between security domains. Ensure that CDS solutions comply with relevant security requirements, including government regulations, industry standards, and organizational policies.
  • Security Controls Assessment Planning:
    Develop comprehensive assessment plans tailored to the unique characteristics of cross domain solutions. Define assessment objectives, scope, methodologies, and success criteria based on established security standards and best practices.
  • Data Diode and Guard Evaluation:
    Assess the security posture of data diodes, guards, or other mechanisms used to enforce one-way data transfers between security domains. Verify the integrity and effectiveness of data transfer mechanisms while maintaining strict data separation.
  • Data Filtering…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary