×
Register Here to Apply for Jobs or Post Jobs. X
More jobs:

Security Control Assessor, Lead

Job in Severn, Anne Arundel County, Maryland, 21144, USA
Listing for: Booz Allen Hamilton
Full Time position
Listed on 2026-09-21
Job specializations:
  • IT/Tech
    Cybersecurity
Salary/Wage Range or Industry Benchmark: 99000 - 225000 USD Yearly USD 99000.00 225000.00 YEAR
Job Description & How to Apply Below

Join a culture of empowerment and connectivity.

Develop your craft

Learn the skills you need to accelerate your career.

Discover benefits that support your life and work.

Innovate with intention

Build mission-ready tech that protects the nation.

The Lead Security Control Assessor directs the SCA workstream and provides independent cybersecurity assessment leadership for CDAO systems and environments to the ISSM. The Lead SCA owns assessment strategy, quality standards, stakeholder coordination, risk adjudication, and final review of Security Assessment Plans (SAPs) and Security Assessment Reports (SARs). The position advises technical leadership and Authorizing Official (AO) stakeholders on control effectiveness, authorization readiness, and residual cybersecurity  this role you will be responsible for developing and governing the assessment approach, schedule, evidence standards, test procedures, and quality-control framework for the SCA team.

What You'll Work On:

Provide eMASS administration, analyze STIG, SCAP, ACAS findings, POA&Ms, architecture, inherited controls, compensating controls, and technical evidence.

Work with the project ISSM to understand customer cybersecurity RMF requirements applicable to the systems in their respective environments.

Lead independent security control assessments in accordance with DoD RMF, NIST guidance, applicable DoD cybersecurity policy, and organizational assessment procedures.

Brief findings and risk recommendations to the ISSM, AO representative, and AO-level stakeholders.

Develop all system applicable RMF Body of Evidence (BOE) documentation ensuring accuracy, relevance, and completion to meet requirements and input BOE documentation into AO approved databases such as eMASS or AO specific SharePoint site.

Review and approve SAPs and SARs for technical accuracy, evidence sufficiency, traceability, consistency, and defensibility before stakeholder delivery.

Coordinate with system owners, ISSMs and ISSOs, cybersecurity engineers, administrators, developers, program leadership, control providers, and AO representatives.

Review system boundaries, data flows, external interfaces, interconnections, inherited controls, common-control dependencies, and significant changes.

Oversee assessment execution for ATO, reauthorization, annual assessment, significant-change assessment, and continuous monitoring activities.

Brief assessment status, systemic risks, unresolved findings, remediation priorities, and authorization recommendations to senior stakeholders.

Mentor assessors, calibrate assessment judgments, and ensure independence and objectivity across the assessment lifecycle.

Develop and maintain strong relationships with stakeholders across the organization

You Have:

8+ years of experience with cybersecurity including substantial DoD or federal RMF, security assessment, security engineering, or authorization

Experience with eMASS, analyzing STIG, SCAP, ACAS findings, POA&Ms, architecture, inherited controls, compensating controls, and technical evidence

Experience leading security control assessments and producing or approving SSPs, SAPs, SARs, POA&Ms, risk assessments, and authorization packages

Experience with administration of Windows, Linux, AWS Cloud, and containerization systems and software configuration

Experience with technical writing, facilitation, quality-assurance, team leadership, and stakeholder-management capabilities

Knowledge of NIST SP 800-53, NIST SP 800-37, DoD RMF, STIGs, vulnerability management, and security-control assessment methodology

Ability to evaluate complex enterprises, cloud, hybrid, containerized, data, and AI-enabled architectures and communicate risks at the AO and executive levels

Ability to lead, organize, and complete various cybersecurity testing events including using applicable automated security scanning tools, system required manual STIGs and SRGs and compiling, reviewing, and analyzing results and providing to the ISSM for review and finalization

TS/SCI clearance

Bachelor's degree in a technical field such as Engineering or Cyber

Nice If You Have:

Experience reviewing system connection requests for completion and ensure that requirements are met and make recommendations to the ISSM for approval

Experience performing dynamic security assessments triggered by system changes, threat changes, vulnerabilities, incidents, or mission conditions

Ability to communicate cybersecurity test result outcomes, risks, and suggest fixes to the project engineering team to fix or…

To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary