Security Control Assessor (SCA) Level II with Security Clearance
Job in
Washington, District of Columbia, 20001, USA
Listed on 2026-08-05
Listing for:
Rividium, Inc
Full Time, Part Time
position Listed on 2026-08-05
Job specializations:
-
IT/Tech
Cybersecurity, Information Security & Data Protection, Security Management & Operations
Job Description & How to Apply Below
The Security Control Assessor provides expert guidance on security control implementation, risk management, continuous monitoring, and authorization package development while working closely with System Owners, Information System Security Officers (ISSOs), Information System Security Managers (ISSMs), Security Engineers, Government Authorizing Officials (AOs), Security Control Assessor Representatives (SCARs), Branch Chiefs, and the DHS I&A Chief Information Security Officer (CISO). The successful candidate will possess extensive experience leading complex A&A efforts for enterprise systems operating in classified, hybrid, cloud, and Cross Domain Solution environments.
Key Responsibilities
* Lead comprehensive Assessment and Authorization (A&A) activities for DHS Intelligence Enterprise information systems operating in Top Secret/Sensitive Compartmented Information (TS/SCI), Secret, and Unclassified environments.
* Conduct security assessments for enterprise systems hosted in:
* On-premises data centers
* DHS DICE
* Commercial Cloud Enterprise (C2E)
* Intelligence Community (IC) Cloud
* AWS Gov Cloud
* Hybrid cloud environments
* Cross Domain Solution (CDS) environments
* CONUS and OCONUS C-LAN extension sites
* Lead project discovery sessions, kickoff meetings, and stakeholder engagements for new system authorizations, reauthorizations, and major system changes.
* Assess the implementation and effectiveness of NIST security controls and document findings within the Security Assessment Report (SAR) and Governance, Risk, and Compliance (GRC) platform.
* Identify security control deficiencies, vulnerabilities, and compliance gaps; provide technical recommendations to reduce organizational risk.
* Validate the accuracy and completeness of Plans of Action and Milestones (POA&Ms), ensuring corrective actions align with identified assessment findings.
* Monitor remediation activities and verify completion of corrective actions before recommending authorization decisions.
* Develop and prepare complete Authorization and Assessment packages, including:
* Authorization to Operate (ATO)
* Authorization to Connect (ATC)
* Interim Authorization to Test (IATT)
* Security Assessment Reports (SARs)
* Risk Recommendation Memoranda
* Risk Management Matrices
* Security Assessment Plans (SAPs)
* Project kickoff memoranda
* System Owner acknowledgment letters
* Conduct technical reviews of System Security Plans (SSPs), Contingency Plans, Configuration Management Plans, and supporting RMF documentation.
* Maintain and update Assessment and Authorization Standard Operating Procedures (SOPs) for all DHS I&A enclaves, ensuring annual review and compliance with evolving Federal and Intelligence Community requirements.
* Participate in Office of Inspector General (OIG), Federal Information Security Modernization Act (FISMA), and Intelligence Community Oversight Program (ICOP) audits, inspections, and cybersecurity assessments.
* Represent the program during DHS and Intelligence Community cybersecurity working groups and technical review boards.
* Maintain enterprise A&A Project Portfolio Listing Reports and Quarterly A&A Assignment Reports.
* Research emerging technologies, cybersecurity standards, and automation opportunities to improve A&A efficiency and support ongoing authorization initiatives.
* Prepare executive briefings, risk summaries, technical presentations, and decision support materials for the DHS I&A CISO, Government leadership, and Authorizing Officials.
* Mentor…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×