Enterprise Cybersecurity GRC Security Controls Assessor
Listed on 2026-07-20
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Overview
Your growth matters to us - explore our career development opportunities.
Enterprise Cybersecurity GRC Security Controls Assessor
- The Opportunity:
Enterprise Cybersecurity (ECS) Governance, Risk, and Compliance (GRC) plays a pivotal role in safeguarding the organization's sensitive information and ensuring compliance with cybersecurity regulations. As the Security Controls Assessor, you will support the GRC team responsible for the assessment and management of compliance and regulatory requirements with key stakeholders. You will work closely on Booz Allen’s internal information systems and environments, assessing their compliance with NIST SP 800-171 security controls and Cybersecurity Maturity Model Certification (CMMC) requirements.
You will review technical and environmental details to assess the threat landscape and provide a hands-on approach with accountability for assessing and managing compliance and regulatory requirements with key stakeholders. Due to the nature of work performed within this facility, US citizenship is required.
- Review and assess cybersecurity controls, artifacts, and scanning results to evaluate effectiveness and ensure continuous compliance.
- Advise on technical security implementations and partner with IT, operations, and delivery teams to drive GRC initiatives and security awareness.
- Leverage automation and AI-driven tools to streamline control assessments, evidence collection, and compliance validation activities.
- Apply knowledge of DoD, FISMA, FedRAMP, NIST, RMF, Dev Sec Ops , and Infrastructure-as-Code (IAC) principles to IL5 environments and risk mitigation.
- Assess alignment of security controls with NIST SP 800-53 (rev. 4/5), NIST SP 800-171 (rev. 2/3), FedRAMP, CMMC, and SOC 2 Type II.
- Identify vulnerabilities, manage risk lifecycle, and communicate remediation plans and metrics across business lines.
- 8+ years of experience in cybersecurity roles such as Security Control Assessor (SCA), System Steward, Information System Owner (ISO), Controls Validator, ISSO, ISSE, or ISSM.
- Experience performing in-depth assessments of cybersecurity controls, artifacts, and scanning results to evaluate effectiveness and ensure continuous compliance.
- Experience partnering with IT, operations, and delivery teams to provide expert guidance and drive GRC initiatives.
- Experience using automation and AI-driven tools to streamline control assessments and evidence collection.
- Knowledge of network defense tools and security control alignment with NIST SP 800-53, NIST SP 800-171, FedRAMP, CMMC, or SOC 2 Type II.
- Ability to manage the full risk lifecycle and communicate metrics on compliance trends and vulnerability management.
- HS diploma or GED.
- Problem-solving mindset with the ability to identify pragmatic solutions and execute with minimal supervision.
- Ability to rapidly comprehend complex problems, draw logical conclusions, and drive closure with sound decisions.
- Strong communication and collaboration skills to engage with senior and executive management.
- Excellent analytical and problem-solving abilities.
At Booz Allen, we offer health, life, disability, financial, and retirement benefits, paid leave, professional development, tuition assistance, work-life programs, dependent care, and an employee recognition program. Eligibility varies by employment type and location. The projected compensation range is $77,600 to $176,000 (annualized USD). This posting will close within 90 days from the posting date.
Identity and AI UsageAs part of the hiring process, we may conduct identity verification to ensure authenticity. Interviews may involve on-camera participation. AI usage during interviews is prohibited unless explicit permission is provided.
Work Model- Remote
:
May require in-person work at a Booz Allen or customer facility on occasion. - Hybrid
:
Regular in-office work at Booz Allen facilities in alignment with role needs; may involve customer facilities. - Onsite
:
Work primarily at Booz Allen or customer facilities with collaboration with colleagues and customers.
All qualified applicants will receive consideration for employment without regard to disability, protected veteran status, or any other status protected by applicable law.
#J-18808-Ljbffr(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).