Junior Security Control Assessor
Newberry Group · Fort Meade, MD · 1 mo ago
On-siteInformation Technology$50k–$60k/yrFull-time
About the Role
Newberry Group seeks a Jr. Security Control Assessor to support its Government Client. This role requires 85% travel to various government locations both domestically and internationally.
Responsibilities
- Conduct cybersecurity assessments, audits, and inspections for DoD organizations and partners handling DoD information or connecting to the DoDIN
- Evaluate systems and Defensive Cyberspace Operations using cyber threat emulation and performance-based testing
- Adhere to policies and processes for each assessment type
- Support assessment development and execution to ensure security expertise is properly applied
- Coordinate logistics, test plans, and scope with the SCA Team Lead
- Perform vulnerability assessments, capture results using STIG Viewer or designated tools, and document findings in eMASS
- Analyze security gaps and provide mitigation recommendations
- Validate cybersecurity controls, TTPs, STIGs, RMF controls, and compliance with DoD policies and guidelines
- Provide risk analysis and assessment results for authorization recommendations
- Participate in daily assessment reviews, in-briefs, and out-briefs, sharing findings with the SCA-R
RMF Review Duties
- Review applicable controls to determine compliance status and enter all test results into eMASS
- Provide key assessment results to the team lead including the number of controls reviewed and risk/residual information for inclusion in the authorization recommendation
- Be certified via the ACP IAW the ACP CONOPS before conducting any assessments
- Be certified in a minimum of two (2) technologies and RMF Control Validation before conducting any assessments
- Maintain active accounts to the tools and systems required to perform risk assessments
- Participate in the in-brief and out-brief of each assessment
Qualifications
- Bachelor's degree in a related area of study (Security, Information Technology)
- 0-1 year of experience required – willing to train on both technologies and RMF
- Active DoD Top Secret clearance with SCI eligibility preferred, but can begin with a Secret clearance
- IAT Level II certification active or obtained within 90 days of hire
Preferred Certifications
- CompTIA Cybersecurity Analyst (CySA+)
- CompTIA Security+
- EC-Council Certified Network Defense (CND) v3
- Red Hat Certified System Administrator (RHCSA)
- CCNA Security
- Global Industrial Cyber Security Professional (GICSP)
- GIAC Security Essentials (GSEC)
- Systems Security Certified Practitioner (SSCP)
Desired Knowledge & Skills
- Familiarity with STIGs (Security Technical Implementation Guides), Security Requirement Guides (SRGs), Plan of Action and Milestones (POA&Ms), and cybersecurity best practices
- Understanding of the RMF process, NIST SP 800-37, NIST SP 800-53, CNSSI 1253
- Familiarity with relevant tools such as eMASS, STIG Viewer, Nessus, ACAS, SCAP, or HBSS
- Strong written and verbal communication skills for reporting assessment findings
Training
Training through the DISA program will be provided after hire and consist of at least 3 months.
Location & Clearance
- Hybrid position – approximately 25% remote support with up to 75% CONUS and OCONUS travel
- Active Secret Clearance (will sponsor); DoD Top Secret/SCI Clearance required or Interim Top Secret preferred
- DoD 8570 IAT II (active or will obtain within 90 days of hire)
Compensation
$50,000 - $60,000
Benefits
- Medical coverage with three plan options
- Dental and vision coverage
- Personal time off
- Paid holidays
- Paid parental leave
- Telecommuting if available
- Retirement savings accounts (Pre-Tax and Roth)
- Flexible and dependent care savings accounts
- Life insurance
- Long and short-term disability coverage
- Tuition and training reimbursement
- Employee assistance program