Junior Security Control Assessor
System One · Bethesda, MD · 1 wk ago
OTHR$100k–$115k/yrContract
Location: Bethesda, MD (mostly remote, occasional onsite required)
About the role
We’re hiring a Junior Security Control Assessor to support independent security control assessments across the system authorization lifecycle. You’ll work under a senior assessor and help evaluate security control implementation, validate evidence, and document results in alignment with NIST Risk Management Framework (RMF) and NIST SP 800-53 Rev. 5, using JCAM practices. This is a great fit for someone who enjoys cybersecurity compliance, evidence-based assessments, and strong technical writing—without being the person who authors the entire authorization package.
Responsibilities
- Support independent Security Control Assessments (SCAs) across the authorization lifecycle
- Review and validate security authorization documentation (SSP, SAP, SAR, POA&M, contingency plans, and supporting artifacts)
- Assess security control implementation through documentation review, interviews, and technical validation
- Help evaluate cloud security packages and inherited controls (as applicable)
- Document findings, recommendations, and remediation activities clearly and professionally
- Assist with evidence validation and remediation tracking
- Partner with system owners and ISSOs while maintaining assessor independence
Requirements
- Education: Bachelor’s in Cybersecurity, IT, Computer Science, Information Systems (or similar) OR 4 additional years of relevant experience in lieu of a degree
- Experience: 3–5 years supporting cybersecurity, information assurance, RMF, security assessments, compliance, or IT operations
- Working knowledge of: NIST RMF (800-37) and NIST SP 800-53 Rev. 5
- JCAM methodology
- Experience reviewing security documentation and assessment evidence/artifacts
- Strong analytical skills and technical writing ability
- Public Trust eligibility (Tier 2/3) required
Preferred Qualifications
- Experience with eMASS or similar GRC platforms
- Familiarity with FedRAMP, cloud security concepts, C-SCRM, and related federal security frameworks
- Experience supporting independent audits/assessments (e.g., external review organizations)
Skills
- JCAM
- Tenable
- CrowdStrike
- Splunk / Splunk Enterprise
- AWS
- Python
Preferred Certifications
- ISC2 CC or CGRC
- CompTIA Security+, CySA+, PenTest+, CASP+
- CEH
- Microsoft SC-900
Benefits
- Medical, dental, and vision coverage
- Spending accounts
- Life insurance
- Voluntary plans
- 401(k) plan
Pay
$100,000–$115,000/year
Schedule
40 hrs/week
Target start: by end of August 2026