Mid-Level Security Control Assessor
System One · Bethesda, MD · 1 mo ago
OTHR$140k/yrContract
Location: Bethesda, Maryland • Hybrid – onsite and remote • 40 hours/week • Public Trust clearance required (current clearance highly desired) • US citizenship required • Work expected to begin on or about August 30, 2026
About the role
System One IT has a direct hire opening for a mid-level Security Control Assessor to support a National Healthcare agency. This position supports a federal end customer and is currently in the bid process, expected to be awarded in early August.
Responsibilities
- Serve as the technical authority for independent security assessments in accordance with NIST standards and agency policies.
- Lead planning, execution, and validation of Security Control Assessments throughout the authorization lifecycle.
- Review and validate authorization packages, including SSPs, SAPs, SARs, POA&Ms, and supporting evidence.
- Assess the implementation and effectiveness of security controls through documentation reviews, interviews, and technical validation.
- Review FedRAMP cloud packages and inherited controls as applicable.
- Document findings, recommendations, and remediation activities.
- Support cybersecurity audits and continuous improvement initiatives.
- Provide risk-based recommendations to the Authorizing Official while maintaining assessment independence.
- Mentor junior assessors and improve assessment methodologies.
Requirements
- Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or related discipline, or four (4) additional years of relevant experience.
- Ten (10) or more years of progressive experience supporting federal cybersecurity, RMF, Security Control Assessment, or information assurance programs.
- Significant experience leading independent Security Control Assessments and validating RMF authorization packages.
- Experience conducting security control testing, evidence validation, and developing SARs per NIST SP 800-37, NIST SP 800-53 Rev. 5, and JCAM.
- Experience supporting federal civilian agencies is highly desirable.
- Experience reviewing FedRAMP authorization packages and supporting OIG, GAO, or independent assessments.
- Strong knowledge of federal cybersecurity assessment principles, excellent analytical and technical writing skills, and effective communication skills.
Pay
$140,000 range annually
Benefits
- Medical, dental, and vision coverage
- Spending accounts
- Life insurance and voluntary plans
- 401(k) plan