SCA Lead
Location: Remote / Hybrid / Onsite (Based on Customer Requirements)
Clearance: Ability to earn a U.S. Public Trust Clearance
Employment Type: Full-Time
About the company
Disruptive Solutions, a Service-Disabled Veteran-Owned Small Business (SDVOSB), delivers mission-focused cybersecurity and technology solutions for federal and commercial clients. We specialize in advanced cybersecurity operations, AI/ML integration, cloud modernization, data governance, and risk management. With a proven track record supporting agencies like the Department of Defense (DoD), Department of Homeland Security (DHS), Cybersecurity and Infrastructure Security Agency (CISA), and the Department of Treasury, we deliver innovative solutions that maximize efficiency and strengthen cyber resilience. At our core, we are dedicated partners committed to securing the mission with innovation, integrity, and measurable impact.
About the role
Disruptive Solutions is seeking a Lead Security Control Assessor (Lead SCA) to lead cybersecurity assessment activities supporting Department of Defense and Federal Civilian agencies. This individual will serve as the technical lead for Security Control Assessments (SCAs), providing oversight, quality assurance, and mentorship to assessment teams while serving as the primary cybersecurity advisor to government stakeholders. The Lead SCA will plan, coordinate, and execute security control assessments for on-premises, hybrid, and cloud environments in accordance with the NIST Risk Management Framework (RMF). This role requires extensive experience interpreting NIST security guidance, evaluating technical implementations, leading assessment teams, and presenting cybersecurity risk to executive leadership.
Responsibilities
- Lead teams of Security Control Assessors supporting multiple federal information systems.
- Serve as the technical Subject Matter Expert (SME) for NIST RMF, NIST SP 800-53 Rev. 5, 800-53A, 800-37, 800-115, and 800-30.
- Plan, coordinate, and execute security control assessments throughout the Authorization to Operate (ATO) lifecycle.
- Develop Security Assessment Plans (SAPs), Security Assessment Reports (SARs), executive briefings, and risk recommendations.
- Lead technical reviews of System Security Plans (SSPs), POA&Ms, and authorization packages.
- Evaluate technical, operational, and management controls across enterprise, cloud, and hybrid environments.
- Assess AWS, Azure, SaaS, PaaS, and IaaS implementations for compliance with federal security requirements.
- Lead vulnerability analysis using enterprise scanning platforms and validate remediation activities.
- Support penetration testing activities, review Rules of Engagement, and present technical and executive-level findings.
- Perform API security testing and evaluate application security controls.
- Utilize scripting and automation to improve assessment quality and efficiency.
- Review assessment quality, mentor junior assessors, and ensure consistency across assessment teams.
- Manage schedules, resource allocation, customer communications, and assessment deliverables.
- Present cybersecurity risks, recommendations, and assessment findings to senior government leadership.
Requirements
- Bachelor’s degree (or equivalent experience).
- 7+ years of cybersecurity experience supporting federal information systems.
- 5+ years performing Security Control Assessments.
- Demonstrated experience leading teams of three or more cybersecurity professionals.
- Expert knowledge of: NIST SP 800-53 Rev. 5, NIST SP 800-53A, NIST SP 800-37, NIST SP 800-115, NIST SP 800-30.
- Experience developing: Security Assessment Plans (SAPs), Security Assessment Reports (SARs), executive-level cybersecurity briefings.
- Experience assessing enterprise network architectures and cloud environments including SaaS, PaaS, and IaaS.
- Experience interpreting vulnerability data and validating remediation activities.
- Experience using enterprise vulnerability assessment tools such as: Tenable/Nessus, Qualys, Burp Suite, Imperva, Prisma Cloud (Twistlock), Core Impact, Netsparker/Invicti, AppDetective.
- Experience with scripting and automation using PowerShell, Python, Bash, or similar languages.
- Experience performing API security assessments.
- Experience utilizing cloud-native security assessment and compliance tools.
- Experience supporting or leading penetration testing activities and reporting technical and executive-level results.
- Strong written, verbal, and executive communication skills.
Preferred Qualifications
- Certified Authorization Professional (CAP)
- CASP+
- CISM
- CEH
- GIAC certifications