Security Control Accessor
NTG · Arlington, VA · Yesterday
On-siteInformation TechnologyFull-time
Northern Technologies Group (NTG) is seeking an experienced Security Control Accessor to provide expert-level support to the Department of Defense (DoD) Chief Information Officer’s SAP IT Cybersecurity program. This role delivers technical and managerial leadership across RMF activities, system accreditation, and enterprise-wide cyber compliance.
Responsibilities
- Lead Risk Management Framework (RMF) activities, including the development, review, and validation of:
- System Security Plans (SSPs)
- Security Assessment Plans (SAPs)
- Plan of Action and Milestones (POA&Ms)
- Security Assessment Reports (SARs)
- Security Control Traceability Matrices (SCTMs)
- Act as an advisor to the Authorizing Official (AO), providing SME input to support Authorization to Operate (ATO) decisions.
- Perform system security assessments, documentation reviews, and artifact evaluations in eMASS or equivalent tools.
- Validate control inheritance and implementation across hybrid, cloud, AI/ML-enabled, or cross-domain architectures.
- Provide technical guidance to system owners, ISSMs, SCAs, and program staff to maintain compliance with DoD cybersecurity mandates.
- Assist in development and standardization of SOPs, cybersecurity scorecards, and dashboards.
- Support cybersecurity incident response documentation and post-event reporting in classified environments.
- Participate in enterprise-wide security initiatives, policy updates (e.g., JSIG revisions), and threat awareness activities.
- Serve as eMASS administrator: manage accounts, permissions, workflows, and enterprise-level metrics reporting.
Requirements
- 15 years of experience and a Master's degree in Cybersecurity (or equivalent); alternatively, 17 years of experience with a Bachelor's degree, or 21 years of relevant experience with no degree.
- Leadership in RMF/A&A efforts.
- Active TS/SCI clearance with eligibility for SAP access.
- Cybersecurity certification at IAT Level III or IAM Level III (e.g., CISSP, CISM, CASP+).
Physical Demands and Work Environment
The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this position. Reasonable accommodations may be made to enable individuals with disabilities to perform these functions.
- Regularly required to talk or hear.
- Frequently required to use hands or fingers, handle or feel objects, tools, or controls.
- Occasionally required to stand, walk, sit, and reach with hands and arms.
- Must occasionally lift and/or move up to 25 pounds.
- Specific vision abilities required include close vision, distance vision, and the ability to adjust focus.
- The noise level in the work environment is usually low to moderate.
Schedule
- Standard 8-hour workdays, Monday–Friday (core hours: 9 AM–3 PM).
- Up to 10% travel: local travel within the National Capital Region (NCR) may be required; occasional CONUS travel possible.
- On-call response may be required for critical system issues or classified facility access.