Jobs · Information Technology · Virginia

Security Control Assessor Representative (SCAR)

KBR Careers · Alexandria, VA · 3 days ago
Information Technology$130k–$170k/yrFull-time

About the Role

KBR is seeking a Security Control Assessor Representative (SCAR) to provide cybersecurity support to systems and applications for the Test Resource Management Center (TRMC) and the Research, Development, Test and Evaluation (RDT&E) Community. The security controls assessor will be responsible for evaluating the security controls within networks/systems to identify vulnerabilities and recommend actions to correct problems, working with the TRMC Cybersecurity team.

Responsibilities

  • Conduct in-depth assessments of the management, operations, and technical security controls.
  • Analyze information and prepare reports describing the vulnerability level of the network/system with specific detail as to what compromises data systems.
  • Develop a plan to address vulnerabilities and continue to monitor the security of network systems.
  • Alongside the TRMC Cybersecurity Team Lead develop and implement cybersecurity independent audit processes for application software/networks/systems and oversee ongoing independent audits to ensure processes and procedures are in compliance with organizational and mandatory cybersecurity requirements and accurately followed by Systems Administrators and other cybersecurity staff when performing their day-to-day activities.
  • Develop security compliance processes and/or audits for external services (e.g., cloud service providers, data centers).
  • Verify that application software/network/system security postures are implemented as stated, document deviations, and recommend required actions to correct those deviations.
  • Perform validation steps, comparing actual results with expected results and analyze the differences to identify impact and risks.
  • Apply confidentiality, integrity, and availability principles.
  • Draft statements of preliminary or residual security risks for system operation.
  • Maintain information systems assurance and accreditation materials.
  • Responsible for identifying, assessing, and managing cybersecurity capabilities and services, providing leadership, team coordination, and subject matter expertise in Assessment and Authorization (A&A) packages and leveraging the A&A process steps as a means for system authorization.
  • Review and analyze Plans of Actions and Milestones (POAMs), Security Assessment Reports (SAR), Security Assessment Plans (SAP).
  • Conduct required vulnerability analysis to support mitigation and residual risk determination.
  • Provide Risk Management Framework guidance and assistance to system engineers and program managers on assessment and risk-related matters and make risk recommendations.
  • Review security requirements, products, configurations, and cybersecurity architectures for compliance with DoD policies.
  • Support a general working knowledge of applicable assessment methods, such as Secure Technical Implementation Guides (STIGs) and automated vulnerability scans and analyze technical test data.
  • Participate in technical interchanges, security impact assessments and security assessment meetings with PMs, Cyber Team Lead, ISSOs/ISSMs and the AO.

Qualifications

  • Subject Matter Expert (SME) with proven experience regarding the Risk Management Framework (RMF) and assessing DoD Security Controls.
  • Experience with Cybersecurity in the RDT&E Community.
  • Proven experience conducting security risk assessments for RMF authorizations.
  • Familiarity with Vulnerability scanning tools and ability to recognize vulnerabilities in information systems and networks.
  • Knowledge of cybersecurity principles and organizational requirements (relevant to confidentiality, integrity, availability, authentication, non-repudiation).
  • Knowledge of cyber threats and vulnerabilities.
  • Knowledge of cloud computing service models Software as a Service (SaaS), Infrastructure as a Service (IaaS), and Platform as a Service (PaaS).
  • Bachelor's degree in engineering, Computer Science, Information Technology, or relevant field along with work experience in data security.
  • Strong project management, teamwork, and communication skills in addition to intermediate technical knowledge.
  • Ability to adapt to process changes, systems changes, in a fast-paced environment.
  • Ability to interface with senior leadership.
  • Ability to support high visibility or high priority projects.
  • Advanced Certification (IAM III) for SCA per DOD MANUAL 8140.03.
  • Travel 25% of time.
  • Top Secret / SSBI clearance required.

Pay

$130,000 - $170,000 (For Maryland, Virginia, DC and California Only). The offered rate will be based on the selected candidate's knowledge, skills, abilities and/or experience and in consideration of internal parity.

Benefits

  • 401K plan with company match
  • Medical, dental, vision, life insurance, AD&D, flexible spending account, disability, paid time off, or flexible work schedule
  • Career advancement through professional training and development

Similar jobs