Security Control Assessor Representative Task Lead
Electrosoft Services, LLC is an award-winning company that provides comprehensive technology-based solutions and services to federal customers. While cybersecurity is our specialty, we also focus on ICAM, Zero Trust, digital engineering and transformation, and enterprise AI and intelligent automation. We retain highly qualified employees and offer them meaningful work, growth opportunities, and work-life balance. Our teamwork culture includes Lunch & Learn sessions, fun group activities, and recognition for outstanding effort.
About the role
Electrosoft is seeking a Security Control Assessor Representative (SCAR) Task Lead to oversee and manage support and communication for our DoD customer requirements at Scott Air Force Base, IL. The SCAR lead will independently assess the adequacy and compliance of security controls applied from the SCARs to the agency on behalf of the Government SCA and Authorizing Official (AO). This role involves managing efforts to assist Government personnel with comprehensive assessments of security controls for over 40 Programs of Record across the Enterprise, as well as maintaining current documentation on authorization processes and procedures.
Responsibilities
- Oversee day-to-day work for specific contract deliverables.
- Lead efforts to assess, identify, and provide a listing of recommended enterprise security controls/enhancements for AO approval, ensuring mission assurance for cyber USTRANSCOM terrain systems.
- Oversee and manage SME support for RMF activities within and/or outside Enterprise Mission Assurance Support Service (eMASS) or other designated tools.
- Act as the primary link between team members, project managers, and the customer, ensuring work stays on schedule and within budget according to contractual requirements.
- Provide oversight and management of technical and operational analyses of supporting artifacts and offer risk analysis recommendations to the SCA.
- Perform triage of authorization, POA&M, System Security Plan, System Categorization, and risk acceptance requests using the Government RMF Artifact Quality Rubric.
- Identify non-compliant submissions, document them in the Package Return Report (PRR), and provide oversight review for accuracy before submission to the Government SCA.
- Validate that SCARs accurately review security artifacts and assess both technical and functional adequacy of cybersecurity/Information Assurance (IA) controls.
- Oversee and manage the Independent Verification and Validation (IV&V) process within eMASS on NIPRNet and SIPRNet, verifying controls are in place, operating as intended, and producing desired outcomes.
- Compile Authorization Official packages, including risk assessments, required artifacts, and approval documents to support risk recommendations to the AO in accordance with Government guidance.
- Review and coordinate RMF packages such as categorizations, security plans, and POA&Ms for signature by approved authorities as designated by the Government.
- Manage eMASS user accounts (add, delete, and assign/update roles) for the customer’s instance of eMASS per Government direction.
- Track the status of checklists and packages from submission through approval or disapproval by the AO.
- Monitor team and individual metrics to ensure SCARs meet PWS required performance standards.
- Lead team meetings to coordinate daily and weekly operations and ensure continuity with the customer.
- Track all RMF package timelines and assignments, addressing questions or concerns posed by the SCA.
- Manage recurring WAR, MSR, IPR, and other contractually required metrics and report them to the PM as needed.
- Manage personnel absences, appointments, PTO authorizations, and semi-annual and annual performance evaluations.
- Monitor the health of the Security Posture Dashboard daily and report any variances to the PM or Cyber Security Risk Analyst.
- Monitor the status of PPSM deliverables and report any variances to the PM.
Requirements
- Current 8140 Cyber Security compliant certification in one of the following: CCISO, CISA, CISM, CISSP, CISSP-ISSEP, CySA+, GSLC, or GSNA.
- Minimum of 6 years of related experience.
- Master’s or higher in Computer Science, Cybersecurity, Data Science, Information Systems, Information Technology, or Software Engineering.
- Active DoD Secret security clearance.
- Thorough understanding and experience with the DoD RMF tool eMASS.
- Excellent written and verbal communication skills, with the ability to present material to senior DoD and non-DoD officials.
- Ability to communicate effectively with senior leaders and customers to clearly present technical approaches and findings.
- Demonstrated knowledge and understanding of the DoD mission.
- Experience with Ports, Protocols, Services Management (PPSM) is desired.
Pay
$140,000 USD - $160,000 USD