Security Control Assessor (SCA)
Position Overview
LV8D Solutions is seeking a Security Control Assessor (SCA) to conduct independent assessments of the management, operational, and technical security controls employed within or inherited by an information technology (IT) system to determine the overall effectiveness of the security controls. A Security Control Assessor (SCA) performs comprehensive INFOSEC assessment of management, operational, and technical security controls to determine overall effectiveness of the controls for A&A determination throughout a program's system lifecycle. SCAs provide an assessment of the severity of weakness or deficiencies discovered in the Information System (IS) and its environment of operation and recommend corrective actions to address identified vulnerabilities. Prior to initiating the security control assessment, the SCA reviews the System Security Plan (SSP) to ensure the plan provides a set of security controls for the ISs that meet the stated security requirements. Additionally, the SCA must verify that all allocated controls have an acceptable status (i.e., implemented, excepted, or inherited) with appropriate documented details and provides responses in the Government's Risk Management Framework (RMF) tools.
Key Responsibilities
- Reviews IS for compliance with applicable Intelligence Community (IC), Department of War (DoW), and National Directorate (ND) guidance, and make recommendations to the Government
- Provides ISs security advice and guidance Joint Analytical Workstation (JAW) applicable IC, DoW, and NDs and guidance to Government and industry partners for the protection of data at all classification levels including Sensitive Compartmented Information (SCI)
- Evaluates threats and vulnerabilities to ISs to ascertain the need for additional safeguards and recommend approval, disapproval, or waiver(s) for IS processing national security data at industry and/or Government facilities
- Supports development and implementation of directives and guidance for policies
- Provides input for consideration in the promulgation of future ISs security policy
- Supports and/or conduct site visits and assessments to inspect and verify IS reports
- Ensures security control assessments are completed for each IS
- Supports the preparation and delivery of presentations, briefings, reports, and memoranda associated with the RMF process
- Uses the RMF system of record to complete RMF workflow duties and maintain the asset documentation repository
- Establishes and maintains means and methods to track RMF process workflow activities to inform task volume, velocity, and duration of activities
- Prepares the final Security Assessment Report (SAR) containing the results and findings from the assessment at the conclusion of each security control assessment activity and the Authorization Recommendation
- Ensures appropriate IS security requirements including applicable Interface Control Documents (ICDs), DoW Instructions, NDs and other guidance are addressed and applied and appropriate documentation is prepared by the system owners or programs. The documentation will be contained in the Security Assessment Package, including, but not limited to, the Concept of Operations (CONOP), SSP, Systems Requirements Traceability Matrix, Risk Management Matrix, Test Results, interface control documents, requests for changes, test plans, and other related program security documentation
- Collaborates with Information Security Officers (ISOs) and Common Control Providers to initiate Plan of Action and Milestones (POAMs) for ISs based on findings and recommendations from the SAR
- Reviews and approves the IS Security Assessment Plan which is comprised of the Security Controls Traceability Matrix and the Security Control Assessment Procedures
- Tracks the completion of the SAR
- Reviews, coordinates, and responds to security issues as requested by the Government
- Provides A&A support to the Government for the protection of special programs and tactical operations related activities
- Supplies the effort needed to conduct the reviews and write reports to support Integrated Security Assessment Program (ISAP) or Technical Information Systems Security Reviews (TISSRs)
Required Qualifications
- Practical experience performing information systems A&A as defined in applicable ICDs and guidance
- Practical experience utilizing risk management strategies for information technology solutions
- Technical understanding of emerging technologies and their implementation within Government system and network environments
- Knowledge of information technology concepts used in the evaluation of security performance and integrity of state-of-the-art applications, communications systems, hardware, software, satellite control systems, and information processing systems
- Technical understanding of information technology systems, software, and networks
- Ability to effectively coordinate A&A activities of industry and Government information systems to meet acquisition milestone requirements
- Effective technical report and general correspondence writing ability
- Ability to manage and track systems or programs involved in the A&A process
- Experience developing and implementing security related directives and guidance for Information Assurance, Information Technology, and Information Management
- Experience working with a mixed level skill team to ensure that appropriate knowledge and skill transfer occurs
- High school's degree and 7+ years of relevant experience, or
- Associate's degree and 7+ years of relevant experience, or
- Bachelor's degree and 5+ years of relevant experience, or
- Master's degree and 3+ years of relevant experience
Certifications
Must have one of the following IAM Level 2 Certifications:
- CGRC (Previously CAP)
- CASP
- CISSP
- CISM
- GSLC
- CCISO
Security Requirements
- U.S. Citizenship
- Active Top Secret/Sensitive Compartmented Information (TS/SCI) clearance
- Active Counterintelligence (CI) or Full Scope (FS) Polygraph
Work Environment
- On-site work in a government or contractor facility
- Occasional travel (up to 10%)
About LV8D Solutions
LV8D Solutions is an elite Systems Engineering and Technical Advisory (SETA) company that delivers advanced systems engineering, integration, acquisition, mission operations, network communications, and cybersecurity support to our defense and intelligence customers. Founded in 2019, we apply our deep technical expertise, understanding, and mission-first mindset to design, acquire, and implement complex, high-impact solutions for our Intelligence Community (IC) and Department of War (DoW) customers. We specialize in every aspect of our customers' space and ground mission systems while offering exceptional work-life balance and an exemplary compensation and total rewards package designed to recruit, train, and retain top talent and committed to national defense and career growth.
Benefits
Performance & Recognition
- Performance-based bonus opportunities tied to contract or organizational performance
- Retention Incentive Benefit Bounty: Receive a payout for unused annual company contributions designated for health insurance premiums and professional training
- Referral Bonus: Earn up to $5,000 for each successful employee referral
- Customer Recognition Letter of Appreciation (LoA) Bonus Opportunities: Bonus opportunities based on customer recognition received through Letters of Appreciation
- Milestone Rewards: Celebrate your career achievements with anniversary awards on your 1st, 5th, 10th, and 20th years of service
Financial & Retirement Benefits
- Profit Sharing: Receive an annual contribution equal to 4% of your W-2 gross earnings into your 401(k), with immediate vesting
- 401(k) Company Match: The company matches your 401(k) contributions dollar-for-dollar up to 6% of your monthly contribution, with immediate vesting
Career Development
- Annual financial support for professional training and industry certifications
- Enhanced financial support for employees actively pursuing a degree at an accredited institution
Work-Life Balance
- Flexible work hours
- Competitive paid time off (PTO)
- Company holidays
Health & Wellness Benefits
- Medical Coverage: Three comprehensive Medical/Rx insurance plan options to meet the unique and individualized benefit needs of our employees
- Dental & Vision: Comprehensive dental insurance for employees and eligible dependents; comprehensive vision insurance for employees and eligible dependents
- Income Protection: 100% Company-Paid Short-Term Disability Insurance; 100% Company-Paid Long-Term Disability Insurance
- Life Insurance: 100% Company-Paid Basic Term Life Insurance with Accidental Death & Dismemberment (AD&D) coverage; optional employee-paid Supplemental Voluntary Life Insurance