Security Control Assessor (SCA) I
Targeted Solutions, LLC · El Segundo, CA · 5 days ago
On-siteInformation TechnologyFull-time
Responsibilities
- Perform oversight of the development, implementation and evaluation of IS security program policy, with special emphasis on integrating existing SAP network infrastructure.
- Conduct assessments of ISs using the Risk Management Framework (RMF) methodology in accordance with the JSIG.
- Advise ISO, IDO, PSO, and DAO/AO on assessment and authorization issues.
- Evaluate Authorization packages and make recommendations to the AO and/or DAO for authorization.
- Evaluate IS threats and vulnerabilities to determine if additional safeguards are needed.
- Assess the impact levels for Confidentiality, Integrity, and Availability for the information on a system.
- Ensure security assessments are completed and results are documented, preparing the Security Assessment Report (SAR).
- Develop and implement a Plan of Action and Milestones (POA&M) for identified weaknesses based on findings and recommendations from the SAR.
- Evaluate security assessment documentation and provide written recommendations for security authorization to the Government.
- Discuss recommendations for authorization and submit security authorization packages to the AO/DAO.
- Assess proposed changes to Authorization boundaries and mission needs to determine continuation of operations.
- Review and concur with all sanitization and clearing procedures in accordance with Government guidance and/or policy.
- Aid in Government compliance inspections and ensure proper handling of security incidents related to cybersecurity.
- Ensure the organization addresses all phases of the system development life cycle (SDLC).
- Evaluate hardware and software for their security impact on Authorization boundaries.
- Evaluate the effectiveness and implementation of Continuous Monitoring Plans.
- Represent the customer on inspection teams.
Requirements
- 5 - 7 years of directly related experience.
- Minimum of three (3) years’ experience in SAP, SCI, or Collateral Information Systems (IS) Security.
- Prior performance in the role of ISSO and ISSM.
- Bachelor’s degree in a related discipline or equivalent experience (4 years).
- Must meet position and certification requirements outlined in DoD Directive 8570.01-M for Information Assurance Technician Level III or Information Assurance Manager Level I within 6 months of hire.
- Top Secret with SCI eligibility.
- Eligible for access to Special Access Program Information.
- Willingness to undergo a Counterintelligence polygraph.
- Ability to regularly lift 50 lbs.