Security Control Assessor - TS/SCI with Polygraph
General Dynamics Information Technology · Bethesda, MD · Yesterday
Information Technology$143k–$188k/yrFull-time
About the role
Conduct Security Control Assessments of IC information systems, with specialized expertise evaluating Zero Trust maturity across identity, device, network, application, data, and analytics domains.
Responsibilities
- Review and validate technical evidence of Zero Trust capability implementation, distinguishing verified, testable controls from self-reported claims.
- Apply hands-on technical knowledge of identity/access management, network segmentation, endpoint detection, data protection, and security monitoring to assess real-world implementation maturity.
- Identify capability gaps and documents risk-based findings that hold up to senior leadership review.
- Communicates assessment results clearly to both technical teams and executive stakeholders.
- Stays current on Zero Trust architecture standards and evolving assessment methodologies.
Qualifications
- Bachelor's degree in computer engineering, Computer Science, Electrical Engineering, Information systems, Information Technology, Cybersecurity, or a closely related discipline.
- Four (4) years of additional demonstrated work experience in Security Control Assessor (SCA) and Defensive Cyber Operations (DCO) Testing will be accepted in lieu of a bachelor's degree.
- A Master's degree in an applicable discipline may be substituted for three years of demonstrated work experience.
- Three (3) years of cybersecurity experience with at least one year of experience conducting SCAs under ICD 503/CNSSI 1253 NIST Cybersecurity Framework, Risk Management Framework (RMF), or a similar framework.
- One full year of SCA experience within the last three calendar years.
- One full year supporting cloud environment and experience performing security assessments in a cloud environment (AWS, Google, IBM, Azure, and Oracle).
- Must meet Department of Defense (DOD) 8570.01-M baseline certification requirement for Information Assurances Technical (IAT) Level III (CASP+CE, CCNP Security, CISA, or CISSP or Associate, GCED, GCIH, or CCSP).
- Knowledge of Independent Verification & Validation (IV&V) of security controls.
- Knowledge of general attack strategies (e.g., MITRE ATT&CK Framework).
- Knowledge of NISPOM, ICD 503, NIST SP 800-53, ICD 705, and other ICDs as appropriate.
- Skill in conducting vulnerability scans and recognizing vulnerability in security systems (e.g., Cloud Environments) AWS, Google, IBM, Azure, and Oracle.
- Make recommendations to the IC CISO or designee for improving TTPS for better cyber threat protection.
- Clearance: TS/SCI with Polygraph
Pay
The likely salary range for this position is $142,792 - $187,709.
Schedule
- Scheduled Weekly Hours: 40
- Travel Required: Less than 10%
- Telecommuting Options: Onsite
- Work Location: USA MD Bethesda
Benefits
- Variety of medical plan options, some with Health Savings Accounts
- Dental plan options
- Vision plan
- 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match
- Full flex work weeks where possible
- Variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave
- Short and long-term disability benefits
- Life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance