Traveling Security Control Assessor
About the role
The position involves significant travel and requires a Top Secret clearance with SCI eligibility and current DoD 8570 IAM II or IAT II certification. The maximum starting salary is $112,500.
Responsibilities
- Conduct cybersecurity assessments, audits, and inspections for DoD organizations and partners.
- Evaluate systems and Defensive Cyberspace Operations using cyber threat emulation and performance-based testing.
- Adhere to policies and processes for each assessment type.
- Support assessment development and execution to ensure security expertise is properly applied.
- Cook up logistics, test plans, and scope with the SCA Team Lead.
- Perform vulnerability assessments, capture results using STIG Viewer or designated tools, and document findings in eMASS.
- Analyze security gaps and provide mitigation recommendations.
- Validate cybersecurity controls, TTPs, STIGs, RMF controls, and compliance with DoD policies and guidelines.
- Provide risk analysis and assessment results for authorization recommendations.
- Participate in daily assessment reviews, in-briefs, and out-briefs, sharing findings with the SCA-R.
- Mentor and guide personnel by providing technical expertise, best practices, and professional development support to enhance team capabilities and knowledge.
Requirements
- Active DoD Top Secret clearance with SCI eligibility required.
- Current DoD 8570 IAM II or IAT II certification.
- Ability and willingness to travel for assessments as required, up to 85% of the time.
- Bachelor's degree (IT-related field preferred) and eight (8) years of cybersecurity or network security experience, including five (5) years of experience in a Certification and Accreditation/A&A role.
- Relevant experience may be considered in lieu of degree.
- Demonstrated experience with STIGs, SRGs, POA&Ms and cybersecurity best practices, as well as relevant tools such as eMASS, STIG Viewer, Nessus, ACAS, SCAP, or HBSS.
- Strong understanding of the RMF process, NIST SP 800-37, NIST SP 800-53, CNSSI 1253, as well as key technologies areas/domain such as: Network, Mobility, Windows, UNIX, Cloud Environments and Cloud Native Tools/Services, Host Based Security System (HBSS)/Endpoint Security Solutions (ESS), Databases, Applications.
- Strong written and verbal communication skills for reporting assessment findings.
Qualifications
- Eight (8) years of cybersecurity or network security experience, including five (5) years of experience in a Certification and Accreditation/A&A role.
- Relevant experience may be considered in lieu of degree.
- Demonstrated experience with STIGs, SRGs, POA&Ms and cybersecurity best practices, as well as relevant tools such as eMASS, STIG Viewer, Nessus, ACAS, SCAP, or HBSS.
- Strong understanding of the RMF process, NIST SP 800-37, NIST SP 800-53, CNSSI 1253, as well as key technologies areas/domain such as: Network, Mobility, Windows, UNIX, Cloud Environments and Cloud Native Tools/Services, Host Based Security System (HBSS)/Endpoint Security Solutions (ESS), Databases, Applications.
- Strong written and verbal communication skills for reporting assessment findings.
Skills
- STIGs, SRGs, POA&Ms and cybersecurity best practices.
- Tools such as eMASS, STIG Viewer, Nessus, ACAS, SCAP, or HBSS.
- RMF process, NIST SP 800-37, NIST SP 800-53, CNSSI 1253.
- Key technologies areas/domain such as: Network, Mobility, Windows, UNIX, Cloud Environments and Cloud Native Tools/Services, Host Based Security System (HBSS)/Endpoint Security Solutions (ESS), Databases, Applications.
Benefits
Pay and benefits are fundamental to any career decision. That's why we craft compensation packages that reflect the importance of the work we do for our customers. Employment benefits include competitive compensation, Health and Wellness programs, Income Protection, Paid Leave and Retirement.
Pay
The maximum starting salary for this position is $112,500. Please note that the broader pay range displayed at the bottom of this page represents the total corporate salary band for similarly-leveled cyber positions across Leidos and does not account for specific contract/program funding and requirements.
Schedule
Your first few weeks will involve assessment training in a virtual classroom environment, which includes training modules, lectures, and exams. You will also gain hands-on experience by shadowing current Assessors on local assessments across the greater DC-Baltimore area (referred to as "check rides"). Once your training and check rides are successfully completed, you will be added to the regular travel schedule.