Security Control Assessor (SME), Level III

OneZero Solutions
  • Baltimore, MD
  • Full-time
  • Quick Apply
6 days ago

Job Description

We are an employee-centric company that truly values our team members and the contributions they make to our customers and the missions they support. We pride ourselves on being forward-leaning thinkers and on building teams that are, and continue to be, technically proficient across a broad range of cyber mission areas. OneZero full-time employees receive a highly competitive benefits package, including health, dental, vision, and life insurance, a 401(k) with company matching, paid time off and holidays, an employee referral program, and educational assistance. Additional details are available on our website: https://www.onezerollc.com/careers/ Position Title : Security Control Assessor (SME), Level IIILocation:  USCG Surface Forces Logistics Center, 2401 Hawkins Point Road, Baltimore, MD 21226. Work may also be performed at the SFLC satellite offices at 707 East Ordnance Road, approximately one mile from the primary site, and at other sites as determined necessary by the Contracting Officer's Representative (COR).Clearance:No security clearance required. This position does not involve access to classified information or classified IT systems.S. citizenship is required in accordance with HSAR 3052.204-71 Alternate I.Position SummaryThe Security Control Assessor (SCA) provides independent security control assessment and authorization support to the USCG SFLC Business Operations Division in support of Surface Domain Operational Technology (OT) and Platform IT systems. The role is the assessment authority on the team: it evaluates whether security and privacy controls are implemented correctly, operating as intended, and producing the intended outcome, and it provides the evidence the Authorizing Official relies on to make risk decisions.This is the senior assessment position on the task order and is distinct from the ISSO roles, which own and maintain the authorization packages. The SCA assesses; the ISSOs prepare and sustain. The position is expected to operate with a high degree of independence and to advise the OT Security Manager (ISSM) directly.Key ResponsibilitiesSupport the OT Security Manager (ISSM) and staff in establishing and maintaining the programs, procedures, and policies that protect Government Sensitive But Unclassified (SBU) information.Perform independent assessments of SFLC Operational Technology to verify that applicable security and privacy controls are implemented correctly, operating as intended, and producing the desired outcome.Provide security assessment and authorization consultation services to the ISSM, on site.Review existing policies, procedures, and guidelines for compliance with DHS, USCG, and DoD cybersecurity policy; draft or revise SFLC policy documentation for ISSM review, approval, and organizational implementation.Assist in preparing RMF security authorization documentation for submission to the Authorizing Official (AO).Maintain security assessment information and supporting documentation within Government-designated systems and repositories.Create and validate SFLC security assessment and authorization accounts within Government-designated systems and tools.Update and maintain assessment and authorization status within Government-designated tracking systems and databases.Upload, track, and update Plans of Action and Milestones (POA&Ms); recommend POA&M updates based on assessment results and maintain traceability from identified vulnerabilities through to the applicable POA&M.Conduct vulnerability scans of SFLC OT, networks, devices, and associated components using Government-approved tools.Provide assistance to system administrators in remediating vulnerabilities identified through scanning.Provide vulnerability and risk management support in conjunction with assessment and authorization activities.Maintain the enterprise tracking log for electronic spillage activities in accordance with Government policy.Support the destruction of removable media generated during assessment activities in accordance with Government procedures.Support cybersecurity strategic planning and continuous monitoring activities, evaluating enterprise services through assessment of priorities and risk.Provide bi-weekly status reports to the SFLC OT Security Manager (ISSM).Conduct a monthly project status update briefing to the ISSM at SFLC Baltimore.Required QualificationsExperienceTen (10) or more years of progressive cybersecurity experience, including at least five (5) years performing security control assessments or independent A&A validation in a federal environment.Demonstrated experience executing NIST SP 800-37 RMF end to end, including control assessment against NIST SP 800-53A.Experience assessing systems to a formal authorization decision and producing assessment artifacts relied upon by an Authorizing Official.Experience conducting and interpreting vulnerability scans and translating findings into risk-based recommendations and POA&M entries.Experience drafting and revising organizational cybersecurity policy for Government review and adoption.CertificationMust hold and maintain at least one active certification approved for Information Assurance Management (IAM) Level II or Level III. Any one of the following satisfies the requirement:CISSP - Certified Information Systems Security Professional (or CISSP Associate)CISM - Certified Information Security ManagerCGRC - Governance, Risk and Compliance Certification (formerly CAP)CASP+ - CompTIA Advanced Security PractitionerGSLC - GIAC Security Leadership CertificationCCISO - EC-Council Certified Chief Information Security Officer (Level III only)Certification requirements are subject to confirmation against COMDTINST M2620.2 (series) Appendix D, the controlling USCG certification matrix. Verify the accepted certification list with the Program Manager before extending an offer.Evidence of active certification in good standing is required prior to onboarding. Waivers and exceptions to certification requirements will not be granted.Certifications must remain current, active, and in good standing throughout performance. Loss, lapse, or revocation of a required certification is grounds for removal from the contract. Continuing education required to maintain certification is at the employee's and company's expense.Ability to work independently and advise a Government security manager at the senior level.Strong written communication: the role produces bi-weekly written reporting and briefs the ISSM monthly.Ability to read, write, speak, and understand English fluently.Preferred QualificationsPrior USCG, DHS, or DoD assessment experience, particularly with Surface Domain OT or Platform IT systems.Familiarity with COMDTINST M2620.2 (series) and COMDTINST 5500.13 (series).Experience assessing OT/ICS or PIT systems where conventional endpoint tooling cannot be deployed.CGRC (formerly CAP), CISA, or GSNA in addition to the required baseline certification.Experience supporting DHS SELC-aligned programs.Master's degree in cybersecurity, information systems, or a related field.Technical SkillsNIST SP 800-37 (RMF), 800-53 / 53A / 53B, 800-137 (ISCM), FIPS 199 and FIPS 200DHS 4300A Sensitive Systems Handbook and the DHS Systems Engineering Life Cycle (SELC)Government-designated A&A repositories and tracking tools (e.g., eMASS or successor)DISA Security Technical Implementation Guides (STIGs) and Security Requirements Guides (SRGs)Government-approved vulnerability scanning and compliance tooling (e.g., ACAS/Nessus, SCAP-validated scanners)POA&M development, tracking, and closure, including waiver and risk acceptance packagesOperational Technology (OT), Platform IT (PIT), and industrial control system environments, including constraints on agent-based toolingNIST SP 800-30 risk assessment methodology and NIST SP 800-115 technical assessment techniquesElectronic spillage handling and removable media sanitization proceduresSecurity ClearanceNo security clearance required. This position does not involve access to classified information or classified IT systems.S. citizenship is required in accordance with HSAR 3052.204-71 Alternate I.A favorably adjudicated Tier 1 background investigation (or higher) is required. Candidates without an existing investigation on file must complete an Electronic Application (eApp) for investigation processing.Note to recruiting: per the task order, the position is not billable until the selected candidate is fully cleared, has a CAC in hand, and has reported to the work site. Fill timelines should assume 30–90 days for investigation and CAC issuance.EducationBachelor's degree in cybersecurity, computer science, information systems, engineering, or a related field.Work EnvironmentPrimarily on-site at SFLC Baltimore. On-site presence is required for the monthly status briefing to the ISSM and for participation in change management boards, technical exchange meetings, and Government working groups.The Government furnishes workspace, telephone, a Standard Workstation, and copy/fax access.Remote work may be authorized at the sole discretion of the Government. If authorized, compliant hardware, software, and internet service are contractor-furnished.Occasional travel outside the local commuting area may be required for training and associated off-site meetings, subject to advance COR approval and reimbursed per the Federal Travel Regulations. The 707 East Ordnance Road satellite office is within the local commuting area.OneZero Solutions, LLC is an Equal Opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, pregnancy, genetic information, disability, status as a protected veteran, or any other protected category under applicable federal, state, and local laws.To request an accommodation, please contact us at recruiting@onezerollc.com or call (202) 987-2580.

Job Posted by ApplicantPro

Numbers & Facts

LocationBaltimore, MD
Job TypeFull-time

Skills

  • Access Authorizationunmatched
  • Adjudicationunmatched
  • Business Operationsunmatched
  • CISA - Certified Information Systems Auditorunmatched
  • CISM - Certified Information Security Managerunmatched
  • CISSP - Certified Information Systems Security Professionalunmatched
  • Change Managementunmatched
  • CompTIA - Computing Technology Industry Associationunmatched
  • Computer Scienceunmatched
  • Computer Securityunmatched
  • Computer Workstationsunmatched
  • Control Systemsunmatched
  • Defense Information Systems Agency (DISA)unmatched
  • Documentationunmatched
  • EC-Councilunmatched
  • English Languageunmatched
  • FIPS (Federal Information Processing Standards) 199unmatched
  • Federal Information Processing Standards (FIPS)unmatched
  • Federal Laws and Regulationsunmatched
  • GIAC - Global Information Assurance Certificationunmatched
  • GSNA - GIAC System & Network Auditorunmatched
  • Governmentunmatched
  • Government Policiesunmatched
  • Homeland Securityunmatched
  • IAM - Information Assurance Managementunmatched
  • Information Technology & Information Systemsunmatched
  • Information/Data Security (InfoSec)unmatched
  • Internet Applicationunmatched
  • Internet Securityunmatched
  • Internet/Online Serviceunmatched
  • Juniper Networks M-Seriesunmatched
  • Leadershipunmatched
  • Logisticsunmatched
  • Machine Toolunmatched
  • Needs Assessmentunmatched
  • Nessusunmatched
  • Onboardingunmatched
  • Operational Auditunmatched
  • Operational Supportunmatched
  • Presentation/Verbal Skillsunmatched
  • Privacy Controlsunmatched
  • Remote Accessunmatched
  • Riskunmatched
  • Risk Analysisunmatched
  • Risk Managementunmatched
  • Security Analysisunmatched
  • Security Clearanceunmatched
  • Security Monitoringunmatched
  • Software Administrationunmatched
  • Status Reportsunmatched
  • Strategic Planningunmatched
  • System Lifecycleunmatched
  • Systems Administration/Managementunmatched
  • Systems Analysisunmatched
  • Systems Engineeringunmatched
  • Team Lead/Managerunmatched
  • Technical Analysisunmatched
  • Technology Analysisunmatched
  • Traceabilityunmatched
  • U.S. National Institute of Standards and Technology (NIST)unmatched
  • United States Coast Guard (USCG)unmatched
  • United States Department of Defense (DoD)unmatched
  • Vulnerability Scannersunmatched
  • Work From Homeunmatched
  • Writing Skillsunmatched

Be found by employers

5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

Level up your application

Professional resume templates

Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

Free resume templates

Free resume builder

Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

Free resume builder