
RMF IT Security Analyst System One
- $120,000–$130,000 Per Year
Security Control Assessor
Job ID: 2614940
Location: Springfield, VA, United States
Date Posted: Jul 24, 2026
Category: Cyber
Subcategory: Cyberspace Ops
Schedule: Full-Time
Shift: Day Job
Travel: Yes - 10% of the time
Minimum Clearance Required: Top Secret
Clearance Level Must Be Able to Obtain: TS/SCI with Poly
Potential for Remote Work: On-Site
Benefits: Click here
Share: mail
Apply Now >
Apply Now >
Job Description
Description
SAIC is seeking a highly skilled and motivated Senior Security Control Assessor (SCA) to support the cybersecurity assessment and compliance needs of mission-critical IT systems for the MAJESTIC Joint Program Office (JPO) Team. The successful candidate will perform independent assessments of security controls to ensure compliance with federal cybersecurity policies, standards, and frameworks, such as the Risk Management Framework (RMF), NIST SP 800-53, and others, to manage and mitigate risks to sensitive and classified systems.
This role will require working closely with Information System Security Managers (ISSMs), Information System Owners (ISOs), and system administrators to conduct technical reviews, evaluate security controls, and assist with Authorization and Accreditation (A&A) efforts. This role requires on-site support in Springfield, VA.
Key Responsibilities:
Conduct independent, objective, and robust assessments of IT systems to validate compliance with security control requirements in alignment with NIST 800-53, RMF, DoD 8510.01, and other applicable federal cybersecurity regulations.
Review and assess Authorization Boundary Diagrams (ABDs), Risk Assessment Reports (RARs), Security Plan Packages (SSPs), STIG checklists, vulnerability scan results, POA&Ms, and other security artifacts required for A&A efforts.
Lead Control Implementation Review and Test (CIRT) procedures and system-level security assessments to evaluate the adequacy of technical, operational, and management security controls.
Provide formal recommendations on system authorization status to Authorizing Officials (AOs), based on assessment results, residual risks, and system compliance to applicable policies.
Analyze and interpret vulnerability scan results (e.g., from ACAS, Nessus, or Qualys) and assist in presenting the organization's vulnerability management posture to relevant stakeholders.
Perform continuous monitoring assessments of information systems to identify risks, ensure ongoing compliance, and document changes impacting the security posture of systems.
Assess and validate security hardening practices using the DISA STIGs or CIS Benchmarks across systems, applications, and networks.
Conduct risk analysis and recommend risk mitigation strategies and control adjustments to minimize threats to system operations and data integrity.
Interface with system engineers, ISSOs, and stakeholders to resolve identified vulnerabilities and ensure timely remediation of risks.
Provide recommendations to improve current processes, tools, and documentation for security control assessments.
Compile and present comprehensive reports, including Security Assessment Reports (SARs) and risk assessment summaries, to senior stakeholders for decision-making.
Maintain up-to-date expertise on cybersecurity threats, technologies, regulatory frameworks, and compliance best practices.
Qualifications
Required Qualifications:
Certifications (CWF Requirements):
This requirement can be met by possessing one or more of the following qualifying certifications:
OR This requirement can be met through:
Experience:
Technical Skills:
Preferred Qualifications:
Clearance Requirement:
Work Environment and Notes:
Apply Now >
| Location | Springfield, VA |
| Industry | Computer/IT Services |
| Company Size | 10,000 employees or more |
| Year Founded | 2013 |
| Website | https://jobs.saic.com/ |

