Science Applications International Corp logo

Security Control Assessor

    Science Applications International Corp
    Want to know if you’re a fit?
    Upload your resume and let our AI show you.

    Skills

    • Analysis Skillsunmatched
    • Automationunmatched
    • Benchmarkingunmatched
    • Best Practicesunmatched
    • CISA - Certified Information Systems Auditorunmatched
    • CISM - Certified Information Security Managerunmatched
    • CISSP - Certified Information Systems Security Professionalunmatched
    • Cloud Computingunmatched
    • CompTIA - Computing Technology Industry Associationunmatched
    • CompTIA Security+unmatched
    • Computer Scienceunmatched
    • Computer Securityunmatched
    • Cyberspaceunmatched
    • Data Qualityunmatched
    • Defense Information Systems Agency (DISA)unmatched
    • Documentationunmatched
    • Federal Laws and Regulationsunmatched
    • GIAC - Global Information Assurance Certificationunmatched
    • GSEC - GIAC Security Essentials Certificationunmatched
    • GSLC - GIAC Security Leadership Certificateunmatched
    • GSNA - GIAC System & Network Auditorunmatched
    • Incident Responseunmatched
    • Information Technology & Information Systemsunmatched
    • Information/Data Security (InfoSec)unmatched
    • Internet Securityunmatched
    • Linux Distributionsunmatched
    • Linux Operating Systemunmatched
    • Maintain Complianceunmatched
    • Metasploitunmatched
    • Microsoft SQL Serverunmatched
    • Microsoft Virtual Serverunmatched
    • Microsoft Windows Serverunmatched
    • Needs Assessmentunmatched
    • Nessusunmatched
    • On Site Supportunmatched
    • Operations Managementunmatched
    • Operations Security (OPSEC)unmatched
    • Penetration Testingunmatched
    • Process Improvementunmatched
    • Red Hat Linux Operating Systemunmatched
    • Regulatory Complianceunmatched
    • Riskunmatched
    • Risk Analysisunmatched
    • Risk Managementunmatched
    • Risk Management Framework (RMF)unmatched
    • Security Analysisunmatched
    • Security Architectureunmatched
    • Security Auditingunmatched
    • Security Complianceunmatched
    • Security Monitoringunmatched
    • Sensitive Compartmented Information (SCI)unmatched
    • System Operationsunmatched
    • System Validationunmatched
    • Systems Administration/Managementunmatched
    • Systems Analysisunmatched
    • Systems Engineeringunmatched
    • Technical Analysisunmatched
    • Time Managementunmatched
    • Top Secret Clearanceunmatched
    • U.S. National Institute of Standards and Technology (NIST)unmatched
    • United States Department of Defense (DoD)unmatched
    • Vulnerability Scannersunmatched
    • Work From Homeunmatched
    • Writing Skillsunmatched

    Description

    Security Control Assessor

    Job ID: 2614940

    Location: Springfield, VA, United States

    Date Posted: Jul 24, 2026

    Category: Cyber

    Subcategory: Cyberspace Ops

    Schedule: Full-Time

    Shift: Day Job

    Travel: Yes - 10% of the time

    Minimum Clearance Required: Top Secret

    Clearance Level Must Be Able to Obtain: TS/SCI with Poly

    Potential for Remote Work: On-Site

    Benefits: Click here

    Share: mail

    Apply Now >

    Apply Now >

    Job Description

    Description

    SAIC is seeking a highly skilled and motivated Senior Security Control Assessor (SCA) to support the cybersecurity assessment and compliance needs of mission-critical IT systems for the MAJESTIC Joint Program Office (JPO) Team. The successful candidate will perform independent assessments of security controls to ensure compliance with federal cybersecurity policies, standards, and frameworks, such as the Risk Management Framework (RMF), NIST SP 800-53, and others, to manage and mitigate risks to sensitive and classified systems.

    This role will require working closely with Information System Security Managers (ISSMs), Information System Owners (ISOs), and system administrators to conduct technical reviews, evaluate security controls, and assist with Authorization and Accreditation (A&A) efforts. This role requires on-site support in Springfield, VA.

    Key Responsibilities:

    • Conduct independent, objective, and robust assessments of IT systems to validate compliance with security control requirements in alignment with NIST 800-53, RMF, DoD 8510.01, and other applicable federal cybersecurity regulations.

    • Review and assess Authorization Boundary Diagrams (ABDs), Risk Assessment Reports (RARs), Security Plan Packages (SSPs), STIG checklists, vulnerability scan results, POA&Ms, and other security artifacts required for A&A efforts.

    • Lead Control Implementation Review and Test (CIRT) procedures and system-level security assessments to evaluate the adequacy of technical, operational, and management security controls.

    • Provide formal recommendations on system authorization status to Authorizing Officials (AOs), based on assessment results, residual risks, and system compliance to applicable policies.

    • Analyze and interpret vulnerability scan results (e.g., from ACAS, Nessus, or Qualys) and assist in presenting the organization's vulnerability management posture to relevant stakeholders.

    • Perform continuous monitoring assessments of information systems to identify risks, ensure ongoing compliance, and document changes impacting the security posture of systems.

    • Assess and validate security hardening practices using the DISA STIGs or CIS Benchmarks across systems, applications, and networks.

    • Conduct risk analysis and recommend risk mitigation strategies and control adjustments to minimize threats to system operations and data integrity.

    • Interface with system engineers, ISSOs, and stakeholders to resolve identified vulnerabilities and ensure timely remediation of risks.

    • Provide recommendations to improve current processes, tools, and documentation for security control assessments.

    • Compile and present comprehensive reports, including Security Assessment Reports (SARs) and risk assessment summaries, to senior stakeholders for decision-making.

    • Maintain up-to-date expertise on cybersecurity threats, technologies, regulatory frameworks, and compliance best practices.

    Qualifications

    Required Qualifications:

    Certifications (CWF Requirements):

    • Candidates must satisfy Cybersecurity Workforce Framework (CWF) ID 612 (Security Control Assessor) requirements, as outlined by Navy COOL.

    This requirement can be met by possessing one or more of the following qualifying certifications:

    • Certified in Governance Risk and Compliance (CGRC)
    • Certified Information Systems Security Officer (C)ISSO-A)
    • CompTIA Cloud+
    • CompTIA PenTest+
    • CompTIA Security+
    • CompTIA SecurityX (formerly CASP+)
    • Federal IT Security Professional-Auditor-NG (FITSP-A)
    • GIAC Cloud Security Automation (GCSA)
    • GIAC Security Essentials Certification (GSEC)
    • Certified Chief Information Security Officer (CCISO)
    • Certified Information Security Manager (CISM)
    • Certified Information Systems Auditor (CISA)
    • Certified Information Systems Security Professional (CISSP)
    • CompTIA Cybersecurity Analyst (CySA+)
    • GIAC Security Leadership Certification (GSLC)
    • GIAC Systems and Network Auditor (GSNA)
    • Information Systems Security Engineering Professional (ISSEP)

    OR This requirement can be met through:

    • A Bachelor's Degree in Cybersecurity, Computer Science, IT, or a related field.

    Experience:

    • 5-9 years of professional experience managing and supporting enterprise-level IT environments.

    Technical Skills:

    • Familiarity with IT environments running enterprise systems, such as Windows Server 2019, MS SQL databases, and Linux distributions (RHEL preferred).
    • Knowledge of incident response functions, security architecture, and penetration testing frameworks (e.g., METASPLOIT, Kali Linux).
    • Strong analytical and documentation skills, with the ability to author comprehensive Security Assessment Reports (SARs) and other system artifacts.

    Preferred Qualifications:

    • Familiarity with IT environments running enterprise systems, such as Windows Server 2019, MS SQL databases, and Linux distributions (RHEL preferred).
    • Knowledge of incident response functions, security architecture, and penetration testing frameworks (e.g., METASPLOIT, Kali Linux).
    • Strong analytical and documentation skills, with the ability to author comprehensive Security Assessment Reports (SARs) and other system artifacts.

    Clearance Requirement:

    • Active TS/SCI clearance with the ability to obtain and maintain a TS/SCI with Poly.

    Work Environment and Notes:

    • On-Site Work: All work must be conducted on-site in Springfield, VA.
    • Program Scope: Supports on-premises enterprise IT environments, including virtualized Windows servers, MS SQL Server databases, and networking layers.
    • Subcontractor Role: Responsibilities and compensation vary based on the subcontract agreement, with a competitive salary aligned to market rates and role-specific requirements.

    Apply Now >

    Numbers & Facts

    LocationSpringfield, VA
    IndustryComputer/IT Services
    Company Size10,000 employees or more
    Year Founded2013
    Websitehttps://jobs.saic.com/

    About Company

    SAIC is a premier Fortune 500® technology integrator driving our nation's digital transformation. Our robust portfolio of offerings across the defense, space, civilian, and intelligence markets includes secure high-end solutions in engineering, IT modernization, and mission solutions. Using our expertise and understanding of existing and emerging technologies, we integrate the best components from our own portfolio and our partner ecosystem to deliver innovative, effective, and efficient solutions that are critical to achieving our customers' missions. We are a team of 26,000 strong driven by mission, united purpose, and inspired by opportunity. Headquartered in Reston, Virginia, SAIC has annual revenues of approximately $7.1 billion. For more information, visit saic.com.

    Similar Jobs

    See more jobs