NewRisk Analyst System OneRisk AnalystMerrifield, VASystem One, and its subsidiaries including Joulé and Mountain Ltd., are leaders in delivering outsourced services and workforce solutions across North America. Bachelor’s Degree in Business Administration, Auditing, or related field or equivalent combination of training, education and experience.
Vice President of Risk Management & Insurance HITT ContractingVice President of Risk Management & InsuranceFalls Church, VA$160,000–$220,000 / yearAs a key member of the leadership team, the Vice President protects HITT's assets and profitability by managing enterprise risk, insurance programs, and claims across all business units, including the operating companies within the holding company structure. This leader negotiates carrier and broker relationships, manages the corporate insurance portfolio and captive insurance program, and partners with Operations, Preconstruction, and Legal to identify and mitigate project and enterprise risk.
Third Party Risk Mgmt Process Improvement Analyst System OneThird Party Risk Mgmt Process Improvement AnalystVienna, VA$50–$60 / hourDedicated resource to support documentation, process mapping, and continuous improvement of the TPRM program, training materials that drive consistency, scalability, audit readiness, and operational effectiveness. Support continuous improvement efforts by documenting current-state processes, identifying enhancement opportunities, and contributing ongoing process enhancements.
Risk Assessor/Toxicologist Interdisciplinary (Environmental) - DIRECT HIRE AUTHORITY United States Air ForceRisk Assessor/Toxicologist Interdisciplinary (Environmental) - DIRECT HIRE AUTHORITYWashington, DC$76,463–$118,204 / yearBasic Requirement for 0020, Community Planner Positions (You must provide a copy of your transcripts): A Bachelors degree (or higher degree) in community planning; or related field such as urban affairs, architecture, landscape architecture, engineering, sociology, geography, economics, political science, or public administration that included at least 12 semester hours in the planning process, socioeconomic and physical elements of planning, urban and regional economic analysis, and development finance. As an environmental professional, provides professional environmental technical and program support to the office of the Assistant Secretary of the Air Force, Installations, Environment and Logistics (SAF/IE), Headquarters, Air Force (HAF) A7C, Environmental Restoration and Quality Program Offices, Major Commands (MAJCOMs), Regional Support Teams (RSTs), and Installation Support Teams (ISTs).
Offensive Security Control Assessor Security Control Assessor Representative Dark Wolf SolutionsOffensive Security Control Assessor Security Control Assessor RepresentativeWashington, DCRemote$135,000–$160,000 / yearFamiliarity evaluating risks unique to LLMs-including prompt injection, data poisoning, model inversion, insecure output handling, and open-source supply chain vulnerabilities in AI libraries (PyTorch, LangChain, LlamaIndex). This position is ideal for a pragmatic cloud assessor or SCAR who excels in fast-paced DevSecOps environments, understands AWS cloud security, and is eager to shape the cybersecurity posture of next-generation DoD AI capabilities.
Security Controls Assessor - Senior SMS DATA PRODUCTS GROUP, INCSecurity Controls Assessor - SeniorSpringfield, VA$123,000–$136,000 / yearThe successful senior level candidate will be responsible for evaluating, testing, and validating the effectiveness of security controls, with a strong emphasis on applying the Risk Management Framework (RMF) and have experience in leading a team of Assessors. Experience as senior or lead member of a team, including experience coaching and providing guidance to less experienced or new team resources, reviewing work products, tracking deadlines, and coverage, reporting, facilitating onboarding / offboarding procedures, etc.
NewSenior Security Analyst (A&A)/Assessor - NIST ITC Federal, Inc.Senior Security Analyst (A&A)/Assessor - NISTGaithersburg, MarylandRemoteFull timeDemonstrable experience: Conducting IT assessor activities based on the NIST Risk Management Framework, to include the interviewing, examining and testing of related control sets; the review and/or updates of core system documents- System Security Plans, Contingency Plans, Privacy Threshold Assessments, hardware and software inventories, and system diagrams. The Senior Security Analyst will demonstrate a strong knowledge of Security Requirement Analysis, Security Architecture, Enterprise Security Program Assessment, evaluating Vulnerability Assessment results and perform other duties as required.
Senior Cloud Security Assessor Spry MethodsSenior Cloud Security AssessorWashington, DC (Hybrid)Extensive experience conducting independent security assessments of federal systems hosted in Microsoft Azure and AWS environments, including evaluation of security controls, architecture, inherited controls, customer-configured controls, and cloud-specific risks. • Conduct detailed analysis of assessment artifacts, including system security plans, policies, procedures, architecture and data-flow diagrams, inventories, configurations, logs, scan results, test outputs, and other supporting evidence.
Security Control Assessor (SCA) CymertekSecurity Control Assessor (SCA)Annapolis Junction, MarylandSecurity Assessor, Information Security Auditor, Security Compliance Analyst, Security Analyst, Risk and Compliance Officer, Security Control Evaluator, IT Auditor, Security Assurance Specialist, Security Risk Assessor, Compliance Manager, ect. In this role, you will be responsible for assessing and evaluating the effectiveness of security controls across various systems, identifying vulnerabilities, and ensuring compliance with relevant security frameworks and regulations.
NewSenior Security Analyst (A&A)/Assessor NIST ITC FederalSenior Security Analyst (A&A)/Assessor NISTGaithersburg, MDRemoteDemonstrable experience: Conducting IT assessor activities based on the NIST Risk Management Framework, to include the interviewing, examining and testing of related control sets; the review and/or updates of core system documents- System Security Plans, Contingency Plans, Privacy Threshold Assessments, hardware and software inventories, and system diagrams. The Senior Security Analyst will demonstrate a strong knowledge of Security Requirement Analysis, Security Architecture, Enterprise Security Program Assessment, evaluating Vulnerability Assessment results and perform other duties as required.
Security Control Assessor Novul SolutionsSecurity Control AssessorArlington, VirginiaThis role is responsible for conducting in-depth security control assessments, validating control implementation, reviewing system security documentation, and supporting the development and maintenance of complete and accurate Authorization to Operate packages. Assess program compliance with security controls associated with registered Ports, Protocols, and Services, including the proper generation, retention, protection, and handling of system log files.
Security Control Assessor (SCA) II Amatriot Group, LLCSecurity Control Assessor (SCA) IIArlington, VA$169,000–$171,500 / yearThe Security Control Assessor (SCA) is responsible for conducting comprehensive assessments of the management, operational, and technical security controls employed within or inherited by an information system (IS) to determine the overall effectiveness of those controls. Advise the Information System Owner (ISO), Information Data Owner (IDO), Program Security Officer (PSO), and Delegated and/or Authorizing Official (DAO/AO) on assessment and authorization issues.
Security Control Assessor Omniscius ConsultingSecurity Control AssessorArlington, VAFull timeExpert knowledge and hands-on experience with FISMA Systems, NIST 800-series guidelines, FIPS, Security Assessment & Authorization (SA&A) requirements and processes, Continuous Monitoring Framework experience and its tools, Plan of Action & Milestones (POA&M) policies, and vulnerability/patch management, risk management, project management, proficient with Microsoft products - Word, Excel, PowerPoint. The security control assessor (SCAs) supports a critical, objective role to evaluate the effectiveness of implemented controls in mitigating security risks.
NewSecurity Control Assessor Peraton IncSecurity Control AssessorFort Belvoir, VA$135,000–$216,000 / yearKnowledge of system and application security threats and vulnerabilities (e.g., buffer overflow, mobile code, cross-site scripting, Procedural Language/Structured Query Language [PL/SQL] and injections, race conditions, covert channel, replay, return oriented attacks, malicious code). As the world's leading mission capability integrator and transformative enterprise IT provider, we deliver trusted, highly differentiated solutions and technologies to protect our nation and allies.
Security Control Assessor Life Cycle EngineeringSecurity Control AssessorSpringfield, VALife Cycle Engineering (LCE) is a privately held, employee-owned company with an emphasis on "doing the right thing the right way”, which applies to the way we treat our customers and employees. Physical Demands and Expectations: Regular physical activity to include walking, climbing stairs, bending, stooping, reaching, lifting (up to 15 pounds), and standing; occasional prolonged sitting.
Senior Security Controls Assessor (TS/SCI #26-143) Strategic Analysis, Inc.Senior Security Controls Assessor (TS/SCI #26-143)fort meade, MDWe are seeking an experiencedSenior Security Control Assessor (SCA)to support Risk Management Framework (RMF) activities, including assessment, authorization, and continuous monitoring of information systems. This role focuses on evaluating security controls, identifying risks, and supporting authorization decisions within DoD and/or IC environments.
Senior Security Control Assessor Representative SCAR Dark Wolf SolutionsSenior Security Control Assessor Representative SCARVA$140,000–$145,000 / yearDark Wolf Solutions is seeking a Senior Security Control Assessor Representative (SCAR) to conduct independent comprehensive assessments of the management, operation, and technical security controls and control enhancements employed within, or inherited by, an Information technology (IT) system to determine the overall effectiveness of the controls. Certification requirements (at least one of the following): SecurityX / CASP+, CCISO, CGRC/CAP, CISA, CISM, CISSO, CISSP, CISSP-ISSEP, Cloud+, CySA+, FITSP-A, GCSA, GSEC, GSLC, GSNA, PenTest+, Security+.
Security Control Assessor - Intermediate RividiumSecurity Control Assessor - IntermediateSpringfield, VirginiaRiVidium Inc. is seeking a Security Control Assessor who conducts independent comprehensive assessments of the management, operational, and technical security controls and control enhancements employed within or inherited by an information technology (IT) system to determine the overall effectiveness of the controls (as defined in NIST 800-37). The listed salary range represents a general guideline; however, RiVidium Inc. considers a number of factors when determining base salary offers such as the scope and responsibilities of the position and the candidate’s experience, education, skills, and current market conditions.
Security Control Assessor - TS/SCI with Polygraph GD Information TechnologySecurity Control Assessor - TS/SCI with PolygraphBethesda, MarylandThree (3) years of cybersecurity experience with at least one year of experience conducting SCAs under ICD 503/CNSSI 1253 NIST Cybersecurity Framework, Risk Management Framework (RMF), or a similar framework. To ensure our employees are able to protect their income, other offerings such as short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available.
Security Control Assessor (SCA) I - greater Washington, DC area General Dynamics Information TechnologySecurity Control Assessor (SCA) I - greater Washington, DC areaSuitland, WashingtonThe Security Control Assessor (SCA) I is responsible for conducting a comprehensive assessment of the management, operational, and technical security controls employed within or inherited by an IS to determine the overall effectiveness of the controls (i.e., the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for the system). 9+ years related experience ; OR 5+ years related experience AND Bachelor’s degree in a related discipline OR Associate’s degree in a related area + 2 years’ experience OR equivalent experience (4 years).