The SCA is responsible for conducting a comprehensive assessment of the management, operational, and technical security controls employed within or inherited by an IS to determine the overall effectiveness of the controls (i.e., the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for the system). The pay Range is determined by various factors such as education, knowledge, skills, competencies, and experience, as well as contract-specific requirements; negotiable based on elected total compensation packages, which include but are not limited to paid time off, healthcare elections, and retirement.