Haystack
← Back to Jobs
Remote
Other

SCA with Active Secret Clearance

Delviom LLCUnited States🇺🇸United StatesPosted 31 Jul 2026

Quick Overview

Work Type
Remote
Level
Mid Senior

Job Description

Security Control Assessor (SCA)

Duration: 3 Years

Location: Remote

Clearance: Secret

 

Role Overview:
The Security Control Assessor (SCA) will provide cybersecurity assessment, authorization, and risk management support for Department of Defense (DoD) systems, including ClientInformation Technology (IT) and Operational Technology (OT) environments. The SCA will execute the full DoD Risk Management Framework (RMF) lifecycle, evaluate security control effectiveness, support Authorization to Operate (ATO) decisions, and provide risk-based recommendations to improve enterprise cybersecurity posture in accordance with DoDI 8510.01, NIST SP 800-53, CNSSI 1253, DoD STIGs, and applicable cybersecurity policies.

Key Responsibilities:

  • Execute all seven (7) steps of the DoD Risk Management Framework (RMF Steps 0–6), including Prepare, Categorize, Select, Implement, Assess, Authorize, and Monitor activities for CLIENT IT and OT systems.
  • Perform Security Control Assessor (SCA) and Information System Security Manager (ISSM)-aligned responsibilities in accordance with DoDI 8510.01, DoD cybersecurity policies, and organizational security requirements.
  • Conduct system categorization activities using CNSSI 1253 impact levels and ensure accurate system registration and lifecycle management within CLIENT eMASS.
  • Evaluate, select, tailor, and assess security controls and control enhancements based on NIST SP 800-53 current revision, DoD overlays, and mission-specific cybersecurity requirements.
  • Develop, review, and maintain RMF authorization artifacts, including System Security Plans (SSP), Security Assessment Reports (SAR), Risk Assessments, Plans of Action and Milestones (POA&M), Privacy Impact Assessments (PIA), and supporting documentation.
  • Perform independent security control assessments to validate control implementation, effectiveness, and compliance with applicable DoD cybersecurity standards.
  • Execute and validate Security Technical Implementation Guide (STIG) and Security Requirements Guide (SRG) compliance assessments, document findings, and coordinate remediation activities with system stakeholders.
  • Prepare and submit complete RMF Authorization packages, including SSP, SAR, OT Risk Assessment Matrix (OT RAM), POA&M, and supporting evidence for Authorizing Official (AO) review and approval.
  • Conduct continuous monitoring activities in accordance with CLIENT RMF Continuous Monitoring strategies, schedules, and cybersecurity governance requirements.
  • Perform vulnerability management activities, including Information Assurance Vulnerability Alert (IAVA) monitoring, Assured Compliance Assessment Solution (ACAS) scan analysis, vulnerability validation, CVE tracking, and remediation coordination.
  • Analyze security assessment results, identify risks, evaluate residual risk, and provide actionable remediation recommendations to system owners and cybersecurity leadership.
  • Prepare and deliver cybersecurity briefings to senior leadership, including J62 Program Managers/System Managers and J61 leadership, regarding RMF status, security risks, vulnerabilities, and authorization readiness.
  • Support cybersecurity incident response activities, including coordination with Computer Emergency Response Teams (CERTs), investigation support, and data spill response procedures.
  • Validate implementation of Access Control Policies (ACP), including privileged and non-privileged account management, authentication mechanisms, user vetting, least privilege enforcement, and access authorization processes.
  • Collaborate with CLIENT ISSMs, Program Managers, System Managers, engineers, administrators, and mission stakeholders to integrate cybersecurity requirements throughout the System Development Life Cycle (SDLC).
  • Provide cybersecurity subject matter expertise to improve RMF processes, strengthen security governance, and maintain operational resilience across DoD mission systems.

Required Experience & Technical Expertise:

  • Demonstrated experience performing DoD RMF activities and supporting Authorization to Operate (ATO) processes for classified, unclassified, IT, and/or OT environments.
  • Strong knowledge of DoDI 8510.01, NIST SP 800-53, CNSSI 1253, DoD STIGs/SRGs, FISMA, and continuous monitoring requirements.
  • Experience with RMF governance tools such as eMASS, Xacta, CSAM, or equivalent GRC platforms.
  • Hands-on experience with vulnerability management tools including ACAS, Nessus, Tenable, or equivalent platforms.
  • Experience developing and reviewing RMF documentation, security assessment artifacts, POA&Ms, and risk acceptance documentation.
  • Ability to communicate technical cybersecurity risks effectively to both technical teams and senior government leadership.
  • Experience supporting cybersecurity operations, incident response coordination, access control assessments, and security compliance initiatives within DoD environments.

Skills

Account Management
Compliance
Risk Assessment
Risk Management

Similar jobs