Haystack
← Back to Jobs
Employee
Administrative
EC

Security Controls Assessor with Security Clearance

ECSWashington, DC🇺🇸United StatesPosted 11 Aug 2026

Why This Role Stands Out

Advance your cybersecurity career with a competitive salary of $150,000-$168,000 in this hybrid Security Controls Assessor role, where you'll conduct critical assessments for a U.S. Government agency and develop your expertise in federal regulations and NIST standards. This opportunity is ideal for meticulous, analytical professionals with an active security clearance who are eager to contribute to vital national security efforts and thrive in a dynamic environment that values professional development. Apply now to join a reputable organization and make a significant impact in the field of cybersecurity.

Quick Overview

Salary
$150k - $168k/yr
Work Type
Hybrid
Schedule
Employee
Level
Mid Senior

Job Description

Job Description ECS is seeking a Security Contr ols Assessor to work in our Washington, DC (hybrid) office.

Please Note: This position is contingent upon contract award. ECS seeks a Security Contr ols Assessor to support a full range of cybersecurity services on a long-term, full-time contract with a U.S. Government civilian agency. This position requires mostly CONUS and occasional OCONUS assessments and is available immediately for a qualified candidate with an active security clearance.

Key Responsibilities

  • Review and update information security policies, standards, and procedures in accordance with federal and departmental regulations
  • Perform independent security and privacy contr ol assessments on behalf of the client CSO in support of Security Assessment && Authorization (SA&&A)
  • Assess existing and new FISMA systems and subsystems, and communicate findings and potential impacts of identified contr ol weaknesses
  • Review and analyze A&&A packages-including System Security Plans (SSP), Risk Assessments, Information System Contingency Plans (ISCP), Backup SOPs, Incident Response Plans (IRP), Configuration Management Plans (CMP), hardware/software inventories, network diagrams, data flows, system change requests, vulnerability scan reports, test reports, and POA&&Ms-for completeness, accuracy, and effective contr ol implementation
  • Develop and maintain test cases for contr ol-level security testing across system components (applications, servers, databases, operating systems, network devices, end-user devices, etc.)
  • Develop and execute security and privacy assessment plans in accordance with NIST SP 800-53A, supporting RMF Steps 4-6
  • Document findings and recommendations that are clear, system-specific, and actionable
  • Analyze security tool outputs to distinguish residual risk from false positives prior to finalizing findings
  • CONUS and OCONUS travel to conduct system assessments
  • Other duties as assigned Salary Range: $150,000-$168,000

Required Skills

  • Active Secret clearance required with eligibility to get Top Secret clearance
  • Bachelor's degree in Computer Science, MIS/IT, Engineering, Information Security/Assurance, or a related field
  • Minimum five (5) years of information security experience
  • Minimum three (3) years of experience supporting security assessment teams, including planning assessments and serving as a senior team member
  • Two (2) years of experience using GRC tools
  • Demonstrated experience conducting full-scope technical security contr ol testing across component types, including development of security and privacy assessment plans
  • Working knowledge of RMF Steps 1-6
  • Strong understanding of NIST SP 800-53 contr ols, the NIST Cybersecurity Framework, and applicable information security/privacy laws and regulations
  • Ability to analyze information system configurations and technical specifications against NIST SP 800-53 and related overlays
  • Experience developing risk-based documentation
  • Excellent written and verbal communication skills, with the ability to present contr ol requirements and deficiencies clearly to both technical and non-technical audiences

Desired Skills

  • Assessment and Authorization (A&&A) activities, including risk assessments, Security Plans, Security Contr ols Assessments (SCA), and related documentation
  • Current industry practices for evaluating, implementing, and disseminating IT security assessment, monitoring, detection, and remediation tools
  • Assessing systems hosted in AWS and/or Azure cloud environments
  • Conducting assessments in accordance with OMB, NIST, and FedRAMP policies, procedures, and standards
  • One of the following:
  • CISSP (Certified Information Systems Security Professional)
  • CEH (Certified Ethical Hacker)
  • CRISC (Certified in Risk and Information Systems Contr ol)
  • CISA (Certified Information Systems Auditor)
  • AAIA (Advanced in AI Audits) ECS Federal LLC is an equal opportunity employer and does not discriminate or allow discrimination on the basis any characteristic protected by law. All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, or local jurisdiction law. is the federal segment of , a $4B global organization with over 10,000 employees. Our nearly 3,500 professionals deliver advanced technology solutions in data and AI, cybersecurity, and enterprise transformation, serving defense, intelligence, and federal civilian agencies. Our work powers mission-critical outcomes, strengthens technology partnerships, and creates meaningful opportunities for our people. We are defined by a commitment to excellence in delivery, a culture of innovation, and an environment where talent can thrive and grow. We value:
  • Attracting and developing top talent and high-performing teams
  • Fostering a culture that is engaging, accountable, and mission-driven Meet the challenge. Make a difference with Everforth ECS!

Similar jobs