Quick Overview
Job Description
JOB DESCRIPTION
Insight Global is seeking a Security Control Assessor (SCA) to support a federal customer in Denver, CO. This individual will be responsible for conducting independent assessments of management, operational, and technical security controls within information systems and networks to ensure compliance with Risk Management Framework (RMF) requirements and overall cybersecurity readiness.
The ideal candidate will have extensive experience supporting Authorization to Operate (ATO) efforts, performing security assessments, developing accreditation documentation, and advising stakeholders on cybersecurity risk management. This position will work closely with cybersecurity, systems engineering, and program leadership teams to evaluate security posture, identify risks, and ensure compliance with federal security standards. Responsibilities Conduct independent assessments of security controls in accordance with NIST SP 800-37 and the Risk Management Framework (RMF).
Review and validate accreditation and authorization packages supporting ATO efforts. Plan and execute security authorization reviews for new and existing systems and networks. Evaluate security documentation, assessment results, and risk determinations to ensure acceptable risk levels. Identify security gaps and provide recommendations to improve system security posture. Perform technical risk assessments and develop mitigation strategies. Support the development and maintenance of cybersecurity metrics, POA&Ms, and continuous monitoring activities.
Review and validate implementation of security controls and document any deviations from approved configurations. Participate in risk governance activities and provide recommendations regarding cybersecurity risks and associated mitigations. Develop and maintain RMF documentation throughout the system lifecycle. Support vulnerability management activities and validate remediation plans. Assess cloud environments, external services, and supporting infrastructure for compliance with security requirements.
Collaborate with technical teams to evaluate how new systems, interfaces, and technologies impact overall security posture. Provide recommendations to support accreditation decisions and authorization activities. REQUIRED SKILLS AND EXPERIENCE TS/SCI Clearance
Bachelor's degree
IAM Level II or IAT Level II certification (Security+, CAP, CASP+, CISSP, or equivalent). Hands-on experience supporting all phases of the Risk Management Framework (RMF). Strong experience managing and supporting Authorization to Operate (ATO) processes. Experience developing, tracking, and maintaining POA&Ms.
Experience performing technical risk assessments and accreditation support activities. Experience with RMF Continuous Monitoring (ConMon) programs. Experience using eMASS, XACTA, or similar RMF management tools. Experience utilizing DISA STIG Viewer and applying STIG requirements. Strong written and verbal communication skills.
Similar jobs
- DU
Senior Analyst, Protective Services
NewDoorDash USA
Austin🇺🇸YesterdaySQLSnowflakeCase Management+3 - ET
Principal Security Architect
NeweTeam, Inc.
Houston, TX🇺🇸HybridYesterdayTechnology - HG
Security Engineer Penetration Testing
NewHallmark Global Technologies
San Jose, CA🇺🇸On-siteYesterdayAWSMachine LearningOWASP+10Technology - MT
Cyber security manager
NewMaxima Technologies, LLC
Atlanta, GA🇺🇸On-siteYesterdayAWSAzureGoogle Cloud+1Technology - AS
Information Security Engineer IV
Apex Systems
OH🇺🇸Remote5 days agoAWSSplunkAgile+4Technology - AS
IT Security Specialist III
NewApex Systems
Jersey City, NJ🇺🇸HybridYesterdayScrumAgileJiraTechnology