Junior Security Control Assessor
Why This Role Stands Out
This role offers fantastic growth potential within cybersecurity compliance, working with NIST frameworks and advanced assessment tools. You'll thrive here if you have a keen eye for detail, enjoy technical writing, and are eager to develop your skills in security control assessment, with a competitive salary of $100,000-$115,000 annually and excellent remote flexibility. Apply today to join a dynamic team and build a rewarding career in a highly reputable company.
Quick Overview
Job Description
Location: Bethesda, MD (mostly remote, occasional onsite required)
Work schedule: 40 hrs/week
Compensation: $100,000–$115,000/year
Target start: by end of August 2026
Clearance / Public Trust: Public Trust eligibility (Tier 2/3) required
About the role
We’re hiring a Junior Security Control Assessor to support independent security control assessments across the system authorization lifecycle. You’ll work under a senior assessor and help evaluate security control implementation, validate evidence, and document results in alignment with NIST Risk Management Framework (RMF) and NIST SP 800-53 Rev. 5, using JCAM practices.
This is a great fit for someone who enjoys cybersecurity compliance, evidence-based assessments, and strong technical writing—without being the person who authors the entire authorization package.
What you’ll do
- Support independent Security Control Assessments (SCAs) across the authorization lifecycle
- Review and validate security authorization documentation (SSP, SAP, SAR, POA&M, contingency plans, and supporting artifacts)
- Assess security control implementation through documentation review, interviews, and technical validation
- Help evaluate cloud security packages and inherited controls (as applicable)
- Document findings, recommendations, and remediation activities clearly and professionally
- Assist with evidence validation and remediation tracking
- Partner with system owners and ISSOs while maintaining assessor independence
Required qualifications
- Education: Bachelor’s in Cybersecurity, IT, Computer Science, Information Systems (or similar)
- OR 4 additional years of relevant experience in lieu of a degree
- Experience: 3–5 years supporting cybersecurity, information assurance, RMF, security assessments, compliance, or IT operations
- Working knowledge of:
- NIST RMF (800-37) and NIST SP 800-53 Rev. 5
- JCAM methodology
- Experience reviewing security documentation and assessment evidence/artifacts
- Strong analytical skills and technical writing ability
Preferred (nice to have)
- Experience with eMASS or similar GRC platforms
- Familiarity with FedRAMP, cloud security concepts, C-SCRM, and related federal security frameworks
- Experience supporting independent audits/assessments (e.g., external review organizations)
Tools/tech exposure (helpful)
- JCAM
- Tenable
- CrowdStrike
- Splunk / Splunk Enterprise
- AWS
- Python (plus)
Certifications (preferred, not all required)
- ISC2 CC or CGRC
- CompTIA Security+, CySA+, PenTest+, CASP+
- CEH
- Microsoft SC-900
System One, and its subsidiaries including Joulé and Mountain Ltd., are leaders in delivering outsourced services and workforce solutions across North America. We help clients get work done more efficiently and economically, without compromising quality. System One not only serves as a valued partner for our clients, but we offer eligible employees health and welfare benefits coverage options including medical, dental, vision, spending accounts, life insurance, voluntary plans, as well as participation in a 401(k) plan.
System One is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, age, national origin, disability, family care or medical leave status, genetic information, veteran status, marital status, or any other characteristic protected by applicable federal, state, or local law.
#M-1
#LI-AJ1
Ref: #856-Baltimore-S1
Similar jobs
Principal Security Incident Lead (Blue Team)
Kforce Technology Staffing · New York, United States
10 minutes agoRMF IT Security Analyst with Security Clearance
System One Holdings, LLC · Bethesda, United States
29 minutes agoHelp Desk Analyst - Tier 2 - RQ224951 with Security Clearance
ASD, Inc. · Quantico, United States
29 minutes agoNetwork Security Analyst II
Fusion Global Solutions · Austin, United States
30 minutes agoLearning Management System (LMS) Course Specialist with Security Clearance
Caelum Research Corporation · Fort Sill, United States
33 minutes agoInformation Technologist with Security Clearance
Caelum Research Corporation · Fort Sill, United States
33 minutes ago