Security Control Assessor
Bethesda, MD
Full Time Clearance required USD 114K - 212K *
Dezign Concepts LLC
20241202-0140-15-008-01
Active Top Secret Clearance with Poly Required
(salary is commensurate with education and experience)
Please Note:
This job requires an existing Top Secret Clearance and Polygraph.
Experience Needed:
- Citizenship: Must Be a US Citizen
- Existing Clearance Required: Active Top Secret SCI with Poly
- Bachelor’s degree in computer engineering, Computer Science, Electrical Engineering, Information systems, Information Technology, Cybersecurity, or a closely related discipline.
- Four years of additional demonstrated work experience in Security Control Assessor (SCA) and Defensive Cyber Operations (DCO)Testing will be accepted in lieu of a bachelor’s degree.
- A Master’s degree in an applicable discipline be substituted for three years of demonstrated work experience
- Three (3) years of cybersecurity experience with at least one year of experience conducting SCAs under ICD 503/CNSSI 1253 NIST Cybersecurity Framework, Risk Management Framework (RMF), or a similar framework.
- One full year of SCA experiences within the last three calendar years.
- One full year supporting cloud environment and experience performing security assessments in a cloud environment (AWS, Google, IBM, Azure, and Oracle).
- Must meet Department of Defense (DOD) 8570.01-M baseline certification requirement for Information Assurances Technical (IAT) Level III CASP+CE, CCNP Security, CISA, or CISSP or Associate, GCED, GCIH, or CCSP.
- Knowledge of Independent Verification & Validation (IV&V) of security controls.
- Knowledge of general attack strategies (e.g., MITRE ATT&CK Framework).
- Knowledge of NISPOM, ICD 503, NIST SP 800-53, ICD 705, and other ICDs as appropriate.
- Skill in conducting vulnerability scans and recognizing vulnerability in security systems (e.g., Cloud Environments) ASW, Google, IBM, Azure, and Oracle.
- Make recommendations to the IC CISO or designee for improving TTPS for better cyber threat protection.
- Knowledge of system and application security threats and vulnerabilities.
- Knowledge of network access, identity, and access management e.g. public key infrastructure (PKI).
- Knowledge of network protocols such as Transition Control Protocol/Internet Protocol (TCP/IP), Dynamic Host Configuration, Domain Name System (DNS), and directory Services.
- Ability to assess the robustness of security systems and designs.
- Knowledge of cybersecurity principles and organizational requirements (relevant to confidentiality, integrity, availability, authentication, non-repudiation).
- Three years of experience performing security assessments in a cloud computing environment.
- Strong writing skills.
- Write final reports and defend all findings, including risk or vulnerability, mitigation strategies, and references.
- Report vulnerabilities identified during security assessments.
- Write penetration testing Rules of Engagement (ROE), Test Plans, and Standard Operating Procedures (SOP).
- Conducted security reviews, technical research and provided reporting to increase security defense mechanisms.
- Travel Domestic and International Travel 0-25%.
Benefits
Our comprehensive benefits package includes Medical, Dental, Vision, Health Savings Account, Paid Time Off, Holidays, Social Events, Employee Assistance Program, Team Building Activities, 401K, Tuition Assistance, and more.
Contact Us: Main Number: 1-888-663-2690 | info@Dezign-Concepts.com | www.dezign-concepts.com
Dezign Concepts provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws.
This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation and training.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: Application security AWS Azure CASP+ CCNP CCSP CISA CISO CISSP Clearance Clearance Required Cloud Computer Science DCO DNS DoD DoDD 8570 GCED GCIH ICD 503 MITRE ATT&CK NISPOM NIST NIST 800-53 Oracle Pentesting PKI Polygraph Risk management RMF Security assessment TCP/IP Top Secret Top Secret Clearance TTPs Vulnerabilities Vulnerability scans
Perks/benefits: Career development Health care Team events
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.