NSS Security Controls Assessor

Springfield, VA 22150, USA

Critical Solutions

Critical Solutions specializes in providing expert cyber security services in the areas of automation, integration and research development.

View all jobs at Critical Solutions

Apply now Apply later

National Security Systems Security Controls Assessor (w/ active TS)

Location: Springfield, VA
Full-time, Hybrid
Clearance: Top Secret w/ SCI eligibility


JOB DESCRIPTION

Critical Solutions has an immediate opening for a National Security Systems (NSS) Security Controls Assessor (SCA) to support our federal customer in Springfield, VA

PRIMARY ROLES AND RESPONSIBILITIES:

  • Provide recommendations for Information Spillage Incident Response efforts on handling and sanitization methods pursuant to industry best practices, NIST 800-88 recommendations, and Federal guidelines.
  • Execute in-depth security control assessments (SCAs) for National Security Systems (NSS) in compliance with NIST RMF and CNSS policy, ensuring the highest level of system security.
  • Develop and maintain formal documentation, including NSS-specific SOPs and Concept of Operations (CONOPs), to streamline and enhance the authorization process.
  • Analyze cyber risk indicators stemming from system threats and vulnerabilities and provide detailed cybersecurity risk recommendations in support of NSS continuous monitoring activities.
  • Research, develop, and implement policies to improve the effectiveness and efficiency of the security authorization process while minimizing operational impacts on critical NSS systems.
  • Conduct vulnerability scans, create Body of Evidence (BoE) artifacts, and produce Security Assessment Reports (SARs) to document risk levels and recommended mitigations.
  • Provide in-depth analysis of cyber threat actor behavior and create detailed white papers to inform DHS NSS of potential risks and threat trends.
  • Actively participate in security meetings, including engineering review boards and cybersecurity supply chain risk management (C-SCRM) sessions, to inform and support NSS initiatives.
  • Develop automated assessment tools and dashboards to support continuous monitoring and ongoing authorization processes, leveraging tools like Splunk, Tenable, and Axonius.

BASIC QUALIFICATIONS:

  • Must be able to obtain and maintain an Entry on Duty (EOD) clearance and hold an active Top Secret clearance with SCI eligibility.
  • Bachelor's Degree in Information Technology, Cybersecurity, or a related technical field (or equivalent experience) AND 4+ years experience OR AS/AA with 6+ years experience OR HS/GED with 8+ years experience
  • Expertise in NIST RMF and CNSS policy frameworks, with the ability to apply them to secure National Security Systems.
  • Strong background in cybersecurity risk analysis and reporting, with experience in creating detailed BoE artifacts.
  • Proficiency in using cybersecurity tools for vulnerability scanning and continuous monitoring.
  • Local to D.C. or Virginia with ability to work on-site for classified work.

PREFERRED QUALIFICATIONS:

  • Expertise in conducting SCAs and cybersecurity assessments for NSS in accordance with NIST RMF and CNSS guidelines.
  • Extensive knowledge of risk management and mitigation techniques tailored to high-security environments, such as those encountered in NSS.
  • Experience developing and maintaining cybersecurity SOPs and CONOPs, with a focus on streamlining the risk assessment and authorization process.
  • Proficiency in using vulnerability assessment tools such as Nessus, Splunk, and AppDetective, along with MGMT compliance tools like CSAM-S.
  • Strong analytical skills to assess cyber threats, identify trends, and create actionable risk mitigation strategies through continuous monitoring.
  • Adept at creating Body of Evidence (BoE) artifacts, security reports, and other documentation required for high-risk systems.
  • Demonstrated ability to lead cross-functional teams in high-security environments and collaborate with government leads and stakeholders.
  • Certifications such as CISSP, CEH, GPEN, or CNSS-related credentials.
  • In-depth knowledge of supply chain risk management and its impact on national security.
  • Experience with federal cybersecurity policies, including DHS 4300B.
  • Hands-on experience developing cybersecurity risk assessments and strategies in classified environments.
  • Familiarity with emerging cybersecurity threats and trends impacting NSS systems

LOCATION:

  • Springfield, VA.
  • Must be able and willing to commute to work location when needed

ADDITIONAL INFORMATION:

CLEARANCE REQUIREMENT: Must possess an active DoD Top Secret clearance. In addition, selected candidate must undergo background investigation (BI) and finger printing by the federal agency and successfully pass the preceding to qualify for the position. US CITIZENSHIP IS REQUIRED due to the nature of the government contracts we support.

CRITICAL SOLUTIONS PAY AND BENEFITS:

Salary range $72,000 - $93,000. The salary range for this position represent the typical salary range for this job level and this does not guarantee a specific salary. Compensation is based upon multiple factors such as responsibilities of the job, education, experience, knowledge, skills, certifications, and other requirements.

BENEFIT SNAPSHOT: 100% premium coverage for Medical, Dental, Vision, and Life Insurance, Supplemental Insurance, 401K matching, Flexible Time Off (PTO/Holidays), Higher Education/Training Reimbursement, and more

Apply now Apply later
Job stats:  1  1  0

Tags: Business Intelligence C CEH CISSP Clearance CNSS Compliance ConOps DoD GPEN Incident response Monitoring Nessus NIST Risk analysis Risk assessment Risk management RMF Security assessment Security Assessment Report Splunk Top Secret Top Secret Clearance Vulnerabilities Vulnerability scans

Perks/benefits: Flex vacation Health care

Region: North America
Country: United States

More jobs like this

Explore more career opportunities

Find even more open roles below ordered by popularity of job title or skills/products/technologies used.