Security Control Assessor (SCA-R) - DoD Secret / TS

MD Ft Meade G Cooper 6910, United States

Full Time Senior-level / Expert Clearance required USD 131K - 140K

Chickasaw Nation Industries, Inc.

CNI serves as a holding company with multiple subsidiaries engaged in several lines of business for both the federal government and commercial enterprises.

View all jobs at Chickasaw Nation Industries, Inc.

Apply now Apply later

The Security Control Assessor Representative (SCA-R) / Cyber Information Assurance SME interface directly with assigned PM to understand the mission, security architecture, deployment locations and model, as well as any changes/upgrades that will occur to the program. Perform cybersecurity assessments/risk analysis. The purpose of the SCA-R support is to perform SCA-R/team lead functions within the A&A process.  Each team lead shall perform team lead/SCA-R duties for approximately 25 programs.  Programs and enclaves can include those supporting DISA, DoD CIO, Combatant Commands, DoD Agencies, Battlefield Information Collection and Exploitation System (BICES), or other DoD entities.  This support can report to multiple AOs.  The team lead shall follow the A&A process guidance and normal procedures of a team lead as outlined by the Government. Functions as a technical expert on multiple project assignments, equipment baselines, operating systems, and communication protocols. Has practical analytic skills to evaluate security posture with automated security tool and recommends mitigation and optimizes security posture of IT components. This position is onsite located at Fort Meade, MD.

Must be able to maintain a Secret clearance which requires U.S. Citizenship.  

As a federal contractor, CNI is a drug-free workplace and adheres to the Federal Controlled Substance Act.   

Chickasaw Nation Industries, Inc. serves as a holding company with multiple subsidiaries engaged in several lines of business (Technology, Infrastructure & Engineering, Health, Manufacturing, Public Safety, Consulting, and Transportation) for the federal government and commercial enterprises. A portion of our profits is used to support Chickasaw citizens. We are proud to support the economic development and long-term viability of the Chickasaw Nation and its people. CNI offers premium benefits eligible on the first day of hire to full time employees; (Medical - Dental – Vision), Company Life Insurance, Short-Term and Long-Term Disability Insurance, 401(K) Immediate Vesting, Professional Development Assistance, Legal Aid Assistance Program, Family Planning / Fertility Assistance, Paid Time Off, and Observance of (11) Federal Holidays.

ESSENTIAL REQUIREMENTS

This position requires one of the following certifications: CISM, CISSP, GSLC, CCISO

**Travel INCONUS and OCONUS is required - 20% travel

Requires DOD Secret or Top Secret Clearance.

ESSENTIAL DUTIES AND RESPONSIBILITIES

Essential duties and responsibilities include the following. Other duties may be assigned.

Perform certification assessments for assigned programs to include review of change requests; review of ports, protocols, and services; whitelist requests; self-assessments results; statements of compliance; scan and STIG reviews; systems security plans; cybersecurity control evidence and artifacts; and on-site review results.

Lead a team to review a system/enclave where the system/enclave resides. The team lead shall be required to conduct an in-brief, a daily hot wash with the review team and system/enclave/site personnel, and an out brief. In briefs and out briefs shall be submitted to RE5 SharePoint Administrator for posting to the repository no more than five business days after the review is complete. The trip report shall be submitted in the Government provided trip resourcing tool no more than five business days after the review is complete.

Present results and recommendations to AOs, Site Commanders, PMs, or other Government leadership.

Attend weekly training sessions and staff meetings to gain an understanding of changes or clarifications to procedures.


Team leads shall be required to use a variety of tools to include the Government provided trip resourcing tool (used to execute and on-site review), eMASS (for control reviews), Team Lead Resource (TLR) (to provide information on a program), nSPECT (to create in and out brief reports), and Requirement Tracking System (RTS) (to submit actions for review/signature). Other tools that will be used include the PPSM database, Whitelist Tool, DoD Information Technology Portfolio Repository (DITPR), RMF Knowledge Service, and Enterprise Security Posture System (ESPS).


Conduct security architecture reviews to ensure that the program’s architecture is in compliance with STIG requirements and best practices. This technical analysis will be considered in the risk analysis and documented/include in the certification recommendation.

Develop customized checklists based on the security architecture, special purpose equipment, type accredited deployment guides, Unified Capabilities Approved Product List deployment guides, and required ancillary equipment.

Analyze Plans of Action and Milestones (POA&M) and mitigation plans for unresolved findings to determine residual risk. This shall include reviewing and analyzing submitted POA&Ms with detailed technical justification and references for mitigations and determining if the proposed solution is adequate mitigation for approval. This technical analysis shall be documented/include in the statement of residual risk.


Conduct a Risk Assessment to analyze threats to and vulnerabilities of an information system and the potential impact that the loss of information or capabilities of a system would have on the user communities and the mission of the organization. The resulting analysis is used as a basis for identifying appropriate and cost-effective countermeasures and to determine residual risk.


Attend weekly training sessions and staff meetings to gain an understanding of changes or clarifications to procedures.

Conduct security architecture reviews to ensure that the program’s architecture in compliance with STIG requirements and best practices. This technical analysis will be considered in the risk analysis and documented/include in the certification recommendation.


Develop customized checklists based on the security architecture, special purpose equipment, type accredited deployment guides, Unified Capabilities Approved Product List deployment guides, and required ancillary equipment.


Analyze Plans of Action and Milestones (POA&M) and mitigation plans for unresolved findings to determine residual risk. This shall include reviewing and analyzing submitted POA&Ms with detailed technical justification and references for mitigations and determining if the proposed solution is adequate mitigation for approval. This technical analysis shall be documented/include in the statement of residual risk.

Attend the A&A Team Lead Training, Reviewer Introduction Training, Network Security Readiness Review (SRR) Course, and become ACP qualified in one SRR technology.

EDUCATION/EXPERIENCE REQUIRED

Bachelor of Science (B.S.) or above, or equivalent combination of IT technical or cybersecurity Associates Degree and seven (7) years’ experience.

Experience with a Program in a Federal organization.

A demonstrated proficiency in Microsoft Windows/Office and Microsoft Project.

CERTIFICATES / LICENSES / REGISTRATION

Must possess a 8570 DOD IAM-III level certification which requires one of the following certifications: CISM, CISSP, GSLC, CCISO.

Must posses a Secret or Top Secret Clearance.

PHYSICAL DEMANDS

Work is primarily performed in an office environment. Regularly required to sit. Regularly required use hands to finger, handle, or feel, reach with hands and arms to handle objects and operate tools, computer, and/or controls. Required to speak and hear. Occasionally required to stand, walk and stoop, kneel, crouch, or crawl. Must frequently lift and/or move up to 10 pounds and occasionally lift and/or move up to 25 pounds. Specific vision abilities required by this job include close vision, distance vision, depth perception, and ability to adjust focus.  Exposed to general office noise with computers printers and light traffic. 

The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job.  Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions of this job.

EOE including Disability/Vet

The estimated pay range for this role is $131K to $140K, with the final offer contingent on location, skillset, and experience. 

CNI offers a comprehensive benefits package that includes:

  • Medical

  • Dental

  • Vision

  • 401(k)

  • STD/LTD/AD&D

  • Employee Assistance Program (EAP)

  • Paid Time Off (PTO)

  • Training and Development Opportunities

Your application submission will be considered for all potential employment opportunities with Chickasaw Nation Industries (CNI).

Apply now Apply later
Job stats:  1  0  0

Tags: CISM CISSP Clearance Compliance DISA DoD DoDD 8570 eMASS GSLC IAM Network security POA&M Risk analysis Risk assessment RMF SharePoint Top Secret Top Secret Clearance Vulnerabilities Windows

Perks/benefits: Career development Fertility benefits Health care Insurance Travel

Region: North America
Country: United States

More jobs like this

Explore more career opportunities

Find even more open roles below ordered by popularity of job title or skills/products/technologies used.