Demo

Security Control Assessor - Journeyman

SMS Data Products Group, Inc.
Springfield, VA Full Time
POSTED ON 8/5/2025
AVAILABLE BEFORE 10/1/2025
Overview:
SMS is seeking a skilled and detail-oriented Security Control Assessor and Validator to join our team. The successful candidate will be responsible for evaluating, testing, and validating the effectiveness of security controls within our organization's information systems and networks, with a strong emphasis on applying the Risk Management Framework (RMF).

As a dynamic systems integrator, SMS offers proven solutions in engineering, operations, cybersecurity, and digital transformation. With expertise in modernizing and optimizing legacy infrastructure and systems, ensuring operational efficiency, and designing, implementing, and managing secure environments, SMS supports business and mission goals with proficiency, quality, and integrity.

SMS has been serving the advanced information technology needs of the federal government since 1976, delivering talented teams and innovative, cost-effective solutions and services to support our customers’ missions for more than 40 years. SMS is headquartered in McLean, Virginia, with offices and on-site operations at customer locations throughout the United States. For additional information on SMS, visit www.sms.com.

Submit your resume today.
Responsibilities:
The Security Control Assessor, you will be responsible for the following:

  • Provide the United States Coast Guard (USCG) with tailored documentation to support their security authorization.
  • Independent assessor for Risk Management Framework Steps 0 to 7.
  • Plan and execute security control assessments for various information systems within the organization.
  • Develop and maintain assessment procedures and methodologies aligned with NIST guidelines and other relevant frameworks.
  • Analyze and evaluate the effectiveness of implemented security controls.
  • Identify vulnerabilities, weaknesses, and potential risks in information systems and infrastructure.
  • Prepare detailed Security Assessment Reports (SARs) documenting findings and recommendations.
  • Collaborate with system owners, ISSOs, and other stakeholders throughout the assessment process.
  • Verify the implementation of remediation actions and conduct follow-up assessments as needed.
  • Provide expert advice on the development and maintenance of System Security Plans (SSPs) and Plans of Action and Milestones (POA&Ms).
  • Stay current with evolving cybersecurity threats, technologies, and best practices.
  • Validate security control implementation and provide test results.
  • Hands-on experience in assessing RMF Step 4 and performing continuous monitoring.
  • Examine security control weaknesses and determine if they are producing the desired intent.
  • Deep understanding of Vulnerability Management practices.
Qualifications:
  • US Citizenship required and hold DOD Secret or higher clearance.
  • Intimate understanding of NIST RMF implementation guidance.
  • Hands-on experience with using eMASS or similar Information Assurance tools.
  • Well-developed understanding of Federal Civilian or DHS Security Assessment and Authorization (SA&A) processes.
  • In-depth understanding of the relevance of NIST Security Controls and Control Implementation methodologies to the SA&A process.
  • Experience analyzing vulnerability scans and STIG implementations.
  • Can demonstrate understanding of critical documentation required in Security Authorization (SA) Packages.
  • Ability to understand and support Privacy Compliance Activities to include the development of Privacy Impact Analysis (PIA), Privacy Threshold Analysis (PTA), and Statement of Record Notices (SORN).
  • At least one of the DOD 8750 IAT II certifications: CCNA Security, CySA , GICSP, GSEC, Security CE, CND, or SSCP.
  • CSSP-AU certification - must obtain within 60days of employment.
  • Knowledge/Familiarity with DoD 8500, DoD 8510, DHS 4300 A and B, NIST SP 800-18, 60, 70, 53, 53A, 137, IACS, CMRS, COAMS, JIMS, Swimlane, Governance, Risk, and Compliance, POA&M (i.e., Management, Assessment, etc.), ERS, FISMA, Knowledge Service, ACAS, Tanium, Power BI, Project/Program Management, TASKORD (i.e., FRAGO, CTO, etc.), and Data Calls (i.e., OIG Audit, etc.)
Desired:
  • Well-developed understanding of Systems Development Lifecycle (SDLC) and ideally the DHS Systems Engineering Lifecycle (SELC) process as it relates to Security Assessment and Authorization (SA&A).
  • Relevant DOD, DHS or .gov Cyber Security Information Assurance focused experience with specific current hands-on experience researching, writing, and submitting complete A&A documentation packages for new system authorizations.

Clearance
  • Active DOD Secret clearance required
Certifications
  • IAT Level II
  • CSSP-AU: At least one of the DOD 8750 IAT II certifications: CASP CE, CCNP Security, CISA, CISSP (or associate), GCED, GCIH, or CCSP . Within 60 days of hire.

SMS is a dynamic systems integrator established in 1976, delivering talented teams and innovative, cost-effective solutions and services to support our customers’ missions for more than 47 years. Our ability to hire and retain quality people in a rapidly evolving IT market is proven through our employee retention rate averaging over 3 years. At SMS, we place a high value on quality of service, customer satisfaction, and best-of-breed policies and practices, resulting in CMMI Level 3 certification and ISO registrations including 9001:2015, 20000-1:2018, and ISO/IEC 27001:2013. SMS is headquartered in McLean, Virginia, with offices and on-site operations at customer locations throughout the United States.

SMS is an Equal Opportunity Employer.
All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.

If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Security Control Assessor - Journeyman?

Sign up to receive alerts about other jobs on the Security Control Assessor - Journeyman career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$91,971 - $119,923
Income Estimation: 
$114,980 - $148,259
Income Estimation: 
$70,462 - $84,818
Income Estimation: 
$77,991 - $108,747
Income Estimation: 
$87,093 - $107,335
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$87,093 - $107,335
Income Estimation: 
$111,725 - $147,313
Income Estimation: 
$112,673 - $137,290
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$112,673 - $137,290
Income Estimation: 
$139,945 - $168,577
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$139,945 - $168,577
Income Estimation: 
$164,835 - $201,088
Income Estimation: 
$135,994 - $168,063
Income Estimation: 
$161,209 - $233,553
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at SMS Data Products Group, Inc.

SMS Data Products Group, Inc.
Hired Organization Address Albuquerque, NM Other
Overview SMS is hiring a Part-Time/After Hours Call Center Technician to work on the C4 contract at Kirtland AFB in New ...
SMS Data Products Group, Inc.
Hired Organization Address Camp Springs, MD Other
Overview SMS is seeking a Subject Matter Expert that has experience in architecting and deploying IP networks within lar...

Not the job you're looking for? Here are some other Security Control Assessor - Journeyman jobs in the Springfield, VA area that may be a better fit.

Security Control Assessor (SCA)

SYSTEM HIGH CORPORATION, Arlington, VA

AI Assistant is available now!

Feel free to start your new journey!