Security Controls Assessor
@ UltraViolet CyberSecurity Controls Assessor
This job is still taking applications, but it's been up a while.
About the job
UltraViolet Cyber provides unified security operations solutions for Fortune 500, government, and commercial clients, combining technology and expertise globally, based in Virginia.
Requirements
- 5+ years cybersecurity experience
- Knowledge of RMF and NIST 800-series
- Deep understanding of NIST SP 800-53
- Experience with vulnerability scanning
Qualifications
- Bachelor’s in cybersecurity or related
- Certifications like CISSP, CISA, CAP
- US Citizenship required
- Ability to conduct comprehensive assessments
Full job description
UltraViolet Cyber is seeking to hire a Senior Security Control Assessor (SCA) to act as an independent evaluator to ensure the effectiveness of management, operational, and technical security controls. The candidate will lead cybersecurity compliance assessments, identify control gaps and vulnerabilities, and recommend risk-mitigation strategies to support enterprise system authorization.
What You'll Do:
- Assessment Execution: Plan and execute comprehensive security control assessments in accordance with frameworks like the Risk Management Framework (RMF) and FISMA.
- Testing & Evaluation: Review system configurations, evaluate evidence, and perform technical testing (e.g., vulnerability scanning) to validate security posture.
- Documentation & Reporting: Compile assessment results into Security Assessment Reports (SARs) and generate risk determinations for Authorizing Officials (AOs).
- Remediation & Tracking: Identify control weaknesses and support the development of Plans of Action and Milestones (POA&Ms).
- Team Leadership: Guide junior assessors, review deliverables, and coordinate assessment activities with ISSOs, system owners, and stakeholders.
What You've Done:
- US Citizenship is required for this role.
- Education: Bachelor’s degree in cybersecurity, computer science, information systems, or a related field. (Or 6 years of experience equivalency)
- Experience: 7+ years of hands-on experience in cybersecurity, audit, or compliance, with specialized focus on RMF and NIST 800-series publications.
- Regulatory Expertise: Deep understanding of statutory guidance such as NIST SP 800-53, NIST SP 800-53A, and FISMA.
- Certifications: Industry-recognized credentials such as the Certified Information Systems Security Professional (CISSP), Certified Information Systems Auditor (CISA), or Certified Authorization Professional (CAP).
- Background Investigation: This role requires a Federal background investigation. A current or prior DHS suitability is highly preferred.
What We Offer:
Similar jobs
- S
Access Control Security Officer
Securitas · Hilliard, OH, United States
Posted 2 weeks ago - S
Security Officer - Access Control
Securitas · Grove City, OH, United States
Posted 1 week ago - G
Response Security Monitor
GardaWorld Security Services U.S. · Columbus, Ohio
Posted 2 days ago - G
As Needed-Special Response Security
GardaWorld Security Services U.S. · Grove City, Ohio
Posted 3 days ago - G
Special Response Security Agent
GardaWorld Security Services U.S. · Grove City, Ohio
Posted 3 days ago - A
Facilities Controls Engineer
Anduril Industries · Ashville, Ohio, United States
Posted 4 weeks ago