Security Control Assesor
big impact tech bitBaltimore, MD
Security Control Assesor
big impact tech bitBaltimore, MD
today
Occupations
Information Security AnalystsSecurity Management SpecialistsInformation Security EngineersIndustries
Other Scientific and Technical Consulting ServicesOther Management Consulting ServicesAdministrative Management and General Management Consulting ServicesAbout the role
Senior Security Control Assessor (SCA)
Location: Washington, DC (Hybrid)
Company: Big Impact Tech (BIT)
Clearance Required: Active Secret; must be able to obtain a TSA clearance About Big Impact TechBig Impact Tech (BIT) is a Small Business providing IT and business management consulting to federal and commercial clients. We deliver mission-focused solutions in data, cloud, cybersecurity, and program management.
Position Overview:
This position requires an active Secret clearance and the ability to obtain a TSA clearance. The Senior Security Control Assessor (SCA) leads independent security control assessments and produces the authorization packages that support Authorization to Operate (ATO) decisions. This position tailors each assessment to the system’s technology, including cloud, operational technology (OT), legacy, and AI systems, and works directly with system owners, ISSOs, and authorizing officials. The minimum 8 years of experience reflects the need for proven assessment judgment, deep knowledge of NIST controls, and the ability to deliver complete, defensible ATO packages.
Responsibilities:
- Conducts independent security control assessments in CSAM/JCAM.
- Develops Security Assessment Plans (SAPs) and Security Assessment Reports (SARs).
- Builds and maintains POA&M matrices.
- Prepares ATO, ATP, ATU, and conditional ATO packages.
- Produces Risk Assessment Memos (RAMs).
- Uploads and manages assessment evidence.
- Leads system kickoff meetings with system owners and ISSOs.
- Performs technology-tailored assessments for cloud, OT, legacy, and AI systems.
- Other duties as assigned.
Required Qualifications:
- BA/BS degree in Cybersecurity, Information Technology, or a related discipline.
- Minimum Experience Required:
- Minimum 8 years of cybersecurity experience, including 5 years performing security control assessments.
- Demonstrated experience with CSAM or JCAM.
- Demonstrated knowledge of NIST SP 800-37 (RMF), NIST SP 800-53 Rev. 5, and NIST SP 800-53A assessment procedures.
- Demonstrated experience writing SAPs, SARs, POA&Ms, and complete ATO packages.
- Demonstrated ability to communicate assessment results to senior government stakeholders. Additional Experience: CISSP, CISA, or CGRC (formerly CAP) certification. Security+ or equivalent DoD 8140 baseline certification. Demonstrated experience assessing cloud (FedRAMP), OT, or AI systems.
Matching similar jobs
JOB OVERVIEW
Experience level
Senior
Location
Baltimore, MD
Occupation
Information Security Analysts
Industry
Other Scientific and Technical Consulting Services
Posted
today
Tired of running searches?
Rank the roles you'd take once, and matches like these arrive on their own.
CREATE PROFILE