Unknown Company

Security Control Assessor

Remote • Posted 4 days ago
Remote Full Time Protective Service Occupations
Security Control Assessor

The Security Control Assessor serves as a junior cybersecurity professional supporting the NIH Office of the Director (OD), Office of Information Technology (Client) Security Assessment Program. Working under the direction of the Senior Security Control Assessor, this position assists with the planning, execution, and documentation of independent Security Control Assessments (SCAs) throughout the authorization lifecycle. The position supports security control testing, evidence validation, documentation reviews, and assessment activities in accordance with the NIST Risk Management Framework (RMF), NIST SP 800-53 Rev. 5, and the Joint Cybersecurity Assessment Methodology (JCAM), while maintaining independence from authorization package development activities.

Key Responsibilities
  • Conduct or support independent Security Control Assessments in accordance with NIST SP 800-37, NIST SP 800-53 Rev. 5, JCAM, and NIH/HHS policy.
  • Review and validate authorization packages, including SSPs, SAPs, SARs, POA&Ms, Contingency Plans, and supporting evidence.
  • Assess the implementation and effectiveness of security controls through documentation reviews, interviews, and technical validation.
  • Review FedRAMP cloud packages and inherited controls, as applicable.
  • Document findings, recommendations, and remediation activities.
  • Support cybersecurity audits and continuous process improvement.
  • Assist senior assessors with evidence validation and remediation tracking.
  • Collaborate with system owners and ISSOs while maintaining assessment independence.
Required Qualifications
Education

• Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or related discipline. • Four (4) additional years of relevant experience may substitute for a bachelor's degree.

Experience
  • Three (3) to five (5) years of experience supporting cybersecurity, information assurance, RMF, Security Control Assessments, compliance, or IT operations.
  • Experience supporting security assessments, authorization activities, or information assurance programs.
  • Working knowledge of NIST RMF, NIST SP 800-37, NIST SP 800-53 Rev. 5, and JCAM.
  • Experience reviewing security documentation, technical evidence, or assessment artifacts.
  • Strong analytical, organizational, and technical writing skills.
Preferred Qualifications
  • Experience supporting NIH, HHS, or other Federal agencies.
  • Experience with eMASS or similar GRC platforms.
  • Familiarity with FedRAMP, NIST AI RMF, C-SCRM, and cloud security concepts.
  • Experience with SSPs, SAPs, SARs, POA&Ms, and Contingency Plans.
  • Experience supporting OIG, GAO, or independent cybersecurity assessments.
Desired Certifications
  • ISC2 Certified in Cybersecurity (CC)
  • ISC2 CGRC
  • CompTIA Security+
  • CompTIA CySA+
  • CompTIA PenTest+
  • Microsoft SC-900
Knowledge, Skills, and Abilities

Strong knowledge of federal cybersecurity assessment principles, excellent analytical and technical writing skills, effective communication, and the ability to work collaboratively while maintaining assessment independence.

Work Environment

Primarily remote with occasional on-site meetings or assessment activities as required.

Back to Job Search