Job Requirements
Denver, CO
Top Secret/SCI Polygraph not specified
Early Career (2+ yrs experience)
$100,000 - $110,000
Job Description
JOB DESCRIPTION
Insight Global is seeking a Security Control Assessor (SCA) to support a federal customer in Denver, CO. This individual will be responsible for conducting independent assessments of management, operational, and technical security controls within information systems and networks to ensure compliance with Risk Management Framework (RMF) requirements and overall cybersecurity readiness.
The ideal candidate will have extensive experience supporting Authorization to Operate (ATO) efforts, performing security assessments, developing accreditation documentation, and advising stakeholders on cybersecurity risk management. This position will work closely with cybersecurity, systems engineering, and program leadership teams to evaluate security posture, identify risks, and ensure compliance with federal security standards.
Responsibilities
Conduct independent assessments of security controls in accordance with NIST SP 800-37 and the Risk Management Framework (RMF).
Review and validate accreditation and authorization packages supporting ATO efforts.
Plan and execute security authorization reviews for new and existing systems and networks. Evaluate security documentation, assessment results, and risk determinations to ensure acceptable risk levels.
Identify security gaps and provide recommendations to improve system security posture.
Perform technical risk assessments and develop mitigation strategies.
Support the development and maintenance of cybersecurity metrics, POA&Ms, and continuous monitoring activities.
Review and validate implementation of security controls and document any deviations from approved configurations.
Participate in risk governance activities and provide recommendations regarding cybersecurity risks and associated mitigations.
Develop and maintain RMF documentation throughout the system lifecycle.
Support vulnerability management activities and validate remediation plans.
Assess cloud environments, external services, and supporting infrastructure for compliance with security requirements.
Collaborate with technical teams to evaluate how new systems, interfaces, and technologies impact overall security posture.
Provide recommendations to support accreditation decisions and authorization activities.
REQUIRED SKILLS AND EXPERIENCE
TS/SCI Clearance
Bachelor's degree
IAM Level II or IAT Level II certification (Security+, CAP, CASP+, CISSP, or equivalent).
Hands-on experience supporting all phases of the Risk Management Framework (RMF).
Strong experience managing and supporting Authorization to Operate (ATO) processes.
Experience developing, tracking, and maintaining POA&Ms.
Experience performing technical risk assessments and accreditation support activities.
Experience with RMF Continuous Monitoring (ConMon) programs.
Experience using eMASS, XACTA, or similar RMF management tools.
Experience utilizing DISA STIG Viewer and applying STIG requirements.
Strong written and verbal communication skills.
Insight Global is seeking a Security Control Assessor (SCA) to support a federal customer in Denver, CO. This individual will be responsible for conducting independent assessments of management, operational, and technical security controls within information systems and networks to ensure compliance with Risk Management Framework (RMF) requirements and overall cybersecurity readiness.
The ideal candidate will have extensive experience supporting Authorization to Operate (ATO) efforts, performing security assessments, developing accreditation documentation, and advising stakeholders on cybersecurity risk management. This position will work closely with cybersecurity, systems engineering, and program leadership teams to evaluate security posture, identify risks, and ensure compliance with federal security standards.
Responsibilities
Conduct independent assessments of security controls in accordance with NIST SP 800-37 and the Risk Management Framework (RMF).
Review and validate accreditation and authorization packages supporting ATO efforts.
Plan and execute security authorization reviews for new and existing systems and networks. Evaluate security documentation, assessment results, and risk determinations to ensure acceptable risk levels.
Identify security gaps and provide recommendations to improve system security posture.
Perform technical risk assessments and develop mitigation strategies.
Support the development and maintenance of cybersecurity metrics, POA&Ms, and continuous monitoring activities.
Review and validate implementation of security controls and document any deviations from approved configurations.
Participate in risk governance activities and provide recommendations regarding cybersecurity risks and associated mitigations.
Develop and maintain RMF documentation throughout the system lifecycle.
Support vulnerability management activities and validate remediation plans.
Assess cloud environments, external services, and supporting infrastructure for compliance with security requirements.
Collaborate with technical teams to evaluate how new systems, interfaces, and technologies impact overall security posture.
Provide recommendations to support accreditation decisions and authorization activities.
REQUIRED SKILLS AND EXPERIENCE
TS/SCI Clearance
Bachelor's degree
IAM Level II or IAT Level II certification (Security+, CAP, CASP+, CISSP, or equivalent).
Hands-on experience supporting all phases of the Risk Management Framework (RMF).
Strong experience managing and supporting Authorization to Operate (ATO) processes.
Experience developing, tracking, and maintaining POA&Ms.
Experience performing technical risk assessments and accreditation support activities.
Experience with RMF Continuous Monitoring (ConMon) programs.
Experience using eMASS, XACTA, or similar RMF management tools.
Experience utilizing DISA STIG Viewer and applying STIG requirements.
Strong written and verbal communication skills.
group id: 10112344
Defining Company Culture