user avatar

Security Control Assessor

Tharros Defense, Inc.

Posted today

Job Requirements

Washington, DC
Public Trust Polygraph
Career Level not specified
Salary not specified
Join Premium to unlock estimated salaries

Job Description

Job Description
Tharros supports the Department of Homeland Security (DHS) with cybersecurity services across its Intelligence Enterprise. In support of this mission, we have an immediate opportunity for a Security Control Assessor.

In this role you will lead independent security control assessments of DHS Intelligence Enterprise systems, on-premise and in the cloud, from discovery through a completed authorization package supporting ATO, ATC, and IATT decisions. You will write assessment reports, validate remediation, and work closely with system owners and ISSOs. This position is on-site in a Government SCIF in Washington, DC.

Duties include but not limited to:
  • Conduct discovery and kick-off meetings with project stakeholders for new and re-authorization activities.
  • Assess management, operational, and technical security controls against NIST, CNSSI, and IC standards.
  • Conduct vulnerability, configuration, container, and serverless testing across on-premise and cloud environments.
  • Document findings in Security Assessment Reports and ensure alignment with POA&Ms.
  • Validate POA&M remediation and document evidence of compliance.
  • Prepare A&A packages in the GRC tool, including risk memoranda and ATO/ATC/IATT letters.
  • Produce System Security Test Reports and A&A portfolio reports.
  • Provide recommendations to mitigate risk and improve the security posture of assigned systems.


Requirements
  • BS degree in Information Technology, Cybersecurity, Information Systems, or Computer Science OR minimum of 6 years' experience in IT or cybersecurity.
  • Minimum of 3 years' experience in RMF security control assessment.
  • Active TS/SCI clearance and U.S. citizenship; willingness to undergo a DHS counterintelligence-scope polygraph.
  • Knowledge of the Risk Management Framework (RMF), NIST SP 800-53A, and CNSSI 1253.
  • Knowledge of the ATO, ATC, and IATT authorization process.
  • Knowledge of POA&M management and risk acceptance processes.
  • Skill in using at least two security tools (e.g., Nessus/ACAS, SCAP, Nmap, WebInspect, SonarQube, STIG Viewer).
  • Skill in writing Security Assessment Reports and risk recommendations.
  • Ability to lead an assessment independently and coordinate with system owners.
  • Proficient in Microsoft Office Suite to include Teams or similar workplace chat and videoconferencing tools.
  • Excellent written and oral communications skills.


Desired
  • CGRC (formerly CAP), CompTIA Security+, or CySA+ certification.
  • Cloud authorization experience (AWS or Azure).
  • Experience with RSA Arche r.


Summary
Tharros combines extensive cyber defense knowledge with the world's preeminent vulnerability expertise to identify and defend against attacks before they become problems. Working at mission speed, we harden mission systems faster and secure them for longer, so agencies never lose the mission edge. Tharros lifts the veil of enterprise cybersecurity to detect zero days before they affect you, enabling mission maneuverability and the confidence to move missions forward.

In the ever-evolving realm of cyberspace, we are dedicated to becoming the paramount defender in the 5th warfighting domain. By pioneering innovative security solutions and fostering an environment of continuous learning and vigilance, we aim to protect the interests of our nation's security. Our commitment to excellence in cybersecurity will establish new benchmarks, transforming the digital landscape into a secure and thriving frontier for future generations.

Tharros. See Everything. Secure Anything.

Tharros is committed to hiring and retaining a diverse workforce. We are proud to be an Equal Opportunity/Affirmative Action Employer and make employment decisions without regard to race, color, religion, creed, sex, sexual orientation, gender identity, marital status, national origin, age, veteran status, disability, or any other protected status.
group id: 10518809
Find Tharros Defense, Inc. on Social Media
Recruiters
user avatar
About Us
Tharros boldly moves missions forward with advanced cyber security tools and deep vulnerability expertise that detect and eliminate threats before they emerge. Tharros combines extensive cyber defense knowledge with the world’s preeminent vulnerability expertise to identify and defend against attacks before they become problems. Working at mission speed, we harden mission systems faster and secure them for longer, so government agencies never lose the mission edge. Tharros lifts the veil of enterprise cyber security to detect zero days before they affect you, enabling mission maneuverability and the confidence to move missions forward. At Tharros, we defend so missions can advance.

Tharros Defense, Inc. Jobs


Job Category
Security
Clearance Level
Public Trust