Security Control Assessor Representative (SCA-R)
Quick Summary
Use Government-assigned tools and databases to perform weekly updates, maintain system records, track assigned actions, and complete cybersecurity assessment and authorization activities.
The Security Control Assessor Representative (SCA-R) provides cybersecurity assessment, Risk Management Framework (RMF), and Assessment and Authorization (A&A) support for Department of Defense (DoD) information systems. The SCA-R works with Information System Security Managers (ISSMs), Program Management Offices (PMOs), system owners, technical teams, and Government cybersecurity stakeholders to assess security controls, identify cybersecurity risks, validate system compliance, and support authorization decisions throughout the system lifecycle.
The SCA-R performs independent technical and risk-based assessments using Government-approved processes, databases, and cybersecurity tools and develops complete, accurate, and defensible authorization documentation for Government and Authorizing Official (AO) review.
Responsibilities
~2 min read- →Use Government-assigned tools and databases to perform weekly updates, maintain system records, track assigned actions, and complete cybersecurity assessment and authorization activities.
- →Coordinate with ISSMs, PMOs, system owners, and technical stakeholders to understand system architectures, security requirements, authorization boundaries, configurations, and system changes.
- →Conduct risk analysis, security control assessment, and authorization activities across applicable RMF steps using approved RE5 tools and processes.
- →Verify system authorization boundaries and validate system security categorizations in accordance with FIPS 199 and applicable DoD requirements.
- →Identify applicable data classifications and conduct system-level cybersecurity risk assessments.
- →Assess threats, vulnerabilities, control deficiencies, and residual risks and compile findings into complete and accurate authorization packages.
- →Evaluate proposed and implemented system changes, determine their potential security and authorization impacts, and provide appropriate status and risk information to the Authorizing Official (AO).
- →Evaluate authorization and change requests, including web-filtering requests, firewall exceptions, ports and protocols, cybersecurity risks, STIG/SRG compliance, and on-site security requirements.
- →Review and validate compliance with applicable Security Technical Implementation Guides (STIGs), Security Requirements Guides (SRGs), security controls, and cybersecurity requirements.
- →Review, validate, and track Plans of Action and Milestones (POA&Ms) and associated cybersecurity deficiencies through resolution.
- →Lead and support on-site assessment visits, including planning, technical assessments, stakeholder coordination, entrance/exit briefings, documentation, findings development, and reporting.
- →Maintain access to and proficiency with required Government cybersecurity databases, vulnerability assessment platforms, endpoint security solutions, scanning tools, and RMF management systems.
- →Attend required Government meetings, technical exchanges, and training to remain current with policies, procedures, tools, and RMF process changes.
- →Complete required assessor, vulnerability scanning, endpoint security, and RMF process training.
- →Support assigned systems throughout their lifecycle in accordance with FISMA, DoD RMF, and applicable cybersecurity requirements.
- →Prepare and submit weekly activity reports documenting completed and ongoing activities, tracking identifiers, assessment status, significant findings, risks, issues, and key updates.
Requirements
~2 min read- Education:
- Bachelor's degree required.
- A bachelor's in information technology, Cybersecurity, Computer Science, Information Systems, or related technical field is preferred.
- Bachelor's degree required.
- Overall Experience:
- Minimum of eight (8) years of experience in a cybersecurity or network security position.
- A&A Experience:
- Minimum of five (5) years of experience performing Certification and Accreditation (C&A) and/or Assessment and Authorization (A&A) activities.
- Security Clearance:
- Must have a minimum of a current DoD Secret Clearance with the ability to obtain a DoD Top Secret clearance with SCI eligibility. A current DoD Top Secret clearance with SCI eligibility strongly preferred.
- Certification:
- Current DoD 8570 IAM Level III certification.
- Skills:
- Demonstrated experience serving as a Security Control Assessor Representative (SCA-R) and performing cybersecurity risk analysis and security control validation.
- Advanced understanding and practical application of the Risk Management Framework (RMF), including NIST SP 800-37, NIST SP 800-53, and CNSSI 1253.
- Demonstrated experience applying and evaluating Security Technical Implementation Guides (STIGs), Security Requirements Guides (SRGs), Plans of Action and Milestones (POA&Ms), cybersecurity security controls, and industry/DoD cybersecurity best practices.
- Demonstrated hands-on experience with relevant cybersecurity and RMF tools, including one or more of the following: eMASS, STIG Viewer, Nessus, ACAS, SCAP, and HBSS/Endpoint Security Solutions (ESS).
- Advanced understanding of multiple cybersecurity technology areas and domains, including network technologies and security, mobility, Windows, UNIX/Linux, cloud environments, cloud-native tools and services, HBSS/Endpoint Security Solutions (ESS), databases, and applications.
- Strong customer service and stakeholder engagement skills, with the ability to effectively coordinate with Government customers, ISSMs, PMOs, technical teams, system owners, and cybersecurity leadership.
- Ability to analyze complex technical and cybersecurity information and clearly communicate security risks, vulnerabilities, assessment findings, residual risk, and recommended corrective actions through written documentation and technical briefings.
- Location and Schedule: This role may be based at one of the following customer locations, with onsite requirements varying by location:
- Chambersburg, PA: Fully onsite, 5 days per week.
- Arlington, VA or Fort Meade, MD: Hybrid schedule, 4 days onsite per week with 1 telework day.
- Travel Requirements:
- Must be willing and able to support occasional domestic (CONUS) and international (OCONUS) travel, approximately 10% of the time.
The projected salary range for this position is $100,000+ annually. Final compensation will be determined based on factors including years of relevant experience, active security clearance level, certifications, technical skillset, contract requirements, and overall qualifications.
What We Offer
~1 min readLocation & Eligibility
Listing Details
- Posted
- September 28, 2026
- First seen
- September 28, 2026
- Last seen
- September 28, 2026
Posting Health
- Days active
- 0
- Repost count
- 0
- Trust Level
- 60%
- Scored at
- September 28, 2026
Signal breakdown
Browse Similar Jobs
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.