Intermediate Security Control Assessor
CapgeminiAbout the role
Capgemini Government is looking for a Security Control Assessor with operational and technical security/privacy controls and control enhancements employed within or inherited by an information technology (IT) system to determine the overall effectiveness of the controls (as defined in NIST SP 800-37). The Security Control Assessor is ideal for collaborating with other business teams to support our government clients.
The successful candidate will have the opportunity to apply and grow their skillset in development work with a motivated and entrepreneurial team, engage with a wide range of stakeholders, and build CGS’ capabilities.
Job Responsibilities
As a Security Control Assessor, you will:
- Assess the implementation of NIST SP 800-53 security controls for major applications and general support systems using manual and automated test methods.
- Assess the severity of weaknesses or deficiencies discovered in the information system and its operating environment and recommend corrective actions to address identified vulnerabilities.
- Support security assessment and authorization (SA&A) during the system development life cycle to maintain the authorization (ATO).
- Perform security reviews, identify gaps in security architecture, and develop a security risk management plan.
- Perform security reviews and identify security gaps in security architecture resulting in recommendations for inclusion in the risk mitigation strategy.
- Perform risk analysis (e.g., threat, vulnerability, and probability of occurrence) whenever an application or system undergoes a major change.
- Plan and conduct security authorization reviews and assurance case development for initial installation of systems and networks.
- Provide input to the Risk Management Framework process activities and related documentation (e.g., system life-cycle support plans, concept of operations, operational procedures, and maintenance training materials).
- Review authorization and assurance documents to confirm that the level of risk is within acceptable limits for each software application, system, and network.
- Ensure that security design and cybersecurity development activities are properly documented (providing a functional description of security implementation) and updated as necessary.
- Support necessary compliance activities (e.g., ensure that system security configuration guidelines are followed, and compliance monitoring occurs).
Required Qualifications
- U.S. Citizenship is required.
- Eligible to obtain and maintain Government Security Clearance.
- 4 to 6 years of experience and the equivalent of a BS/BA in a cyber-related field. Direct experience or certifications may substitute for academic credentials.
- Must have one or more of the following CSSM, CAP, CISA and CISSP
- Understand network security architecture concepts, including topology, protocols, components, and principles (e.g., application of defense-in-depth).
- Knowledge of cyber defense and vulnerability assessment tools and their capabilities.
- Familiarity and understanding of applicable laws, statutes (e.g., in Titles 10, 18, 32, 50 and U.S. Code), Presidential Directives, executive branch guidelines, and/or administrative/criminal legal guidelines and procedures.
- Business continuity and disaster recovery continuity of operations plans.
- Knowledge of data use, processing, storage, and transmission controls.
- Must know and understand cybersecurity and privacy principles used to manage risks related to the use, processing, storage, and transmission of information or data.
- Knowledge of data backup and recovery, database systems, and Risk Management Framework (RMF) requirements
- Knowledge of Security Assessment and Authorization process and security models (e.g., Bell-LaPadula model, Biba integrity model, Clark-Wilson integrity model).
Company Overview
A global leader in consulting, technology services and digital transformation, Capgemini is at the forefront of innovation to address the entire breadth of client’s opportunities in the evolving world of cloud and digital platforms. Building on its strong 50-year heritage and deep industry-specific expertise, Capgemini enables organizations to realize their business ambitions through various services from strategy to operations. Capgemini is driven by the conviction that the business value of technology comes from and through people. It is a multicultural company of 300,000 team members in over 50 countries. The Group reported 2021 global revenues of EUR 18.2 billion. Capgemini Government Solutions, LLC (Capgemini GS) is a subsidiary of Capgemini focused on providing high-quality services to the U.S. Federal
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s