Jobs and Careers
SK

Senior Security Control Assessor

SkyePoint Decisions
United States, United StatesRemotefull_timeVerifiedPosted 13 Nov 2025

About the role

Overview

 

SkyePoint Decisions is a leading Cybersecurity Architecture and Engineering, Critical Infrastructure and Operations, and Applications Development and Maintenance IT service provider headquartered in Dulles, Virginia with operations across the U.S. We provide innovative enterprise-wide solutions as well as targeted services addressing the complex challenges faced by our federal government clients. Our focus is on enabling our clients to deliver their mission most efficiently and effectively – anytime, anywhere, securely. We combine technical expertise, mission awareness, and an empowered workforce to produce meaningful results.

 

Join the SkyePoint team and become part of a highly skilled, professional workforce dedicated to delivering mission-critical solutions. Our exceptional technical experts provide innovative services and solutions to federal agencies, making a meaningful impact every day. At SkyePoint, we value top talent and foster an environment where your ideas and contributions truly matter. Be part of a team that values excellence and rewards innovation—your future starts here!

 

This is a contingent position based upon customer approval.

 

Responsibilities

SkyePoint Decisions, Inc. is seeking a highly motivated team member to fill the role of a Senior Security Control Assessor to join our team supporting the Department of Education’s (DoED) Federal Student Aid (FSA) Cybersecurity and Privacy Support Services (CPSS) in Washington, DC. The Senior Security Control Assessor (SCA) conducts independent, comprehensive assessments of the management, operational, and technical security/privacy controls employed within or inherited by an information technology (IT) system to evaluate overall control effectiveness, as defined in NIST SP 800-37. The SCA ensures IT systems meet organizational, regulatory, and compliance standards while balancing mission goals with security requirements. 

 

This is a remote position. 

 

Responsibilities:

  • Perform security reviews to identify architectural gaps and provide recommendations for risk mitigation. 
  • Conduct risk analyses (e.g., threats, vulnerabilities, probability of occurrence) during significant system/application changes. 
  • Plan and execute security authorization reviews, assurance case development, and audits for system installations and networks. 
  • Provide input to the Risk Management Framework (RMF) and related documentation, including lifecycle support plans, CONOPS, and operational procedures. 
  • Review authorization packages and assurance documents to confirm risk levels are acceptable for systems, applications, and networks. 
  • Verify that system, network, and application security postures are implemented as designed, documenting deviations and recommending corrective actions. 
  • Perform security reviews to identify architectural gaps and provide recommendations for risk mitigation. 
  • Assess the effectiveness of implemented security controls across management, operational, and technical areas. 
  • Support compliance activities by ensuring security configuration guidelines and standards are followed. 
  • Evaluate configuration management and release processes for security impacts. 
  • Define/document how new systems or interfaces affect the organization’s current security posture. 
  • Develop security compliance processes and perform audits of external services (e.g., CSPs, data centers). 
  • Ensure Plans of Action & Milestones (POA&Ms) and remediation plans are established for vulnerabilities. 
  • Participate in Risk Governance processes by presenting risks, mitigations, and technical assessments. 
  • Support acquisition and procurement efforts to ensure information security requirements are integrated. 
  • Produce reports, briefings, and technical documentation reflecting assessment results and recommendations. 

Qualifications

Required Qualifications:

  • Must be able to obtain a DoED Level 6 High Risk/Public Trust Security Clearance 
  • 7+ years of relevant IT/cybersecurity experience. 
  • Certification in A+, Net+, Security+; Preferred: CISSP, CISM 
  • Degree in a technical/cyber-related field (or equivalent experience/certifications). 
  • Proficiency in assessing security controls against standards (e.g., NIST SP 800-53, CIS CSC, Cybersecurity Framework). 
  • Strong skills in vulnerability scanning, penetration testing principles, and interpreting results. 
  • Ability to conduct risk, impact, and compliance assessments. 
  • Skill in technical documentation, briefings, and audit reporting. 
  • Proficiency in security architecture review and system design evaluation. 
  • Know

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

SkyePoint Decisions

View company profile →