Security Controls Assessor (SCA)
CoalfireAbout the role
About Coalfire
Coalfire Federal is a market leading cybersecurity consultancy firm that provides independent and tailored advice, assessments, technical testing and a full suite of cyber engineering services to Federal agency customers. Coalfire Federal along with its parent company, Coalfire, has an unparalleled client list with deep customer relationships with leading cloud and technology providers including Amazon, Microsoft, IBM, Google and Oracle and Federal agencies. Coalfire has been a cybersecurity thought leader for over 20 years and has offices throughout the United States and Europe and is committed to making the world a safer place by solving our clients’ toughest security challenges.
But that’s not who we are – that’s just what we do.
We are thought leaders, consultants, and cybersecurity experts, but above all else, we are a team of passionate problem-solvers who are hungry to learn, grow, and make a difference.
We’re on the lookout for a Security Controls Assessor (SCA) to support our Federal team in the DMV area.
Location
Our clientele is largely in the government space, primarily within the Washington, D.C. / Maryland / Northern Virginia (DMV) areas. While we do offer opportunities that are remote, hybrid, or on-site - this position location and travel may vary based on client needs, therefore local candidates with the availability to go on site on a hybrid basis are highly preferred.
Position Summary
Possesses and applies a comprehensive knowledge across key tasks and high impact assignments. Plans and leads major technology assignments. Evaluates performance results and recommends major changes affecting short-term project growth and success. Functions as a technical expert across multiple project assignments. May supervise others.
What you'll do
- Determines enterprise information assurance and security standards.
- Develops and implements information assurance/security standards and procedures.
- Coordinates, develops, and evaluates security programs for an organization.
- Recommends information assurance/security solutions to support customers’ requirements.
- Identifies, reports, and resolves security violations.
- Supports customers at the highest levels in the development and implementation of doctrine and policies.
- Applies know-how to government and commercial common user systems, as well as to dedicated special purpose systems requiring specialized security features and procedures.
- Provides integration and implementation of the computer system security solution.
- Analyzes general information assurance-related technical problems and provides basic engineering and technical support in solving these problems.
- Ensures that all information systems are functional and secure.
What you'll bring
- Computer networking concepts and protocols, and network security methodologies.
- Risk management processes (e.g., methods for assessing and mitigating risk).
- Laws, regulations, policies, and ethics as they relate to cybersecurity and privacy.
- Cybersecurity and privacy principles.
- Cyber threats and vulnerabilities, including application vulnerabilities.
- Specific operational impacts of cybersecurity lapses.
- Authentication, authorization, and access control methods.
- Applicable business processes and operations of customer organizations.
- Capabilities and applications of network equipment including routers, switches, bridges, servers, transmission media, and related hardware.
- Cyber defense and vulnerability assessment tools and their capabilities.
- Server administration and client operating systems engineering theories, concepts, and methods.
- System software and organizational design standards, policies, and authorized approaches (e.g., international organization for standardization [iso] guidelines) relating to system design.
- System life cycle management principles, including software security and usability.
Education
Completed Bachelor’s degree from an accredited university, preferably in an IT related field.
Clearance / Suitability
Ability to obtain a clearance or a Public Trust is preferred, however all clearance levels and non-cleared applicants will also be considered.
Certifications One or more of the following: CISSP, CISM, or equivalent senior industry recognized cybersecurity certification.
Years of Experience
5 to 10 years of hands-on work experience with Assessor (SCA) duties; performing sy
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s