Security Control Assessor (SCA)
CACI International IncAbout the role
CACI is seeking a Security Control Assessor (SCA) to join our team of talented Cybersecurity professionals in Reston, VA. You will evaluate Government customer systems and other security standards and publications as well as Government customer defined security guidelines and regulations. You will also determine the extent to which the assigned security controls are implemented correctly; operating as intended; and producing the desired outcome with respect to meeting the regulatory and or statutory security requirements for National Security Systems.
Duties include but are not limited to:
Evaluate Government customer systems against NIST SP 800 53/53A R4, 30, 37 and 39, RMF and other security standards and publications as well as Government customer defined security guidelines and regulations utilizing the customer assessment tracking system.
Conduct a comprehensive assessment of the management, operational, and technical security controls employed within or inherited by complex and diverse information systems to determine the overall effectiveness of the control implementation.
Function as an independent and unbiased advocate who provides evidence to validate the trustworthiness of the system for the designated Authorizing Official (AO).
Conduct hands-on security control testing, analyze Body of Evidence (BoE) documentation and test results, document risk and recommend countermeasures.
Provide an assessment of the severity of weakness or deficiencies discovered in the information system and its environment of operation and recommend corrective actions to address identified vulnerabilities.
Conduct hands-on security testing leveraging commercial tools and custom developed scripts and procedures.
Execute vulnerability/compliance assessment tools and evaluate results for systems undergoing security assessment.
Participate in joint test teams with other customer organizations and or Government Agencies to complete security assessment and adjudication.
Coordinate with other program elements conducting security testing.
Actively participate in or lead technical exchange meetings and application review boards, documenting actions items/results of these events.
Brief management, as needed, on the status of action items and/or results of activities.
Prepare security assessment reports containing the results and findings form the assigned security control assessments.
Provide documentation to the customer which describes all identified system risks, planned test procedures taken and test results.
Provide enhancement capabilities and SOPs to assessment operations for execution and implementation.
Responsible for implementing and applying technologies, processes, and practices designed to protect networks, devices, programs, and data from malicious attack, damage, or unauthorized access.
Investigates network device and information security incidents to determine extent of compromise to national security information and automated information systems.
You’ll Bring These Qualifications
TS/SCI with Polygraph (active / in-scope)
15+ Years of relevant experience (Bachelor’s Degree in related field may be substituted for 5 years of relevant experience), or Bachelor’s Degree + 10 years of related experience.
4+ years of relative experience. Additional experience may be considered in lieu of a degree
Familiarity with conducting security assessment in support of accreditation and or authorization (A&A) decisions.
Familiarity with National Institute of Standards and Technology (NIST) Cybersecurity Framework and National Institute of Standards and Technology (NIST) Risk Management Framework (RMF) requirements.
Familiarity with National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53 and or 800-53A Revision 4 as well as 800-30, 37 and 39.
Familiarity with the Committee on National Security Systems (CNSS) Instruction No. 1253.
Knowledge of Federal laws, regulations, policies, and ethics as they relate to cybersecurity.
Knowledge of cyber defense and vulnerability assessment tools, including open source tools, and their capabilities.
Knowledge of cybersecurity principles and organizational requirements (
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s