RMF Expert SCA Lead
Pueo Business SolutionsAbout the role
Pueo is known for bringing the best talent and unique tools to every opportunity. Pueo's Parliament (aka workforce) is composed of professionals who are seeking the opportunity to work in a small business with a flat organization that thrives on career development and independence. In support of mission and professional growth, our Parliament has supported the development of multiple patents, proprietary tools, and applications as well as trademarked processes.
Our flat organization emphasizes career development across multiple career environments (at the members own pace) and ensures those who contribute broadly are properly rewarded. Pueo has four career environments where every member of the parliament can participate. Each environment has opportunities available for all levels. Opportunities are framed by an employee's desires and capabilities, and we ensure challenges, growth, and unique experiences are available for employees at all levels.
Our Career Environments (Program, Functional, Service, and Leadership) provide numerous opportunities for employees to invest in their personal growth and those things that offer fulfillment. We invest in helping our members create and execute their career development plans. Our Pods (small teams of 5 or less) are comprised of personnel with similar skillsets to ensure mentorship, understanding, and peer support.
Role: Pueo has an opportunity for an experienced TS/SCI cleared SCA Lead to join our team in Reston, VA. The SCA Lead is responsible for leading evaluations and ensuring the effectiveness of security controls within an organization. Their administrative and team managerial functions are key to success. Their technical functions encompass a range of tasks aimed at assessing, testing, and validating security measures to identify vulnerabilities and enhance overall security posture.
Responsibilities:
- Works with senior members of the client organization to ensure that overall program and project direction, strategy and expectations are met.
- Possesses the ability to understand DIA's CIO mission and the impact of managerial practices.
- Facilitates discussions and analysis to inform the decision process.
- Offers expertise in the form of knowledge, specialty skills, experience, or creativity.
- Have a firm understanding of IC and DOD Risk Management Frameworks, continuous monitoring, risk scoring, and risk management experience.
- Act as a high-level assessor able to help all the Security Control Assessor's (SCA) on the RMF Team with their assessments and assessment report reviews prior to submission to the government.
- SME in one or more of the following specialties: cloud and systems architectures, security architecture, cloud applications and storage, high performance computing, and software development.
- Has solid inter-personal skills and a desire to see the team succeed.
- Mentor to junior Security Control Assessors.
- Security Documentation Review: Review security documentation, including policies, procedures, guidelines, and technical documentation, to assess alignment with security requirements and industry standards. Ensure documentation accurately reflects implemented security controls and practices.
- Risk Assessment and Mitigation: Conduct risk assessments to identify and prioritize security risks based on their likelihood and impact. Collaborate with stakeholders to develop risk mitigation strategies and action plans to address identified vulnerabilities.
Security Controls Testing:
- Conduct rigorous technical testing of security controls across various domains such as access control, cryptography, network security, and incident response. Use automated tools, manual techniques, and specialized testing methodologies to identify weaknesses and vulnerabilities,
- Manage security controls assessments including kickoff, submission of deliverables, final report, and executive briefing,
- Conduct controls assessments of existing security measures and identify areas for improvement,
- Lead assessment interviews, testing, and coordinate evidence requests,
- Conduct audits to ensure that security controls are implemented correctly and operating effectively,
- Monitor and evaluate a system's compliance with security, resilience, and dependability requirements,
- Perform security reviews and identify security gaps in architecture resulting in recommendations for inclusion in the risk management strategy,
- Verify that application software/network/system security postures are implemented as stated, document deviations, and recommend required actions to correct those deviations through the development of POA&Ms,
- Vulnerability Scanning and Analysis: Perform vulnerability scans using automa
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s