72-025 – Security Control Assessor (SCA) I
Position Overview
Sandy Mac Evolution LLC is seeking a Security Control Assessor (SCA) I to support Department of Defense Special Access Program information systems at Peterson AFB, Colorado.
The SCA conducts comprehensive assessments of management, operational, and technical security controls to determine whether controls are implemented correctly, operating as intended, and effectively meeting information-system security requirements.
The position also evaluates identified weaknesses and vulnerabilities and provides recommendations for corrective action across Collateral, SCI, and SAP environments.
Current Billet Requirements
- Mandatory: 5–7 years of related experience.
- Mandatory: 3+ years of experience with SAP, SCI, or Collateral Information Systems security and implementation of applicable regulations.
- Mandatory: Prior performance as an ISSO and ISSM.
- Desired: SAP experience.
- IAM Level I required in lieu of IAT Level III.
Key Responsibilities
- Oversee development, implementation, and evaluation of information-system security policy.
- Assess information systems using Risk Management Framework methodology and applicable JSIG requirements.
- Advise system owners, data owners, Program Security Officers, and Authorizing Officials regarding assessment and authorization matters.
- Evaluate authorization packages and provide authorization recommendations.
- Evaluate threats and vulnerabilities to determine whether additional safeguards are required.
- Advise government personnel regarding confidentiality, integrity, and availability impact levels.
- Ensure security assessments are completed and results are documented.
- Prepare Security Assessment Reports for authorization boundaries.
- Initiate and maintain POA&Ms addressing weaknesses identified during assessments.
- Evaluate security-assessment documentation and provide written authorization recommendations.
- Submit security authorization packages to the AO/DAO.
- Assess proposed changes to authorization boundaries, operating environments, and mission requirements.
- Review and concur with sanitization and clearing procedures.
- Support government compliance inspections.
- Support investigation and remediation of cybersecurity incidents.
- Ensure information systems address all applicable phases of the system development life cycle.
- Evaluate hardware and software changes for security impact.
- Evaluate implementation and effectiveness of continuous-monitoring plans.
- Represent the customer on inspection teams.
Experience
- 5–7 years of related experience.
- Minimum three years of SAP, SCI, or Collateral Information Systems security experience.
- Prior performance as both an ISSO and ISSM.
Education
- Bachelor’s degree in a related discipline or equivalent experience.
- A bachelor’s degree may count as four years of equivalent experience.
Certifications
- DoD 8570.01-M IAM Level I required in lieu of IAT Level III.
Security Clearance
- Active Top Secret clearance required.
- SCI eligibility required.
- Eligibility for access to Special Access Program information.
- Must be willing to undergo a Counterintelligence polygraph.
Other Requirements
- Must be able to regularly lift 50 pounds.
Learn more about this Employer on their Career Site
