SonicJobs Logo
Left arrow iconBack to search

Security Control Accessor

Koniag Government Services, LLC
Posted 2 days ago, valid for 4 hours
Location

Washington, DC, US

Salary

$100,000 - $130,000 per year

Contract type

Full Time

Health Insurance
Paid Time Off
Flexible Spending Account

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.

Koniag Data Solutions, a Koniag Government Services company, is seeking an experienced Security Control Assessor (SCA) to support a comprehensive enterprise cybersecurity services program for a federal government client.

This position requires the ability to obtain and maintain a Minimum Background Investigation (MBI) or higher, PIV credentials, and all requisite IT access authorizations prior to performing work. Primary work will be performed at the client site in Washington DC and approved remote/telework locations.

 

We offer competitive compensation and an extraordinary benefits package including health, dental and vision insurance, 401K with company matching, flexible spending accounts, paid holidays, three weeks paid time off, and more.

 

This role serves as a key technical contributor responsible for the independent assessment and evaluation of security and privacy controls across the client's enterprise IT portfolio—spanning on-premises, cloud-hosted, and hybrid systems—in support of the agency's Federal Information Security Modernization Act (FISMA) compliance program, Risk Management Framework (RMF) activities, and Ongoing Authorization (OA) initiatives.

 

The ideal candidate is a detail-oriented and technically proficient security assessment professional with demonstrated experience conducting NIST SP 800-53 security and privacy controls assessments, developing Security Assessment Reports (SARs), supporting Authority to Operate (ATO) activities, and executing continuous monitoring assessments across a diverse federal enterprise IT environment. This individual must possess the ability to work independently across complex, multi-technology system boundaries and deliver thorough, accurate, and well-written assessment artifacts that meet rigorous federal documentation standards.

 

The Security Control Assessor will serve as an independent technical evaluator responsible for planning, executing, and reporting on security and privacy controls assessments for assigned systems and services across the client's enterprise IT portfolio. This individual is responsible for assessing the implementation and effectiveness of NIST SP 800-53 security and privacy controls, documenting assessment findings in accordance with NIST SP 800-53A methodologies, producing high-quality assessment artifacts, and supporting the full RMF assessment lifecycle from initial planning through final report delivery and POA&M development. The SCA works closely with ISSOs, system owners, security engineers, and Government stakeholders to ensure assessments are thorough, accurate, and completed within required timelines.

 

Principal responsibilities will include but are not limited to:

Security & Privacy Controls Assessment

  • Plan, execute, and report on comprehensive security and privacy controls assessments for assigned federal information systems and services, including on-premises, IaaS, PaaS, and SaaS implementations, in accordance with NIST SP 800-53 Rev 5, NIST SP 800-53A Rev 5, and applicable agency implementation procedures.
  • Conduct point-in-time full controls assessments, annual controls assessments, multi-year one-third assessments, and Ongoing Authorization (OA) evaluation assessments in accordance with the agency's assessment schedule and applicable implementation procedures.
  • Develop and deliver draft Security Assessment Plans (SAPs) no less than ten (10) business days prior to beginning each assessment, clearly documenting the assessment scope, boundaries, sampling strategies, test methods, and schedule.
  • Execute NIST SP 800-53A Determine If Statements (DISs) for all in-scope controls, documenting assessment findings to a level of detail sufficient to demonstrate that the implementation of each control objective is validated or not validated, avoiding high-level summary statements and ensuring technical depth across all technology types within the system boundary.
  • Conduct technical controls assessments across all technology types within each system boundary, including Windows and UNIX servers, network devices (routers, switches, Cisco, F5 load balancers), web applications, databases, cloud platforms, and endpoint systems, applying appropriate sampling strategies approved by the Government prior to implementation.
  • Develop Government-approved sampling strategies encompassing all asset types within each system boundary, typically between ten (10) and twenty (20) percent of applicable assets where appropriate, ensuring sampling covers all relevant device types, users, and services.
  • Map identified vulnerabilities and assessment findings to applicable NIST SP 800-53 Rev 5 controls and control families, ensuring accurate and complete linkage between technical findings and corresponding control deficiencies.
  • Produce comprehensive draft and final Security Assessment Reports (SARs) within required timelines, ensuring reports are comprehensive to the scope identified in the SAP, fully aligned to the agency's Governance, Risk, and Compliance (GRC) tool, include visual representation against the NIST Cybersecurity Framework (CSF), and are peer-reviewed for accuracy and grammar prior to submission.
  • Develop draft Plans of Action and Milestones (POA&M) entries for identified control deficiencies, typically using the agency's GRC tool, delivering draft POA&Ms within thirty (30) calendar days from point-in-time assessment kickoff.
  • Develop draft Annual Assessment Reports (AARs) per in-scope system within one-hundred-twenty (120) business days from point-in-time annual assessment kickoff, and deliver draft summary reports for multi-year assessment efforts no later than sixty (60) business days prior to the end of each Fiscal Year.
  • Incorporate all Government feedback into assessment artifacts within five (5) business days of receipt of comments, delivering finalized deliverables that accurately reflect all Government-provided corrections, questions, and recommendations.

Ongoing Authorization (OA) Evaluation Support

  • Conduct Ongoing Authorization (OA) controls assessments for systems approved for OA, applying agency-specific OA test procedures that replace traditional NIST SP 800-53A test procedures for OA-approved systems.
  • Execute OA Positive Testing monthly for OA-approved systems, using automated or semi-automated techniques to determine whether controls are operating effectively under normal circumstances, documenting results in the agency GRC tool in accordance with OA implementation procedures.
  • Execute OA Negative Testing annually for OA-approved systems, using automated or semi-automated techniques to determine whether controls respond as expected under abnormal circumstances where misuse is injected to attempt to circumvent the control, coordinating as necessary with penetration testing purple team resources.
  • Assist in the development and submission of OA Playbooks for Government approval, documenting the testing methodology for each OA core control including Test Strategy, Test Design, Test Execution, Results Evaluation, and Visualization components.
  • Conduct OA testing comprehensively across all technology types within each target system's boundary, including sampling across in-scope devices, users, and services, documenting all test results in detail within the agency GRC tool in accordance with applicable OA implementation procedures.
  • Ensure all OA Positive and Negative Testing documentation is peer-reviewed for accuracy and grammar prior to submission to the Government.

ISSO Support & Collaboration

  • Collaborate closely with assigned ISSOs to support their development of in-depth technical and operational knowledge about assigned systems, providing assessment expertise, technical guidance, and documentation support as needed.
  • Provide technical support and expertise to ISSOs in the development and maintenance of all security documentation in the ATO package, including System Security Plans (SSPs), Configuration Management Plans (CMPs), Information System Contingency Plans (ISCPs), and other RMF artifacts, ensuring documentation aligns with applicable agency implementation procedures and template requirements.
  • Support ISSOs in reviewing and validating system security documentation for technical accuracy, completeness, and alignment with the system boundary and technology stack, providing specific and actionable feedback to improve documentation quality.
  • Assist ISSOs in ensuring control implementation descriptions within SSPs are written to the required level of technical detail, clearly explaining how each control is implemented across all technologies within the system boundary using specific naming conventions, configurations, and operational procedures rather than high-level general statements.
  • Participate in Enterprise Change Control Board (ECCB) activities as needed, providing security assessment expertise to support the evaluation of proposed system changes and their potential impact on the system's security posture and ATO status.

Audit & Compliance Support

  • Support internal and external audit activities for assigned FISMA systems, facilitating meetings and walkthroughs of key cybersecurity capabilities, coordinating with system support personnel, and supplying auditors with requested artifacts and evidence within required timeframes.
  • Ensure audit artifacts are complete, accurate, and delivered on time to avoid repeated requests from auditors, communicating any issues or problems to the Government immediately upon discovery.
  • Support FISMA continuous monitoring activities, including the collection, validation, and submission of system-level FISMA metrics for assigned systems in alignment with federal CIO metrics requirements and agency reporting schedules.
  • Assist in the development and maintenance of automated visualizations and dashboards that reflect the status and effectiveness of security controls for assigned systems, providing continuous visibility into the security posture and compliance status of assigned systems.
  • Support High Value Asset (HVA) assessment activities for designated HVA systems, including vulnerability scanning and remediation validation, monitoring and analysis of relevant audit logs, and identification of connections between HVAs and other systems.
  • Assist in FedRAMP Continuous Monitoring (CONMON) management activities for applicable cloud service provider systems, including review of vulnerability, penetration testing, and ad hoc reporting to ensure vendor actions pose no security risk to the enterprise environment.

Documentation & Reporting

  • Develop and maintain all assigned security and privacy assessment documentation in alignment with applicable agency implementation procedures, ensuring all documents are complete, well-written, aligned to agency templates, and meet the level of detail specified in agency procedures.
  • Ensure all assigned documents are updated in the agency's GRC tool and relevant SharePoint repositories in accordance with required timelines and agency standards.
  • Prepare and submit all assigned deliverables peer-reviewed for accuracy, punctuation, and grammar prior to submission, ensuring deliverables are delivered on or before agency-defined completion dates.
  • Address all Government-provided comments, edits, errors, and questions within ten (10) business days of receipt, and escalate stakeholder unresponsiveness to the Government POC after ten (10) business days without receiving a required response.
  • Ensure all documentation created under the contract is Government owned, properly marked, accessible via Section 508 compliant formats as required, and not marked with any proprietary or company-restrictive language.

 

Education and Experience:

Required:

  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Information Systems, or a related field from an accredited college or university.
  • Minimum of 5 years of experience in federal information security, with demonstrated hands-on experience conducting NIST SP 800-53 security and privacy controls assessments for federal information systems.
  • Demonstrated experience developing Security Assessment Plans (SAPs), Security Assessment Reports (SARs), Annual Assessment Reports (AARs), and Plans of Action and Milestones (POA&Ms) in accordance with NIST SP 800-53A methodologies and federal RMF requirements.
  • Experience conducting technical controls assessments across diverse technology stacks, including Windows and UNIX servers, network devices, web applications, databases, and cloud platforms (IaaS, PaaS, SaaS).
  • Experience working with federal agency Governance, Risk, and Compliance (GRC) tools for documentation management, POA&M tracking, and continuous monitoring activities.
  • Ability to obtain and maintain a Minimum Background Investigation (MBI) or higher, PIV credentials, and all requisite IT access authorizations; must be eligible for Top Secret clearance access should such a requirement arise during the period of performance.

Preferred:

  • CISSP certification or demonstrated equivalent experience and commitment to obtain within 12 months of award.
  • Prior experience supporting federal civilian agency FISMA compliance programs in a Security Control Assessor or ISSO capacity.
  • Experience working on GSA Multiple Award Schedule (MAS) HACS SIN contracts or comparable federal IT cybersecurity contract vehicles.
  • Experience conducting Ongoing Authorization (OA) assessments using agency-specific positive and negative testing methodologies.

 

Required Skills and Competencies:

  • Exceptional written communication skills in English with demonstrated ability to produce clear, concise, technically thorough, and professionally written security assessment artifacts that meet rigorous federal documentation standards, including SSPs, SAPs, SARs, AARs, and POA&Ms.
  • Deep knowledge of NIST SP 800-53 Rev 5 security and privacy control families, including the ability to assess all control families across diverse federal information systems and accurately document implementation status at the required level of technical detail.
  • Strong proficiency with NIST SP 800-53A Rev 5 assessment methodologies, including development and execution of Determine If Statements (DISs), examination, interview, and testing assessment methods, and objective-based evidence collection and validation techniques.
  • Demonstrated ability to conduct technical controls assessments across heterogeneous technology stacks, including the ability to assess controls across Windows and UNIX operating systems, Cisco and other network devices, F5 load balancers, web applications, SQL and NoSQL databases, and cloud service environments.
  • Experience developing and applying Government-approved sampling strategies for large-scale system assessments, ensuring sampling encompasses all asset types and is representative of the full system boundary.
  • Proficiency with federal GRC tools for documentation development, POA&M management, continuous monitoring tracking, and assessment results documentation.
  • Familiarity with the NIST Risk Management Framework (RMF) lifecycle, including all six RMF steps—Categorize, Select, Implement, Assess, Authorize, and Monitor—and the contractor's role in supporting each step.
  • Knowledge of FISMA reporting requirements, federal CIO metrics, and the agency reporting process including CyberScope submission requirements.
  • Experience supporting federal audit activities, including IG, GAO, and internal auditor engagements, including preparation and delivery of audit artifacts within required timeframes.
  • Familiarity with NIST Cybersecurity Framework (CSF) and the ability to represent assessment findings visually against CSF functions in assessment reports.
  • Familiarity with FedRAMP authorization and continuous monitoring requirements for cloud service providers, including review of CSP vulnerability and penetration testing reports.
  • Knowledge of High Value Asset (HVA) assessment requirements, including OMB M-19-03 and CISA HVA 3.0 framework requirements.
  • Strong organizational skills with the ability to manage multiple concurrent assessment workstreams, meet tight deadlines, and maintain accurate and current documentation across a portfolio of assigned systems.
  • Familiarity with Section 508 accessibility requirements for federal documentation and the ability to produce Section 508 compliant deliverables in Adobe and Microsoft Word formats as required.

 

Desired Skills and Competencies:

  • Certified Information Systems Security Professional (CISSP) certification, or demonstrated commitment to obtain within 12 months of contract award.
  • Certified Authorization Professional (CAP) / ISC2 Certified in Governance, Risk and Compliance (CGRC) certification or equivalent RMF-focused professional certification.
  • CompTIA Security+ certification or equivalent foundational cybersecurity certification.
  • Experience conducting Ongoing Authorization (OA) assessments using agency-specific outcome-based positive and negative testing methodologies, including coordination with penetration testing purple team resources for negative testing activities.
  • Experience developing OA Playbooks documenting test strategy, test design, test execution, results evaluation, and visualization components for OA core controls.
  • Familiarity with NIST SP 800-37 Rev 2 Risk Management Framework and its practical application within a federal civilian agency environment.
  • Knowledge of cloud security assessment methodologies for IaaS, PaaS, and SaaS environments, including AWS and Microsoft Azure/M365 security control implementations and assessment approaches.
  • Familiarity with NIST SP 800-207 Zero Trust Architecture and its implications for security control implementation and assessment within a federal enterprise environment.
  • Experience with enterprise vulnerability scanning tools, including Tenable Security Center and Nessus, sufficient to review and incorporate vulnerability scan data into security control assessments and continuous monitoring activities.
  • Familiarity with Microsoft Defender suite, Microsoft Sentinel, and other Microsoft M365 security capabilities sufficient to assess and document relevant security controls within systems leveraging these platforms.
  • Knowledge of NIST SP 800-171 Rev 3 requirements for protecting Controlled Unclassified Information (CUI) in non-federal systems and their relationship to NIST SP 800-53 control implementations.
  • Experience with privacy controls assessments, including assessment of NIST SP 800-53 privacy control families and documentation of privacy control implementation status within SSPs and SARs.
  • Familiarity with the Factor Analysis of Information Risk (FAIR) methodology as applied to risk quantification activities supporting security assessment findings and POA&M prioritization.
  • Experience supporting tabletop exercises and functional exercises related to incident response and contingency planning in support of FISMA compliance activities.
  • Familiarity with the ServiceNow GRC module or equivalent enterprise GRC platform for POA&M tracking, continuous monitoring, and assessment documentation management.
  • Knowledge of NIST SP 800-160 systems security engineering principles as they relate to security architecture review and assessment activities within the secure SDLC.

 

Our Equal Employment Opportunity Policy:

The company is an equal opportunity employer. The company shall not discriminate against any employee or applicant because of race, color, religion, creed, ethnicity, sex, sexual orientation, gender or gender identity (except where gender is a bona fide occupational qualification), national origin or ancestry, age, disability, citizenship, military/veteran status, marital status, genetic information or any other characteristic protected by applicable federal, state, or local law. We are committed to equal employment opportunity in all decisions related to employment, promotion, wages, benefits, and all other privileges, terms, and conditions of employment.

 

The company is dedicated to seeking all qualified applicants. If you require an accommodation to navigate or to apply to a position on our website, please contact Heaven Wood via e-mail at accommodations@koniag-gs.com or by calling 703-488-9377 to request accommodations.

 

Koniag Government Services (KGS) is an Alaska Native Owned corporation supporting the values and traditions of our native communities through an agile employee and corporate culture that delivers Enterprise Solutions, Professional Services and Operational Management to Federal Government Agencies. As a wholly owned subsidiary of Koniag, we apply our proven commercial solutions to a deep knowledge of Defense and Civilian missions to provide forward leaning technical, professional, and operational solutions. KGS enables successful mission outcomes for our customers through solution-oriented business partnerships and a commitment to exceptional service delivery. We ensure long-term success with a continuous improvement approach while balancing the collective interests of our customers, employees, and native communities. For more information, please visit www.koniag-gs.com.

 

Equal Opportunity Employer/Veterans/Disabled. Shareholder Preference in accordance with Public Law 88-352




Learn more about this Employer on their Career Site

Apply now in a few quick clicks

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.