Skip to content
← All positions

Security Control Assessor (SCA)New

Location
Multiple in VA and MD
Employment type
Full time
Posted
September 17, 2026

Job Description:

ISEA is searching for an experienced and motivated Security Control Assessor (SCA) to join our growing team. In this role, you will serve as an independent validator of system security postures within the customer’s agency, conducting comprehensive and independent assessments of information systems to determine the overall effectiveness of implemented security controls and navigating the Risk Management Framework (RMF) under the guidelines of ICD 503 and CNSSI 1253. The ideal candidate possesses the deep technical knowledge required to verify security safeguards as well as the analytical and interpersonal skills to provide risk-based recommendations to authorizing officials.

Responsibilities:

• Plan and conduct comprehensive security control assessments based on NIST SP 800-53, CNSSI 1253, and customer-specific security requirements.

• Perform hands-on and automated validation of security controls, including reviewing system configurations, audit logs, access controls, and network boundary defenses.

• Utilize vulnerability scanning tools, STIGs, and manual verification methods to test the resilience of complex architectures, including cloud, on-premise, and hybrid environments.

• Critically evaluate Body of Evidence, or BoE, packages, including System Security Plans, CONOPS, and network diagrams, with a focus on accuracy and completeness.

• Translate complex technical vulnerabilities into actionable risk assessments, providing the Authorizing Official (AO) with a clear picture of the risk associated with system operation.

• Work closely with ISSMs, System Owners, and engineers, guiding them through the remediation of identified findings.

• Support the continuous monitoring program by reviewing periodic assessments, system security relevant change requests, and updated vulnerability data.

Qualifications:

• 5-10+ years’ experience in information assurance, cybersecurity assessment, or IT auditing, with a heavy emphasis on the RMF within the DoD or Intelligence Community.

• Bachelor’s or Master’s degree in Cybersecurity, Computer Science, Information Technology, or a related technical discipline.

• Active certifications in accordance with DoD 8140/8570 requirements (IAM Level III or IAT Level III): CISSP, CISA, CGRC (formerly CAP)

• Mastery of ICD 503, CNSSI 1253, and NIST Special Publications (NIST SP 800-37, 800-53, 800-53A).

• Proficiency with cybersecurity tools such as Xacta, Assured Compliance Assessment Solution (ACAS/Nessus), SCAP Compliance Checker (SCC), and STIG Viewer.

• Comprehensive understanding of enterprise networks, cross-domain solutions (CDS), database security, and advanced cloud environments.

• Strong interpersonal skills and the ability to maintain a strict, independent posture during assessments, while working constructively with system teams.

• Excellent technical writing skills to produce concise, accurate SARs and executive-level risk briefings.

• Ability to evaluate non-standard system architectures and determine appropriate compensatory controls when standard controls cannot be met.

Desired Skills:

• CEH or higher technical testing certifications.

Citizenship/Clearance Requirements:

• US Citizenship is required.

• Must be eligible to obtain and maintain a government security clearance.

Apply for this role

PDF or Word, up to 10 MB.

We use what you send here to consider you for this role. Please do not include classified or controlled information.

Security Control Assessor (SCA) — ISEA-Corp