Security Control Assessor Representative (SCAR)
Core
Obtain and maintain Authority to Operate (ATO) approvals for AFNWC weapon subsystems and supporting IT systems by adhering to the Risk Management Framework (RMF) and providing advice/recommendations to SCAs and AOs.
Role type
Senior Security Control Assessor Representative (SCAR)
Builds
ATO approvals for government information systems
Domain
Defense / Cybersecurity
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
NIST RMF mastery, NIST SP 800-53 controls, Windows/Linux OS hardening (STIGs), network protocols (TCP/IP), firewall configurations, IDS/IPS, cloud security (FedRAMP, AWS/Azure GovCloud), virtualization, database security, vulnerability scanning (ACAS/Tenable.sc/Nessus), configuration assessment (SCAP/STIG tools), log analysis/SIEM platforms (Splunk, Elastic Stack), System Security Plan (SSP) development, Security Assessment Report (SAR) writing, POA&M management, residual risk articulation
Technologies
ACAS, Tenable.sc, Nessus, SCAP, STIG, Splunk, Elastic Stack, AWS GovCloud, Azure GovCloud
Responsibilities
Review and assess security controls for assigned programs, develop and review System Security Plans (SSPs), write comprehensive Security Assessment Reports (SARs), manage Plans of Action and Milestones (POA&Ms), analyze control effectiveness and identify critical risks, articulate residual risk to Authorizing Officials (AOs)
Seniority
Senior, hands-on IC