Senior Security Control Assessor Representative (SCAR)
Core
Conduct independent comprehensive assessments of IT system security controls and control enhancements to determine overall effectiveness and ensure cybersecurity readiness.
Role type
Senior Security Control Assessor Representative (SCAR)
Builds
Security authorization artifacts, risk assessments, and compliance reports for DoD/DAF systems
Domain
Defense / Cybersecurity / Risk Management Framework (RMF)
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Security control assessment, RMF compliance, NIST 800-53, DoD/DAF policies, cloud security (AWS/Azure/GCP), eMASS/Xacta, STIG evaluation, vulnerability assessment, POA&M review, technical writing, stakeholder briefing
Preferred skills
Fast Track ATO, CI/CD pipelines, DevSecOps, JIRA/Confluence
Technologies
AWS, Azure, Google GCP, eMASS, Xacta
Responsibilities
Evaluate IT infrastructure risk and define artifacts for Federal/DoD/DAF compliance; Assess IT systems against RMF, NIST CSF, and NIST 800-53; Support system/application assessment and authorization (A&A) efforts; Collect and verify business processes and validate mitigating controls; Review risk and control matrices and testing plans; Identify control gaps and test control design; Formulate conclusions on internal controls and process efficiency; Recommend policies for system reliability and access prevention; Conduct risk and vulnerability assessments; Review POA&Ms; Provide reports to SCA, AO, and CISO; Review network/system design for accuracy.
Seniority
Senior, hands-on IC
