Security Control Assessor - IT Security Specialist 3

Tyton LLC
United States
about 2 months ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
2 years minimum
Compensation
$120,000.0 - $150,000.0
Working hours
Regular working hours
Job source

Tech stack

Cyber Security Information Systems Linux Supervisory Control and Data Acquisition (SCADA) Google Cloud Cloud Platform System SC Clearance Information Technology

Job description

Join our team supporting NASA cyber security in the area of Risk Management and Enterprise Assessment Services.

Our team provides Risk Management services supporting Independent Assessments in accordance with Federal mandates, NIST guidance, and NASA policies and procedures. This includes support to an effective and comprehensive enterprise independent assessment service for NASA information systems, including Operational Technologies and cloud systems.

Security Control Assessor (SCA) Position Description:

  • Conduct independent comprehensive assessments of the management, operational, and technical security controls and control enhancements employed within or inherited for traditional information technology (IT), operational technology (OT), and mission systems to determine the overall effectiveness of the controls (as defined in NIST SP 800-37)
  • Create a pre-assessment verification checklist and submit to ISO
  • Provide verification that System Security Plans (SSPs) to be assessed and audited are ready for an assessment via use of an Agency approved tool
  • Create security assessment plan prior to scheduling assessment
  • Submit security assessment plan to Information System Owner (ISO) for approval
  • Schedule assessments
  • Conduct technical and non-technical security assessment
  • Create Security Assessment Report (SAR) using agreed upon format
  • Schedule and perform system assessment out-brief with ISO
  • Attend Authorization To Operate (ATO) brief with Authorizing Official (to be scheduled by ISO)
  • Upload all security assessment documentation in the Agency approved tool
  • Work collaboratively with cross-functional teams to gather necessary information for assessments
  • Ensure timely and accurate reporting of assessment results, vulnerabilities, and compliance status
  • Collaborate with stakeholders to develop and implement corrective action plans based on assessment findings
  • Provide expertise in scaling security measures to meet the unique requirements of diverse IT systems
  • Maintain awareness of emerging threats and industry best practices to continually enhance assessment methodologies
  • Operate effectively in a fast-paced environment, demonstrating the ability to be proactive and adaptive
  • Act as a client-facing representative of the organization, engaging with clients professionally and effectively
  • Perform security assessment duties including

Requirements

  • Bachelor’s degree
  • 12 years of relevant experience
  • 2 years of hands-on experience in Security Control Assessments
  • Proven ability to handle a high volume of assessments, with a focus on program-scale operations
  • In-depth knowledge of NIST 800-53/800-30 standards
  • Effective communication skills to convey complex security concepts to various stakeholders
  • Excellent organizational skills and the ability to manage a rotating schedule of assessments
  • Ability to obtain Secret clearance
  • Within 50 miles radius for a NASA facility (https://science.nasa.gov/about-us/nasa-centers)
  • Availability for occasional travel 20%

Nice to Have Qualifications:

  • Security control assessments or ISSO, ISSM, ISSE experience.
  • Demonstrated proficiency in cloud platforms, with a preference for Google Cloud Platform (GCP)
  • Strong expertise in Linux systems and the ability to apply security measures across a diverse range of IT systems
  • Supervisory control and data acquisition (SCADA) experience.
  • Experience in assessing non-traditional IT systems, particularly in a program-scale context
  • Within 50 mile radius of NASA JPL, Ames, Armstrong, Marshall, JSC , Glenn or KSC (https://science.nasa.gov/about-us/nasa-centers), * relevant IT: 10 years (Required)
  • NIST 800-53/800-30 standards: 5 years (Required)
  • IT Security Control Assessments: 2 years (Required)

Benefits & conditions

$120,000 - $150,000 a year - Full-time, Pulled from the full job description

  • Professional development assistance
  • 401(k)
  • Health insurance
  • Paid time off
  • Vision insurance
  • Dental insurance
  • Flexible spending account, * 401(k)
  • Dental insurance
  • Employee assistance program
  • Flexible spending account
  • Health insurance
  • Life insurance
  • Paid time off
  • Professional development assistance
  • Vision insurance

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

6:10 min

Unlocking free learning credits via Google Cloud Innovators

Asrar Asrar · World Congress 2024

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

4:42 min

Container hosting options available on Google Cloud Platform

Federico Fregosi · World Congress 2022

3:55 min

Demonstrating .NET installation on Debian and Azure Linux

Silvano Coriani Silvano Coriani · Europe 2026 Virtual

10:42 min

Essential soft skills and evaluating security candidates

Kurt Eder · LIVE

Videos

See all

Related articles

See all