Security Control Assessor - IT Security Specialist 3
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
Join our team supporting NASA cyber security in the area of Risk Management and Enterprise Assessment Services.
Our team provides Risk Management services supporting Independent Assessments in accordance with Federal mandates, NIST guidance, and NASA policies and procedures. This includes support to an effective and comprehensive enterprise independent assessment service for NASA information systems, including Operational Technologies and cloud systems.
Security Control Assessor (SCA) Position Description:
- Conduct independent comprehensive assessments of the management, operational, and technical security controls and control enhancements employed within or inherited for traditional information technology (IT), operational technology (OT), and mission systems to determine the overall effectiveness of the controls (as defined in NIST SP 800-37)
- Create a pre-assessment verification checklist and submit to ISO
- Provide verification that System Security Plans (SSPs) to be assessed and audited are ready for an assessment via use of an Agency approved tool
- Create security assessment plan prior to scheduling assessment
- Submit security assessment plan to Information System Owner (ISO) for approval
- Schedule assessments
- Conduct technical and non-technical security assessment
- Create Security Assessment Report (SAR) using agreed upon format
- Schedule and perform system assessment out-brief with ISO
- Attend Authorization To Operate (ATO) brief with Authorizing Official (to be scheduled by ISO)
- Upload all security assessment documentation in the Agency approved tool
- Work collaboratively with cross-functional teams to gather necessary information for assessments
- Ensure timely and accurate reporting of assessment results, vulnerabilities, and compliance status
- Collaborate with stakeholders to develop and implement corrective action plans based on assessment findings
- Provide expertise in scaling security measures to meet the unique requirements of diverse IT systems
- Maintain awareness of emerging threats and industry best practices to continually enhance assessment methodologies
- Operate effectively in a fast-paced environment, demonstrating the ability to be proactive and adaptive
- Act as a client-facing representative of the organization, engaging with clients professionally and effectively
- Perform security assessment duties including
Requirements
- Bachelor’s degree
- 12 years of relevant experience
- 2 years of hands-on experience in Security Control Assessments
- Proven ability to handle a high volume of assessments, with a focus on program-scale operations
- In-depth knowledge of NIST 800-53/800-30 standards
- Effective communication skills to convey complex security concepts to various stakeholders
- Excellent organizational skills and the ability to manage a rotating schedule of assessments
- Ability to obtain Secret clearance
- Within 50 miles radius for a NASA facility (https://science.nasa.gov/about-us/nasa-centers)
- Availability for occasional travel 20%
Nice to Have Qualifications:
- Security control assessments or ISSO, ISSM, ISSE experience.
- Demonstrated proficiency in cloud platforms, with a preference for Google Cloud Platform (GCP)
- Strong expertise in Linux systems and the ability to apply security measures across a diverse range of IT systems
- Supervisory control and data acquisition (SCADA) experience.
- Experience in assessing non-traditional IT systems, particularly in a program-scale context
- Within 50 mile radius of NASA JPL, Ames, Armstrong, Marshall, JSC , Glenn or KSC (https://science.nasa.gov/about-us/nasa-centers), * relevant IT: 10 years (Required)
- NIST 800-53/800-30 standards: 5 years (Required)
- IT Security Control Assessments: 2 years (Required)
Benefits & conditions
$120,000 - $150,000 a year - Full-time, Pulled from the full job description
- Professional development assistance
- 401(k)
- Health insurance
- Paid time off
- Vision insurance
- Dental insurance
- Flexible spending account, * 401(k)
- Dental insurance
- Employee assistance program
- Flexible spending account
- Health insurance
- Life insurance
- Paid time off
- Professional development assistance
- Vision insurance
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Dev Digest 134 - Where pixels sing?
Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence
Dev Digest 138 - Are you secure about this?
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.