> Markdown version of [/jobs/ext/1840704-security-control-accessor](https://www.wearedevelopers.com/jobs/ext/1840704-security-control-accessor). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Control Accessor - **Company:** Northern Technologies Group, Inc. - **Location:** Arlington, VA, United States - **Salary:** $190,000.0 - $200,000.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Cyber Security, Identity and Access Management, SAP (Applications), SARS Software Products, SAPBasis, Plan of Action and Milestones - **Published:** July 31, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9068762/security-control-accessor ## About the Role * 15 years of experience and a Master's degree in Cybersecurity (or equivalent); alternatively, 17 years of experience with a Bachelor's degree, or 21 years of relevant experience with no degree. * Leadership in RMF/A&A efforts. * Clearance: Active TS/SCI with eligibility for SAP access * Certifications: Must hold a cybersecurity certification at IAT Level III or IAM Level III (e.g., CISSP, CISM, CASP+) ## Description Northern Technologies Group (NTG) is seeking an experienced Security Control Accessor to provide expert-level support to the Department of Defense (DoD) Chief Information Officer's SAP IT Cybersecurity program. This role delivers technical and managerial leadership across RMF activities, system accreditation, and enterprise-wide cyber compliance. The Security Control Accessor will serve as a trusted cybersecurity advisor, managing high-impact assessments and helping to ensure secure operations across highly classified SAP environments., * Lead Risk Management Framework (RMF) activities, including the development, review, and validation of: * System Security Plans (SSPs) * Security Assessment Plans (SAPs) * Plan of Action and Milestones (POA&Ms) * Security Assessment Reports (SARs) * Security Control Traceability Matrices (SCTMs) * Act as an advisor to the Authorizing Official (AO), providing SME input to support Authorization to Operate (ATO) decisions. * Perform system security assessments, documentation reviews, and artifact evaluations in eMASS or equivalent tools. * Validate control inheritance and implementation across hybrid, cloud, AI/ML-enabled, or cross-domain architectures. * Provide technical guidance to system owners, ISSMs, SCAs, and program staff to maintain compliance with DoD cybersecurity mandates. * Assist in development and standardization of SOPs, cybersecurity scorecards, and dashboards. * Support cybersecurity incident response documentation and post-event reporting in classified environments. * Participate in enterprise-wide security initiatives, policy updates (e.g., JSIG revisions), and threat awareness activities. * Serve as eMASS administrator: manage accounts, permissions, workflows, and enterprise-level metrics reporting., The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this position. Reasonable accommodations may be made to enable individuals with disabilities to perform these functions. While performing the duties of this position, the employee is regularly required to talk or hear. The employee frequently is required to use hands or fingers, handle or feel objects, tools, or controls. The employee is occasionally required to stand; walk; sit; and reach with hands and arms. The employee must occasionally lift and/or move up to 25 pounds. Specific vision abilities required by this position include close vision, distance vision, and the ability to adjust focus. The noise level in the work environment is usually low to moderate. Travel Up to 10% - Local travel within NCR may be required; occasional CONUS travel possible Shift * Standard 8-hour workdays, Monday-Friday (core hours: 9 AM-3 PM) * May require occasional travel within the National Capital Region (NCR) and limited CONUS travel * On-call response may be required for critical system issues or classified facility access Note This job description is not designed to cover or contain a comprehensive listing of activities, duties or responsibilities that are required of the employee for this job. Duties, responsibilities and activities may change at any time with or without notice. Employees will be required to follow any other job-related instructions and to perform any other job-related duties requested by any person authorized to give instructions or assignments. This document does not create an employment contract, implied or otherwise, other than an "at will" relationship. ## Related Videos - [Independently together: how micro-applications improve developer experience + app performance](https://www.wearedevelopers.com/videos/452-independently-together-how-micro-applications-improve-developer-experience-app-performance) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Replacing Excel with SAP APIs & Python validation](https://www.wearedevelopers.com/videos/1944-replacing-excel-with-sap-apis-python-validation) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [Everything a Developer Needs to Know About MCP with Neo4j](https://www.wearedevelopers.com/magazine/604-everything-a-developer-needs-to-know-about-mcp-with-neo4j) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Coffee with Developers - Maria Apazoglou - Making AI understandable for all in production](https://www.wearedevelopers.com/magazine/475-coffee-with-developers-maria-apazoglou-making-ai-understandable-for-all-in-production) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again)