> Markdown version of [/jobs/ext/2147054-sr-control-assessment-analyst](https://www.wearedevelopers.com/jobs/ext/2147054-sr-control-assessment-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Sr. Control Assessment Analyst - **Company:** Stellent IT LLC - **Location:** Washington, DC, United States - **Experience:** Expert - **Salary:** $110,000.0 - $137,000.0 - **Contract:** Permanent contract - **Skills:** Xacta, Software System Penetration Testing, Cloud Computing Security, Cyber Security, Security Content Automation Protocol, Information Technology, Nessus, Vulnerability Analysis - **Published:** August 20, 2026 - **Apply:** https://www.careerjet.com/jobad/usac1367d5ed9654ee69b3a9232fdd8525 ## About the Role The candidate shall possess the knowledge and skills set forth in the Technical Services BOA, Section 3.6.2.1 for labor category External Auditor Consultant (FISMA). The candidate shall also demonstrate the below knowledge and experience: Bachelor's degree in Computer Science, Information Security, or related field 3-5 years of experience in information security or cybersecurity compliance Experience with federal government systems and FISMA compliance Hands-on experience with RMF/ATO processes Security Authorization & Compliance, Strong knowledge of NIST frameworks (800-53, 800-37, 800-171) Familiarity with security assessment tools (Nessus, ACAS, SCAP) Understanding of cloud security (FedRAMP preferred) Experience with compliance management tools (Xacta, or similar) Knowledge of security controls implementation across various platforms. ## Description We are seeking FISMA Support Analyst(s) to support the Governance, Risk and Compliance (GRC) team within the IT division at the Board of Governors of the Federal Reserve. This team is responsible for defining, implementing and managing processes that support compliance, policy, outreach, and privacy related work across the organization., Prepare and maintain security authorization packages (System Security Plans, Security Assessment Reports, Plans of Action & Milestones) Conduct continuous monitoring activities and maintain Authority to Operate (ATO) status Ensure compliance with FISMA, NIST 800-53 security controls, and agency-specific policies Risk Management Perform security control assessments and vulnerability analyses Identify, document, and track security weaknesses and deficiencies Develop and maintain Plans of Action & Milestones (POA&Ms) Conduct risk assessments and recommend risk mitigation strategies Support Annual Security Reviews and security authorization updates Documentation & Reporting Develop and maintain System Security Plans (SSPs) Create and update security-related documentation (SOPs, diagrams, inventory) Generate security metrics and reports for management and auditors Maintain system security authorization documentation in compliance repositories Security Operations Support Coordinate security scans and penetration testing activities Review and analyze vulnerability scan results Assist with incident response and security event investigations Support security tool implementation and configuration Stakeholder Coordination Serve as primary liaison between system owners, authorizing officials, and security teams Coordinate with vendors, contractors, and technical teams on security requirements Provide security guidance to development and operations teams, MANTECH seeks a motivated, career and customer-oriented Budget Analyst to join our team in Arlington, VA. This is an onsite position. Responsibilities include, but are not limite… + 4 days ago, Control Assessment Analyst/FISMA (Sr.) Washington, DC Pay From: $138,000 per year MUST: Experienced Sr. Control Assessment Analyst Experienced FISMA Support Analyst(s) U.S. … + 17 hours ago ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Maturity assessment for technicians or how I learned to love OWASP SAMM](https://www.wearedevelopers.com/videos/351-maturity-assessment-for-technicians-or-how-i-learned-to-love-owasp-samm) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) - [Less Is More: How Lagom and Agile Can Create Harmonious Workflows](https://www.wearedevelopers.com/videos/1993-less-is-more-how-lagom-and-agile-can-create-harmonious-workflows) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers)