> Markdown version of [/jobs/ext/472962-sr-cybersecurity-engineer-security-controls-assessor-representative](https://www.wearedevelopers.com/jobs/ext/472962-sr-cybersecurity-engineer-security-controls-assessor-representative). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Sr. Cybersecurity Engineer Security Controls Assessor Representative - **Company:** KBR Inc - **Location:** Wright-Patterson Air Force Base, OH, United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Cyber Security, Firmware, Identity and Access Management, Network Security, Network Administration, SAP (Applications), Security Software, Technical Data Management Systems, Information Technology - **Published:** June 5, 2026 - **Apply:** https://dejobs.org/x/x/4DA8E3A500034E48ABD1FCBB9E68E0A5/job/ ## About the Role * 10+ years of experience in information assurance and/or cybersecurity with BS Degree in Information Technology, Computer Science, or related field. 8 years of experience may be substituted for a bachelor's degree * DoD 8140 IAM Level II is required (CAP, CASP+ CE, CISM, CISSP (or Associate), GSLC) CCISO, HCISPP)Familiarity with DoDIs 8500.01 & 8510.01, NIST SP 800-53, and RMF * Active Top Secret/SCI Clearance with ability to gain SAP Desired Qualifications: * Prior performance in role as ISSM * Information Assurance background with policy, STIGS, ACAS. Network security and Network management/operations experience is desired * Weapon system/airborne platform software, avionics or networking experience is desired. * Knowledge of Enterprise Mission Assurance Support Service (eMASS) is desired Ready to Make a Difference? ## Description KBR is seeking an experienced Security Controls Assessor Representative (SCAR) to provide product support located at Wright-Patterson Air Force Base, Ohio. This successful candidate will provide AFLCMC/EZAS analyses and deliverables that include documentation, reports, technical data, and other products necessary to support the alignment, standardization, and cybersecurity processes across Air Force Life Cycle Management Center (AFLCMC) aeronautical weapon systems. Analyses will include the performance of in-depth technical review and assessment of the documentation and related products. Candidate will provide critical inputs into Program Office Risk Management Framework (RMF)-based cybersecurity documents including (but not limited to) Architecture Analysis Reports, Security Plans, Security Assessment Plans/Reports, Risk Assessment Reports, POA&Ms, Continuous Monitoring Plans, and Annual Authorization Updates. Roles and Responsibilities: Provide technical recommendations based on results of evaluation of the technical implementation of the security design to ascertain that security software, hardware, and firmware features affecting confidentiality, integrity, availability, accountability, and non repudiation have been implemented. Analysis of weapons systems' Supply Chain Risk Management plans and implementation. Develop A&A package artifacts for assigned systems as well as, assisting the program managers in developing decision briefings for the Security Control Assessor (SCA) and the Authorizing Official (AO).Conduct hardware and software assurance assessments. Participate in Continuous Monitoring activities to include document or process reviews and onsite inspection/ audit / validation activities. Participate in requirements prioritization, reviews and inspections of processes and documents. Participate in peer reviews of work products derived from requirements specifications to ensure that the requirements were interpreted correctly. Perform other duties as assigned by management. Work Environment: The primary place of performance for this role is Wright-Patterson AFB, OH, due to the requirement to work in a secure facility. As such, remote work opportunities will be minimal. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Small, Secure, Interconnected: The next Internet Protocol](https://www.wearedevelopers.com/videos/100062-small-secure-interconnected-the-next-internet-protocol) - [Playing Pong on a shoulder press machine](https://www.wearedevelopers.com/videos/100140-playing-pong-on-a-shoulder-press-machine) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [System change: restart as developer?](https://www.wearedevelopers.com/magazine/39-system-change-restart-as-developer) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers)