Location: Bethesda, MD (mostly remote, occasional onsite required)
Work schedule: 40 hrs/week
Compensation: $100,000-$115,000/year
Target start: by end of August 2026
Clearance / Public Trust: Public Trust eligibility (Tier 2/3) required
About the role
We're hiring a Junior Security Control Assessor to support independent security control assessments across the system authorization lifecycle. You'll work under a senior assessor and help evaluate security control implementation, validate evidence, and document results in alignment with NIST Risk Management Framework (RMF) and NIST SP 800-53 Rev. 5, using JCAM practices.
This is a great fit for someone who enjoys cybersecurity compliance, evidence-based assessments, and strong technical writing-without being the person who authors the entire authorization package.
What you'll do
Support independent Security Control Assessments (SCAs) across the authorization lifecycle
Review and validate security authorization documentation (SSP, SAP, SAR, POA&M, contingency plans, and supporting artifacts)
Assess security control implementation through documentation review, interviews, and technical validation
Help evaluate cloud security packages and inherited controls (as applicable)
Document findings, recommendations, and remediation activities clearly and professionally
Assist with evidence validation and remediation tracking
Partner with system owners and ISSOs while maintaining assessor independence
Required qualifications
Education: Bachelor's in Cybersecurity, IT, Computer Science, Information Systems (or similar)
OR 4 additional years of relevant experience in lieu of a degree
Experience: 3-5 years supporting cybersecurity, information assurance, RMF, security assessments, compliance, or IT operations
Working knowledge of:
NIST RMF (800-37) and NIST SP 800-53 Rev. 5
JCAM methodology
Experience reviewing security documentation and assessment evidence/artifacts
Strong analytical skills and technical writing ability
Preferred (nice to have)
Experience with eMASS or similar GRC platforms
Familiarity with FedRAMP, cloud security concepts, C-SCRM, and related federal security frameworks
Experience supporting independent audits/assessments (e.g., external review organizations)
Tools/tech exposure (helpful)
JCAM
Tenable
CrowdStrike
Splunk / Splunk Enterprise
AWS
Python (plus)
Certifications (preferred, not all required)
ISC2 CC or CGRC
CompTIA Security+, CySA+, PenTest+, CASP
- CEH
Microsoft SC-900
System One, and its subsidiaries including Joulé and Mountain Ltd., are leaders in delivering outsourced services and workforce solutions across North America. We help clients get work done more efficiently and economically, without compromising quality. System One not only serves as a valued partner for our clients, but we offer eligible employees health and welfare benefits coverage options including medical, dental, vision, spending accounts, life insurance, voluntary plans, as well as participation in a 401(k) plan.
System One is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, age, national origin, disability, family care or medical leave status, genetic information, veteran status, marital status, or any other characteristic protected by applicable federal, state, or local law.
#M-1
#LI-AJ1
Ref: #856-Baltimore-S1
System One, and its subsidiaries including Joulé, ALTA IT Services, CM Access, TPGS, and MOUNTAIN, LTD., are leaders in delivering workforce solutions and integrated services across North America. We help clients get work done more efficiently and economically, without compromising quality. System One not only serves as a valued partner for our clients, but we offer eligible full-time employees health and welfare benefits coverage options including medical, dental, vision, spending accounts, life insurance, voluntary plans, as well as participation in a 401(k) plan.
System One is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, age, national origin, disability, family care or medical leave status, genetic information, veteran status, marital status, or any other characteristic protected by applicable federal, state, or local law.
Location: Bethesda, MD (mostly remote, occasional onsite required)
Work schedule: 40 hrs/week
Compensation: $100,000-$115,000/year
Target start: by end of August 2026
Clearance / Public Trust: Public Trust eligibility (Tier 2/3) required
About the role
We're hiring a Junior Security Control Assessor to support independent security control assessments across the system authorization lifecycle. You'll work under a senior assessor and help evaluate security control implementation, validate evidence, and document results in alignment with NIST Risk Management Framework (RMF) and NIST SP 800-53 Rev. 5, using JCAM practices.
This is a great fit for someone who enjoys cybersecurity compliance, evidence-based assessments, and strong technical writing-without being the person who authors the entire authorization package.
What you'll do
Support independent Security Control Assessments (SCAs) across the authorization lifecycle
Review and validate security authorization documentation (SSP, SAP, SAR, POA&M, contingency plans, and supporting artifacts)
Assess security control implementation through documentation review, interviews, and technical validation
Help evaluate cloud security packages and inherited controls (as applicable)
Document findings, recommendations, and remediation activities clearly and professionally
Assist with evidence validation and remediation tracking
Partner with system owners and ISSOs while maintaining assessor independence
Required qualifications
Education: Bachelor's in Cybersecurity, IT, Computer Science, Information Systems (or similar)
OR 4 additional years of relevant experience in lieu of a degree
Experience: 3-5 years supporting cybersecurity, information assurance, RMF, security assessments, compliance, or IT operations
Working knowledge of:
NIST RMF (800-37) and NIST SP 800-53 Rev. 5
JCAM methodology
Experience reviewing security documentation and assessment evidence/artifacts
Strong analytical skills and technical writing ability
Preferred (nice to have)
Experience with eMASS or similar GRC platforms
Familiarity with FedRAMP, cloud security concepts, C-SCRM, and related federal security frameworks
Experience supporting independent audits/assessments (e.g., external review organizations)
Tools/tech exposure (helpful)
JCAM
Tenable
CrowdStrike
Splunk / Splunk Enterprise
AWS
Python (plus)
Certifications (preferred, not all required)
ISC2 CC or CGRC
CompTIA Security+, CySA+, PenTest+, CASP
- CEH
Microsoft SC-900
System One, and its subsidiaries including Joulé and Mountain Ltd., are leaders in delivering outsourced services and workforce solutions across North America. We help clients get work done more efficiently and economically, without compromising quality. System One not only serves as a valued partner for our clients, but we offer eligible employees health and welfare benefits coverage options including medical, dental, vision, spending accounts, life insurance, voluntary plans, as well as participation in a 401(k) plan.
System One is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, age, national origin, disability, family care or medical leave status, genetic information, veteran status, marital status, or any other characteristic protected by applicable federal, state, or local law.
#M-1
#LI-AJ1
Ref: #856-Baltimore-S1
System One, and its subsidiaries including Joulé, ALTA IT Services, CM Access, TPGS, and MOUNTAIN, LTD., are leaders in delivering workforce solutions and integrated services across North America. We help clients get work done more efficiently and economically, without compromising quality. System One not only serves as a valued partner for our clients, but we offer eligible full-time employees health and welfare benefits coverage options including medical, dental, vision, spending accounts, life insurance, voluntary plans, as well as participation in a 401(k) plan.
System One is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, age, national origin, disability, family care or medical leave status, genetic information, veteran status, marital status, or any other characteristic protected by applicable federal, state, or local law.
Government Careers
Government jobs offer stability, competitive benefits, and the chance to make a meaningful impact on your community and country.
Whether you’re starting your career or seeking new opportunities, these roles provide pathways for growth, security, and service.
Explore positions across a wide range of fields and take the first step toward a rewarding future in public service.
MORE JOBS
-
Behavior Detection Officer (BDO) - No Experience Required
- Indian Trail, North Carolina
- Airport Security Careers
- Aug 01, 2026
-
SOC Operator | Security Surveillance & Dispatch
- San Jose, California
- Securitas
- Aug 01, 2026
-
Security Concierge Sat-Sun 3pm-11pm
- Silver Spring, Maryland
- Comstock Companies
- Aug 01, 2026
-
TSA Administrative and Law Enforcement Careers - No Experience Required
- Fort Irwin, California
- Airport Security Careers
- Aug 01, 2026
-
Behavior Detection Officer (BDO) - No Experience Required
- Dallas, Texas
- Airport Security Careers
- Aug 01, 2026
-
Corrections Officer Trainee Hands-On Training
- New York, New York
- Commonwealth of Pennsylvania
- Aug 01, 2026