Summary
Security Control Assessor (SCA) Level IIFull-Time/Part-Time Full-TimeDescriptionThe Security Control Assessor (SCA) - Level II serves as a senior technical authority responsible for leading Assessment and Authorization (A&A) activities across the Department of Homeland Security (DHS) Intelligence Enterprise (DHS IE) . This position conducts comprehensive security control assessments for classified and unclassified information systems, cloud environments, Cross Domain Solutions (CDS), and C-LAN extension sites in support of the NIST Risk Management Framework (RMF) and DHS/Intelligence Community (IC) cybersecurity requirements.The Security Control Assessor provides expert guidance on security control implementation, risk management, continuous monitoring, and authorization package development while working closely with System Owners, Information System Security Officers (ISSOs), Information System Security Managers (ISSMs), Security Engineers, Government Authorizing Officials (AOs), Security Control Assessor Representatives (SCARs), Branch Chiefs, and the DHS I&A Chief Information Security Officer (CISO). The successful candidate will possess extensive experience leading complex A&A efforts for enterprise systems operating in classified, hybrid, cloud, and Cross Domain Solution environments.Key ResponsibilitiesLead comprehensive Assessment and Authorization (A&A) activities for DHS Intelligence Enterprise information systems operating in Top Secret/Sensitive Compartmented Information (TS/SCI), Secret, and Unclassified environments.Conduct security assessments for enterprise systems hosted in:On-premises data centersDHS DICECommercial Cloud Enterprise (C2E)Intelligence Community (IC) CloudAWS GovCloudHybrid cloud environmentsCross Domain Solution (CDS) environmentsCONUS and OCONUS C-LAN extension sitesLead project discovery sessions, kickoff meetings, and stakeholder engagements for new system authorizations, reauthorizations, and major system changes.Assess the implementation and effectiveness of NIST security controls and document findings within the Security Assessment Report (SAR) and Governance, Risk, and Compliance (GRC) platform.Identify security control deficiencies, vulnerabilities, and compliance gaps; provide technical recommendations to reduce organizational risk.Validate the accuracy and completeness of Plans of Action and Milestones (POA&Ms), ensuring corrective actions align with identified assessment findings.Monitor remediation activities and verify completion of corrective actions before recommending authorization decisions.Develop and prepare complete Authorization and Assessment packages, including:Authorization to Operate (ATO)Authorization to Connect (ATC)Interim Authorization to Test (IATT)Security Assessment Reports (SARs)Risk Recommendation MemorandaRisk Management MatricesSecurity Assessment Plans (SAPs)Project kickoff memorandaSystem Owner acknowledgment lettersConduct technical reviews of System Security Plans (SSPs), Contingency Plans, Configuration Management Plans, and supporting RMF documentation.Maintain and update Assessment and Authorization Standard Operating Procedures (SOPs) for all DHS I&A enclaves, ensuring annual review and compliance with evolving Federal and Intelligence Community requirements.Participate in Office of Inspector General (OIG), Federal Information Security Modernization Act (FISMA), and Intelligence Community Oversight Program (ICOP) audits, inspections, and cybersecurity assessments.Represent the program during DHS and Intelligence Community cybersecurity working groups and technical review boards.Maintain enterprise A&A Project Portfolio Listing Reports and Quarterly A&A Assignment Reports.Research emerging technologies, cybersecurity standards, and automation opportunities to improve A&A efficiency and support ongoing authorization initiatives.Prepare executive briefings, risk summaries, technical presentations, and decision support materials for the DHS I&A CISO, Government leadership, and Authorizing Officials.Mentor junior cybersecurity personnel and provide technical guidance on RMF implementation, security control assessments, and authorization processes.Minimum QualificationsActive Top Secret/Sensitive Compartmented Information (TS/SCI) clearance with SAP eligibility .Minimum 10 years of experience in information security, cybersecurity risk management, or Assessment and Authorization (A&A), including demonstrated experience in:Assessment and Authorization (A&A)Federal Information Security Modernization Act (FISMA) complianceIntelligence Community cybersecurity policyContinuous Monitoring (ConMon)Cross Domain Solutions (CDS)Secure cloud and hybrid cloud environmentsCurrent Certified Information Security Manager (CISM) , Certified Authorization Professional (CAP) , or comparable Governance, Risk, and Compliance (GRC) certification.Certified Information Systems Security Professional (CISSP) certification is highly desirable.Expert knowledge of:NIST Risk Management Framework (RMF)NIST SP 800-37NIST SP 800-53NIST SP 800-53ACNSSI 1253ICD 503DHS Sensitive Systems Policy Directive 4300CIntelligence Community security overlays and authorization requirementsExperience using Governance, Risk, and Compliance (GRC) platforms such as RSA Archer .Experience using security assessment and vulnerability management tools, including:NessusSCAPNmapWebInspectSonarQubeComparable security assessment toolsDemonstrated experience leading A&A activities for Cross Domain Solutions (CDS), classified information systems, and cloud-based environments.Bachelor's degree in Cybersecurity, Computer Science, Information Systems, Information Assurance, or a related technical discipline.Preferred QualificationsAWS Certified Security - Specialty, Microsoft Certified: Azure Security Engineer Associate , Google Professional Cloud Security Engineer , or equivalent cloud security certification.Experience supporting DHS Intelligence & Analysis (I&A) or other Intelligence Community cybersecurity organizations.Experience conducting Assessment and Authorization activities for OCONUS locations and C-LAN authorization extension sites.Experience supporting National Cross Domain Strategy and Management Office (NCDSMO) accreditation requirements and Raise the Bar (RTB) initiatives.Experience implementing Continuous Authorization (cATO) , Agile RMF, or automated security assessment processes.Knowledge of DevSecOps security controls, Infrastructure as Code (IaC), and cloud-native security assessment methodologies.Required CertificationsOne of the following current certifications is required:Certified Information Security Manager (CISM)Certified Authorization Professional (CAP)Governance, Risk, and Compliance (GRC) CertificationPreferred certifications include :Certified Information Systems Security Professional (CISSP)AWS Certified Security - SpecialtyMicrosoft Certified: Azure Security Engineer AssociateGoogle Professional Cloud Security EngineerClearance RequirementActive Top Secret/Sensitive Compartmented Information (TS/SCI) Clearance RequiredSAP Eligibility RequiredAbout the Organization Established in 2008, RiVidium, Inc. (dba TripleCyber) is a VA-Verified SDVOSB and an SBA-Certified 8(a) company. To prepare our clients for the future, RiVidium has balanced all parts of our organization to attract the finest employees in order to 'Strive to be the missing element defining tomorrow's technology'. RiVidium keeps pace and surpasses its competitors by meeting challenges of advancements in Logistics, Human Capital, Cyber, Intelligence & Technology.EOE Statement We are an equal employment opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veteran status or any other characteristic protected by law. If you need a reasonable accommodation for any part of the employment process, please contact Human Resources (HR) at hr@rividium.com.This position is currently accepting applications.Follow us#J-18808-Ljbffr
Job Description
Security Control Assessor (SCA) Level IIFull-Time/Part-Time Full-TimeDescriptionThe Security Control Assessor (SCA) - Level II serves as a senior technical authority responsible for leading Assessment and Authorization (A&A) activities across the Department of Homeland Security (DHS) Intelligence Enterprise (DHS IE) . This position conducts comprehensive security control assessments for classified and unclassified information systems, cloud environments, Cross Domain Solutions (CDS), and C-LAN extension sites in support of the NIST Risk Management Framework (RMF) and DHS/Intelligence Community (IC) cybersecurity requirements.The Security Control Assessor provides expert guidance on security control implementation, risk management, continuous monitoring, and authorization package development while working closely with System Owners, Information System Security Officers (ISSOs), Information System Security Managers (ISSMs), Security Engineers, Government Authorizing Officials (AOs), Security Control Assessor Representatives (SCARs), Branch Chiefs, and the DHS I&A Chief Information Security Officer (CISO). The successful candidate will possess extensive experience leading complex A&A efforts for enterprise systems operating in classified, hybrid, cloud, and Cross Domain Solution environments.Key ResponsibilitiesLead comprehensive Assessment and Authorization (A&A) activities for DHS Intelligence Enterprise information systems operating in Top Secret/Sensitive Compartmented Information (TS/SCI), Secret, and Unclassified environments.Conduct security assessments for enterprise systems hosted in:On-premises data centersDHS DICECommercial Cloud Enterprise (C2E)Intelligence Community (IC) CloudAWS GovCloudHybrid cloud environmentsCross Domain Solution (CDS) environmentsCONUS and OCONUS C-LAN extension sitesLead project discovery sessions, kickoff meetings, and stakeholder engagements for new system authorizations, reauthorizations, and major system changes.Assess the implementation and effectiveness of NIST security controls and document findings within the Security Assessment Report (SAR) and Governance, Risk, and Compliance (GRC) platform.Identify security control deficiencies, vulnerabilities, and compliance gaps; provide technical recommendations to reduce organizational risk.Validate the accuracy and completeness of Plans of Action and Milestones (POA&Ms), ensuring corrective actions align with identified assessment findings.Monitor remediation activities and verify completion of corrective actions before recommending authorization decisions.Develop and prepare complete Authorization and Assessment packages, including:Authorization to Operate (ATO)Authorization to Connect (ATC)Interim Authorization to Test (IATT)Security Assessment Reports (SARs)Risk Recommendation MemorandaRisk Management MatricesSecurity Assessment Plans (SAPs)Project kickoff memorandaSystem Owner acknowledgment lettersConduct technical reviews of System Security Plans (SSPs), Contingency Plans, Configuration Management Plans, and supporting RMF documentation.Maintain and update Assessment and Authorization Standard Operating Procedures (SOPs) for all DHS I&A enclaves, ensuring annual review and compliance with evolving Federal and Intelligence Community requirements.Participate in Office of Inspector General (OIG), Federal Information Security Modernization Act (FISMA), and Intelligence Community Oversight Program (ICOP) audits, inspections, and cybersecurity assessments.Represent the program during DHS and Intelligence Community cybersecurity working groups and technical review boards.Maintain enterprise A&A Project Portfolio Listing Reports and Quarterly A&A Assignment Reports.Research emerging technologies, cybersecurity standards, and automation opportunities to improve A&A efficiency and support ongoing authorization initiatives.Prepare executive briefings, risk summaries, technical presentations, and decision support materials for the DHS I&A CISO, Government leadership, and Authorizing Officials.Mentor junior cybersecurity personnel and provide technical guidance on RMF implementation, security control assessments, and authorization processes.Minimum QualificationsActive Top Secret/Sensitive Compartmented Information (TS/SCI) clearance with SAP eligibility .Minimum 10 years of experience in information security, cybersecurity risk management, or Assessment and Authorization (A&A), including demonstrated experience in:Assessment and Authorization (A&A)Federal Information Security Modernization Act (FISMA) complianceIntelligence Community cybersecurity policyContinuous Monitoring (ConMon)Cross Domain Solutions (CDS)Secure cloud and hybrid cloud environmentsCurrent Certified Information Security Manager (CISM) , Certified Authorization Professional (CAP) , or comparable Governance, Risk, and Compliance (GRC) certification.Certified Information Systems Security Professional (CISSP) certification is highly desirable.Expert knowledge of:NIST Risk Management Framework (RMF)NIST SP 800-37NIST SP 800-53NIST SP 800-53ACNSSI 1253ICD 503DHS Sensitive Systems Policy Directive 4300CIntelligence Community security overlays and authorization requirementsExperience using Governance, Risk, and Compliance (GRC) platforms such as RSA Archer .Experience using security assessment and vulnerability management tools, including:NessusSCAPNmapWebInspectSonarQubeComparable security assessment toolsDemonstrated experience leading A&A activities for Cross Domain Solutions (CDS), classified information systems, and cloud-based environments.Bachelor's degree in Cybersecurity, Computer Science, Information Systems, Information Assurance, or a related technical discipline.Preferred QualificationsAWS Certified Security - Specialty, Microsoft Certified: Azure Security Engineer Associate , Google Professional Cloud Security Engineer , or equivalent cloud security certification.Experience supporting DHS Intelligence & Analysis (I&A) or other Intelligence Community cybersecurity organizations.Experience conducting Assessment and Authorization activities for OCONUS locations and C-LAN authorization extension sites.Experience supporting National Cross Domain Strategy and Management Office (NCDSMO) accreditation requirements and Raise the Bar (RTB) initiatives.Experience implementing Continuous Authorization (cATO) , Agile RMF, or automated security assessment processes.Knowledge of DevSecOps security controls, Infrastructure as Code (IaC), and cloud-native security assessment methodologies.Required CertificationsOne of the following current certifications is required:Certified Information Security Manager (CISM)Certified Authorization Professional (CAP)Governance, Risk, and Compliance (GRC) CertificationPreferred certifications include :Certified Information Systems Security Professional (CISSP)AWS Certified Security - SpecialtyMicrosoft Certified: Azure Security Engineer AssociateGoogle Professional Cloud Security EngineerClearance RequirementActive Top Secret/Sensitive Compartmented Information (TS/SCI) Clearance RequiredSAP Eligibility RequiredAbout the Organization Established in 2008, RiVidium, Inc. (dba TripleCyber) is a VA-Verified SDVOSB and an SBA-Certified 8(a) company. To prepare our clients for the future, RiVidium has balanced all parts of our organization to attract the finest employees in order to 'Strive to be the missing element defining tomorrow's technology'. RiVidium keeps pace and surpasses its competitors by meeting challenges of advancements in Logistics, Human Capital, Cyber, Intelligence & Technology.EOE Statement We are an equal employment opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veteran status or any other characteristic protected by law. If you need a reasonable accommodation for any part of the employment process, please contact Human Resources (HR) at hr@rividium.com.This position is currently accepting applications.Follow us#J-18808-Ljbffr
Government Careers
Government jobs offer stability, competitive benefits, and the chance to make a meaningful impact on your community and country.
Whether you’re starting your career or seeking new opportunities, these roles provide pathways for growth, security, and service.
Explore positions across a wide range of fields and take the first step toward a rewarding future in public service.
MORE JOBS
-
Field Artillery Recruit 13U - Start Your Career with the US Army (98208)
- Everett, Washington
- U.S. Army
- Aug 25, 2026
-
Infantryman - Start Your Career with the US Army (94546)
- Castro Valley, California
- U.S. Army
- Aug 25, 2026
-
Special Forces Candidate - Start Your Career with the US Army (98501)
- Olympia, Washington
- U.S. Army
- Aug 25, 2026
-
Combat Engineer - Find Your Full Time or Part Time Army Career (98848)
- Quincy, Washington
- U.S. Army
- Aug 25, 2026
-
Police Officer - Serve Your Community
- Florida, New York
- US Government Jobs
- Aug 25, 2026
-
Combat Engineer - Find Your Full Time or Part Time Army Career (95006)
- Boulder Creek, California
- U.S. Army
- Aug 25, 2026