Insight Global logo

TS/SCI Security Control Assessor

Insight Global

Denver, COJobSeen 1 day agoSeen in employer's feed 1 day ago

Most applications go out cold — see where you stand first. No sign-up to start.

Watch jobs like this.

At a glance

Compensation
No compensation found
Location
Denver, CO
Work Authorization
Not specified

Olive lists jobs from US employers, including remote roles you can work from the United States.

Requirements

Credentials this posting asks for.

IAM Level II Or IAT Level II CertificationCISSPCAPGSLCCASP+TS/SCI clearanceBachelor's degree

Job overview

Insight Global seeks a Security Control Assessor in Denver to conduct independent assessments of security controls, review accreditation packages, and support RMF and ATO processes. The role involves evaluating documentation, identifying gaps, developing mitigation strategies, and collaborating with technical teams to ensure compliance with federal cybersecurity standards.

Skills & qualifications

RequiredNice to have

Skills

NIST SP 800-37Risk Management FrameworkeMASSXACTADISA STIG ViewerFedRAMPCloud SecurityDoDIN ArchitectureStrong Written and Verbal CommunicationDISA Cybersecurity GuidanceHybrid-Cloud Environments

Qualifications

TS/SCI ClearanceBachelor's DegreeIAM Level II or IAT Level II CertificationCISSPCAPGSLCCASP+

Full job description

Job Description

Insight Global is seeking a Security Control Assessor (SCA) to support a federal customer in Denver, CO. This individual will be responsible for conducting independent assessments of management, operational, and technical security controls within information systems and networks to ensure compliance with Risk Management Framework (RMF) requirements and overall cybersecurity readiness.

The ideal candidate will have extensive experience supporting Authorization to Operate (ATO) efforts, performing security assessments, developing accreditation documentation, and advising stakeholders on cybersecurity risk management. This position will work closely with cybersecurity, systems engineering, and program leadership teams to evaluate security posture, identify risks, and ensure compliance with federal security standards.

Responsibilities Conduct independent assessments of security controls in accordance with NIST SP 800-37 and the Risk Management Framework (RMF). Review and validate accreditation and authorization packages supporting ATO efforts. Plan and execute security authorization reviews for new and existing systems and networks. Evaluate security documentation, assessment results, and risk determinations to ensure acceptable risk levels. Identify security gaps and provide recommendations to improve system security posture. Perform technical risk assessments and develop mitigation strategies. Support the development and maintenance of cybersecurity metrics, POA&Ms, and continuous monitoring activities. Review and validate implementation of security controls and document any deviations from approved configurations. Participate in risk governance activities and provide recommendations regarding cybersecurity risks and associated mitigations. Develop and maintain RMF documentation throughout the system lifecycle. Support vulnerability management activities and validate remediation plans. Assess cloud environments, external services, and supporting infrastructure for compliance with security requirements. Collaborate with technical teams to evaluate how new systems, interfaces, and technologies impact overall security posture. Provide recommendations to support accreditation decisions and authorization activities.

Skills and Requirements

TS/SCI Clearance Bachelor's degree IAM Level II or IAT Level II certification (Security+, CAP, CASP+, CISSP, or equivalent). Hands-on experience supporting all phases of the Risk Management Framework (RMF). Strong experience managing and supporting Authorization to Operate (ATO) processes. Experience developing, tracking, and maintaining POA&Ms. Experience performing technical risk assessments and accreditation support activities. Experience with RMF Continuous Monitoring (ConMon) programs. Experience using eMASS, XACTA, or similar RMF management tools. Experience utilizing DISA STIG Viewer and applying STIG requirements. Strong written and verbal communication skills. Experience supporting DoD or Intelligence Community programs. Knowledge of DoDIN architecture and DISA cybersecurity guidance. Familiarity with FedRAMP cloud security requirements. Experience assessing cloud service providers or hybrid-cloud environments. Experience supporting enterprise-level accreditation efforts. CISSP, CAP, GSLC, CASP+, or equivalent advanced cybersecurity certification. Experience briefing technical findings and risk recommendations to leadership.

We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal employment opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment without regard to race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or the recruiting process, please send a request to [email protected].

Similar jobs, posted recently

Open roles like this one, listed in the last 30 days.

You've read the whole posting — now see how you match it.