Insight Global logo

Security Control Assessor Representative (SCAR)

Insight Global

Shiloh Valley, ILJobSeen 1 day agoSeen in employer's feed 1 day ago

Most applications go out cold — see where you stand first. No sign-up to start.

Watch jobs like this.

At a glance

Compensation
No compensation found
Location
Shiloh Valley, IL
Work Authorization
Not specified

Olive lists jobs from US employers, including remote roles you can work from the United States.

Requirements

Credentials this posting asks for.

Secret clearance

Job overview

The role serves as an independent cybersecurity assessor for a DoD program at Scott Air Force Base, evaluating security controls, validating RMF compliance, and supporting authorization decisions for enterprise systems supporting critical missions.

Skills & qualifications

RequiredNice to have

Skills

AWSAzureGCPOracle CloudSplunkPalo AltoCiscoZscalerMicrosoft SecurityELKNISTRMFFedRAMPFISMAZero Trust ArchitectureSASESD-WANSOARUEBAIAMThreat ModelingCloud SecurityCISSPCASP+CCSPCISAGCIHGCEDCISSP-ISSAPGCIAGCSAGCLDVisibility & AnalyticsSIEMSecurity Operations

Qualifications

2+ Years Experience in Network Engineering, Architecture, or Security EngineeringActive Secret ClearanceActive IA Level III Certification (CISSP, CASP+, CCSP, CISA, GCIH, GCED, Etc.)

Full job description

Job Description

A client is seeking an experienced Secret Security Control Assessor Representative (SCAR) to support a large Department of Defense cybersecurity program at Scott Air Force Base. This individual will serve as an independent cybersecurity assessor responsible for evaluating security controls, validating RMF compliance, and supporting authorization decisions for enterprise systems supporting critical DoD missions. This position functions as a cybersecurity auditor and risk assessor, reviewing documentation, security controls, and authorization packages to determine whether systems are secure, compliant with DoD requirements, and capable of receiving Authorization to Operate (ATO) approval. The SCAR will support more than 40 Programs of Record across the enterprise and act as a trusted advisor to the Security Control Assessor (SCA) and Authorizing Official (AO) by providing risk-based recommendations and independent assessments.

Key Responsibilities

  • Conduct independent security control assessments to evaluate the effectiveness of management, operational, technical, and privacy controls.
  • Review RMF documentation including:
  • System Security Plans (SSPs)
  • Plans of Action & Milestones (POA&Ms)
  • Security Categorization Packages
  • Authorization Packages
  • Risk Acceptance Requests
  • Assess security artifacts and identify cybersecurity risks, compliance gaps, and control deficiencies.
  • Perform Independent Verification & Validation (IV&V) activities within eMASS to ensure controls are:
  • Implemented correctly
  • Operating as intended
  • Producing desired security outcomes
  • Provide recommendations for risk acceptance, remediation activities, and authorization decisions.
  • Support Security Control Assessor (SCA) activities and Authorizing Official (AO) package preparation.
  • Compile and coordinate authorization packages and required approval documentation for leadership review.
  • Review and triage RMF submissions using Government Artifact Quality Rubrics.
  • Document deficiencies through Package Return Reports (PRRs) and coordinate corrective actions.
  • Support risk analysis efforts and provide technical recommendations to government stakeholders.
  • Track authorization package status from submission through approval or denial.
  • Maintain cybersecurity compliance records and authorization documentation.
  • Manage eMASS user accounts and permissions as directed.
  • Provide subject matter expertise on RMF processes, cybersecurity controls, and DoD compliance requirements.
  • Collaborate with system owners, ISSOs, cybersecurity teams, and government stakeholders to ensure successful system authorizations.

Skills and Requirements

  • 2+ years of experience in network engineering, architecture, or security engineering.
  • Experience with cloud environments (AWS, Azure, GCP, or Oracle Cloud).
  • Hands-on experience with enterprise security technologies (Splunk, Palo Alto, Cisco, Zscaler, Microsoft Security, ELK, etc.).
  • Experience with enterprise security architecture and cyber security best practices.
  • Familiarity with NIST, RMF, FedRAMP, FISMA, and related security frameworks.
  • Knowledge of Zero Trust Architecture (ZTA) principles.
  • Active Secret Clearance.
  • Active IA Level III certification (CISSP, CASP+, CCSP, CISA, GCIH, GCED, etc.).
  • Experience supporting DoD or federal government environments.
  • Experience implementing Zero Trust strategies, assessments, or roadmaps.
  • Knowledge of SASE, SD-WAN, SOAR, UEBA, IAM, threat modeling, or cloud security.
  • Cloud security certifications (AWS, Azure, GCP).
  • Advanced cyber certifications (CISSP-ISSAP, GCIA, GCSA, GCLD, etc.).
  • Experience with Visibility & Analytics, SIEM, and security operations.

We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal employment opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment without regard to race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or the recruiting process, please send a request to [email protected].

Similar jobs, posted recently

Open roles like this one, listed in the last 30 days.

You've read the whole posting — now see how you match it.