Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy, and consent to receive emails from Rise
Jobs / Job page
Security Control Assessor - Journeyman image - Rise Careers
Job details

Security Control Assessor - Journeyman

Overview

SMS is seeking a skilled and detail-oriented Security Control Assessor and Validator to join our team. The successful candidate will be responsible for evaluating, testing, and validating the effectiveness of security controls within our organization's information systems and networks, with a strong emphasis on applying the Risk Management Framework (RMF). 

 

As a dynamic systems integrator, SMS offers proven solutions in engineering, operations, cybersecurity, and digital transformation. With expertise in modernizing and optimizing legacy infrastructure and systems, ensuring operational efficiency, and designing, implementing, and managing secure environments, SMS supports business and mission goals with proficiency, quality, and integrity.

 

SMS has been serving the advanced information technology needs of the federal government since 1976, delivering talented teams and innovative, cost-effective solutions and services to support our customers’ missions for more than 40 years. SMS is headquartered in McLean, Virginia, with offices and on-site operations at customer locations throughout the United States. For additional information on SMS, visit www.sms.com.

 

Submit your resume today.

Responsibilities

The Security Control Assessor, you will be responsible for the following:

 

  • Provide the United States Coast Guard (USCG) with tailored documentation to support their security authorization.
  • Independent assessor for Risk Management Framework Steps 0 to 7.
  • Plan and execute security control assessments for various information systems within the organization.
  • Develop and maintain assessment procedures and methodologies aligned with NIST guidelines and other relevant frameworks.
  • Analyze and evaluate the effectiveness of implemented security controls.
  • Identify vulnerabilities, weaknesses, and potential risks in information systems and infrastructure.
  • Prepare detailed Security Assessment Reports (SARs) documenting findings and recommendations.
  • Collaborate with system owners, ISSOs, and other stakeholders throughout the assessment process.
  • Verify the implementation of remediation actions and conduct follow-up assessments as needed.
  • Provide expert advice on the development and maintenance of System Security Plans (SSPs) and Plans of Action and Milestones (POA&Ms).
  • Stay current with evolving cybersecurity threats, technologies, and best practices.
  • Validate security control implementation and provide test results.
  • Hands-on experience in assessing RMF Step 4 and performing continuous monitoring.
  • Examine security control weaknesses and determine if they are producing the desired intent.
  • Deep understanding of Vulnerability Management practices.

Qualifications

  • US Citizenship required and hold DOD Secret or higher clearance.
  • Intimate understanding of NIST RMF implementation guidance.
  • Hands-on experience with using eMASS or similar Information Assurance tools.
  • Well-developed understanding of Federal Civilian or DHS Security Assessment and Authorization (SA&A) processes.
  • In-depth understanding of the relevance of NIST Security Controls and Control Implementation methodologies to the SA&A process.
  • Experience analyzing vulnerability scans and STIG implementations.
  • Can demonstrate understanding of critical documentation required in Security Authorization (SA) Packages.
  • Ability to understand and support Privacy Compliance Activities to include the development of Privacy Impact Analysis (PIA), Privacy Threshold Analysis (PTA), and Statement of Record Notices (SORN).
  • At least one of the DOD 8750 IAT II certifications:  CCNA Security, CySA+, GICSP, GSEC, Security + CE, CND, or SSCP.
  • CSSP-AU certification - must obtain within 60days of employment.
  • Knowledge/Familiarity with DoD 8500, DoD 8510, DHS 4300 A and B, NIST SP 800-18, 60, 70, 53, 53A, 137, IACS, CMRS, COAMS, JIMS, Swimlane, Governance, Risk, and Compliance, POA&M (i.e., Management, Assessment, etc.), ERS, FISMA, Knowledge Service, ACAS, Tanium, Power BI, Project/Program Management, TASKORD (i.e., FRAGO, CTO, etc.), and Data Calls (i.e., OIG Audit, etc.) 

Desired:

  • Well-developed understanding of Systems Development Lifecycle (SDLC) and ideally the DHS Systems Engineering Lifecycle (SELC) process as it relates to Security Assessment and Authorization (SA&A).
  • Relevant DOD, DHS or .gov Cyber Security Information Assurance focused experience with specific current hands-on experience researching, writing, and submitting complete A&A documentation packages for new system authorizations.

 

Clearance

  • Active DOD Secret clearance required

Certifications

  • IAT Level II
  • CSSP-AU: At least one of the DOD 8750 IAT II certifications: CASP+ CE, CCNP Security, CISA, CISSP (or associate), GCED, GCIH, or CCSP . Within 60 days of hire. 

 

SMS is a dynamic systems integrator established in 1976, delivering talented teams and innovative, cost-effective solutions and services to support our customers’ missions for more than 47 years. Our ability to hire and retain quality people in a rapidly evolving IT market is proven through our employee retention rate averaging over 3 years. At SMS, we place a high value on quality of service, customer satisfaction, and best-of-breed policies and practices, resulting in CMMI Level 3 certification and ISO registrations including 9001:2015, 20000-1:2018, and ISO/IEC 27001:2013. SMS is headquartered in McLean, Virginia, with offices and on-site operations at customer locations throughout the United States. 

 

SMS is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.

SMS Data Products Group Glassdoor Company Review
4.5 Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon
SMS Data Products Group DE&I Review
No rating Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon
CEO of SMS Data Products Group
SMS Data Products Group CEO photo
Matthew Rosecan
Approve of CEO

Average salary estimate

$110000 / YEARLY (est.)
min
max
$90000K
$130000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

Similar Jobs
Photo of the Rise User
Posted 17 hours ago

A 12-month full-time internship on Tencent’s LA IT team focused on end-user support, IT asset management, and workflow automation.

Photo of the Rise User

Lead the administration, enhancement, and user support of the UKG (Kronos) timekeeping system to deliver compliant, efficient workforce solutions for Lucile Packard Children’s Hospital Stanford.

Photo of the Rise User

Baltimore City's IT team seeks an IT Specialist II (Drupal Administrator) to maintain server and network systems, support applications and databases, and deliver user-facing technical support across municipal departments.

Posted 18 hours ago

Lead advanced Epic application architecture and integration efforts for UHealth, designing innovative clinical solutions and guiding high-complexity projects to improve patient care and operational workflows.

Photo of the Rise User

St. Luke's Health System is seeking a Systems Analyst to design, configure, test, and support EPIC Clinical Research solutions that optimize clinical workflows and ensure system reliability.

Photo of the Rise User
Posted 22 hours ago

Lead enterprise-wide technology governance, risk oversight, and architectural alignment at MFS as the Sr. Director, Governance and IT Risk.

modernatx Hybrid Norwood, Massachusetts
Posted 15 hours ago

Experienced GxP IT Engineer needed to support and maintain compliant endpoints, lab instruments, and systems (MES, DeltaV, OSI PI) across Moderna’s Norwood site and global GxP environments.

Posted 16 hours ago

Lead the end-to-end lifecycle and secure operations of CSfC-compliant enterprise network solutions for a mission-critical intelligence sharing program while mentoring junior staff and ensuring NSA/DoD audit readiness.

Photo of the Rise User
Mandolin Hybrid San Francisco
Posted 2 hours ago

Mandolin is hiring an experienced IT Engineer to own infrastructure, security, and compliance-aligned IT practices for a fast-growing, regulated healthcare AI startup.

Posted 23 hours ago

Cleveland Clinic Health System is hiring an Access Optimization Analyst III to lead EPIC access projects, integrate practices, and optimize front-end workflows across the enterprise.

Photo of the Rise User
Posted 9 hours ago

ProtoLabs is hiring a Senior Salesforce Administrator to drive platform configuration, scalable automation, integrations, and governance for its global Salesforce org from the Maple Plain, MN headquarters on a hybrid schedule.

Photo of the Rise User

The Associate Director, Cyber Defense at Emory will lead security operations, incident response, and vulnerability management while providing strategic guidance and supervising information security professionals across the university.

Corebridge Financial is hiring an SAP Insurance Functional Lead to drive SAP FSCD/FPSL insurance accounting delivery, transformation, and production support across finance and IT stakeholders.

As a dynamic systems integrator, SMS offers proven solutions in engineering, operations, cyber-security, and digital transformation. With expertise in modernizing and optimizing legacy infrastructure and systems, ensuring operational efficiency, a...

3 jobs
MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, onsite
DATE POSTED
October 16, 2025
Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!