Summary
Security Controls Assessor
ECS is seeking a Security Controls Assessor to work in our Washington, DC (hybrid) office. Please Note: This position is contingent upon contract award. ECS seeks a Security Controls Assessor to support a full range of cybersecurity services on a long-term, full-time contract with a U.S. Government civilian agency. This position requires mostly CONUS and occasional OCONUS assessments and is available immediately for a qualified candidate with an active security clearance. Key Responsibilities
- Review and update information security policies, standards, and procedures in accordance with federal and departmental regulations
- Perform independent security and privacy control assessments on behalf of the client CSO in support of Security Assessment & Authorization (SA&A)
- Assess existing and new FISMA systems and subsystems, and communicate findings and potential impacts of identified control weaknesses
- Review and analyze A&A packages-including System Security Plans (SSP), Risk Assessments, Information System Contingency Plans (ISCP), Backup SOPs, Incident Response Plans (IRP), Configuration Management Plans (CMP), hardware/software inventories, network diagrams, data flows, system change requests, vulnerability scan reports, test reports, and POA&Ms-for completeness, accuracy, and effective control implementation
- Develop and maintain test cases for control-level security testing across system components (applications, servers, databases, operating systems, network devices, end-user devices, etc.)
- Develop and execute security and privacy assessment plans in accordance with NIST SP 800-53A, supporting RMF Steps 4-6
- Document findings and recommendations that are clear, system-specific, and actionable
- Analyze security tool outputs to distinguish residual risk from false positives prior to finalizing findings
- CONUS and OCONUS travel to conduct system assessments
- Other duties as assigned
Salary Range: $150,000-$168,000 General Description of Benefits
- Active Secret clearance required with eligibility to get Top Secret clearance
- Bachelor's degree in Computer Science, MIS/IT, Engineering, Information Security/Assurance, or a related field
- Minimum five (5) years of information security experience
- Minimum three (3) years of experience supporting security assessment teams, including planning assessments and serving as a senior team member
- Two (2) years of experience using GRC tools
- Demonstrated experience conducting full-scope technical security control testing across component types, including development of security and privacy assessment plans
- Working knowledge of RMF Steps 1-6
- Strong understanding of NIST SP 800-53 controls, the NIST Cybersecurity Framework, and applicable information security/privacy laws and regulations
- Ability to analyze information system configurations and technical specifications against NIST SP 800-53 and related overlays
- Experience developing risk-based documentation
- Excellent written and verbal communication skills, with the ability to present control requirements and deficiencies clearly to both technical and non-technical audiences
Job Description
Security Controls Assessor
ECS is seeking a Security Controls Assessor to work in our Washington, DC (hybrid) office. Please Note: This position is contingent upon contract award. ECS seeks a Security Controls Assessor to support a full range of cybersecurity services on a long-term, full-time contract with a U.S. Government civilian agency. This position requires mostly CONUS and occasional OCONUS assessments and is available immediately for a qualified candidate with an active security clearance. Key Responsibilities
- Review and update information security policies, standards, and procedures in accordance with federal and departmental regulations
- Perform independent security and privacy control assessments on behalf of the client CSO in support of Security Assessment & Authorization (SA&A)
- Assess existing and new FISMA systems and subsystems, and communicate findings and potential impacts of identified control weaknesses
- Review and analyze A&A packages-including System Security Plans (SSP), Risk Assessments, Information System Contingency Plans (ISCP), Backup SOPs, Incident Response Plans (IRP), Configuration Management Plans (CMP), hardware/software inventories, network diagrams, data flows, system change requests, vulnerability scan reports, test reports, and POA&Ms-for completeness, accuracy, and effective control implementation
- Develop and maintain test cases for control-level security testing across system components (applications, servers, databases, operating systems, network devices, end-user devices, etc.)
- Develop and execute security and privacy assessment plans in accordance with NIST SP 800-53A, supporting RMF Steps 4-6
- Document findings and recommendations that are clear, system-specific, and actionable
- Analyze security tool outputs to distinguish residual risk from false positives prior to finalizing findings
- CONUS and OCONUS travel to conduct system assessments
- Other duties as assigned
Salary Range: $150,000-$168,000 General Description of Benefits
- Active Secret clearance required with eligibility to get Top Secret clearance
- Bachelor's degree in Computer Science, MIS/IT, Engineering, Information Security/Assurance, or a related field
- Minimum five (5) years of information security experience
- Minimum three (3) years of experience supporting security assessment teams, including planning assessments and serving as a senior team member
- Two (2) years of experience using GRC tools
- Demonstrated experience conducting full-scope technical security control testing across component types, including development of security and privacy assessment plans
- Working knowledge of RMF Steps 1-6
- Strong understanding of NIST SP 800-53 controls, the NIST Cybersecurity Framework, and applicable information security/privacy laws and regulations
- Ability to analyze information system configurations and technical specifications against NIST SP 800-53 and related overlays
- Experience developing risk-based documentation
- Excellent written and verbal communication skills, with the ability to present control requirements and deficiencies clearly to both technical and non-technical audiences
Government Careers
Government jobs offer stability, competitive benefits, and the chance to make a meaningful impact on your community and country.
Whether you’re starting your career or seeking new opportunities, these roles provide pathways for growth, security, and service.
Explore positions across a wide range of fields and take the first step toward a rewarding future in public service.
MORE JOBS
-
Intelligence Analyst
- Reston, Virginia
- US101 Guidehouse
- Aug 17, 2026
-
Junior Procurement Expeditor with Security Clearance
- Aiea, Hawaii
- ManTech
- Aug 17, 2026
-
Strategic Deterrence Advisor Space & NC3
- El Segundo, California
- Booz Allen Hamilton
- Aug 17, 2026
-
Senior All-Source Cyber Intelligence Analyst
- Fort Meade, Maryland
- Athena Technology Group
- Aug 17, 2026
-
Secret Clearance AI Subject Matter Expert (31)
- all cities, New Hampshire
- Virtual Vocations
- Aug 17, 2026
-
Senior Academic Instructor SME DoD Training Programs
- Florida, New York
- B3H Corporation
- Aug 17, 2026