Where Technology and Simplicity Connect
Senior Security Control Assessor
Location
Virginia
Posted
80 days ago
Salary
0
Seniority
Senior
Job Description
Senior Security Control Assessor
Arlo Solutions
• Provide the AO with an independent risk assessment of assigned systems and authorization. • Advise Program Managers on AO determination utilizing OVL documentation. • Provide senior advisory support to OUSW (R&E) AO regarding authorizations of OUSW (R&E) capabilities. • Utilize expert knowledge and experience regarding risk management strategies in support of a major DoW program. • Providing support regarding the agile authorization and OVL processes. • Provide independent risk analysis and recommendation. • Collaborate between the AO and the program as well as Program leadership. • Identify the security baseline based on the mission and security impacts to the system. • Determine assessment criteria, develop, review, and create a plan to assess the security requirements. • Assess the security requirements in accordance with the assessment procedures defined in the Security. • Assessment Plan (SAP). • Prepare the Security Assessment Report (SAR). • Monitor POAM actions based on findings and reassess remediated risk(s) as appropriate. • Develop the Risk Recommendation and AO Determination Brief. • Develop a system-level continuous monitoring strategy. • Author and present briefs regarding status of authorizations to AO and other senior Government officials. • Provides security architecture and DoW compliance advisory support. • Perform other duties as assigned or required.
Job Requirements
- Must have an active Top-Secret Clearance SCI eligible.
- Bachelor’s degree in computer science/information technology, or other related degree fields (master’s degree is preferred or at least 10 years of related experience)
- At least 10+ years of cybersecurity experience including a senior technical or management role, Project or Program Management experience a plus.
- At least one IAT/IAM or equivalent security certifications ex. CISSP, CCSP, CISM, CISA, or CASP
Benefits
- Top Secret with SCI eligibility
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
• Own end-to-end information security strategy across cloud, application, infrastructure, and corporate environments. • Define a pragmatic security roadmap aligned to business risk, regulatory requirements, and engineering velocity. • Serve as the executive owner for security posture, risk management, and incident response. • Act as a trusted advisor to the CTO and executive team on security, risk, and operational tradeoffs. • Drive a DevSecOps-first operating model, embedding security into CI/CD pipelines, infrastructure as code, and developer workflows. • Partner deeply with engineering leadership to make security scalable, automated, and measurable. • Lead threat modeling, secure design reviews, and risk assessments for new platform initiatives. • Champion policy-as-code, guardrails, and automation over manual process. • Own security architecture and operations for a primarily AWS-based environment. • Lead application security programs, including secure SDLC, dependency scanning, SAST/DAST, penetration testing, and vulnerability management. • Build and run effective security operations, including monitoring, investigation, incident response, and post-incident learning. • Manage vendor relationships, including CrowdStrike, Flashpoint, RAD, and Okta. • Lead end-user computing, device management, endpoint security, identity lifecycle management, and access controls.
• Build detection systems at scale. • Engineer response automation. • Lead incident response. • Architect observability. • Hunt proactively. • Ship production code. • Mentor and elevate.
• Análisis de cumplimiento de ISO/SAE 21434 y UNECE R155 . • Colaborarás en el diseño de planes de implementación de medidas de ciberseguridad. • Participarás en el ciclo de vida de productos como ECUs, BMS, Power Electronics , aplicando principios de “cybersecure by design” . • Identificar y mitigar amenazas en buses de comunicación, gateways, actualizaciones OTA, etc.
Security Engineer
Menlo Security Inc.Menlo Security protects productivity online with a one-of-a-kind, isolation-powered cloud security platform.
• Multi-Cloud Governance (AWS & GCP): Deploy and manage Cloud Security Posture Management (CSPM) tools to automatically detect and remediate misconfigurations across both providers. • Container Security Lifecycle: Implement Cloud Native Application Protection Platform (CNAPP) strategies by shifting left and integrating container image scanning directly into Jenkins and GitLab pipelines. • Workload Protection: Deploy and tune Cloud Workload Protection Platform (CWPP) tools to monitor runtime behavior and detect anomalies in both VMs and Kubernetes pods. • Advanced Automation & SOAR: Build Automated Response Playbooks to automatically enrich alerts, isolate compromised resources, and dismiss low-fidelity noise without human intervention. • Infrastructure Review & Identity: Manage effective permissions across complex multi-cloud IAM structures and standardize secret management workflows. • Release Readiness & Customer Trust: Collaborate closely with Technical Program Managers (TPMs) during software releases to enforce compliance standards and oversee vulnerability scanning. Additionally, respond to customer inquiries regarding the impact of Common Vulnerabilities and Exposures (CVEs) on our product.




