Security Control Assessor, Mid
Location
United States
Posted
23 days ago
Salary
$70K / year
Seniority
Mid Level
Job Description
Security Control Assessor, Mid
AGE Solutions
Role Description AGE Solutions is looking for a Security Control Assessor, Intermediate to join our team in support of a cybersecurity risk management and assessment program with our DoD customer. - Conduct cybersecurity assessments, audits, and inspections for DoD organizations and partners handling DoD information or connecting to the DoDIN. - Evaluate systems and Defensive Cyberspace Operations using cyber threat emulation and performance-based testing. - Adhere to policies and processes for each assessment type. - Support assessment development and execution to ensure security expertise is properly applied. - Coordinate logistics, test plans, and scope with the SCA Team Lead. - Perform vulnerability assessments, capture results using STIG Viewer or designated tools, and document findings in eMASS. - Analyze security gaps and provide mitigation recommendations. - Validate cybersecurity controls, TTPs, STIGs, RMF controls, and compliance with DoD policies and guidelines. - Provide risk analysis and assessment results for authorization recommendations. - Participate in daily assessment reviews, in-briefs, and out-briefs, sharing findings with the SCA-R. Qualifications - Bachelor's degree (IT-related field preferred) - Five (5) years of overall experience in cybersecurity or network security position - Three (3) years of experience in a Certification and Accreditation/A&A role - Must have and maintain an active DoD Top Secret clearance with SCI eligibility - DoD 8570 IA Technical (IAT) Level II certification - Demonstrated experience with STIGs (Security Technical Implementation Guides), Security Requirement Guides (SRGs), Plan of Action and Milestones (POA&Ms) and cybersecurity best practices - Strong understanding of the RMF process, NIST SP 800-37, NIST SP 800-53, CNSSI 1253 - Demonstrated experience with relevant tools such as eMASS, STIG Viewer, Nessus, ACAS, SCAP, or HBSS - Demonstratable understanding of key technologies areas/domain such as: Network, Mobility, Windows, UNIX, Cloud Environments and Cloud Native Tools/Services, Host Based Security System (HBSS)/Endpoint Security Solutions (ESS), Databases, Applications - Strong written and verbal communication skills for reporting assessment findings. Requirements - This is a remote role requiring approximately 85% travel both CONUS AND OCONUS. - Candidates must have a valid US Passport, or the ability to obtain one quickly. Benefits - 26 Days Paid Leave: Includes vacation, sick, personal time, and holidays. You choose how to use it. - Performance Bonuses: Performance bonuses are awarded based on individual contributions and company-wide results, aligning recognition with impact. - 401(k) with Match: We match 3% of your contributions with immediate vesting. - Financial Protection: Company-paid life insurance up to $300K and options for additional coverage for you and your dependents. - Health Benefits: Multiple medical plans, dental, vision, FSA and HSA options to fit your needs. - Parental Leave: 15 days of fully paid leave for new parents, because family matters. - Military Differential Pay: We bridge the gap for employees on active duty, so they don’t take a financial hit while serving. - Professional Growth: Paid training and certifications, tuition reimbursement, and the tools and tech to get the job done right. - Shared Success: In the event of a company sale, our CEO has committed to returning 80% of net proceeds to employees. This ensures our team shares in the long term value they help create.
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Program Manager, Security Business Enablement
Stripe, Inc.Stripe, Inc. is a global technology company with offices and remote employees worldwide, team members who speak more than 30 languages, and millions of users. A
Role Description The Security Business Enablement Program Manager position will be part of Stripe’s Office of the CISO pillar. You will represent all of Stripe directly to our customers and partners, facilitate conversations with Legal and Security teams, and identify opportunities to enhance our coverage and scalability with tooling and automation. Responsibilities - Function as an information security subject matter expert and lead cross-functional teams to engage with customers and partners to build trust and grow our business. - Serve as the main point of contact for all go-to-market related requests. - Operate autonomously, leading large-scale efforts to implement and operate tooling and automation across multiple teams and functions, with stakeholders in different disciplines and time zones. - Identify and evaluate information security control gaps and oversee remediation efforts, in partnership with control owners. - Develop information security policies and standards based on cybersecurity framework guidelines. - Develop, define, and report on the team’s program health and success metrics to provide insights to management to help drive strategic direction. Qualifications - You are a subject matter expert in information security frameworks, practices, policies, standards and procedures (e.g. NIST CSF, PCI DSS, ISO 27001, SOC 2 or equivalent). - You understand how to balance business needs with security requirements and focus on business outcomes. - You have 5+ years engaging with customer and partner business, engineering, security, compliance, and legal teams as part of the go-to-market sales cycle. - You have experience driving large-scale projects and programs from start to finish within highly complex operating environments. - You have strong written and verbal communication skills, building strong relationships at all levels of the organization from executives to project teams. - You communicate clear and succinct security compliance controls and requirements with external Stripe stakeholders, including security counter-parties at global financial institutions. - You possess a strong background in information security operations, risks and controls identification, and assessment. - You are a critical thinker, passionate, self-driven, and detail-oriented. Preferred Qualifications - You have developed reports on program performance via dashboards and OKRs, and perform detailed data analysis. - You have experience working with engineers for the automation of security controls and generation of evidence. - You have utilized AI to automate complex information gathering tasks and built interfaces for non-technical users.
Role Description AGE Solutions is looking for a Security Control Assessor, Junior to join our team in support of a cybersecurity risk management and assessment program with our DoD customer. - Conduct cybersecurity assessments, audits, and inspections for DoD organizations and partners handling DoD information or connecting to the DoDIN. - Evaluate systems and Defensive Cyberspace Operations using cyber threat emulation and performance-based testing. - Adhere to policies and processes for each assessment type. - Support assessment development and execution to ensure security expertise is properly applied. - Coordinate logistics, test plans, and scope with the SCA Team Lead. - Perform vulnerability assessments, capture results using STIG Viewer or designated tools, and document findings in eMASS. - Analyze security gaps and provide mitigation recommendations. - Validate cybersecurity controls, TTPs, STIGs, RMF controls, and compliance with DoD policies and guidelines. - Provide risk analysis and assessment results for authorization recommendations. - Participate in daily assessment reviews, in-briefs, and out-briefs, sharing findings with the SCA-R. Qualifications - Bachelor's degree (IT-related field preferred) - Three (3) years of overall experience in a DoD or Federal IT environment - Must have an active DoD Top Secret clearance with SCI eligibility - DoD 8570 IA Technical (IAT) Level II certification required - Familiarity with STIGs (Security Technical Implementation Guides), Security Requirement Guides (SRGs), Plan of Action and Milestones (POA&Ms) and cybersecurity best practices - Understanding of the RMF process, NIST SP 800-37, NIST SP 800-53, CNSSI 1253 - Familiarity with relevant tools such as eMASS, STIG Viewer, Nessus, ACAS, SCAP, or HBSS - Strong written and verbal communication skills for reporting assessment findings. Requirements - This is a remote role requiring approximately 85% travel both CONUS AND OCONUS. - Candidates must have a valid US Passport, or the ability to obtain one quickly. Benefits - 26 Days Paid Leave: Includes vacation, sick, personal time, and holidays. You choose how to use it. - Performance Bonuses: Performance bonuses are awarded based on individual contributions and company-wide results, aligning recognition with impact. - 401(k) with Match: We match 3% of your contributions with immediate vesting. - Financial Protection: Company-paid life insurance up to $300K and options for additional coverage for you and your dependents. - Health Benefits: Multiple medical plans, dental, vision, FSA and HSA options to fit your needs. - Parental Leave: 15 days of fully paid leave for new parents, because family matters. - Military Differential Pay: We bridge the gap for employees on active duty, so they don’t take a financial hit while serving. - Professional Growth: Paid training and certifications, tuition reimbursement, and the tools and tech to get the job done right. - Shared Success: In the event of a company sale, our CEO has committed to returning 80% of net proceeds to employees. This ensures our team shares in the long term value they help create.
• Working closely with sales, educating customers on Akamai's emerging AI security products and services • Supporting the technical pre-sales process for field teams and evangelising our AI security solutions internally and externally • Engaging with customers on demos, POC and deep-dive technical conversations to drive AI security sales • Influencing product roadmaps and ensuring the inclusion of business priorities and requirements of customers • Staying nimble and growing with us as we bring new security products to market
Identity Security Engineer – ITDR, CSPM
Dragonfli GroupCyberSecurity as a Solution: Enabling Secure Business.
• Own end-to-end strategy, implementation, and operational health of CrowdStrike Falcon Identity Protection and the CSPM capabilities within CrowdStrike Cloud Security • Proactively identify identity-based threats, misconfigurations, and cloud security gaps; drive remediation to closure in accordance with client policies and procedures • Configure, tune, and maintain identity protection policies, IOM and IOA policies, and risk-based authentication controls • Serve as the escalation point and trusted technical advisor to client leadership on identity and cloud security matters • Develop runbooks, detection logic, and automation to reduce manual effort and improve response times • Monitor the threat landscape and translate emerging risks into actionable hardening recommendations • Coordinate and lead governance calls with stakeholders; produce agenda, notes, and follow-up actions independently • Partner with other cybersecurity teams to integrate CrowdStrike telemetry into broader security operations • Produce metrics, dashboards, and executive-level reporting on identity and cloud security posture • Apply deep knowledge of identity-based attack techniques — including lateral movement, credential theft, Kerberoasting, and pass-the-hash — to inform detection and response strategy


