Skip to content

Open nowPosted 5 days ago

Security Control Assessor Representative (SCA-R)

AGE Solutions67 open roles

Pay
$100,000 a year
Where
Arlington, Virginia, United States, Chambersburg, Pennsylvania, United States, Fort Meade, Maryland, United States
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSecurity Control Assessor Representative (SCA-R)AGE Solutions · Arlington, Virginia, United States, Chambersburg, Pennsylvania, United States, Fort Meade, Maryland, United States
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on AGE Solutions's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market. AGE Solutions postings stay open a median of 6 days.

Share of postings closed within
  1. 1.7%1 day
  2. 3.5%3 days
  3. 7.8%7 days
  4. 14.6%14 days
  5. 34.1%30 days
This job: posted 5 days ago

AGE Solutions median: 6 days open

The posting

About Us

AGE Solutions is a premier technology and professional services company, providing in-depth consulting, advanced technology solutions, and essential services throughout the U.S. government, defense, and intelligence sectors. Prioritizing innovation and client-focused solutions, we assist major agencies in addressing intricate issues and ensuring a more secure future.

The Security Control Assessor Representative (SCA-R) provides cybersecurity assessment, Risk Management Framework (RMF), and Assessment and Authorization (A&A) support for Department of Defense (DoD) information systems. The SCA-R works with Information System Security Managers (ISSMs), Program Management Offices (PMOs), system owners, technical teams, and Government cybersecurity stakeholders to assess security controls, identify cybersecurity risks, validate system compliance, and support authorization decisions throughout the system lifecycle.

The SCA-R performs independent technical and risk-based assessments using Government-approved processes, databases, and cybersecurity tools and develops complete, accurate, and defensible authorization documentation for Government and Authorizing Official (AO) review.

Responsibilities Include:

  • Use Government-assigned tools and databases to perform weekly updates, maintain system records, track assigned actions, and complete cybersecurity assessment and authorization activities.
  • Coordinate with ISSMs, PMOs, system owners, and technical stakeholders to understand system architectures, security requirements, authorization boundaries, configurations, and system changes.
  • Conduct risk analysis, security control assessment, and authorization activities across applicable RMF steps using approved RE5 tools and processes.
  • Verify system authorization boundaries and validate system security categorizations in accordance with FIPS 199 and applicable DoD requirements.
  • Identify applicable data classifications and conduct system-level cybersecurity risk assessments.
  • Assess threats, vulnerabilities, control deficiencies, and residual risks and compile findings into complete and accurate authorization packages.
  • Evaluate proposed and implemented system changes, determine their potential security and authorization impacts, and provide appropriate status and risk information to the Authorizing Official (AO).
  • Evaluate authorization and change requests, including web-filtering requests, firewall exceptions, ports and protocols, cybersecurity risks, STIG/SRG compliance, and on-site security requirements.
  • Review and validate compliance with applicable Security Technical Implementation Guides (STIGs), Security Requirements Guides (SRGs), security controls, and cybersecurity requirements.
  • Review, validate, and track Plans of Action and Milestones (POA&Ms) and associated cybersecurity deficiencies through resolution.
  • Lead and support on-site assessment visits, including planning, technical assessments, stakeholder coordination, entrance/exit briefings, documentation, findings development, and reporting.
  • Maintain access to and proficiency with required Government cybersecurity databases, vulnerability assessment platforms, endpoint security solutions, scanning tools, and RMF management systems.
  • Attend required Government meetings, technical exchanges, and training to remain current with policies, procedures, tools, and RMF process changes.
  • Complete required assessor, vulnerability scanning, endpoint security, and RMF process training.
  • Support assigned systems throughout their lifecycle in accordance with FISMA, DoD RMF, and applicable cybersecurity requirements.
  • Prepare and submit weekly activity reports documenting completed and ongoing activities, tracking identifiers, assessment status, significant findings, risks, issues, and key updates.

Required Skills, Qualifications and Experience:

  • Education: Bachelor's degree required. A bachelor's in information technology, Cybersecurity, Computer Science, Information Systems, or related technical field is preferred.
  • Overall Experience: Minimum of eight (8) years of experience in a cybersecurity or network security position.
  • A&A Experience: Minimum of five (5) years of experience performing Certification and Accreditation (C&A) and/or Assessment and Authorization (A&A) activities.
  • Security Clearance: Must have a minimum of a current DoD Secret Clearance with the ability to obtain a DoD Top Secret clearance with SCI eligibility. A current DoD Top Secret clearance with SCI eligibility strongly preferred.
  • Certification: Current DoD 8570 IAM Level III certification.
  • Skills: Demonstrated experience serving as a Security Control Assessor Representative (SCA-R) and performing cybersecurity risk analysis and security control validation. Advanced understanding and practical application of the Risk Management Framework (RMF), including NIST SP 800-37, NIST SP 800-53, and CNSSI 1253. Demonstrated experience applying and evaluating Security Technical Implementation Guides (STIGs), Security Requirements Guides (SRGs), Plans of Action and Milestones (POA&Ms), cybersecurity security controls, and industry/DoD cybersecurity best practices. Demonstrated hands-on experience with relevant cybersecurity and RMF tools, including one or more of the following: eMASS, STIG Viewer, Nessus, ACAS, SCAP, and HBSS/Endpoint Security Solutions (ESS). Advanced understanding of multiple cybersecurity technology areas and domains, including network technologies and security, mobility, Windows, UNIX/Linux, cloud environments, cloud-native tools and services, HBSS/Endpoint Security Solutions (ESS), databases, and applications. Strong customer service and stakeholder engagement skills, with the ability to effectively coordinate with Government customers, ISSMs, PMOs, technical teams, system owners, and cybersecurity leadership. Ability to analyze complex technical and cybersecurity information and clearly communicate security risks, vulnerabilities, assessment findings, residual risk, and recommended corrective actions through written documentation and technical briefings.
  • Location and Schedule: This role may be based at one of the following customer locations, with onsite requirements varying by location: Chambersburg, PA: Fully onsite, 5 days per week. Arlington, VA or Fort Meade, MD: Hybrid schedule, 4 days onsite per week with 1 telework day.
  • Travel Requirements: Must be willing and able to support occasional domestic (CONUS) and international (OCONUS) travel, approximately 10% of the time.

The projected salary range for this position is $100,000+ annually. Final compensation will be determined based on factors including years of relevant experience, active security clearance level, certifications, technical skillset, contract requirements, and overall qualifications.

At AGE Solutions, we reward performance, invest in growth, and share success. Our benefits support the whole person, professionally, financially, and personally.

  • 26 Days Paid Leave: Includes vacation, sick, personal time, and holidays. You choose how to use it.
  • Performance Bonuses: Performance bonuses are awarded based on individual contributions and company-wide results, aligning recognition with impact.
  • 401(k) with Match: We match 3% of your contributions with immediate vesting.
  • Financial Protection: Company-paid life insurance up to $300K and options for additional coverage for you and your dependents.
  • Health Benefits: Multiple medical plans, dental, vision, FSA and HSA options to fit your needs.
  • Parental Leave: 15 days of fully paid leave for new parents, because family matters.
  • Military Differential Pay: We bridge the gap for employees on active duty, so they don’t take a financial hit while serving.
  • Professional Growth: Paid training and certifications, tuition reimbursement, and the tools and tech to get the job done right.
  • Shared Success: In the event of a company sale, our CEO has committed to returning 80% of net proceeds to employees. This ensures our team shares in the long term value they help create.

At AGE, you’ll do work that matters, supported by a company that delivers for its people.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against AGE Solutions's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on AGE Solutions's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    AGE Solutions's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.