Skip to content

Open nowPosted 3 days ago

Security Control Assessor

Xcelerate Solutions83 open roles

Where
Arlington, VA, United States
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSecurity Control AssessorXcelerate Solutions · Arlington, VA, United States
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Xcelerate Solutions's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.6%1 day
  2. 3.4%3 days
  3. 7.8%7 days
  4. 14.3%14 days
  5. 33.7%30 days
This job: posted 3 days ago

The posting

VMD Corp, now part of Xcelerate Solutions, seeks a Security Control Assessor to be responsible for the cybersecurity of a program, organization, system, or enclave. The Security Control Assessor ensures that the security and privacy posture is maintained for an organizational system and works in close collaboration with the FDIC system owners. The Security Control Assessor serves as an advisor on all matters, technical and otherwise, involving the security and privacy controls for the system and has the knowledge and expertise to manage the security and privacy aspects of an organizational system.

Responsibilities:

  • Identify the security and privacy requirements allocated to a system and to the organization, identify the characteristics of a system, contribute to determining the boundary of a system.
  • Collaborate with the System Owner to categorize the system and document the security categorization results as part of system requirements.
  • Identify stakeholders who have a security and/or privacy interest in the development, implementation, operation, or sustainment of a system.
  • Conduct an initial risk assessment of stakeholder assets and update the risk assessment on an ongoing basis.
  • Select the security and privacy controls for a system and document the functional description of the planned control implementations in a security/privacy plan.
  • Develop a strategy for monitoring security and privacy control effectiveness; coordinate the system-level strategy with the organization and mission/business process-level monitoring strategy.
  • Develop, review, and approve a plan to assess the security and privacy controls in a system and the organization.
  • Document changes to planned security and privacy control implementation and establish the configuration baseline for a system.
  • Respond to system risk posture based on the results of ongoing monitoring activities, assessment of risk, and outstanding items in a plan of action and milestones (POA&M).
  • Update a security plan, security assessment report, and plan of action and milestones based on the results of a continuous monitoring process.
  • Review the security and privacy status of a system (including the effectiveness of security and privacy controls) on an ongoing basis to determine whether the risk remains acceptable.
  • Report the security status of a system (including the effectiveness of security and privacy controls) to an authorizing official on an ongoing basis in accordance with the monitoring strategy.
  • Ensure that plans of actions and milestones or remediation plans are in place for vulnerabilities identified during risk assessments, audits, inspections, ensure that security improvement actions are evaluated, validated, and implemented as required.

Experience needed to be successful:

  • Demonstrated knowledge in the use of cyber legal, regulatory, and policy, specifically knowledge of federal cybersecurity governance frameworks, i.e., RMF, FedRAMP, and NIST Special Publications such as SP 800-53 and SP 800-171. Development and review of key authorization artifacts such as SSPs, SARs, POA&Ms
  • Demonstrated knowledge of cybersecurity principles, threats, and vulnerabilities, specifically strong knowledge of cybersecurity principles, i.e., confidentiality, integrity, availability, authentication, and risk management.
  • Demonstrated experience in the application of frameworks such as RMF, NIST SP 800-53, and FedRAMP to ensure enterprise-wide security compliance
  • Demonstrated experience of technical systems and tools in a wide range of cyber security defense tools and systems
  • Demonstrated experience of access, architecture, and infrastructure through applied knowledge of authentication, authorization, and access control methods
  • Demonstrated experience in business, operations, and risk management in particular risk management processes using frameworks such as RMF, NIST SP 800-53, and FedRAMP to assess and mitigate vulnerabilities across federal and commercial environments. Development of security documentation, including SSPs, SARs, and POA&Ms

Requirements:

  • Experience: 4-6 years of Relevant Cybersecurity Experience - specifically performing security control assessments in a SCA role, including supporting federal clients
  • Education: Bachelors Degree in Cyber-related field (Direct experience or certifications may substitute for the academic credentials)
  • Desired Certifications: Recognized cybersecurity certifications (e.g., CISSP, CISM, CISA, CAP, GIAC, or CompTIA certifications such as Security+ or CASP+)
  • Citizenship: U.S. Citizen
  • Clearance: Public Trust

Location: Arlington, VA (Hybrid). Must reside within the DC Metro area.

VMD provides equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion, gender, sexual orientation, gender identity or expression, national origin, age, disability, genetic information, marital status, amnesty, or status as a covered veteran in accordance with applicable Federal, state and local laws. VMD maintains a drug-free workplace.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Xcelerate Solutions's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Xcelerate Solutions's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Xcelerate Solutions's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.