About this role
MTSI is seeking a Security Control Assessor to support an Assistant Secretary of the Air Force, Acquisition, Technology and Logistics contract. The SCA conducts a comprehensive assessment of the management, operational, and technical security controls within or inherited by an Information System to determine the overall effectiveness of the controls. The role includes assessing the severity of weaknesses or deficiencies in the IS and its environment of operation and recommending corrective actions. Responsibilities cover Collateral, Sensitive Compartmented Information (SCI), and Special Access Program (SAP) activities within the customer’s area of responsibility.
- Perform oversight of the development, implementation, and evaluation of an information system security program, with emphasis on integrating existing SAP network infrastructure.
- Assess information systems using the Risk Management Framework (RMF) methodology in accordance with the Joint SAP Implementation Guide (JSIG).
- Advise the Information System Owner (ISO), Information Data Owner (IDO), Program Security Officer (PSO), and the Delegated/Authorizing Official (DAO/AO) on assessment and authorization issues.
- Evaluate authorization packages and make recommendations to the AO/DAO for authorization.
- Assess IS threats and vulnerabilities to determine if additional safeguards are required.
- Advise the Government on impact levels for confidentiality, integrity, and availability of information on a system.
- Ensure security assessments are completed, document results, and prepare the Security Assessment Report (SAR) for the authorization boundary.
- Initiate a Plan of Action and Milestones (POA&M) with identified weaknesses for each authorization boundary based on SAR findings and recommendations.
- Evaluate security assessment documentation and provide written recommendations for security authorization to the Government.
- Assess proposed changes to authorization boundaries, operating environment, and mission needs to determine continued operation.
- Review and concur with all sanitization and clearing procedures in accordance with Government guidance and policy.
- Assist Government compliance inspections and respond to security incidents related to cybersecurity, ensuring proper corrective measures are taken.
- Evaluate hardware and software to determine security impact on authorization boundaries.
- Evaluate the effectiveness and implementation of Continuous Monitoring Plans.
Requirements
- 15+ years related experience required; 9 years highly desired.
- Prior performance in roles such as System Administrator, Network Administrator, or Information System Security Officer (ISSO).
- Minimum of 2 years’ experience in SAP, SCI, or Collateral Information Systems Security and implementing regulations described in the duties.
- Prior performance in the role of ISSO and Information System Security Manager (ISSM).
- Education: Bachelor's Degree in Computer Science, Computer Engineering, or a related field.
- Clearance: Current/active Top Secret/SCI; current or recent DoD SAP access; subject to a Counterintelligence (CI) polygraph.