waypointjobs

Cherokee Federal

Security Controls Assessor - Senior

Remote — United States (see country and timezone requirements)

Check who can apply and the requirements below before continuing.

Job description

Security Controls Assessor – Senior

This position requires an active Public Trust clearance or the ability to obtain a Public Trust clearance to be considered.

The Senior Security Controls Assessor provides independent assessments of MARAD information systems in support of system authorization, reauthorization, and continuous monitoring activities. This role evaluates management, operational, and technical security controls in accordance with NIST Risk Management Framework (RMF) requirements, supports Authority to Operate (ATO) decisions, develops assessment documentation and reports, and collaborates with MARAD, DOT, and cybersecurity stakeholders to ensure compliance, risk visibility, and mission assurance.

Compensation & Benefits

Pay commensurate with experience. $150,000 - $155,000

Full-time benefits include Medical, Dental, Vision, 401(k), and other possible benefits as provided. Benefits are subject to change with or without notice.

Security Controls Assessor – Senior Responsibilities Include:

Assess MARAD systems in one of three states: Initial Authorization, Reauthorization, or Continuous Monitoring Assessment (CMA), also known as ongoing authorization. The Independent Assessor must be prepared to support each of these three authorization states.

Provide annual assessment support to the NSMV and MARAD CIO programs. NSMV assessment support will involve conducting on-site evaluations at the Philadelphia shipyard and other locations.

Conduct independent assessments of specified MARAD information systems following the System Authorization process defined in the current DOT Security Authorization and Continuous Monitoring Performance Guide and associated templates.

Review existing information-system core documentation, including privacy requirements and data, to support the development of security assessment plans and schedules supporting Authority to Operate (ATO) dates.

Review and establish annual assessment schedules in support of required deliverables and artifacts.

Identify noncompliance with security requirements and recommend possible mitigation strategies.

Validate the security requirements of information systems.

Verify that systems meet applicable security requirements.

Conduct independent and comprehensive assessments of management, operational, and technical security controls and control enhancements to determine their overall effectiveness.

Execute and analyze network and system assessments to validate appropriate security-control implementation.

Develop Security Assessment Plans and Security Assessment Reports compliant with the latest revisions of NIST Special Publication 800-53A, Assessing Security and Privacy Controls in Information Systems and Organizations, and NIST SP 800-37, Risk Management Framework for Information Systems and Organizations.

Develop Security Assessment Plans (SAPs) that clearly define the assessment scope, exclusions when necessary, controls being assessed, assessment methods, sampling methods, “determine if” statements, proposed schedules, assessment staff, targeted system endpoints and components, software inventories, processes, and the status of system-specific, hybrid, and inherited controls.

Follow the approved SAP when assessing security controls for targeted information systems.

Use approved techniques to collect and catalog supporting evidence, including documents, screenshots, scanning reports, and interview notes, to substantiate security-control implementation findings.

Develop Security Assessment Reports (SARs) according to the scope and schedule defined in the SAP. The SAR must document assessment findings and include evidence supporting the implementation status of each assessed control.

Develop and update qualitative Risk Assessment Reports (RARs) compliant with NIST SP 800-30, Guide for Conducting Risk Assessments.

Develop recommendation reports supporting Plan of Action and Milestones (POA&M) development. Reports must document findings and recommend actions and levels of effort for remediation.

Develop executive-summary documents and presentations that provide an overview of assessment activities, findings, risks, and mitigation recommendations.

Enter assessment data into the Cyber Security Assessment and Management (CSAM) database, DOT’s system of record for ATOs.

Provide presentations, reports, evaluations, reviews, meeting minutes, and working papers supporting all assigned tasks, as requested by the Contracting Officer’s Representative (COR).

Apply MARAD and DOT Assessment and Authorization guidance and policies to achieve program objectives and improve the overall quality of ATO packages.

Collaborate actively with the designated Information Systems Security Manager (ISSM).

Perform other job-related duties as assigned.

Security Controls Assessor – Senior Experience, Education, Skills, and Abilities Requested:

Bachelor’s degree in Cybersecurity or a related IT field may be substituted for four years of experience.

Bachelor’s degree in an IT-related field.

Certified Information Systems Auditor (CISA), Advanced in AI Audit (AAIA), or an equivalent certification.

Twelve years of related work experience.

Prior experience supporting U.S. Navy or Coast Guard maritime cybersecurity assessments.

Must possess or be able to obtain a Public Trust clearance.

Prior Department of Transportation experience is a plus.

Must pass Cherokee Federal’s pre-employment qualifications.

Company Information

Criterion is part of Cherokee Federal, the division of tribally owned federal contracting companies owned by Cherokee Nation Businesses. As a trusted partner for more than 60 federal clients, Cherokee Federal LLCs are focused on building a brighter future, solving complex challenges, and serving the government’s mission with compassion and heart. To learn more about Criterion, visit cherokee-federal.com.

#CherokeeFederal #AppC

Cherokee Federal is a military-friendly employer. Veterans and active-duty military members transitioning to civilian status are encouraged to apply.

Similar Searchable Job Titles

Senior Information Security Assessor

RMF Security Controls Assessor

Senior Cybersecurity Assessor

Information Assurance Assessor

ATO/RMF Lead Assessor

Keywords

Continuous Monitoring Assessment (CMA)

Risk Assessment

Security Assessment Plan (SAP)

Security Assessment Report (SAR)

Federal Cybersecurity

Legal Disclaimer

Cherokee Federal is an equal opportunity employer. Please visit cherokee-federal.com/careers for information regarding our Affirmative Action and Equal Opportunity Employer Statement and accommodation requests.

Many of our job openings require access to government buildings or military installations. Candidates must pass Cherokee Federal’s pre-employment qualifications.

Originally posted on Himalayas

Who can apply

Eligible countries: United States. Accepted UTC offsets: UTC-10, UTC-9, UTC-8, UTC-7, UTC-6, UTC-5, UTC+14. Review the full description for employer-specific work authorization, residency and schedule requirements.

Ready for your next step?Apply on the official website
Apply on Himalayas ↗

Explore related searches

Current related jobs

Red Wine and Blue

Himalayas

General Interest Application

Remote — United States (see country and timezone requirements)

Salary not specifiedfull timeRemote

WHO THE HECK ARE WE? Red Wine & Blue is a national community of over 600,000 diverse suburban women working together to defeat extremism, one fr…

Listing expires 2026-12-04View job

Carle Health

Himalayas

Finance Systems Analyst

Remote — United States (see country and timezone requirements)

$26.41 – $44.10 per hourfull timeRemote

OverviewThe Finance Systems Analyst assists with supporting assigned finance/accounting applications for the enterprise such as costing, producti…

Listing expires 2026-12-04View job

Kyowa Kirin

Himalayas

Scientific Relations Manager

Remote — Worldwide (see timezone requirements)

Salary not specifiedfull timeRemote

OverviewWE PUSH THE BOUNDARIES OF MEDICINE. LEAPING FORWARD TO MAKE PEOPLE SMILE At Kyowa Kirin International (KKI), our purpose is to make peop…

Listing expires 2026-12-04View job

Belden, Inc

Himalayas

Solution Consultant - Cybersecurity Practice (US)

Remote — United States (see country and timezone requirements)

$125,000.00 – $160,000.00 per yearfull timeRemote

Innovation Starts With YouPropel your career at Belden, where innovation creates possibilities—for our people, our customers, and the communities…

Listing expires 2026-12-04View job