Security Control Assessor
Location
United States
Posted
10 days ago
Salary
Not specified
No structured requirement data.
Job Description
Harmonia Holdings Group, LLC is an award-winning, rapidly growing federal government contractor committed to providing innovative, high-performing solutions to our government clients and focused on fostering a workplace that encourages growth, initiative, creativity, and employee satisfaction.
Description
Title: Security Control Assessor
Location: Remote
Terms: Full-time
Clearance: Public Trust
Travel: <10%
Position Description
We have an opening for a full-time Security Control Assessor to join our talented, dynamic team in support of the Department of Veterans Affairs. As a Security Control Assessor, you will be trusted to support the delivery of our cybersecurity solutions and services. In this role, you will be a part of a security control assessment team working on the tasks outlined below.
Veterans are encouraged to apply.
Responsibilities:
- Conducts independent comprehensive assessments of the management, operational, and technical security controls and control enhancements employed within or inherited by an information technology (IT) system to determine the overall effectiveness of the controls (as defined in NIST SP 800-37).
- Plans and conducts security authorization reviews and assurance case development for initial installation of systems and networks.
- Reviews authorization and assurance documents to confirm that the level of risk is within acceptable limits for each software application, system, and network.
- Verifies that application software/network/system security postures are implemented as stated, document deviations, and recommend required actions to correct those deviations.
- Develops security compliance processes and/or audits for external services (e.g., cloud service providers, data centers).
- Performs security reviews and identifies security gaps in security architecture resulting in recommendations for inclusion in the risk mitigation strategy.
- Performs risk analysis (e.g., threat, vulnerability, and probability of occurrence) whenever an application or system undergoes a major change.
- Provide input to the Risk Management Framework process activities and related documentation (e.g., system life-cycle support plans, concept of operations, operational procedures, and maintenance training materials).
Requirements
- Bachelor's degree in computer science, electronics engineering or other engineering or technical discipline is required, and will accept relevant experience in lieu of degree.
- 1+ years hands-on experience with Cybersecurity policy, risk management, or security and privacy control assessments.
- Knowledge of cybersecurity and privacy principles and organizational requirements (relevant to confidentiality, integrity, availability, authentication, non-repudiation).
- Knowledge of system and application security threats and vulnerabilities.
- Knowledge of Personally Identifiable Information (PII), Payment Card Industry (PCI), and Personal Health Information (PHI) data security standards.
Desired
- Experience with security control assessments within the VA using the NIST Risk Management Framework (RMF) is a plus.
- Certifications such as SCA and CISA are a plus.
- Exceptional written and verbal communication skills.
- Strong planning, organizational, and time management skills.
- Exceptional analytical and conceptual thinking skills.
- Ability to work collaboratively with a team of peers.
___________________________________________________________________________________________________________
Here at Harmonia we are pleased to have been repeatedly recognized for our outstanding work culture, the innovative work we do, and the employees on our team who make a difference each day. Some of these recognitions include:
- Recognized as a Top 20 "Best Place to Work in Virginia"
- Recipient of Department of Labor's HireVets Gold Medallion
- Great Place to Work Certification for five years running
- A Virginia Chamber of Commerce Fantastic 50 company
- A Northern Virginia Technology Council Tech 100 company
- Inc. 5000 list of fastest growing companies for eleven years
- Two-time SBA SBIR Tibbett's Award winner
- Virginia Values Veterans (V3) Certification
We recognize that every bit of our success is the result of our teams of hard-working, motivated, and innovative professionals who are proud to call themselves part of the Harmonia family! In addition to competitive compensation, a family-focused culture, and a dynamic, productive work environment, we offer all full-time employees a variety of benefits including, but not limited to
- Traditional and HSA- eligible medical insurance plans
- 100% employer-paid dental and vision insurance options
- 100% employer-sponsored STD, LTD, and life insurance
- 5% 401(k) company matching
- Flexible-schedules and teleworking options
- Paid holidays and PTO Accrual Plans
- Paid Parental Leave
- Professional development and career growth opportunities
- Team and company-wide events, recognition, and appreciation-- and so much more!
Check out our LinkedIn, Facebook, and Instagram to find out a little more about who we are and if we are the right next step for your career!
Harmonia is an Equal Opportunity Employer providing equal employment opportunity to all employees and applicants for employment without regard to race, color, religion, national origin, age, gender, gender identity, sexual orientation, disability, or genetics. Harmonia does and will take affirmative action to employ and advance in employment individuals with disabilities and protected veterans. To perform the above job successfully, an individual must possess the knowledge, skills, and abilities listed; meet the education and work experience required; and must be able to perform each essential duty and responsibility satisfactorily. Other duties in addition to those listed may be assigned as necessary to meet business needs. Reasonable accommodation will be made to enable an applicant with a disability to successfully apply for and/or perform the essential duties of the job. If you are in need of an accommodation, please contact HR@harmonia.com.
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Chief Information Security Officer (CISO)
Nymbus, Inc.Nymbus empowers banks and global financial institutions to modernize their capabilities and drive measurable value in today’s digital marketplace. We believe innovation should bring excitement and confidence — not complexity and uncertainty. At Nymbus, we are redefining digital banking and creating meaningful impact for our partners and their customers. Our success starts with our people. If you’re looking to grow your career in a fast-moving fintech environment where operational excellence and innovation intersect, we invite you to explore this opportunity. Nymbus is a remote-first organization. This position is fully remote; however, occasional travel may be required for client meetings or designated team gatherings.
The CISO will own and continuously mature the enterprise Information Security Program, aligning controls with major regulatory frameworks like NIST, FFIEC, and PCI DSS. This role involves translating strategy into measurable execution plans, driving remediation of findings, and leading the security team across detection engineering, vulnerability management, and security architecture functions.
Director, Information Security
Human Rights WatchHuman Rights Watch is one of the world’s leading independent organizations dedicated to defending and protecting human rights. By focusing international attention where human rights are violated, we give voice to the oppressed and hold oppressors accountable for their crimes. Our rigorous, objective investigations and strategic, targeted advocacy build intense pressure for action and raise the cost of human rights abuse. For 30 years, Human Rights Watch has worked tenaciously to lay the legal and moral groundwork for deep-rooted change and has fought to bring greater justice and security to people around the world.
FULL-TIME JOB VACANCY Director, Information Security Information Security Division Multiple Locations Considered Application Deadline: March 29th Human Rights Watch (“HRW”) is seeking a highly skilled and forward-thinking Director of Information Security to lead our efforts in en...
The Senior Risk Mitigation and Security Manager plays a critical role in protecting the credit union through strong risk management, vendor oversight, and business continuity programs. This position ensures appropriate bond and insurance coverage and supports robust information s...
Senior Incident Response Engineer
RemitlyLexisNexis® Risk Solutions provides customers with solutions and decision tools that combine public and industry specific content with advanced technology and analytics to assist them in evaluating and predicting risk and enhancing operational efficiency. We use the power of data and advanced analytics to help our customers make better, timelier decisions. By bringing clarity to information, we ultimately help make communities safer, insurance rates more accurate, commerce more transparent, business decisions easier and processes more efficient. You can learn more about LexisNexis Risk at the link below: LexisNexis Risk Solutions
The role involves serving as the senior technical member of the incident response team, focusing on improving security resilience and readiness through the development and execution of response plans and forensic investigations across physical and cloud environments. Key duties include leading full-life-cycle incident response, developing comprehensive reports, and proactively collecting intelligence to detect high-confidence threats to the enterprise.