{"schemaVersion":"jobsearcher.job.v1","id":"9bdcd8d9e9b99dd030e99a4e","url":"https://jobsearcher.com/jobs/9bdcd8d9e9b99dd030e99a4e","canonicalUrl":"https://jobsearcher.com/jobs/9bdcd8d9e9b99dd030e99a4e","title":"Security Control Assessor (Mid-Level)","description":"Security Control Assessor (Mid-Level)The Security Control Assessor (SCA) serves as the technical authority for independent security assessments supporting the NIH Office of the Director (OD), Office of Information Technology (Client). The Senior SCA leads the planning, execution, and validation of Security Control Assessments throughout the authorization lifecycle, ensuring compliance with the NIST Risk Management Framework (RMF), NIST SP 800-53 Rev. 5, and the Joint Cybersecurity Assessment Methodology (JCAM). This position maintains strict independence from authorization package development activities to preserve the objectivity and integrity of the assessment process. Work is performed primarily remotely, with occasional on-site meetings or assessment activities as required.Key ResponsibilitiesConduct or support independent Security Control Assessments in accordance with NIST SP 800-37, NIST SP 800-53 Rev. 5, JCAM, and NIH/HHS policy.Review and validate authorization packages, including SSPs, SAPs, SARs, POA&Ms, Contingency Plans, and supporting evidence.Assess the implementation and effectiveness of security controls through documentation reviews, interviews, and technical validation.Review FedRAMP cloud packages and inherited controls, as applicable.Document findings, recommendations, and remediation activities.Support cybersecurity audits and continuous process improvement.Provide risk-based recommendations to the Authorizing Official while maintaining assessment independence.Mentor junior assessors and improve assessment methodologies.Required QualificationsEducationBachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or related discipline.Four (4) additional years of relevant experience may substitute for a bachelor's degree.ExperienceTen (10) or more years of progressive experience supporting federal cybersecurity, RMF, Security Control Assessment, security authorization, or information assurance programs.Demonstrated experience leading independent Security Control Assessments and validating RMF authorization packages.Extensive experience conducting security control testing, evidence validation, and developing SARs in accordance with NIST SP 800-37, NIST SP 800-53 Rev. 5, and JCAM.Experience supporting NIH, HHS, or other Federal civilian agencies is highly desirable.Experience reviewing FedRAMP authorization packages and supporting OIG, GAO, or independent assessments.Preferred QualificationsExperience supporting NIH, HHS, or other Federal agencies.Experience with eMASS or similar GRC platforms.Familiarity with FedRAMP, NIST AI RMF, C-SCRM, and cloud security concepts.Experience with SSPs, SAPs, SARs, POA&Ms, and Contingency Plans.Experience supporting OIG, GAO, or independent cybersecurity assessments.Desired CertificationsISC2 CISSPISC2 CGRCISACA CISMCompTIA CySA+CompTIA SecurityX (CASP+)GIAC GSECKnowledge, Skills, and AbilitiesStrong knowledge of federal cybersecurity assessment principles, excellent analytical and technical writing skills, effective communication, and the ability to work collaboratively while maintaining assessment independence.Work EnvironmentPrimarily remote with occasional on-site meetings or assessment activities as required.","company":"Merit 321","rawCompany":"merit 321","city":"Denver","state":"CO","isRemote":false,"isActive":true,"createdAt":"2026-09-12T12:17:46.704Z","occupations":[{"code":"15-1212.00","title":"Information Security Analysts","slug":"information-security-analysts"},{"code":"13-1199.07","title":"Security Management Specialists","slug":"security-management-specialists"},{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"}],"industries":[{"code":"541690","title":"Other Scientific and Technical Consulting Services","slug":"other-scientific-and-technical-consulting-services"},{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541618","title":"Other Management Consulting Services","slug":"other-management-consulting-services"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Security Control Assessor (Mid-Level)","description":"Security Control Assessor (Mid-Level)The Security Control Assessor (SCA) serves as the technical authority for independent security assessments supporting the NIH Office of the Director (OD), Office of Information Technology (Client). The Senior SCA leads the planning, execution, and validation of Security Control Assessments throughout the authorization lifecycle, ensuring compliance with the NIST Risk Management Framework (RMF), NIST SP 800-53 Rev. 5, and the Joint Cybersecurity Assessment Methodology (JCAM). This position maintains strict independence from authorization package development activities to preserve the objectivity and integrity of the assessment process. Work is performed primarily remotely, with occasional on-site meetings or assessment activities as required.Key ResponsibilitiesConduct or support independent Security Control Assessments in accordance with NIST SP 800-37, NIST SP 800-53 Rev. 5, JCAM, and NIH/HHS policy.Review and validate authorization packages, including SSPs, SAPs, SARs, POA&Ms, Contingency Plans, and supporting evidence.Assess the implementation and effectiveness of security controls through documentation reviews, interviews, and technical validation.Review FedRAMP cloud packages and inherited controls, as applicable.Document findings, recommendations, and remediation activities.Support cybersecurity audits and continuous process improvement.Provide risk-based recommendations to the Authorizing Official while maintaining assessment independence.Mentor junior assessors and improve assessment methodologies.Required QualificationsEducationBachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or related discipline.Four (4) additional years of relevant experience may substitute for a bachelor's degree.ExperienceTen (10) or more years of progressive experience supporting federal cybersecurity, RMF, Security Control Assessment, security authorization, or information assurance programs.Demonstrated experience leading independent Security Control Assessments and validating RMF authorization packages.Extensive experience conducting security control testing, evidence validation, and developing SARs in accordance with NIST SP 800-37, NIST SP 800-53 Rev. 5, and JCAM.Experience supporting NIH, HHS, or other Federal civilian agencies is highly desirable.Experience reviewing FedRAMP authorization packages and supporting OIG, GAO, or independent assessments.Preferred QualificationsExperience supporting NIH, HHS, or other Federal agencies.Experience with eMASS or similar GRC platforms.Familiarity with FedRAMP, NIST AI RMF, C-SCRM, and cloud security concepts.Experience with SSPs, SAPs, SARs, POA&Ms, and Contingency Plans.Experience supporting OIG, GAO, or independent cybersecurity assessments.Desired CertificationsISC2 CISSPISC2 CGRCISACA CISMCompTIA CySA+CompTIA SecurityX (CASP+)GIAC GSECKnowledge, Skills, and AbilitiesStrong knowledge of federal cybersecurity assessment principles, excellent analytical and technical writing skills, effective communication, and the ability to work collaboratively while maintaining assessment independence.Work EnvironmentPrimarily remote with occasional on-site meetings or assessment activities as required.","datePosted":"2026-09-12T12:17:46.704Z","dateModified":"2026-09-12T12:17:46.704Z","hiringOrganization":{"@type":"Organization","name":"Merit 321","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Denver","addressRegion":"CO","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"9bdcd8d9e9b99dd030e99a4e"},"url":"https://jobsearcher.com/jobs/9bdcd8d9e9b99dd030e99a4e"}}