{"schemaVersion":"jobsearcher.job.v1","id":"be5f33dea9733a4180c2c3a7","url":"https://jobsearcher.com/jobs/be5f33dea9733a4180c2c3a7","canonicalUrl":"https://jobsearcher.com/jobs/be5f33dea9733a4180c2c3a7","title":"Security Control Assessor","description":"Evolver is looking for a Security Control Assessor to join our team supporting our federal client in Washington, DC. This position requires on-site 5 days/week at our federal client's HQ located in Washington, DC.\n\nThe Security Control Assessor is responsible for providing independent security control testing to the client for 20 FIPS Moderate and Low systems. Duties include conducting security control assessments through interviews, examination, and/or testing for all applicable management, operational, and technical controls, including analyzing findings and results and validating test results/ reports. Duties also include developing Security Control Assessment Plans, Risk Assessment Reports, and ATO Memos, as well as developing and maintaining testing policies and related Standard Operating Procedures (SOPs). The Security Control Assessor is also responsible for documenting and presenting the results of the Security Test & Evaluation (ST&E) to government stakeholders including System Owners, ISSOs, the CISO and Authorizing Official. Responsibilities also include reviewing artifacts and providing recommendations on POA&M closures.\n\nResponsibilities\nConduct security testing in accordance with NIST SP 800-53-A.\nDevelop Security Controls Assessment Plans, including:\nInterviewing, examining, and/or testing management, operational, and technical controls.\nGathering evidence for tested controls.\nSummarizing testing results, highlighting high/moderate risk items and compliance percentages.\nDocumenting results within the Security Controls Assessment Plan.\nAnalyzing and summarizing scan results, utilizing scans provided by the cloud environment.\nAssist in updating the client's IT Security Program policies and procedures.\nProvide timely reminders to Agency ISSOs to support Continuous Monitoring efforts.\nAssist in launching the client's Configuration Management program, including compliance testing and guidance on implementing DISA's Security Technical Implementation Guides (STIGs).\nProduce Security Assessment Reports (SAR) using the Agency's Information Assurance tool.\nEvaluate the risk of SAR findings from security testing and summarize them into Plan of Action and Milestone (POA&M) tracking documentation.\nTrack the progress of the IT Risk Management program through POA&M updates and/or data submission to the Agency's Office of Risk Management.\nReview supporting artifacts, evaluate remediation of risk, and recommend POA&M closure\n\nBasic Qualifications\n\nBachelor's degree in computer science, Information Technology, or a related field.\n4 years of experience in conducting security testing in accordance with NIST SP 800-53A.\n4 years of experience creating POA&Ms in the CSAM tool.\n2 years of experience with NIST SP 800-53-A and security control assessment methodologies.\n2 years of experience with security program management, including policy and procedure development, Continuous Monitoring, and risk management.\nUS Citizen with the ablity to pass a comprehensive background check.\n2 years of previous client-engagement experience.\n\nPreferred Qualifications\nStrong analytical skills and ability to quantify and analyze test findings.\nKnowledge of security tools and techniques, including scanning tools.\nUnderstanding of cloud environments and related security implications.\nExcellent communication (verbal and written) and collaboration skills, with the ability to work effectively with security staff and Agency ISSOs.\nImpeccable work ethic, the ability to make sound decisions, and a commitment to integrity and accountability.\nExcellent organizational skills and attention to detail.\nStrong analytical, critical thinking, and problem-solving skills.\nAbility to function well in a high-paced and at times stressful environment.\nAbility to prioritize tasks.\nProficient with Microsoft Office Suite; specifically, Excel, Word, and Outlook a must.\nOne or more of the following certifications preferred: CISSP, CAP, CISM, Security+, CASP, CISA.\n\nEvolver Federal is an equal opportunity employer and welcomes all job seekers. It is the policy of Evolver Federal not to discriminate based on race, color, ancestry, religion, gender, age, national origin, gender identity or expression, sexual orientation, genetic factors, pregnancy, physical or mental disability, military/veteran status, or any other factor protected by law.\n\nActual salary will depend on factors such as skills, qualifications, experience, market and work location. Evolver Federal offers competitive benefits, including health, dental and vision insurance, 401(k), flexible spending account, and paid leave (including PTO and parental leave) in accordance with our applicable plans and policies.","company":"Evolver","rawCompany":"evolver","city":"Washington","state":"DC","isRemote":false,"isActive":false,"createdAt":"2026-04-14T10:31:26.479Z","occupations":[{"code":"15-1212.00","title":"Information Security Analysts","slug":"information-security-analysts"},{"code":"13-1199.07","title":"Security Management Specialists","slug":"security-management-specialists"},{"code":"15-1299.04","title":"Penetration Testers","slug":"penetration-testers"}],"industries":[{"code":"541690","title":"Other Scientific and Technical Consulting Services","slug":"other-scientific-and-technical-consulting-services"},{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541618","title":"Other Management Consulting Services","slug":"other-management-consulting-services"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Security Control Assessor","description":"Evolver is looking for a Security Control Assessor to join our team supporting our federal client in Washington, DC. This position requires on-site 5 days/week at our federal client's HQ located in Washington, DC.\n\nThe Security Control Assessor is responsible for providing independent security control testing to the client for 20 FIPS Moderate and Low systems. Duties include conducting security control assessments through interviews, examination, and/or testing for all applicable management, operational, and technical controls, including analyzing findings and results and validating test results/ reports. Duties also include developing Security Control Assessment Plans, Risk Assessment Reports, and ATO Memos, as well as developing and maintaining testing policies and related Standard Operating Procedures (SOPs). The Security Control Assessor is also responsible for documenting and presenting the results of the Security Test & Evaluation (ST&E) to government stakeholders including System Owners, ISSOs, the CISO and Authorizing Official. Responsibilities also include reviewing artifacts and providing recommendations on POA&M closures.\n\nResponsibilities\nConduct security testing in accordance with NIST SP 800-53-A.\nDevelop Security Controls Assessment Plans, including:\nInterviewing, examining, and/or testing management, operational, and technical controls.\nGathering evidence for tested controls.\nSummarizing testing results, highlighting high/moderate risk items and compliance percentages.\nDocumenting results within the Security Controls Assessment Plan.\nAnalyzing and summarizing scan results, utilizing scans provided by the cloud environment.\nAssist in updating the client's IT Security Program policies and procedures.\nProvide timely reminders to Agency ISSOs to support Continuous Monitoring efforts.\nAssist in launching the client's Configuration Management program, including compliance testing and guidance on implementing DISA's Security Technical Implementation Guides (STIGs).\nProduce Security Assessment Reports (SAR) using the Agency's Information Assurance tool.\nEvaluate the risk of SAR findings from security testing and summarize them into Plan of Action and Milestone (POA&M) tracking documentation.\nTrack the progress of the IT Risk Management program through POA&M updates and/or data submission to the Agency's Office of Risk Management.\nReview supporting artifacts, evaluate remediation of risk, and recommend POA&M closure\n\nBasic Qualifications\n\nBachelor's degree in computer science, Information Technology, or a related field.\n4 years of experience in conducting security testing in accordance with NIST SP 800-53A.\n4 years of experience creating POA&Ms in the CSAM tool.\n2 years of experience with NIST SP 800-53-A and security control assessment methodologies.\n2 years of experience with security program management, including policy and procedure development, Continuous Monitoring, and risk management.\nUS Citizen with the ablity to pass a comprehensive background check.\n2 years of previous client-engagement experience.\n\nPreferred Qualifications\nStrong analytical skills and ability to quantify and analyze test findings.\nKnowledge of security tools and techniques, including scanning tools.\nUnderstanding of cloud environments and related security implications.\nExcellent communication (verbal and written) and collaboration skills, with the ability to work effectively with security staff and Agency ISSOs.\nImpeccable work ethic, the ability to make sound decisions, and a commitment to integrity and accountability.\nExcellent organizational skills and attention to detail.\nStrong analytical, critical thinking, and problem-solving skills.\nAbility to function well in a high-paced and at times stressful environment.\nAbility to prioritize tasks.\nProficient with Microsoft Office Suite; specifically, Excel, Word, and Outlook a must.\nOne or more of the following certifications preferred: CISSP, CAP, CISM, Security+, CASP, CISA.\n\nEvolver Federal is an equal opportunity employer and welcomes all job seekers. It is the policy of Evolver Federal not to discriminate based on race, color, ancestry, religion, gender, age, national origin, gender identity or expression, sexual orientation, genetic factors, pregnancy, physical or mental disability, military/veteran status, or any other factor protected by law.\n\nActual salary will depend on factors such as skills, qualifications, experience, market and work location. Evolver Federal offers competitive benefits, including health, dental and vision insurance, 401(k), flexible spending account, and paid leave (including PTO and parental leave) in accordance with our applicable plans and policies.","datePosted":"2026-04-14T10:31:26.479Z","dateModified":"2026-04-14T10:31:26.479Z","hiringOrganization":{"@type":"Organization","name":"Evolver","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Washington","addressRegion":"DC","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"be5f33dea9733a4180c2c3a7"},"url":"https://jobsearcher.com/jobs/be5f33dea9733a4180c2c3a7"}}