{"schemaVersion":"jobsearcher.job.v1","id":"f4d9bf708e4e314322839733","url":"https://jobsearcher.com/jobs/f4d9bf708e4e314322839733","canonicalUrl":"https://jobsearcher.com/jobs/f4d9bf708e4e314322839733","title":"Security Controls Assessor","description":"ECS is seeking a Security Controls Assessor to work in our Washington, DC (hybrid) office. Please Note: This position is contingent upon contract award.\n\nECS seeks a Security Controls Assessor to support a full range of cybersecurity services on a long-term, full-time contract with a U.S. Government civilian agency. This position requires mostly CONUS and occasional OCONUS assessments and is available immediately for a qualified candidate with an active security clearance.\n\nKey Responsibilities\n\nReview and update information security policies, standards, and procedures in accordance with federal and departmental regulations\nPerform independent security and privacy control assessments on behalf of the client CSO in support of Security Assessment & Authorization (SA&A)\nAssess existing and new FISMA systems and subsystems, and communicate findings and potential impacts of identified control weaknesses\nReview and analyze A&A packages—including System Security Plans (SSP), Risk Assessments, Information System Contingency Plans (ISCP), Backup SOPs, Incident Response Plans (IRP), Configuration Management Plans (CMP), hardware/software inventories, network diagrams, data flows, system change requests, vulnerability scan reports, test reports, and POA&Ms—for completeness, accuracy, and effective control implementation\nDevelop and maintain test cases for control-level security testing across system components (applications, servers, databases, operating systems, network devices, end-user devices, etc.)\nDevelop and execute security and privacy assessment plans in accordance with NIST SP 800-53A, supporting RMF Steps 4–6\nDocument findings and recommendations that are clear, system-specific, and actionable\nAnalyze security tool outputs to distinguish residual risk from false positives prior to finalizing findings\nCONUS and OCONUS travel to conduct system assessments\nOther duties as assigned\n\nSalary Range: $150,000-$168,000\n\nGeneral Description of Benefits\n\nRequirements:\nActive Secret clearance required with eligibility to get Top Secret clearance\nBachelor's degree in Computer Science, MIS/IT, Engineering, Information Security/Assurance, or a related field\nMinimum five (5) years of information security experience\nMinimum three (3) years of experience supporting security assessment teams, including planning assessments and serving as a senior team member\nTwo (2) years of experience using GRC tools\nDemonstrated experience conducting full-scope technical security control testing across component types, including development of security and privacy assessment plans\nWorking knowledge of RMF Steps 1-6\nStrong understanding of NIST SP 800-53 controls, the NIST Cybersecurity Framework, and applicable information security/privacy laws and regulations\nAbility to analyze information system configurations and technical specifications against NIST SP 800-53 and related overlays\nExperience developing risk-based documentation\nExcellent written and verbal communication skills, with the ability to present control requirements and deficiencies clearly to both technical and non-technical audiences\n\nReq Benefits:\nBenefits - Everforth ECS","company":"Everforth Ecs","rawCompany":"everforth ecs","city":"Washington","state":"DC","isRemote":false,"isActive":false,"createdAt":"2026-08-22T15:56:45.718Z","occupations":[{"code":"15-1212.00","title":"Information Security Analysts","slug":"information-security-analysts"},{"code":"13-1199.07","title":"Security Management Specialists","slug":"security-management-specialists"},{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"}],"industries":[{"code":"541690","title":"Other Scientific and Technical Consulting Services","slug":"other-scientific-and-technical-consulting-services"},{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541618","title":"Other Management Consulting Services","slug":"other-management-consulting-services"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Security Controls Assessor","description":"ECS is seeking a Security Controls Assessor to work in our Washington, DC (hybrid) office. Please Note: This position is contingent upon contract award.\n\nECS seeks a Security Controls Assessor to support a full range of cybersecurity services on a long-term, full-time contract with a U.S. Government civilian agency. This position requires mostly CONUS and occasional OCONUS assessments and is available immediately for a qualified candidate with an active security clearance.\n\nKey Responsibilities\n\nReview and update information security policies, standards, and procedures in accordance with federal and departmental regulations\nPerform independent security and privacy control assessments on behalf of the client CSO in support of Security Assessment & Authorization (SA&A)\nAssess existing and new FISMA systems and subsystems, and communicate findings and potential impacts of identified control weaknesses\nReview and analyze A&A packages—including System Security Plans (SSP), Risk Assessments, Information System Contingency Plans (ISCP), Backup SOPs, Incident Response Plans (IRP), Configuration Management Plans (CMP), hardware/software inventories, network diagrams, data flows, system change requests, vulnerability scan reports, test reports, and POA&Ms—for completeness, accuracy, and effective control implementation\nDevelop and maintain test cases for control-level security testing across system components (applications, servers, databases, operating systems, network devices, end-user devices, etc.)\nDevelop and execute security and privacy assessment plans in accordance with NIST SP 800-53A, supporting RMF Steps 4–6\nDocument findings and recommendations that are clear, system-specific, and actionable\nAnalyze security tool outputs to distinguish residual risk from false positives prior to finalizing findings\nCONUS and OCONUS travel to conduct system assessments\nOther duties as assigned\n\nSalary Range: $150,000-$168,000\n\nGeneral Description of Benefits\n\nRequirements:\nActive Secret clearance required with eligibility to get Top Secret clearance\nBachelor's degree in Computer Science, MIS/IT, Engineering, Information Security/Assurance, or a related field\nMinimum five (5) years of information security experience\nMinimum three (3) years of experience supporting security assessment teams, including planning assessments and serving as a senior team member\nTwo (2) years of experience using GRC tools\nDemonstrated experience conducting full-scope technical security control testing across component types, including development of security and privacy assessment plans\nWorking knowledge of RMF Steps 1-6\nStrong understanding of NIST SP 800-53 controls, the NIST Cybersecurity Framework, and applicable information security/privacy laws and regulations\nAbility to analyze information system configurations and technical specifications against NIST SP 800-53 and related overlays\nExperience developing risk-based documentation\nExcellent written and verbal communication skills, with the ability to present control requirements and deficiencies clearly to both technical and non-technical audiences\n\nReq Benefits:\nBenefits - Everforth ECS","datePosted":"2026-08-22T15:56:45.718Z","dateModified":"2026-08-22T15:56:45.718Z","hiringOrganization":{"@type":"Organization","name":"Everforth Ecs","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Washington","addressRegion":"DC","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"f4d9bf708e4e314322839733"},"url":"https://jobsearcher.com/jobs/f4d9bf708e4e314322839733"}}