Logo for Cherokee Federal

Security Controls Assessor - Senior

Role overview

Qualifications

  • Bachelor's degree in Cybersecurity or a related IT field
  • Certified Information Systems Auditor (CISA), Advanced in AI Audit (AAIA), or an equivalent certification
  • Twelve years of related work experience
  • Prior experience supporting U.S. Navy or Coast Guard maritime cybersecurity assessments

Responsibilities

  • Assess MARAD systems in Initial Authorization, Reauthorization, or Continuous Monitoring Assessment
  • Conduct independent assessments of MARAD information systems following the System Authorization process
  • Review existing information-system core documentation to support the development of security assessment plans
  • Develop Security Assessment Plans and Security Assessment Reports compliant with NIST standards

Key facts

  • Remote from: United States
  • Full time
  • Senior (5-10 years)
  • English

Hard skills

Other skills

  • Collaboration
  • Problem Solving
  • Communication
  • Time Management

About the company

Cherokee Federal logo

Cherokee Federal

Government Administration

Cherokee Federal – a division of Cherokee Nation Businesses – is a team of tribally owned federal contracting companies focused on building solutions, solving complex challenges, and serving the nation’s mission around the globe for more than 60 federal clients. With our heritage of ingenuity coupled with modern business practices, we serve as a trusted partner that can innovate and implement solutions. Our team of companies, with more than 9,000+ employees, manages nearly 2,000 projects of all sizes across the construction, engineering and manufacturing, and mission solutions portfolios — ranging from advanced data analytics and telehealth to cybersecurity, cloud and logistics. Cherokee Federal’s team of small disadvantaged business entities, many of which are 8(a) and/or HUBZone certified, offer attractive contract vehicles with unique advantages – resulting in a streamlined, responsive contract management process.

Company details

Company typeXLarge
IndustryGovernment Administration
Company size5001 - 10000

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

Security Controls Assessor – Senior

This position requires an active Public Trust clearance or the ability to obtain a Public Trust clearance to be considered.

The Senior Security Controls Assessor provides independent assessments of MARAD information systems in support of system authorization, reauthorization, and continuous monitoring activities. This role evaluates management, operational, and technical security controls in accordance with NIST Risk Management Framework (RMF) requirements, supports Authority to Operate (ATO) decisions, develops assessment documentation and reports, and collaborates with MARAD, DOT, and cybersecurity stakeholders to ensure compliance, risk visibility, and mission assurance.

Compensation & Benefits

Pay commensurate with experience. $150,000 - $155,000

Full-time benefits include Medical, Dental, Vision, 401(k), and other possible benefits as provided. Benefits are subject to change with or without notice.

Security Controls Assessor – Senior Responsibilities Include:

  • Assess MARAD systems in one of three states: Initial Authorization, Reauthorization, or Continuous Monitoring Assessment (CMA), also known as ongoing authorization. The Independent Assessor must be prepared to support each of these three authorization states.
  • Provide annual assessment support to the NSMV and MARAD CIO programs. NSMV assessment support will involve conducting on-site evaluations at the Philadelphia shipyard and other locations.
  • Conduct independent assessments of specified MARAD information systems following the System Authorization process defined in the current DOT Security Authorization and Continuous Monitoring Performance Guide and associated templates.
  • Review existing information-system core documentation, including privacy requirements and data, to support the development of security assessment plans and schedules supporting Authority to Operate (ATO) dates.
  • Review and establish annual assessment schedules in support of required deliverables and artifacts.
  • Identify noncompliance with security requirements and recommend possible mitigation strategies.
  • Validate the security requirements of information systems.
  • Verify that systems meet applicable security requirements.
  • Conduct independent and comprehensive assessments of management, operational, and technical security controls and control enhancements to determine their overall effectiveness.
  • Execute and analyze network and system assessments to validate appropriate security-control implementation.
  • Develop Security Assessment Plans and Security Assessment Reports compliant with the latest revisions of NIST Special Publication 800-53A, Assessing Security and Privacy Controls in Information Systems and Organizations, and NIST SP 800-37, Risk Management Framework for Information Systems and Organizations.
  • Develop Security Assessment Plans (SAPs) that clearly define the assessment scope, exclusions when necessary, controls being assessed, assessment methods, sampling methods, “determine if” statements, proposed schedules, assessment staff, targeted system endpoints and components, software inventories, processes, and the status of system-specific, hybrid, and inherited controls.
  • Follow the approved SAP when assessing security controls for targeted information systems.
  • Use approved techniques to collect and catalog supporting evidence, including documents, screenshots, scanning reports, and interview notes, to substantiate security-control implementation findings.
  • Develop Security Assessment Reports (SARs) according to the scope and schedule defined in the SAP. The SAR must document assessment findings and include evidence supporting the implementation status of each assessed control.
  • Develop and update qualitative Risk Assessment Reports (RARs) compliant with NIST SP 800-30, Guide for Conducting Risk Assessments.
  • Develop recommendation reports supporting Plan of Action and Milestones (POA&M) development. Reports must document findings and recommend actions and levels of effort for remediation.
  • Develop executive-summary documents and presentations that provide an overview of assessment activities, findings, risks, and mitigation recommendations.
  • Enter assessment data into the Cyber Security Assessment and Management (CSAM) database, DOT’s system of record for ATOs.
  • Provide presentations, reports, evaluations, reviews, meeting minutes, and working papers supporting all assigned tasks, as requested by the Contracting Officer’s Representative (COR).
  • Apply MARAD and DOT Assessment and Authorization guidance and policies to achieve program objectives and improve the overall quality of ATO packages.
  • Collaborate actively with the designated Information Systems Security Manager (ISSM).
  • Perform other job-related duties as assigned.

Security Controls Assessor – Senior Experience, Education, Skills, and Abilities Requested:

  • Bachelor’s degree in Cybersecurity or a related IT field may be substituted for four years of experience.
  • Bachelor’s degree in an IT-related field.
  • Certified Information Systems Auditor (CISA), Advanced in AI Audit (AAIA), or an equivalent certification.
  • Twelve years of related work experience.
  • Prior experience supporting U.S. Navy or Coast Guard maritime cybersecurity assessments.
  • Must possess or be able to obtain a Public Trust clearance.
  • Prior Department of Transportation experience is a plus.
  • Must pass Cherokee Federal’s pre-employment qualifications.

Company Information

Criterion is part of Cherokee Federal, the division of tribally owned federal contracting companies owned by Cherokee Nation Businesses. As a trusted partner for more than 60 federal clients, Cherokee Federal LLCs are focused on building a brighter future, solving complex challenges, and serving the government’s mission with compassion and heart. To learn more about Criterion, visit cherokee-federal.com.

#CherokeeFederal #LI-SM2 #LI-REMOTE #AppC

Cherokee Federal is a military-friendly employer. Veterans and active-duty military members transitioning to civilian status are encouraged to apply.

Similar Searchable Job Titles

  • Senior Information Security Assessor
  • RMF Security Controls Assessor
  • Senior Cybersecurity Assessor
  • Information Assurance Assessor
  • ATO/RMF Lead Assessor

Keywords

  • Continuous Monitoring Assessment (CMA)
  • Risk Assessment
  • Security Assessment Plan (SAP)
  • Security Assessment Report (SAR)
  • Federal Cybersecurity

Legal Disclaimer

Cherokee Federal is an equal opportunity employer. Please visit cherokee-federal.com/careers for information regarding our Affirmative Action and Equal Opportunity Employer Statement and accommodation requests.

Many of our job openings require access to government buildings or military installations. Candidates must pass Cherokee Federal’s pre-employment qualifications.

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Related jobs

Other jobs at Cherokee Federal

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.