Security Control Assessor I

General Dynamics

Confirmed live 2 days ago High trust

Quick summary

Work type
On-site
Location
Washington, DCSuitland, MDArlington, VA
Salary
$96,569–$130,651 / yr
Posted
9 days ago
Freshness
Confirmed live 2 days ago

Market check

Salary context

Below market

How this pay compares to similar roles

Similar $165k
This role $114k
$85k most similar roles pay here $206k

This role pays less than 88% of similar roles. Most pay $134,725–$194,640 — the shaded band above. At the midpoint, this role pays about $114k versus about $165k for comparable roles.

Based on 239 similar postings.

Employer

About General Dynamics

General Dynamics is a global aerospace and defense company offering a broad portfolio of products and services in business aviation, ship construction, land combat vehicles, and information technology. It serves customers in the U.S. government, allied governments, and a diverse array of commercial markets.

General Dynamics currently has 1123 open roles on FindRole.

Listed pay typically runs $124,093–$150,385 across 984 roles with salary data.

Most-posted roles

View all roles at General Dynamics

At a glance

TL;DR · Security Control Assessor I

The Security Control Assessor (SCA) I joins the Cyber and IT Risk Management team to conduct comprehensive assessments of management, operational, and technical security controls for information systems. This role involves evaluating the effectiveness of controls, identifying vulnerabilities, and recommending corrective actions within Collateral, Sensitive Compartmented Information (SCI), and Special Access Program (SAP) environments. The individual will perform assessments based on the Risk Management Framework (RMF) methodology in accordance with Joint Special Access Program Implementation Guide (JSIG) standards. Key responsibilities include evaluating authorization packages, preparing Security Assessment Reports, initiating Plans of Action and Milestones, and advising stakeholders on confidentiality, integrity, and availability impacts. Required expertise includes Information Security Management, Risk Management, and Standards. The role requires proficiency in the system development life cycle (SDLC) to ensure security compliance across various hardware and software components.

What you'll do

  • Assess management, operational, and technical security controls to determine overall effectiveness for information systems.
  • Perform system assessments based on Risk Management Framework (RMF) methodology and JSIG guidelines.
  • Identify vulnerabilities and recommend corrective actions or additional safeguards to mitigate risks.
  • Prepare Security Assessment Reports (SAR) and initiate Plans of Action and Milestones (POA&M) for identified weaknesses.
  • Evaluate authorization packages and provide written recommendations for security authorizations to the government.
  • Advise stakeholders on impact levels for confidentiality, integrity, and availability of system information.
  • Review hardware and software changes to determine their impact on authorization boundaries.
  • Evaluate the effectiveness and implementation of Continuous Monitoring Plans for protected systems.

What we're looking for

  • Must be a United States citizen.
  • Must possess an active Top Secret/SCI clearance and be willing to submit to a CI polygraph.
  • Must have 9 years of related experience, or 5 years with a Bachelor's degree, or 5 years with an Associate's degree plus 2 years of experience.
  • Must have experience in SAP, SCI, or Collateral Information Systems security and relevant regulation implementation.
  • Prior performance in the roles of ISSO and ISSM is required.
  • Must possess IAT Level 3 (e.g., CISSP, CASP+ CE, CCNP Security, CISA) or IAM Level 1 certification within 6 months of hire.
  • Must have expertise in Information Security Management, Risk Management, Standards, and System Security.
  • US Citizenship.

More like this

Similar roles

Security Control Assessor I

General Dynamics

Colorado Springs, CO 16 days ago $129,813$158,815
Risk Management Framework (RMF) JSIG SDLC Information Security Cybersecurity Continuous Monitoring Security Assessment Report (SAR) Plan of Action and Milestones (POA&M) CISSP CASP+ CCNP Security CISA
5+ yrs exp

Security Control Assessor II

General Dynamics

Arlington, VA 30 days ago $142,792$181,010
Risk Management Framework (RMF) JSIG Information Security SDLC Continuous Monitoring Cybersecurity Security Assessment Report (SAR) Plan of Action and Milestones (POA&M) CISSP CISA CASP+ CCNP Security SAP SCI
7+ yrs exp

Security Control Assessor II

General Dynamics

Ogden, UT 57 days ago $129,965$175,835
Risk Management Framework (RMF) JSIG Information Assurance Cybersecurity SDLC Continuous Monitoring Security Assessment Report (SAR) Plan of Action and Milestones (POA&M) Information Security Management System Development Life Cycle (SDLC)
7+ yrs exp

Security Control Assessor II

General Dynamics

Bedford, MA +12 5 days ago $142,792$181,010
Risk Management Framework (RMF) JSIG Information Assurance Cybersecurity SDLC Continuous Monitoring Security Assessment Report (SAR) Plan of Action and Milestones (POA&M) Information Security Management System Development Life Cycle
7+ yrs exp

Security Control Assessor II

General Dynamics

West Lake Hills, TX 65 days ago $96,569$130,651
Risk Management Framework (RMF) JSIG Cross-Domain Solutions (CDS) SDLC Information Security Risk Management Continuous Monitoring Microsoft Office CISSP CASP+ CCNP Security CISA Cybersecurity Security Assessment Report (SAR) Plan of Action and Milestones (POA&M)
3+ yrs exp

Security Controls Assessor

Booz Allen Hamilton

San Diego, CA 32 days ago $99,000$225,000
Risk Management Framework Cybersecurity Information Security Cross Domain Solutions Virtualization Artificial Intelligence Machine Learning Operational Technology Information Technology Security Controls Assessment TS/SCI Clearance
10+ yrs exp