Location: Oak Ridge, TN
Job Title: CYB - Security Control Assessor
Career Level From: Associate
Career Level To: Specialist
Job Specialty: Cyber Security
What You'll Do
The Security Control Assessor (SCA) is responsible for conducting comprehensive security control assessments and evaluations of Federal information systems in support of the Assessment and Authorization (A&A) process. This person performs detailed technical and administrative reviews of security controls, documents findings, and provides evidence-based recommendations for control implementation and remediation. The SCA works collaboratively with Information System Security Officers (ISSOs), System Owners, and cybersecurity teams to evaluate compliance with NIST standards and organizational security requirements. This role requires expertise in the NIST Risk Management Framework (RMF), particularly in the Assessment phase, and the ability to independently assess control effectiveness against established baselines. Successful candidates will demonstrate strong analytical skills, attention to detail, and the ability to communicate complex security findings to both technical and non-technical stakeholders.
Position Duties And Responsibilities
- Conducts security control assessments in accordance with NIST SP 800-53A assessment procedures and organizational assessment methodologies
- Evaluates the implementation and effectiveness of security controls aligned with approved baselines and NIST standards
- Develops and documents security assessment reports, including control findings, evidence summaries, and risk determinations
- Performs gap analysis to identify control deficiencies and non-compliance with security requirements
- Collaborates with system teams to gather assessment evidence and validate control implementation
- Supports the development and refinement of System Security Plans (SSPs) and assessment documentation
- Reviews and evaluates Plans of Action and Milestones (POA&Ms) for completeness and appropriateness of remediation strategies
- Assesses the security impact of proposed system changes and evaluates control modifications
- Participates in security assessments, audits, and Authorizing Official reviews
- Maintains current knowledge of NIST standards, assessment methodologies, and emerging security assessment practices
- Provides technical guidance and recommendations for control implementation and remediation
- Prepares assessment packages and supporting documentation for review and authorization
- Serves as a subject matter expert on security control assessment practices and RMF processes
What You Can Expect
- Meaningful work and unique opportunities to support missions vital to national and global security
- Top-notch, dedicated colleagues
- Generous pay and benefits with a stable organization
- Career advancement and professional development programs
- Work-life balance fostered through flexible work options and wellness initiatives
Minimum Job Requirements
- Bachelor's degree in engineering, computer science, mathematics, information technology, or related discipline
- Eight or more years of relevant education, training, and/or progressive experience may be considered to satisfy educational and years-of-experience requirements for this posting
Preferred Job Requirements
- Minimum of 3 years of direct experience conducting security control assessments or security evaluations
- Demonstrated expertise in NIST SP 800-53/53A security control assessment procedures
- Knowledge of the NIST Risk Management Framework (RMF), particularly the Assessment phase
- Experience conducting security assessments in accordance with NIST assessment methodologies
- Knowledge of computer networking concepts, protocols, and network security methodologies
- Knowledge of cybersecurity and privacy principles
- Knowledge of cybersecurity threats, vulnerabilities, and their security control implications
- Knowledge of information technology (IT) security principles and methods (e.g., firewalls, demilitarized zones, encryption, access controls)
- Knowledge of authentication, authorization, and access control methods
- Knowledge of application security risks and secure development practices
- Knowledge of database systems and database security
- Knowledge of Industrial Control Systems (NIST SP 800-82)
- Knowledge of Supply Chain Risk Management Practices (NIST SP 800-161)
- Knowledge of Personally Identifiable Information (PII) data security standards
- Knowledge of laws, regulations, policies, and ethics as they relate to cybersecurity and privacy
- Ability to present technical and administrative information clearly and effectively through written assessments, oral presentations, and visual documentation
- Experience with Assessment and Authorization (A&A) processes in the DOE Community
- Experience with FedRAMP and Cloud compliance assessments
- Experience conducting 171 vendor Controlled Unclassified Information (CUI) assessments
- Knowledge of emerging technologies and their potential security implications
- Strong analytical and critical thinking skills with attention to detail
- Excellent written and verbal communication skills
- Security+, CEH, CISSP, or CISM Certification
- NIST RMF or security assessment-focused certifications
Why Y-12?
You get #morethanajob. We encourage employees to achieve a healthy personal balance among home, work and the community. One of the ways we embrace work-life balance is by offering flexible work arrangements that provide alternatives to the traditional workweek, while still meeting business needs. Top talent and personal commitment mean more to our success than any other factors, so we reward our people with the kinds of benefits that make a positive difference in the quality of their lives. Benefits such as: medical plan, prescription drug plan, vision plan, dental plan, employer matched 401(k) savings plan, disability coverage, education reimbursement and many more. Want to stay healthy and fit but hate the cost of a gym membership? Take advantage of one of our onsite workout facilities and eat healthy in our onsite cafeterias. Much more than a workplace, at Y-12, you can build a career that lasts a lifetime.
Notes
The minimum education and experience for the lowest career level in the job posting range are listed under Minimum Job Requirements. Successful candidates hired into a higher career level than the minimum in the range must meet the requirements listed in the job leveling charts for the career level into which they are being hired.
If a range of Career Levels is posted, i.e., Senior Associate to Senior Specialist, internal applicants already in one of the Career Levels would come across at their current Career Level. Internal applicants currently in a lower level Career Level would move to the lowest posted Career Level.
Requires a Q clearance; however all qualified candidates will be considered regardless of their current clearance status. The ability to obtain and maintain a Department of Energy Q clearance is required.
This position may require entry into the Material Access Areas (MAA) and participation in the Human Reliability Program (10 C.F.R. Part 712), which requires successful competition of a DOE counterintelligence evaluation and may include a counterintelligence-scope polygraph examination.
This position may be categorized as a “designated position” identified by 10 C.F.R. Part 709, requiring successful completion of a DOE counterintelligence evaluation that may include a counterintelligence-scope polygraph examination.
CNS is a drug-free workplace. Candidates accepting a job offer will be required to pass a pre-placement physical, drug screening and background investigation. As an employee, you may be required to receive and maintain a security clearance from the United States Department of Energy in order to meet eligibility requirements for access to sensitive information or matter. U.S. citizenship is a requirement for security clearance applicants. All employees are subject to being randomly selected for drug testing without advance notification.
CNS is an equal opportunity employer. All qualified applicants will receive consideration for employment based on merit and without regard to race, color, religion, sex, sexual orientation, national origin, protected veteran status or disability.