Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
VMD Corp

Security Control Assessor

VMD Corp

. Ensure the cybersecurity of a program, organization, system, or enclave .

Posted 9/29/2026full-timeArlington • Virginia • United StatesMid-LevelSeniorWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in cybersecurity governance frameworks, including RMF and NIST standards, while effectively managing security control assessments and risk management processes. Proficient in developing security documentation and collaborating with stakeholders to ensure compliance and system security.

Highest-signal resume keywords
Cybersecurity Control AssessmentsRisk Management Framework (RMF)NIST SP 800-53 ComplianceSecurity Documentation DevelopmentCybersecurity Certifications (CISSP, CISM, CISA)

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Security Control AssessmentsRisk AssessmentsSecurity Plans DevelopmentSecurity CategorizationMonitoring StrategiesVulnerability RemediationAuthentication and AuthorizationAccess ControlCybersecurity PrinciplesThreat and Vulnerability Management
Soft Skills
CollaborationAdvisory SkillsStakeholder EngagementCommunication
Tools & Technologies
Cybersecurity Defense ToolsSecurity Assessment Reports (SARs)Plan of Action and Milestones (POA&Ms)System Security Plans (SSPs)
Certifications & Qualifications
CISSPCISMCISACAPGIACSecurity+CASP+
Industry Keywords
Federal Cybersecurity GovernanceFedRAMPNIST SP 800-171Public Trust ClearanceDC Metro Area Residency

Tech Stack

Tools & technologies
Cyber Security

About the role

Key responsibilities & impact
  • Ensure the cybersecurity of a program, organization, system, or enclave
  • Maintain the security and privacy posture of an organizational system
  • Collaborate closely with FDIC system owners
  • Advise on technical and non-technical matters involving system security and privacy controls
  • Identify security and privacy requirements and system characteristics
  • Contribute to determining system boundaries
  • Collaborate with the System Owner to categorize systems and document security categorization results
  • Identify stakeholders with security or privacy interests in system development, implementation, operation, or sustainment
  • Conduct and continually update risk assessments
  • Select security and privacy controls and document planned implementations in security/privacy plans
  • Develop monitoring strategies for security and privacy control effectiveness
  • Develop, review, and approve security and privacy control assessment plans
  • Document changes to control implementations and establish system configuration baselines
  • Respond to system risk posture based on monitoring, risk assessment, and POA&M results
  • Update security plans, security assessment reports, and POA&Ms through continuous monitoring
  • Review system security and privacy status on an ongoing basis
  • Report system security status to an authorizing official
  • Ensure remediation plans and POA&Ms address vulnerabilities and that improvement actions are evaluated, validated, and implemented

Requirements

What you’ll need
  • 4–6 years of relevant cybersecurity experience, specifically performing security control assessments in an SCA role, including supporting federal clients
  • Bachelor's degree in a cyber-related field; direct experience or certifications may substitute for the academic credentials
  • Recognized cybersecurity certifications desired, such as CISSP, CISM, CISA, CAP, GIAC, Security+, or CASP+
  • U.S. citizenship
  • Public Trust clearance
  • Must reside within the DC Metro area
  • Knowledge of federal cybersecurity governance frameworks, including RMF, FedRAMP, NIST SP 800-53, and NIST SP 800-171
  • Experience developing and reviewing SSPs, SARs, and POA&Ms
  • Knowledge of cybersecurity principles, threats, vulnerabilities, and risk management
  • Experience applying RMF, NIST SP 800-53, and FedRAMP for enterprise-wide security compliance
  • Experience with cybersecurity defense tools and systems
  • Applied knowledge of authentication, authorization, access control, architecture, and infrastructure
  • Experience with business, operations, and risk management processes across federal and commercial environments
  • Experience developing security documentation, including SSPs, SARs, and POA&Ms

Benefits

Comp & perks
  • Equal employment opportunities in accordance with applicable Federal, state and local laws
  • Drug-free workplace