Security Control Assessor
REMT - Remote Worker Location
Secure our Nation, Ignite your Future
Become an integral part of a diverse team while working at an industry leading organization, where our employees come first. At ManTech, you’ll help protect our national security while working on innovative projects that offer opportunities for advancement.
ManTech is seeking a motivated, career and customer-oriented Security Control Assessor to join our team. This is a remote position with the potential of some travel (up to 25% annually) to work sites in various cities in the continental United States. As a Security Control Assessor, you will be performing NIST-based assessments of security controls that protect federal government and banking organizations.
Responsibilities include but are not limited to:
Lead and perform NIST based security controls assessments including management, operational, and technical controls
Develop security assessment plans, security assessment reports, and deliver executive-level briefings
Qualify the risk associated with identified vulnerabilities
Understand mitigating/compensating controls and extenuating circumstances that drive risk.
Provide viable recommendations to remediate identified vulnerabilities
Proficiency with MS Office suite including Word, Excel, PowerPoint, Visio
Oversee and quality control the work of other team members on assessments
Capable of operating independently and delivering quality products in a timely manner
Minimum Qualifications:
5+ years of security controls assessment experience
Extensive knowledge of the NIST SP 800-37 Risk Management Framework (RMF), NIST SP 800-53 Security and Privacy Controls, and NIST SP 800-30 Guide for Conducting Risk Assessments
Possess a basic understanding of networking concepts, active directory, group policy objects, various operating systems, web applications, networking devices (routers, switches, firewalls, IDS and IPS), storage, databases, virtualization and cloud technologies
Proficient public speaker capable of confidently presenting identified vulnerabilities to technical and non-technical audiences
Ability to work independently, manage multiple assessments at various stages in the assessment life cycle, and deliver quality products in a timely manner
Expertise in identifying security gaps resulting in vulnerabilities
Able to provide viable recommendations to remediate identified vulnerabilities
Strong written communication skills with experience creating security assessment plans, security assessment reports, and executive-level briefings
Proficient with Microsoft Office
Preferred Qualifications:
Bachelor’s degree in IT or related field
Subject Matter Expert (SME) in interpreting NIST SP 800-53, 800-30, 800-37, 800-53A, 800-60, 800-115, 800-137, FIPS199 (and related OMB and NIST guidance)
Ability to analyze mitigating/compensating controls and extenuating issues to determine risk
Familiar with the OWASP Top 10 web application vulnerabilities and able to clearly explain associated risks to technical and non-technical audiences
Familiarity with testing tools such as Burp, Nessus, Nmap, Nipper and an understanding of how various vulnerabilities can be exploited
A technical understanding of networking concepts, active directory, group policy objects, various operating systems, web applications, networking devices (routers, switches, firewalls, IDS and IPS), storage, databases, virtualization and cloud technologies
Possess at least one industry recognized security certification, such as: CISSP, CEH, CISA, CISM, CASP, GSNA, CGRC (CAP), Security+
Clearance Requirements:
Must be a U.S. Citizenship
Ability to obtain and maintain a Public Trust clearance/ Keypoint High clearance
Physical Requirements:
Sedentary work that primarily involves sitting/standing/walking/talking and must be able to remain in a stationary position 50%.
Moving about to accomplish tasks or moving from one work site to another.
The person in this position needs to occasionally move about inside the office to access file cabinets, office machinery, etc.
Requires frequently communicates with co-workers, management, and customers.
Communicating with others to exchange information.
Working with computers.
Must be able to lift and move hardware weighing up to 50 pounds.
For all positions requiring access to technology/software source code that is subject to export control laws, employment with the company is contingent on either verifying U.S.-person status or obtaining any necessary license. The applicant will be required to answer certain questions for export control purposes, and that information will be reviewed by compliance personnel to ensure compliance with federal law. ManTech may choose not to apply for a license for such individuals whose access to export-controlled technology or software source code may require authorization and may decline to proceed with an applicant on that basis alone.
ManTech International Corporation, as well as its subsidiaries proactively fulfills its role as an equal opportunity employer. We do not discriminate against any employee or applicant for employment because of race, color, sex, religion, age, sexual orientation, gender identity and expression, national origin, marital status, physical or mental disability, status as a Disabled Veteran, Recently Separated Veteran, Active Duty Wartime or Campaign Badge Veteran, Armed Forces Services Medal, or any other characteristic protected by law.
If you require a reasonable accommodation to apply for a position with ManTech through its online applicant system, please contact ManTech's Corporate EEO Department at (703) 218-6000. ManTech is an affirmative action/equal opportunity employer - minorities, females, disabled and protected veterans are urged to apply. ManTech's utilization of any external recruitment or job placement agency is predicated upon its full compliance with our equal opportunity/affirmative action policies. ManTech does not accept resumes from unsolicited recruiting firms. We pay no fees for unsolicited services.
If you are a qualified individual with a disability or a disabled veteran, you have the right to request an accommodation if you are unable or limited in your ability to use or access http://www.mantech.com/careers/Pages/careers.aspx as a result of your disability. To request an accommodation please click careers@mantech.com and provide your name and contact information.
ApplyJob Profile
Countries Benefits/PerksHealth insurance Holiday Pay Learning and Development Learning and development opportunities Life Insurance Other optional benefit elections Paid Time Off Retirement and Savings Short Term and Long Term Disability Wellness programs
SkillsActive Directory Burp Cloud Cloud Technologies Communication Compliance Databases Development Excel Firewalls Group Policy Objects IDS IPS MS Office Nessus Networking Networking concepts Networking Devices Nipper NIST SP 800-30 NIST SP 800-37 NIST SP 800-53 Nmap Operating Systems OWASP Top 10 PowerPoint Risk Management Routers Software Storage Switches Virtualization Visio Web applications Word
Tasks- Communication
- Deliver executive-level briefings
- Development
- Develop security assessment plans and reports
- Identify security gaps
- Manage multiple assessments
- Oversee and quality control team work
- Perform NIST-based security controls assessments
- Present vulnerabilities to technical and non-technical audiences
- Provide recommendations for remediation
- Qualify risks associated with vulnerabilities
- Risk Management
5+ years
EducationBachelor's Degree in IT or related field Education IT Related Field
CertificationsCASP CEH CGRC (CAP) CISA CISM CISSP GSNA Public Trust Security+
RestrictionsMust be a U.S. Citizen