We use cookies. Find out more about it here. By continuing to browse this site you are agreeing to our use of cookies.
#alert
Back to search results
New

Junior Security Control Assessor

ANALYGENCE
United States, D.C., Washington
Oct 01, 2026

Tharros supports the Department of Homeland Security (DHS) with cybersecurity services across its Intelligence Enterprise. In support of this mission, we have an immediate opportunity for a Junior Security Control Assessor.

In this role you will support assessment and authorization (A&A) of classified and unclassified information systems, executing security control test procedures under the direction of senior assessors. You will run vulnerability and configuration scans, document findings, and help assemble authorization packages. This position is on-site in a Government SCIF in Washington, DC.

Duties include but not limited to:


  • Execute security control test procedures against NIST, CNSSI, and IC standards.
  • Conduct vulnerability and configuration testing against DISA STIGs and CIS Benchmarks.
  • Document control weaknesses and deficiencies for Security Assessment Reports.
  • Review POA&M entries for accuracy and completeness.
  • Perform quality assurance reviews of SSPs, Security Assessment Plans, and POA&Ms.
  • Assist in preparing A&A packages in the GRC tool.
  • Support System Security Test Reports and portfolio status reporting.
  • BS degree in Information Technology, Cybersecurity, Information Systems, or Computer Science OR minimum of 4 years' experience in IT or cybersecurity.
  • Minimum of 1 year of experience in RMF security testing or assessment.
  • Active TS/SCI clearance and U.S. citizenship; willingness to undergo a DHS counterintelligence-scope polygraph.
  • Knowledge of the Risk Management Framework (RMF) and NIST SP 800-53A assessment procedures.
  • Knowledge of CNSSI 1253 security control baselines.
  • Knowledge of vulnerability scanning and configuration compliance concepts (e.g., STIGs, SCAP).
  • Skill in using at least one scanning tool (e.g., Nessus/ACAS, SCAP Compliance Checker, Nmap, STIG Viewer).
  • Ability to document findings clearly and accurately.
  • Proficient in Microsoft Office Suite to include Teams or similar workplace chat and videoconferencing tools.
  • Excellent written and oral communications skills.

Desired


  • CompTIA Security+ or CySA+ certification.
  • Experience with RSA Archer or a similar GRC tool.

Applied = 0

(web-9db6c7984-5xhmq)