Home › Companies › Careers Gotyto Icims Com › Junior Security Controls Assessor
Junior Security Controls Assessor
Careers Gotyto Icims Com · Washington, DC, US · Hybrid · Active · iCIMS
Job facts
| Field | Value |
|---|---|
| Company | Careers Gotyto Icims Com |
| Title | Junior Security Controls Assessor |
| Normalized title | - |
| Department / team | Cybersecurity |
| Location | Washington, DC, United States |
| Work model | Hybrid / Hybrid |
| Employment type | Full Time |
| Salary | - |
| Status | active |
| ATS provider | iCIMS |
| Posted / first seen | 2026-06-01 / 2026-06-02 |
| Changed / last seen | 2026-06-04 / 2026-06-06 |
Related slices
| Page | What it contains | Open |
|---|---|---|
| Company jobs | Active postings from Careers Gotyto Icims Com. | Open |
| Company breakdowns | Role, location, ATS, and work model facets for this company. | Open |
| ATS provider jobs | Active postings observed through iCIMS. | Open |
| Provider filtered search | The same provider as a filtered job collection. | Open |
| City jobs | Active postings in Washington. | Open |
| Department jobs | Active postings in Cybersecurity. | Open |
| Work model jobs | Active Hybrid postings. | Open |
| Lifecycle events | Open, update, close, and reopen events for this posting. | Open |
| Original posting | Canonical source or apply URL captured from the ATS. | Open |
Linked records
| Company | Careers Gotyto Icims Com |
| Source | fc123edd-d671-42f2-b50b-70b70ebc7699 |
| ATS provider | iCIMS |
Description
Description
Tyto Athene is searching for a Junior Security Controls Assessor to support one of our federal customers in Washington, DC. The candidate will ensure that security requirements for information systems meet FISMA requirements.
Responsibilities:
Support RMF steps 4 –assess, 5 –authorize, step 6 –monitor controls: conducting system security assessments, supporting the system security authorization to operate process, and conducting annual assessments, respectively
Produce quality security assessment deliverables, ensuring the content of each deliverable is specific to the subject systems, complete, and accurate
Develop and execute a security and privacy assessment plan for each security assessment project
Create and maintain test cases for security assessment testing
Perform security testing at the control-requirement level for each unique component of each system (e.g., application, web application server, financial systems, database server/instance, operating systems, specialized appliances, network and infrastructure devices, and end-user devices (e.g., mobile phones, laptops, etc.)
Conduct technical content review and analysis of technical reports from security vulnerability scan, penetration test, and configuration compliance scan tools with respect to the subject system’s context and environment in order to analyze the findings accurately and completely
Analyze security tool reports and determine residual risk or false positives from technical reports and artifacts before assigning findings
Document and provide findings and recommendations that are concise, system-specific, and actionable
Perform and document client and system-specific risk analysis for each finding identified during each assessment in accordance with NIST SP 800-30, the client’s risk appetite, and the client’s security policies. The results of this risk analysis shall be documented in the Security Assessment Report (SAR) for each assessed FISMA system, and a summary of the assessment results and risk shall be provided in the respective Assessment/Authorization Briefing.
Qualifications
Required:
Bachelor's Degree or eight years of relevant equivalent experience
Minimum of 1 years of relevant experience in functional responsibility
Thorough understanding and knowledge of FISMA, NIST, and SPA&A process
Critical thinking
Strategy development
Balancing security requirements with mission needs
Ability to provide an assessment of the severity of weaknesses or deficiencies discovered in the information system and its environment of operation, and the ability to recommend corrective actions to address identified vulnerabilities
Knowledge of NIST SP 800-53, 53A Rev 5, and 800-137
Proficiency in writing technical analysis reports
Strong written and oral communication skills
Legislative branch experience a plus
Desired:
Certified Authorization Professional (CAP)
Certified in Risk and Information Systems Control (CRISC)
Experience with GRC Tools such as ServiceNow, CSAM, etc.
Clearance: US Citizen with Public Trust eligibility required
Location:
On-site contract with Hybrid allowance in Washington DC a minimum of two days a week (Tuesday and Thursday) but can be increased based on customer needs.
About Tyto Athene
Compensation:
Compensation is unique to each candidate and relative to the skills and experience they bring to the position. Salary for this role is between 75-95K. This does not guarantee a specific salary as compensation is based upon multiple factors such as education, experience, certifications, and other requirements, and may fall outside of the above-stated range.
Benefits:
Highlights of our benefits include Health/Dental/Vision, 401(k) match, Flexible Time Off, STD/LTD/Life Insurance, Referral Bonuses, professional development reimbursement, and maternity/paternity leave.
Tyto Athene is a trusted leader in IT services and solutions, delivering mission-focused digital transformation that drives measurable success. Our expertise spans four core technology domains—Network Modernization, Hybrid Cloud, Cybersecurity, and Enterprise IT—empowering our clients with cutting-edge solutions tailored to their evolving needs. With over 50 years of experience, Tyto Athene proudly support Defense, Intelligence, Space, National Security, Civilian, Health, and Public Safety clients across the United States and worldwide. At Tyto Athene, we believe that success starts with our people. We foster a collaborative, innovative, and mission-driven environment where every team member plays a critical role in shaping the future of technology. Are you ready to join #TeamTyto? Tyto Athene, LLC is an Equal Opportunity Employer; all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, [sexual orientation, gender identity,] national origin, disability, status as a protected veteran, or any characteristic protected by applicable law.
Full job record
| Job ID | 2d08e062f4fb9217ca833551f72b16c63f51a0be |
| Org ID | e04648bb-5c2f-4c07-a70a-fa37689ba9b9 |
| Source ID | fc123edd-d671-42f2-b50b-70b70ebc7699 |
| Board ID | fc123edd-d671-42f2-b50b-70b70ebc7699 |
| Provider | icims |
| Provider Job Key | 1920 |
| Title | Junior Security Controls Assessor |
| Normalized Title | — |
| Status | active |
| Active | yes |
| Location Text | Washington, DC, US |
| Department | Cybersecurity |
| Team | — |
| Employment Type | full_time |
| Workplace Type | hybrid |
| Remote Policy | hybrid |
| Country | United States |
| Region | DC |
| City | Washington |
| Salary Raw | Description Tyto Athene is searching for a Junior Security Controls Assessor to support one of our federal customers in Washington, DC. The candidate will ensure that security requirements for information systems meet FISMA requirements. Responsibilities: Support RMF steps 4 –assess, 5 –authorize, step 6 –monitor controls: conducting system security assessments, supporting the system security authorization to operate process, and conducting annual assessments, respectively Produce quality security assessment deliverables, ensuring the content of each deliverable is specific to the subject systems, complete, and accurate Develop and execute a security and privacy assessment plan for each security assessment project Create and maintain test cases for security assessment testing Perform security testing at the control-requirement level for each unique component of each system (e.g., application, web application server, financial systems, database server/instance, operating systems, specialized appliances, network and infrastructure devices, and end-user devices (e.g., mobile phones, laptops, etc.) Conduct technical content review and analysis of technical reports from security vulnerability scan, penetration test, and configuration compliance scan tools with respect to the subject system’s context and environment in order to analyze the findings accurately and completely Analyze security tool reports and determine residual risk or false positives from technical reports and artifacts before assigning findings Document and provide findings and recommendations that are concise, system-specific, and actionable Perform and document client and system-specific risk analysis for each finding identified during each assessment in accordance with NIST SP 800-30, the client’s risk appetite, and the client’s security policies. The results of this risk analysis shall be documented in the Security Assessment Report (SAR) for each assessed FISMA system, and a summary of the assessment results and risk shall be provided in the respective Assessment/Authorization Briefing. Qualifications Required: Bachelor's Degree or eight years of relevant equivalent experience Minimum of 1 years of relevant experience in functional responsibility Thorough understanding and knowledge of FISMA, NIST, and SPA&A process Critical thinking Strategy development Balancing security requirements with mission needs Ability to provide an assessment of the severity of weaknesses or deficiencies discovered in the information system and its environment of operation, and the ability to recommend corrective actions to address identified vulnerabilities Knowledge of NIST SP 800-53, 53A Rev 5, and 800-137 Proficiency in writing technical analysis reports Strong written and oral communication skills Legislative branch experience a plus Desired: Certified Authorization Professional (CAP) Certified in Risk and Information Systems Control (CRISC) Experience with GRC Tools such as ServiceNow, CSAM, etc. Clearance: US Citizen with Public Trust eligibility required Location: On-site contract with Hybrid allowance in Washington DC a minimum of two days a week (Tuesday and Thursday) but can be increased based on customer needs. About Tyto Athene Compensation: Compensation is unique to each candidate and relative to the skills and experience they bring to the position. Salary for this role is between 75-95K. This does not guarantee a specific salary as compensation is based upon multiple factors such as education, experience, certifications, and other requirements, and may fall outside of the above-stated range. Benefits: Highlights of our benefits include Health/Dental/Vision, 401(k) match, Flexible Time Off, STD/LTD/Life Insurance, Referral Bonuses, professional development reimbursement, and maternity/paternity leave. Tyto Athene is a trusted leader in IT services and solutions, delivering mission-focused digital transformation that drives measurable success. Our expertise spans four core technology domains—Network Modernization, Hybrid Cloud, Cybersecurity, and Enterprise IT—empowering our clients with cutting-edge solutions tailored to their evolving needs. With over 50 years of experience, Tyto Athene proudly support Defense, Intelligence, Space, National Security, Civilian, Health, and Public Safety clients across the United States and worldwide. At Tyto Athene, we believe that success starts with our people. We foster a collaborative, innovative, and mission-driven environment where every team member plays a critical role in shaping the future of technology. Are you ready to join #TeamTyto? Tyto Athene, LLC is an Equal Opportunity Employer; all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, [sexual orientation, gender identity,] national origin, disability, status as a protected veteran, or any characteristic protected by applicable law. |
| Salary Min | — |
| Salary Max | — |
| Salary Currency | — |
| Salary Period | week |
| Source URL | https://careers-gotyto.icims.com/jobs/1920/junior-security-controls-assessor/job |
| Apply URL | https://careers-gotyto.icims.com/jobs/1920/junior-security-controls-assessor/job |
| First Seen At | 2026-06-02 14:01:19Z |
| Last Seen At | 2026-06-06 08:42:02Z |
| Last Checked At | 2026-06-06 08:42:02Z |
| Last Changed At | 2026-06-04 14:22:49Z |
| Inactive At | — |
| Source Posted At | 2026-06-01 04:00:00Z |
| Source Updated At | 2026-06-03 16:40:55Z |
| Raw Payload Uri | s3://job-postings-prod-raw-590183727216/raw/provider=icims/board=careers-gotyto.icims.com/date=2026-06-06/2026-06-06T08-42-00-516Z-0074a493f0dea17c2080a92f25ff0e1c71e24b8626c6330ca985ab550f9de599.json |
Event Fields
{
"content_hash": "90f45213578db7f0f9b637b28c6b4291348e5b69c3295cded0a5fb98b187a4d4",
"source_hash": "e14db50c3540e7a61fe021fd4bea15210644eb85a0044c22b403c089055faea9",
"last_changed_at": "2026-06-04T14:22:49.832Z",
"active_status": "active"
}Parsed Structured
{
"language": "en",
"location": {
"raw": "Washington, DC, US",
"city": "Washington",
"region": "DC",
"country": "United States",
"is_remote": false,
"confidence": 0.8
},
"salary_max": null,
"salary_min": null,
"inferred_at": "2026-06-06T08:42:02.391Z",
"launch_scope": {
"reason": "english_us_canada",
"included": true,
"language": "en",
"location": {
"raw": "Washington, DC, US",
"city": "Washington",
"region": "DC",
"country": "United States",
"is_remote": false,
"confidence": 0.8
},
"countries": [
"United States"
]
},
"remote_policy": "hybrid",
"salary_period": "week",
"workplace_type": "hybrid",
"salary_currency": null
}Extensions
{}Native Structured
{
"json_ld": {
"url": "https://careers-gotyto.icims.com/jobs/1920/junior-security-controls-assessor/job",
"@type": "JobPosting",
"title": "Junior Security Controls Assessor",
"@context": "http://schema.org",
"baseSalary": {
"@type": "MonetaryAmount",
"currency": "USD",
"maxValue": 95000,
"minValue": 80000
},
"datePosted": "2026-06-01T04:00:00.000Z",
"description": "<h2>Description</h2>\n<p>Tyto Athene is searching for a <strong>Junior Security Controls Assessor </strong>to support one of our federal customers in Washington, DC. The candidate will ensure that security requirements for information systems meet FISMA requirements.</p>\n<p><strong>Responsibilities:</strong></p>\n<ul>\n <li>Support RMF steps 4 –assess, 5 –authorize, step 6 –monitor controls: conducting system security assessments, supporting the system security authorization to operate process, and conducting annual assessments, respectively</li>\n <li>Produce quality security assessment deliverables, ensuring the content of each deliverable is specific to the subject systems, complete, and accurate</li>\n <li>Develop and execute a security and privacy assessment plan for each security assessment project</li>\n <li>Create and maintain test cases for security assessment testing</li>\n <li>Perform security testing at the control-requirement level for each unique component of each system (e.g., application, web application server, financial systems, database server/instance, operating systems, specialized appliances, network and infrastructure devices, and end-user devices (e.g., mobile phones, laptops, etc.)</li>\n <li>Conduct technical content review and analysis of technical reports from security vulnerability scan, penetration test, and configuration compliance scan tools with respect to the subject system’s context and environment in order to analyze the findings accurately and completely</li>\n <li>Analyze security tool reports and determine residual risk or false positives from technical reports and artifacts before assigning findings</li>\n <li>Document and provide findings and recommendations that are concise, system-specific, and actionable</li>\n <li>Perform and document client and system-specific risk analysis for each finding identified during each assessment in accordance with NIST SP 800-30, the client’s risk appetite, and the client’s security policies. The results of this risk analysis shall be documented in the Security Assessment Report (SAR) for each assessed FISMA system, and a summary of the assessment results and risk shall be provided in the respective Assessment/Authorization Briefing.</li>\n</ul>\n<h2>Qualifications</h2>\n<p><strong>Required:</strong></p>\n<ul>\n <li>Bachelor's Degree or eight years of relevant equivalent experience</li>\n <li>Minimum of 1 years of relevant experience in functional responsibility</li>\n <li>Thorough understanding and knowledge of FISMA, NIST, and SPA&A process</li>\n <li>Critical thinking</li>\n <li>Strategy development</li>\n <li>Balancing security requirements with mission needs</li>\n <li>Ability to provide an assessment of the severity of weaknesses or deficiencies discovered in the information system and its environment of operation, and the ability to recommend corrective actions to address identified vulnerabilities</li>\n <li>Knowledge of NIST SP 800-53, 53A Rev 5, and 800-137</li>\n <li>Proficiency in writing technical analysis reports</li>\n <li>Strong written and oral communication skills</li>\n <li>Legislative branch experience a plus</li>\n</ul>\n<p><strong>Desired:</strong></p>\n<ul>\n <li>Certified Authorization Professional (CAP)</li>\n <li>Certified in Risk and Information Systems Control (CRISC)</li>\n <li>Experience with GRC Tools such as ServiceNow, CSAM, etc.</li>\n</ul>\n<p><strong>Clearance: </strong>US Citizen with Public Trust eligibility required</p>\n<p><strong>Location:</strong></p>\n<ul>\n <li>On-site contract with Hybrid allowance in Washington DC a minimum of two days a week (Tuesday and Thursday) but can be increased based on customer needs.</li>\n</ul>\n<h2>About Tyto Athene</h2>\n<p><strong>Compensation:</strong></p>\n<ul>\n <li>Compensation is unique to each candidate and relative to the skills and experience they bring to the position. Salary for this role is between 75-95K. This does not guarantee a specific salary as compensation is based upon multiple factors such as education, experience, certifications, and other requirements, and may fall outside of the above-stated range.</li>\n</ul>\n<p><strong>Benefits:</strong></p>\n<ul>\n <li>Highlights of our benefits include Health/Dental/Vision, 401(k) match, Flexible Time Off, STD/LTD/Life Insurance, Referral Bonuses, professional development reimbursement, and maternity/paternity leave.</li>\n</ul>\n<p> </p>Tyto Athene is a trusted leader in IT services and solutions, delivering mission-focused digital transformation that drives measurable success. Our expertise spans four core technology domains—Network Modernization, Hybrid Cloud, Cybersecurity, and Enterprise IT—empowering our clients with cutting-edge solutions tailored to their evolving needs. With over 50 years of experience, Tyto Athene proudly support Defense, Intelligence, Space, National Security, Civilian, Health, and Public Safety clients across the United States and worldwide. At Tyto Athene, we believe that success starts with our people. We foster a collaborative, innovative, and mission-driven environment where every team member plays a critical role in shaping the future of technology. Are you ready to join #TeamTyto? Tyto Athene, LLC is an Equal Opportunity Employer; all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, [sexual orientation, gender identity,] national origin, disability, status as a protected veteran, or any characteristic protected by applicable law.",
"directApply": true,
"jobLocation": [
{
"@type": "Place",
"address": {
"@type": "PostalAddress",
"postalCode": "20003",
"addressRegion": "DC",
"streetAddress": "499 South Capitol Street Southwest",
"addressCountry": "US",
"addressLocality": "Washington",
"postOfficeBoxNumber": "UNAVAILABLE"
}
}
],
"validThrough": "2027-06-01T04:00:00.000Z",
"employmentType": "FULL_TIME",
"salaryCurrency": "USD",
"hiringOrganization": {
"name": "Tyto Athene, LLC",
"@type": "Organization",
"sameAs": "https://gotyto.com"
},
"occupationalCategory": "Cybersecurity"
},
"detail_meta": {
"url": "https://careers-gotyto.icims.com/jobs/1920/junior-security-controls-assessor/job?in_iframe=1",
"http_status": 200,
"content_type": "text/html;charset=UTF-8",
"response_bytes": 42644,
"compact_response_bytes": 6699,
"original_response_bytes": 42644
},
"sitemap_job": {
"id": "1920",
"url": "https://careers-gotyto.icims.com/jobs/1920/junior-security-controls-assessor/job",
"slug": "junior-security-controls-assessor",
"lastmod": "2026-06-03T12:40:55-04:00"
},
"detail_errors": []
}Get this page with API
Rendered from the bluedoor Job Postings API. Reproduce it:
GET https://api.bluedoor.sh/job-postings/v1/jobs/2d08e062f4fb9217ca833551f72b16c63f51a0be?include=descriptionJSONGET https://api.bluedoor.sh/job-postings/v1/orgs/e04648bb-5c2f-4c07-a70a-fa37689ba9b9JSONGET https://api.bluedoor.sh/job-postings/v1/sources/fc123edd-d671-42f2-b50b-70b70ebc7699JSONGET https://api.bluedoor.sh/job-postings/v1/jobs/2d08e062f4fb9217ca833551f72b16c63f51a0be/eventsJSON