bluedoor data·Job Postings API·bluedoor.sh ↗

HomeCompaniesCareers Sms Icims ComSecurity Control Assessor - Journeyman

Security Control Assessor - Journeyman

Careers Sms Icims Com · Springfield, VA, US · On Site · Active · iCIMS

Job facts

FieldValue
CompanyCareers Sms Icims Com
TitleSecurity Control Assessor - Journeyman
Normalized title-
Department / team-
LocationSpringfield, VA, United States
Work modelOn Site
Employment typeOTHER
Salary-
Statusactive
ATS provideriCIMS
Posted / first seen2026-04-21 / 2026-05-31
Changed / last seen2026-06-01 / 2026-06-04

Related slices

PageWhat it containsOpen
Company jobsActive postings from Careers Sms Icims Com.Open
Company breakdownsRole, location, ATS, and work model facets for this company.Open
ATS provider jobsActive postings observed through iCIMS.Open
Provider filtered searchThe same provider as a filtered job collection.Open
City jobsActive postings in Springfield.Open
Work model jobsActive On Site postings.Open
Lifecycle eventsOpen, update, close, and reopen events for this posting.Open
Original postingCanonical source or apply URL captured from the ATS.Open

Linked records

CompanyCareers Sms Icims Com
Sourceef590a2d-99e8-47bb-888d-e28638c76a14
ATS provideriCIMS

Description

Overview SMS is seeking a skilled and detail-oriented Security Control Assessor and Validator to join our team. The successful candidate will be responsible for evaluating, testing, and validating the effectiveness of security controls within our organization's information systems and networks, with a strong emphasis on applying the Risk Management Framework (RMF). As a dynamic systems integrator, SMS offers proven solutions in engineering, operations, cybersecurity, and digital transformation. With expertise in modernizing and optimizing legacy infrastructure and systems, ensuring operational efficiency, and designing, implementing, and managing secure environments, SMS supports business and mission goals with proficiency, quality, and integrity. SMS has been serving the advanced information technology needs of the federal government since 1976, delivering talented teams and innovative, cost-effective solutions and services to support our customers’ missions for more than 40 years. SMS is headquartered in McLean, Virginia, with offices and on-site operations at customer locations throughout the United States. For additional information on SMS, visit www.sms.com. Submit your resume today. Responsibilities The Security Control Assessor, you will be responsible for the following: Provide the United States Coast Guard (USCG) with tailored documentation to support their security authorization. Independent assessor for Risk Management Framework Steps 0 to 7. Plan and execute security control assessments for various information systems within the organization. Develop and maintain assessment procedures and methodologies aligned with NIST guidelines and other relevant frameworks. Analyze and evaluate the effectiveness of implemented security controls. Identify vulnerabilities, weaknesses, and potential risks in information systems and infrastructure. Prepare detailed Security Assessment Reports (SARs) documenting findings and recommendations. Collaborate with system owners, ISSOs, and other stakeholders throughout the assessment process. Verify the implementation of remediation actions and conduct follow-up assessments as needed. Provide expert advice on the development and maintenance of System Security Plans (SSPs) and Plans of Action and Milestones (POA&Ms). Stay current with evolving cybersecurity threats, technologies, and best practices. Validate security control implementation and provide test results. Hands-on experience in assessing RMF Step 4 and performing continuous monitoring. Examine security control weaknesses and determine if they are producing the desired intent. Deep understanding of Vulnerability Management practices. Qualifications Required Qualifications: Intimate understanding of NIST RMF implementation guidance. Hands-on experience with using eMASS or similar Information Assurance tools. Well-developed understanding of Federal Civilian or DHS Security Assessment and Authorization (SA&A) processes. In-depth understanding of the relevance of NIST Security Controls and Control Implementation methodologies to the SA&A process. Experience analyzing vulnerability scans and STIG implementations. Can demonstrate understanding of critical documentation required in Security Authorization (SA) Packages. Ability to understand and support Privacy Compliance Activities to include the development of Privacy Impact Analysis (PIA), Privacy Threshold Analysis (PTA), and Statement of Record Notices (SORN). At least one of the DOD 8750 IAT II certifications: CCNA Security, CySA+, GICSP, GSEC, Security + CE, CND, or SSCP. CSSP-AU certification - must obtain within 60days of employment. Knowledge/Familiarity with DoD 8500, DoD 8510, DHS 4300 A and B, NIST SP 800-18, 60, 70, 53, 53A, 137, IACS, CMRS, COAMS, JIMS, Swimlane, Governance, Risk, and Compliance, POA&M (i.e., Management, Assessment, etc.), ERS, FISMA, Knowledge Service, ACAS, Tanium, Power BI, Project/Program Management, TASKORD (i.e., FRAGO, CTO, etc.), and Data Calls (i.e., OIG Audit, etc.) Desired Qualifications: Well-developed understanding of Systems Development Lifecycle (SDLC) and ideally the DHS Systems Engineering Lifecycle (SELC) process as it relates to Security Assessment and Authorization (SA&A). Relevant DOD, DHS or .gov Cyber Security Information Assurance focused experience with specific current hands-on experience researching, writing, and submitting complete A&A documentation packages for new system authorizations. Clearance Requirement: Active DOD Secret security clearance required Certifications Requirement: IAT Level II: Security+ CE, CySA+, CCNA Security, GICSP, GSEC, CND, SSCP CSSP-AU: CEH, CySA+, CISA, PenTest+, GSNA, CFR . Within 60 days of hire. SMS is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.

Full job record

Job ID44276c2b6c85570a90b4f54020dd9a09fdca815c
Org ID249c87ec-e3e9-45c3-a412-d28461625678
Source IDef590a2d-99e8-47bb-888d-e28638c76a14
Board IDef590a2d-99e8-47bb-888d-e28638c76a14
Providericims
Provider Job Key5321
TitleSecurity Control Assessor - Journeyman
Normalized Title
Statusactive
Activeyes
Location TextSpringfield, VA, US
Department
Team
Employment TypeOTHER
Workplace Typeon_site
Remote Policy
CountryUnited States
RegionVA
CitySpringfield
Salary RawOverview SMS is seeking a skilled and detail-oriented Security Control Assessor and Validator to join our team. The successful candidate will be responsible for evaluating, testing, and validating the effectiveness of security controls within our organization's information systems and networks, with a strong emphasis on applying the Risk Management Framework (RMF). As a dynamic systems integrator, SMS offers proven solutions in engineering, operations, cybersecurity, and digital transformation. With expertise in modernizing and optimizing legacy infrastructure and systems, ensuring operational efficiency, and designing, implementing, and managing secure environments, SMS supports business and mission goals with proficiency, quality, and integrity. SMS has been serving the advanced information technology needs of the federal government since 1976, delivering talented teams and innovative, cost-effective solutions and services to support our customers’ missions for more than 40 years. SMS is headquartered in McLean, Virginia, with offices and on-site operations at customer locations throughout the United States. For additional information on SMS, visit www.sms.com. Submit your resume today. Responsibilities The Security Control Assessor, you will be responsible for the following: Provide the United States Coast Guard (USCG) with tailored documentation to support their security authorization. Independent assessor for Risk Management Framework Steps 0 to 7. Plan and execute security control assessments for various information systems within the organization. Develop and maintain assessment procedures and methodologies aligned with NIST guidelines and other relevant frameworks. Analyze and evaluate the effectiveness of implemented security controls. Identify vulnerabilities, weaknesses, and potential risks in information systems and infrastructure. Prepare detailed Security Assessment Reports (SARs) documenting findings and recommendations. Collaborate with system owners, ISSOs, and other stakeholders throughout the assessment process. Verify the implementation of remediation actions and conduct follow-up assessments as needed. Provide expert advice on the development and maintenance of System Security Plans (SSPs) and Plans of Action and Milestones (POA&Ms). Stay current with evolving cybersecurity threats, technologies, and best practices. Validate security control implementation and provide test results. Hands-on experience in assessing RMF Step 4 and performing continuous monitoring. Examine security control weaknesses and determine if they are producing the desired intent. Deep understanding of Vulnerability Management practices. Qualifications Required Qualifications: Intimate understanding of NIST RMF implementation guidance. Hands-on experience with using eMASS or similar Information Assurance tools. Well-developed understanding of Federal Civilian or DHS Security Assessment and Authorization (SA&A) processes. In-depth understanding of the relevance of NIST Security Controls and Control Implementation methodologies to the SA&A process. Experience analyzing vulnerability scans and STIG implementations. Can demonstrate understanding of critical documentation required in Security Authorization (SA) Packages. Ability to understand and support Privacy Compliance Activities to include the development of Privacy Impact Analysis (PIA), Privacy Threshold Analysis (PTA), and Statement of Record Notices (SORN). At least one of the DOD 8750 IAT II certifications: CCNA Security, CySA+, GICSP, GSEC, Security + CE, CND, or SSCP. CSSP-AU certification - must obtain within 60days of employment. Knowledge/Familiarity with DoD 8500, DoD 8510, DHS 4300 A and B, NIST SP 800-18, 60, 70, 53, 53A, 137, IACS, CMRS, COAMS, JIMS, Swimlane, Governance, Risk, and Compliance, POA&M (i.e., Management, Assessment, etc.), ERS, FISMA, Knowledge Service, ACAS, Tanium, Power BI, Project/Program Management, TASKORD (i.e., FRAGO, CTO, etc.), and Data Calls (i.e., OIG Audit, etc.) Desired Qualifications: Well-developed understanding of Systems Development Lifecycle (SDLC) and ideally the DHS Systems Engineering Lifecycle (SELC) process as it relates to Security Assessment and Authorization (SA&A). Relevant DOD, DHS or .gov Cyber Security Information Assurance focused experience with specific current hands-on experience researching, writing, and submitting complete A&A documentation packages for new system authorizations. Clearance Requirement: Active DOD Secret security clearance required Certifications Requirement: IAT Level II: Security+ CE, CySA+, CCNA Security, GICSP, GSEC, CND, SSCP CSSP-AU: CEH, CySA+, CISA, PenTest+, GSNA, CFR . Within 60 days of hire. SMS is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.
Salary Min
Salary Max
Salary Currency
Salary Period
Source URLhttps://careers-sms.icims.com/jobs/5321/security-control-assessor---journeyman/job
Apply URLhttps://careers-sms.icims.com/jobs/5321/security-control-assessor---journeyman/job
First Seen At2026-05-31 18:48:19Z
Last Seen At2026-06-04 14:22:13Z
Last Checked At2026-06-04 14:22:13Z
Last Changed At2026-06-01 14:04:52Z
Inactive At
Source Posted At2026-04-21 04:00:00Z
Source Updated At2026-05-28 20:46:37Z
Raw Payload Uris3://bluework-jobs-prod-raw-590183727216/raw/provider=icims/board=careers-sms.icims.com/date=2026-06-04/2026-06-04T14-22-10-829Z-b101dc68e44a4d61cd34b68bc5c8e557ed3e91ae4a04abab6bf948f4a567fafe.json
Event Fields
{
  "content_hash": "90add13614be29f57f3ed765af4c8a491f9c671c917365c6783fdee3e6d2c66e",
  "source_hash": "41c418ead9a1cc0d713f038930172284375e463d7db74951f4ae443a4ed0d3a1",
  "last_changed_at": "2026-06-01T14:04:52.645Z",
  "active_status": "active"
}
Parsed Structured
{
  "language": "en",
  "location": {
    "raw": "Springfield, VA, US",
    "city": "Springfield",
    "region": "VA",
    "country": "United States",
    "is_remote": false,
    "confidence": 0.8
  },
  "salary_max": null,
  "salary_min": null,
  "inferred_at": "2026-06-04T14:22:13.573Z",
  "launch_scope": {
    "reason": "english_us_canada",
    "included": true,
    "language": "en",
    "location": {
      "raw": "Springfield, VA, US",
      "city": "Springfield",
      "region": "VA",
      "country": "United States",
      "is_remote": false,
      "confidence": 0.8
    },
    "countries": [
      "United States"
    ]
  },
  "remote_policy": null,
  "salary_period": null,
  "workplace_type": "on_site",
  "salary_currency": null
}
Extensions
{}
Native Structured
{
  "json_ld": {
    "url": "https://careers-sms.icims.com/jobs/5321/security-control-assessor---journeyman/job",
    "@type": "JobPosting",
    "title": "Security Control Assessor - Journeyman",
    "@context": "http://schema.org",
    "datePosted": "2026-04-21T04:00:00.000Z",
    "description": "<h2>Overview</h2>\n<p>SMS is seeking a skilled and detail-oriented Security Control Assessor and Validator to join our team. The successful candidate will be responsible for evaluating, testing, and validating the effectiveness of security controls within our organization's information systems and networks, with a strong emphasis on applying the Risk Management Framework (RMF). </p>\n<p> </p>\n<p>As a dynamic systems integrator, SMS offers proven solutions in engineering, operations, cybersecurity, and digital transformation. With expertise in modernizing and optimizing legacy infrastructure and systems, ensuring operational efficiency, and designing, implementing, and managing secure environments, SMS supports business and mission goals with proficiency, quality, and integrity.</p>\n<p> </p>\n<p>SMS has been serving the advanced information technology needs of the federal government since 1976, delivering talented teams and innovative, cost-effective solutions and services to support our customers’ missions for more than 40 years. SMS is headquartered in McLean, Virginia, with offices and on-site operations at customer locations throughout the United States. For additional information on SMS, visit www.sms.com.</p>\n<p> </p>\n<p>Submit your resume today.</p>\n<h2>Responsibilities</h2>\n<p>The Security Control Assessor, you will be responsible for the following:</p>\n<p> </p>\n<ul>\n <li>Provide the United States Coast Guard (USCG) with tailored documentation to support their security authorization.</li>\n <li>Independent assessor for Risk Management Framework Steps 0 to 7.</li>\n <li>Plan and execute security control assessments for various information systems within the organization.</li>\n <li>Develop and maintain assessment procedures and methodologies aligned with NIST guidelines and other relevant frameworks.</li>\n <li>Analyze and evaluate the effectiveness of implemented security controls.</li>\n <li>Identify vulnerabilities, weaknesses, and potential risks in information systems and infrastructure.</li>\n <li>Prepare detailed Security Assessment Reports (SARs) documenting findings and recommendations.</li>\n <li>Collaborate with system owners, ISSOs, and other stakeholders throughout the assessment process.</li>\n <li>Verify the implementation of remediation actions and conduct follow-up assessments as needed.</li>\n <li>Provide expert advice on the development and maintenance of System Security Plans (SSPs) and Plans of Action and Milestones (POA&Ms).</li>\n <li>Stay current with evolving cybersecurity threats, technologies, and best practices.</li>\n <li>Validate security control implementation and provide test results.</li>\n <li>Hands-on experience in assessing RMF Step 4 and performing continuous monitoring.</li>\n <li>Examine security control weaknesses and determine if they are producing the desired intent.</li>\n <li>Deep understanding of Vulnerability Management practices.</li>\n</ul>\n<h2>Qualifications</h2>\n<p><strong>Required Qualifications:</strong></p>\n<p> </p>\n<ul>\n <li>Intimate understanding of NIST RMF implementation guidance.</li>\n <li>Hands-on experience with using eMASS or similar Information Assurance tools.</li>\n <li>Well-developed understanding of Federal Civilian or DHS Security Assessment and Authorization (SA&A) processes.</li>\n <li>In-depth understanding of the relevance of NIST Security Controls and Control Implementation methodologies to the SA&A process.</li>\n <li>Experience analyzing vulnerability scans and STIG implementations.</li>\n <li>Can demonstrate understanding of critical documentation required in Security Authorization (SA) Packages.</li>\n <li>Ability to understand and support Privacy Compliance Activities to include the development of Privacy Impact Analysis (PIA), Privacy Threshold Analysis (PTA), and Statement of Record Notices (SORN).</li>\n <li>At least one of the DOD 8750 IAT II certifications:  CCNA Security, CySA+, GICSP, GSEC, Security + CE, CND, or SSCP.</li>\n <li>CSSP-AU certification - must obtain within 60days of employment.</li>\n <li>Knowledge/Familiarity with <strong>DoD 8500, DoD 8510, DHS 4300 A and B, NIST SP 800-18, 60, 70, 53, 53A, 137, </strong>IACS, CMRS, COAMS, JIMS, Swimlane, Governance, Risk, and Compliance, POA&M (i.e., Management, Assessment, etc.), ERS, FISMA, Knowledge Service, ACAS, Tanium, Power BI, Project/Program Management, TASKORD (i.e., FRAGO, CTO, etc.), and Data Calls (i.e., OIG Audit, etc.) </li>\n</ul>\n<p><strong>Desired Qualifications:</strong></p>\n<p> </p>\n<ul>\n <li>Well-developed understanding of Systems Development Lifecycle (SDLC) and ideally the DHS Systems Engineering Lifecycle (SELC) process as it relates to Security Assessment and Authorization (SA&A).</li>\n <li>Relevant DOD, DHS or .gov Cyber Security Information Assurance focused experience with specific current hands-on experience researching, writing, and submitting complete A&A documentation packages for new system authorizations.</li>\n</ul>\n<p> </p>\n<p><strong>Clearance Requirement:</strong></p>\n<ul>\n <li>Active DOD Secret security clearance required</li>\n</ul>\n<p> </p>\n<p><strong>Certifications Requirement:</strong></p>\n<ul>\n <li>IAT Level II: Security+ CE, CySA+, CCNA Security, GICSP, GSEC, CND, SSCP</li>\n <li>CSSP-AU: CEH, CySA+, CISA, PenTest+, GSNA, CFR . Within 60 days of hire. </li>\n</ul>\n<p> </p>\n<p><strong>SMS is an Equal Opportunity Employer. </strong><strong>All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.</strong></p>",
    "directApply": true,
    "jobLocation": [
      {
        "@type": "Place",
        "address": {
          "@type": "PostalAddress",
          "postalCode": "UNAVAILABLE",
          "addressRegion": "VA",
          "streetAddress": "UNAVAILABLE",
          "addressCountry": "US",
          "addressLocality": "Springfield",
          "postOfficeBoxNumber": "UNAVAILABLE"
        }
      }
    ],
    "validThrough": "2027-04-21T04:00:00.000Z",
    "employmentType": "OTHER",
    "hiringOrganization": {
      "name": "SMS Data Products Group, Inc.",
      "@type": "Organization",
      "sameAs": "www.sms.com"
    },
    "educationRequirements": "High School Diploma/GED"
  },
  "detail_meta": {
    "url": "https://careers-sms.icims.com/jobs/5321/security-control-assessor---journeyman/job?in_iframe=1",
    "http_status": 200,
    "content_type": "text/html;charset=UTF-8",
    "response_bytes": 41999,
    "compact_response_bytes": 6797,
    "original_response_bytes": 41999
  },
  "sitemap_job": {
    "id": "5321",
    "url": "https://careers-sms.icims.com/jobs/5321/security-control-assessor---journeyman/job",
    "slug": "security-control-assessor---journeyman",
    "lastmod": "2026-05-28T16:46:37-04:00"
  },
  "detail_errors": []
}
Get this page with API

Rendered from the bluedoor Job Postings API. Reproduce it:

GET https://api.bluedoor.sh/job-postings/v1/jobs/44276c2b6c85570a90b4f54020dd9a09fdca815c?include=descriptionJSON
GET https://api.bluedoor.sh/job-postings/v1/orgs/249c87ec-e3e9-45c3-a412-d28461625678JSON
GET https://api.bluedoor.sh/job-postings/v1/sources/ef590a2d-99e8-47bb-888d-e28638c76a14JSON
GET https://api.bluedoor.sh/job-postings/v1/jobs/44276c2b6c85570a90b4f54020dd9a09fdca815c/eventsJSON