Tyto Athene, LLC

Junior Security Controls Assessor

Location US-DC-Washington
ID 2025-1384
Category
Cybersecurity
Position Type
Full-Time

Description

Tyto Athene is searching for a Junior Security Controls Assessor to support one of our law enforcment customers in Washington, DC. The candidate will ensure that security requirements for information systems meet FISMA requirements.

Responsibilities:

  • Support RMF steps 4 –assess, 5 -authorize, step 6 –monitor controls: conducting system security assessments, supporting the system security authorization to operate process, and conducting annual assessments, respectively
  • Produce quality security assessment deliverables, ensuring the content of each deliverable is specific to the subject systems, complete, and accurate
  • Develop and execute a security and privacy assessment plan for each security assessment project
  • Create and maintain test cases for security assessment testing
  • Perform security testing at the control-requirement level for each unique component of each system (e.g., application, web application server, financial systems, database server/instance, operating systems, specialized appliances, network and infrastructure devices, and end-user devices (e.g., mobile phones, laptops, etc.)
  • Conduct technical content review and analysis of technical reports from security vulnerability scan, penetration test, and configuration compliance scan tools with respect to the subject system’s context and environment in order to analyze the findings accurately and completely
  • Analyze security tool reports and determine residual risk or false positives from technical reports and artifacts before assigning findings
  • Document and provide findings and recommendations that are concise, system-specific, and actionable
  • Perform and document client and system-specific risk analysis for each finding identified during each assessment in accordance with NIST SP 800-30, the client’s risk appetite, and the client’s security policies. The results of this risk analysis shall be documented in the Security Assessment Report (SAR) for each assessed FISMA system, and a summary of the assessment results and risk shall be provided in the respective Assessment/Authorization Briefing.

Qualifications

Required:

  • Bachelor's Degree or eight years of relevant equivalent experience
  • Minimum of 1 years of relevant experience in functional responsibility
  • Thorough understanding and knowledge of FISMA, NIST, and SPA&A process
  • Critical thinking
  • Strategy development
  • Balancing security requirements with mission needs
  • Ability to provide an assessment of the severity of weaknesses or deficiencies discovered in the information system and its environment of operation, and the ability to recommend corrective actions to address identified vulnerabilities
  • Knowledge of NIST SP 800-53, 53A Rev 5, and 800-137
  • Proficiency in writing technical analysis reports
  • Strong written and oral communication skills
  • Legislative branch experience a plus

Desired:

  • Certified Authorization Professional (CAP)
  • Certified in Risk and Information Systems Control (CRISC)
  • Experience with GRC Tools such as ServiceNow, CSAM, etc.

Clearance: US Citizen with Public Trust eligibility required

Location: Hybrid with on-site in Washington DC a couple days a week.

About Tyto Athene

Compensation:

  • Compensation is unique to each candidate and relative to the skills and experience they bring to the position. Salary for this role is between 75-95K. This does not guarantee a specific salary as compensation is based upon multiple factors such as education, experience, certifications, and other requirements, and may fall outside of the above-stated range.

Benefits:

  • Highlights of our benefits include Health/Dental/Vision, 401(k) match, Flexible Time Off, STD/LTD/Life Insurance, Referral Bonuses, professional development reimbursement, and maternity/paternity leave.

 

Tyto Athene is a trusted leader in IT services and solutions, delivering mission-focused digital transformation that drives measurable success. Our expertise spans four core technology domains—Network Modernization, Hybrid Cloud, Cybersecurity, and Enterprise IT—empowering our clients with cutting-edge solutions tailored to their evolving needs. With over 50 years of experience, Tyto Athene proudly support Defense, Intelligence, Space, National Security, Civilian, Health, and Public Safety clients across the United States and worldwide. 
 
At Tyto Athene, we believe that success starts with our people. We foster a collaborative, innovative, and mission-driven environment where every team member plays a critical role in shaping the future of technology. Are you ready to join #TeamTyto? 
 
Tyto Athene, LLC is an Equal Opportunity Employer; all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, [sexual orientation, gender identity,] national origin, disability, status as a protected veteran, or any characteristic protected by applicable law.

Options

Sorry the Share function is not working properly at this moment. Please refresh the page and try again later.