Summary
Imagineeer delivers secure, AI-ready modernization solutions for federal agencies across health, defense, homeland security, and transportation. The SME Security Control Assessor supports HHS-ACF information system assessments by applying NIST controls and frameworks, gathering evidence, conducting testing, supporting vulnerability analysis and continuous monitoring, and preparing assessment documentation and deliverables.
Responsibilities
- Support security control assessment activities
- Gather and organize assessment evidence
- Document security control implementation
- Conduct security testing and evaluations
- Assist with vulnerability scans and analysis
- Create of assessment reports and briefings
- Maintain assessment documentation and tracking sheets
- Lead security control interviews
- Prepare assessment deliverables
- Applying NIST security controls and frameworks
- Support continuous monitoring activities
- Assist with security documentation review
- Contribute to Plans of Action and Milestones (POA&Ms) development
- Participate in team meetings and technical discussions
Skills
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related field
- 2+ years of experience in security control assessments
- Basic understanding of cybersecurity principles and concepts
- Knowledge of NIST frameworks and security controls
- Familiarity with common security tools and technologies
- Strong attention to detail
- Excellent organizational skills
- Basic technical writing abilities
- Proficiency in Microsoft Office suite
- Strong analytical and problem-solving skills
- Ability to follow detailed instructions and procedures
- Good communication skills
- Eagerness to learn and develop professional skills
- Basic understanding of networking concepts
- Ability to work effectively in a team environment
- Commitment to maintaining confidentiality and security protocols
- Familiarity with Risk Management Framework (RMF)
- Security+ certification or in progress
- Basic understanding of FISMA requirements
- Experience with vulnerability scanning tools
- Knowledge of basic scripting or programming
- Familiarity with cloud computing concepts
- Understanding of basic system administration
- Experience with documentation management systems
- Knowledge of compliance frameworks
- Basic understanding of security assessment methodologies
- Familiarity with cybersecurity best practices
- Experience with technical documentation
- Interest in federal government cybersecurity
- Basic understanding of privacy principles
- Employment for this position is contingent upon the candidate being a United States citizen and having the ability to successfully obtain and maintain a Public Trust clearance, in accordance with applicable federal regulations
Qualifications
Must Haves
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related field
- 2+ years of experience in security control assessments
- Basic understanding of cybersecurity principles and concepts
- Knowledge of NIST frameworks and security controls
- Familiarity with common security tools and technologies
- Strong attention to detail
- Excellent organizational skills
- Basic technical writing abilities
- Proficiency in Microsoft Office suite
- Strong analytical and problem-solving skills
- Ability to follow detailed instructions and procedures
- Good communication skills
- Eagerness to learn and develop professional skills
- Basic understanding of networking concepts
- Ability to work effectively in a team environment
- Commitment to maintaining confidentiality and security protocols
- Familiarity with Risk Management Framework (RMF)
- Security+ certification or in progress
- Basic understanding of FISMA requirements
- Experience with vulnerability scanning tools
- Knowledge of basic scripting or programming
- Familiarity with cloud computing concepts
- Understanding of basic system administration
- Experience with documentation management systems
- Knowledge of compliance frameworks
- Basic understanding of security assessment methodologies
- Familiarity with cybersecurity best practices
- Experience with technical documentation
- Interest in federal government cybersecurity
- Basic understanding of privacy principles
- Employment for this position is contingent upon the candidate being a United States citizen and having the ability to successfully obtain and maintain a Public Trust clearance, in accordance with applicable federal regulations