About this role
About Us
AGE Solutions is a premier technology and professional services company, providing in-depth consulting, advanced technology solutions, and essential services throughout the U.S. government, defense, and intelligence sectors. Prioritizing innovation and client-focused solutions, we assist major agencies in addressing intricate issues and ensuring a more secure future.
The Security Control Assessor Representative (SCA-R) provides cybersecurity assessment, Risk Management Framework (RMF), and Assessment and Authorization (A&A) support for Department of Defense (DoD) information systems. The SCA-R works with Information System Security Managers (ISSMs), Program Management Offices (PMOs), system owners, technical teams, and Government cybersecurity stakeholders to assess security controls, identify cybersecurity risks, validate system compliance, and support authorization decisions throughout the system lifecycle.
The SCA-R performs independent technical and risk-based assessments using Government-approved processes, databases, and cybersecurity tools and develops complete, accurate, and defensible authorization documentation for Government and Authorizing Official (AO) review.
Responsibilities Include:
- Use Government-assigned tools and databases to perform weekly updates, maintain system records, track assigned actions, and complete cybersecurity assessment and authorization activities.
- Coordinate with ISSMs, PMOs, system owners, and technical stakeholders to understand system architectures, security requirements, authorization boundaries, configurations, and system changes.
- Conduct risk analysis, security control assessment, and authorization activities across applicable RMF steps using approved RE5 tools and processes.
- Verify system authorization boundaries and validate system security categorizations in accordance with FIPS 199 and applicable DoD requirements.
- Identify applicable data classifications and conduct system-level cybersecurity risk assessments.
- Assess threats, vulnerabilities, control deficiencies, and residual risks and compile findings into complete and accurate authorization packages.
- Evaluate proposed and implemented system changes, determine their potential security and authorization impacts, and provide appropriate status and risk information to the Authorizing Official (AO).
- Evaluate authorization and change requests, including web-filtering requests, firewall exceptions, ports and protocols, cybersecurity risks, STIG/SRG compliance, and on-site security requirements.
- Review and validate compliance with applicable Security Technical Implementation Guides (STIGs), Security Requirements Guides (SRGs), security controls, and cybersecurity requirements.
- Review, validate, and track Plans of Action and Milestones (POA&Ms) and associated cybersecurity deficiencies through resolution.
- Lead and support on-site assessment visits, including planning, technical assessments, stakeholder coordination, entrance/exit briefings, documentation, findings development, and reporting.
- Maintain access to and proficiency with required Government cybersecurity databases, vulnerability assessment platforms, endpoint security solutions, scanning tools, and RMF management systems.
- Attend required Government meetings, technical exchanges, and training to remain current with policies, procedures, tools, and RMF process changes.
- Complete required assessor, vulnerability scanning, endpoint security, and RMF process training.
- Support assigned systems throughout their lifecycle in accordance with FISMA, DoD RMF, and applicable cybersecurity requirements.
- Prepare and submit weekly activity reports documenting completed and ongoing activities, tracking identifiers, assessment status, significant findings, risks, issues, and key updates.
Required Skills, Qualifications and Experience:
- Education:
Bachelor's degree required.
A bachelor's in information technology, Cybersecurity, Computer Science, Information Systems, or related technical field is preferred.
- Overall Experience:
Minimum of eight (8) years of experience in a cybersecurity or network security position.
- A&A Experience:
Minimum of five (5) years of experience performing Certification and Accreditation (C&A) and/or Assessment and Authorization (A&A) activities.
- Security Clearance:
Must have a minimum of a current DoD Secret Clearance with the ability to obtain a DoD Top Secret clearance with SCI eligibility. A current DoD Top Secret clearance with SCI eligibility strongly preferred.
- Certification:
Current DoD 8570 IAM Level III certification.
- Skills:
Demonstrated experience serving as a Security Control Assessor Representative (SCA-R) and performing cybersecurity risk analysis and security control validation.
- Advanced understanding and practical application of the Risk Management Framework (RMF), including NIST SP 800-37, NIST SP 800-53, and CNSSI 1253.
- Demonstrated experience applying and evaluating Security Technical Implementation Guides (STIGs), Security Requirements Guides (SRGs), Plans of Action and Milestones (POA&Ms), cybersecurity security controls, and industry/DoD cybersecurity best practices.
- Demonstrated hands-on experience with relevant cybersecurity and RMF tools, including one or more of the following: eMASS, STIG Viewer, Nessus, ACAS, SCAP, and HBSS/Endpoint Security Solutions (ESS).
- Advanced understanding of multiple cybersecurity technology areas and domains, including network technologies and security, mobility, Windows, UNIX/Linux, cloud environments, cloud-native tools and services, HBSS/Endpoint Security Solutions (ESS), databases, and applications.
- Strong customer service and stakeholder engagement skills, with the ability to effectively coordinate with Government customers, ISSMs, PMOs, technical teams, system owners, and cybersecurity leadership.
- Ability to analyze complex technical and cybersecurity information and clearly communicate security risks, vulnerabilities, assessment findings, residual risk, and recommended corrective actions through written documentation and technical briefings.
- Location and Schedule: This role may be based at one of the following customer locations, with onsite requirements varying by location:
Chambersburg, PA: Fully onsite, 5 days per week.
- Arlington, VA or Fort Meade, MD: Hybrid schedule, 4 days onsite per week with 1 telework day.
- Travel Requirements:
Must be willing and able to support occasional domestic (CONUS) and international (OCONUS) travel, approximately 10% of the time.
The projected salary range for this position is $100,000+ annually. Final compensation will be determined based on factors including years of relevant experience, active security clearance level, certifications, technical skillset, contract requirements, and overall qualifications.
At AGE Solutions, we reward performance, invest in growth, and share success. Our benefits support the whole person, professionally, financially, and personally.
- 26 Days Paid Leave: Includes vacation, sick, personal time, and holidays. You choose how to use it.
- Performance Bonuses: Performance bonuses are awarded based on individual contributions and company-wide results, aligning recognition with impact.
- 401(k) with Match: We match 3% of your contributions with immediate vesting.
- Financial Protection: Company-paid life insurance up to $300K and options for additional coverage for you and your dependents.
- Health Benefits: Multiple medical plans, dental, vision, FSA and HSA options to fit your needs.
- Parental Leave: 15 days of fully paid leave for new parents, because family matters.
- Military Differential Pay: We bridge the gap for employees on active duty, so they don’t take a financial hit while serving.
- Professional Growth: Paid training and certifications, tuition reimbursement, and the tools and tech to get the job done right.
- Shared Success: In the event of a company sale, our CEO has committed to returning 80% of net proceeds to employees. This ensures our team shares in the long term value they help create.
At AGE, you’ll do work that matters, supported by a company that delivers for its people.
