Demo

Cloud Security Control Assessor

Steampunk, Inc.
Washington, DC Full Time
POSTED ON 12/20/2025
AVAILABLE BEFORE 1/18/2026
Steampunk  wants you to be a  Cloud Security Control Assessor on our team to support a government customer. The primary responsibilities for the position are to support all security assessment activities that ensure risk with in the system is maintained at an acceptable level. The nature of the work requires that the candidate demonstrates initiative, organization, responsibility, customer service skills, and the ability to be flexible and adaptive to a fast-paced, fluid business environment. The candidate must be able to communicate effectively and decisively with all levels of the organization and be able to solve practical problems as well as exercise sound judgement with regards to sensitive and confidential information.

Contributions

As a member of one of our assessment teams, you will play an important role in performing a wide array of c ybersecurity duties including: 

  • Lead security assessments in accordance with NIST SP 800-53, NIST RMF (SP 800-37), FedRAMP, and agency-specific guidance.
  • Evaluate technical, operational, and management controls across cloud, on-premises, and hybrid environments.
  • Develop Assessment Plans and Security Assessment Reports (SARs) .
  • Coordinate with Information System Security Officers (ISSOs), System Owners, and authorization officials to review evidence and mitigate control deficiencies.
  • Analyze vulnerability scans, configuration baselines, and penetration test results to determine control effectiveness.
  • Provide technical recommendations to remediate weaknesses and strengthen security posture.
  • Maintain assessment documentation in compliance with organizational and federal standards (e.g., FISMA , FedRAMP ).
  • Present findings and risk analysis to management and Authorization Officials (AOs).
  • Support continuous monitoring processes and control validation efforts for ongoing authorization.

Qualifications

  • Bachelor's Degree and 5 years of relevant IT cybersecurity experience; OR
  • No degree with a total of ten ( 10 ) years of cybersecurity experience, including two ( 2 ) years of FISMA experience.
  • One of the following certifications (may be obtained within six (6) months of hire):
  • Certified Information System Security Professional (CISSP)
  • CompTIA Advanced Security Practitioner (CASP)
  • Certified Information Systems Auditor (CISA)
  • Certified Information Security Manager (CISM)
  • Familiarity with one or more : DHS Directive 4300A and NIST Special Pubs 800-30, 800-37, 800-39, 800-53, 800-60 .
  • Strong understanding of NIST SP 800-53 controls, FIPS publications 199 and 200 , and cybersecurity compliance standards.
  • Hands-on experience reviewing security control artifacts related to the NIST SP 800-53 controls .
  • Proficiency with assessment tools (e.g., Nessus, Splunk, Tenable.SC, SCAP scanners).
  • D irect experience providing independent evaluations for system authorization packages, including in cloud environments (AWS, Azure, etc.).
  • Analytical skills to interpret vulnerabilities, compliance gaps, and potential threats in diverse systems .
  • Understands the difference between cloud and non-cloud security control baselines.

Preferred Qualifications

  • Experience as an Information System Security Officer (ISSO) .
  • Experience with Vulnerability, Configuration, and Asset Management tools in support of Continuous Monitoring .
  • Excellent analytical, written, and verbal communication skills.
  • Strong attention to detail in preparing federal security documentation .
  • Experience with :
  • POA&M management
  • P erforming Security Authorization
  • P erforming Risk Analysis and Assessment
  • CSAM or similar tool GRC tool

Preferred Skills

  • E xperience providing ISSO support to DHS
  • Experience supporting systems hosted in Cloud environments.
  • Experience supporting systems in Agile and DevOps environments

About Steampunk

Steampunk relies on several factors to determine salary, including but not limited to geographic location, contractual requirements, education, knowledge, skills, competencies, and experience. The projected compensation range for this position is $115,000 to $165,000. The estimate displayed represents a typical annual salary range for this position. Annual salary is just one aspect of Steampunk’s total compensation package for employees. Learn more about additional Steampunk benefits here.

Identity Statement

As part of the application process, you are expected to be on camera during interviews and assessments. We reserve the right to take your picture to verify your identity and prevent fraud.

Steampunk is a Change Agent in the Federal contracting industry, bringing new thinking to clients in the Homeland, Federal Civilian, Health and DoD sectors. Through our Human-Centered delivery methodology , we are fundamentally changing the expectations our Federal clients have for true shared accountability in solving their toughest mission challenges. As an employee owned company , we focus on investing in our employees to enable them to do the greatest work of their careers – and rewarding them for outstanding contributions to our growth. If you want to learn more about our story, visit http://www.steampunk.com .

Salary : $115,000 - $165,000

If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Cloud Security Control Assessor?

Sign up to receive alerts about other jobs on the Cloud Security Control Assessor career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$91,971 - $119,923
Income Estimation: 
$114,980 - $148,259
Income Estimation: 
$77,991 - $108,747
Income Estimation: 
$111,725 - $147,313
Income Estimation: 
$112,673 - $137,290
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at Steampunk, Inc.

  • Steampunk, Inc. Mc Lean, VA
  • Are you a leader? Energetic? Ever worked as part of a program that is Agile? Are you interested in being an agent of change on a team committed to achievin... more
  • 13 Days Ago

  • Steampunk, Inc. Mc Lean, VA
  • We are seeking a Principal Data Solution Architect / Lead Data Architect to serve as the senior-most technical authority for end-to-end data architectures,... more
  • 13 Days Ago

  • Steampunk, Inc. Mc Lean, VA
  • Steampunk wants you to join our awesome team as Data Visualization Specialist . In this role, you'll be working with a large team of Steampunk and clients ... more
  • 14 Days Ago

  • Steampunk, Inc. Mc Lean, VA
  • We are looking for seasoned Data Scientist (Generative) to work with our existing team of Data Scientists and Engineers to use Generative AI technology in ... more
  • 14 Days Ago


Not the job you're looking for? Here are some other Cloud Security Control Assessor jobs in the Washington, DC area that may be a better fit.

  • ClearanceJobs Washington, DC
  • Overview Steampunk wants you to be a Cloud Security Control Assessor on our team to support a government customer. The primary responsibilities for the pos... more
  • 24 Days Ago

  • Cymertek Chantilly, VA
  • Security Control Assessor (SCA) LOCATION Chantilly, VA 20151 CLEARANCE TS/SCI Full Poly (Please note this position requires full U.S. Citizenship) KEY SUMM... more
  • 15 Days Ago

AI Assistant is available now!

Feel free to start your new journey!