Dark Wolf Solutions logo

Dark Wolf Solutions

Offensive Security Control Assessor Security Control Assessor Representative at Dark Wolf Solutions

Washington DC Metro AreaFull-timeCybersecurityPosted about 2 months ago
Apply with Pipeline

About the Role

<p class="p1"><strong>Dark Wolf Solutions</strong> is seeking <strong>Security Control Assessor/Representatives (SCA/Rs)</strong> to&nbsp;lead security control assessments across high-priority projects. Working at the intersection of&nbsp;cybersecurity engineering, cloud architecture, and DevSecOps prototyping, you will evaluate&nbsp;security controls for cutting-edge AI/LLM technologies across multiple classification levels. This&nbsp;position is ideal for a pragmatic cloud assessor or SCAR who excels in fast-paced DevSecOps&nbsp;environments, understands AWS cloud security, and is eager to shape the cybersecurity posture&nbsp;of next-generation DoD AI capabilities.This position will be based out of Arlington, VA with&nbsp;hybrid/remote opportunities. Additional responsibilities include:</p> <p class="p3"><strong>Key Responsibilities</strong></p> <ul> <li class="p2">Execute formal SCA/R duties.</li> <li class="p2">Lead security assessment efforts, establishing reusable security playbooks and assessment frameworks for rapid AI deployment into enterprise workflows.</li> <li class="p2">Evaluate technical control effectiveness across AWS cloud infrastructure, DevSecOps pipelines, microservices, containerized workloads, and GenAI/LLM application stacks.</li> <li class="p2">Bridge the gap between OffSec and development by applying software design best practices. Lead technical exchange meetings (TEMs), participate in Discovery &amp; Framing workshops, and maintain effective communication with cross-functional teams and stakeholders.</li> <li class="p2">Act as the primary subject matter expert and lead developer for custom offensive tooling, integrating disparate capabilities into a cohesive, mission-ready platform.</li> <li class="p2">Review, author, and maintain assessment packages—including System Security Plans (SSPs), Security Assessment Plans (SAPs), Security Assessment Reports (SARs), and POA&amp;Ms—tailored to rapid prototyping and AI systems.</li> <li class="p2">Assess technical security risks specific to AI/LLM implementations, such as API exposure, vector database access controls, model integration surface area, and software supply chain dependencies.</li> <li class="p2">Support continuous monitoring (ConMon), technical risk evaluations, and cloud architecture reviews across multi-tenant, multi-classification environments.</li> <li class="p2">Coordinate with Authorizing Officials (AOs), program managers, and engineering leads to deliver decision-ready risk briefings and ATO recommendations.</li> <li class="p2">Provide technical input and oversight for cybersecurity engineering and penetration testing activities across prototype projects.</li> </ul> <p class="p3"><strong>Required Qualifications</strong></p> <ul> <li class="p2">Active Top Secret security clearance</li> <li class="p2">Current DoD 8570/8140 IAM Level II or Level III certification (e.g., Security+, CySA+, CISM, CISSP, CCISO, CAP/CISC)</li> <li class="p2">5–7+ years of experience conducting security control assessments, compliance testing, or A&amp;A/RMF activities for DoD or federal information systems</li> <li class="p2">Solid operational understanding of core AWS cloud services (EC2, S3, IAM, VPCs, Security Groups, Security Hub) and how security controls function within cloud-native and CI/CD pipeline environments.</li> <li class="p2">Experience with GitLab CI/CD (pipeline design, runners, artifact management) and AWS Cloud services (EC2, VPC, IAM, S3).</li> <li class="p2">Strong working knowledge of NIST SP 800-53 (Rev. 4/5), NIST SP 800-37 (RMF), DoD Cloud Computing SRG, and FedRAMP baselines.</li> <li class="p2">Demonstrated experience writing and evaluating core RMF artifacts (SSPs, SAPs, SARs, POA&amp;Ms)</li> <li class="p2">Exceptional written and verbal communication skills, with the ability to articulate technical risk clearly to executive stakeholders, Authorizing Officials, and engineering teams.</li> <li class="p2">Hands-on experience navigating government GRC repositories, such as eMASS or XACTA.</li> </ul> <p class="p3"><strong>Desired Qualifications</strong></p> <ul> <li class="p2">Hands-on experience mapping security controls to the NIST AI Risk Management Framework (AI RMF), the OWASP Top 10 for LLM Applications, or the DoD Responsible AI (RAI) Guidelines.</li> <li class="p2">Familiarity evaluating secure design patterns for autonomous AI Agents (e.g., tool-calling permissions, sandboxing agent execution environments, prompt boundaries, and ReAct/LangGraph architectures).</li> <li class="p2">Experience assessing cloud-managed AI ecosystems and foundation model platforms (e.g., AWS Bedrock, AWS SageMaker, Hugging Face Enterprise, or self-hosted open-source models).</li> <li class="p2">Understanding of data protection, access controls, and boundary security for RAG pipelines and vector databases (e.g., OpenSearch Vector Engine, Pinecone, Milvus, or PostgreSQL pgvector).</li> <li class="p2">Familiarity evaluating risks unique to LLMs—including prompt injection, data poisoning, model inversion, insecure output handling, and open-source supply chain vulnerabilities in AI libraries (PyTorch, LangChain, LlamaIndex).</li> <li class="p2">Exposure to LLM guardrail platforms, evaluation frameworks, or AI security tools (e.g., Promptfoo, Garak, Giskard, NeMo Guardrails) used to test model robustness and output safety.</li> <li class="p2">Experience with cATO methodologies, Infrastructure as Code (IaC) templates (Terraform, CloudFormation), and container security (AWS EKS/ECS, Docker).</li> <li class="p2">Active AWS Certifications (e.g., AWS Certified Security – Specialty or AWS Certified Solutions Architect).</li> <li class="p2">Background or familiarity with offensive security, penetration testing</li> </ul> <p>The salary range for this position is estimated to be between $135,000.00 - $160,000.00, commensurate on experience and technical skillset.</p> <p><span style="font-weight: 400;">We are proud to be an EEO/AA employer Minorities/Women/Veterans/Disabled and other protected categories.</span></p> <p>In compliance with federal law, all persons hired will be required to verify identity, confirm US Citizenship, and complete the required employment eligibility verification upon hire.</p> <p><span style="font-weight: 400;">We are strictly looking for direct, full-time W2 employees. We do not engage with third-party staffing agencies, C2C, or 1099 independent contractors for this role.</span></p>