Dark Wolf Solutions is seeking Security Control Assessor/Representatives (SCA/Rs) to lead security control assessments across high-priority projects. Working at the intersection of cybersecurity engineering, cloud architecture, and DevSecOps prototyping, you will evaluate security controls for cutting-edge AI/LLM technologies across multiple classification levels. This position is ideal for a pragmatic cloud assessor or SCAR who excels in fast-paced DevSecOps environments, understands AWS cloud security, and is eager to shape the cybersecurity posture of next-generation DoD AI capabilities.This position will be based out of Arlington, VA. Additional responsibilities include:
Key Responsibilities
- Execute formal SCA/R duties.
- Lead security assessment efforts, establishing reusable security playbooks and assessment frameworks for rapid AI deployment into enterprise workflows.
- Evaluate technical control effectiveness across AWS cloud infrastructure, DevSecOps pipelines, microservices, containerized workloads, and GenAI/LLM application stacks.
- Partner directly with cybersecurity engineering and DevSecOps prototyping teams to integrate security controls early in the development lifecycle.
- Review, author, and maintain assessment packages—including System Security Plans (SSPs), Security Assessment Plans (SAPs), Security Assessment Reports (SARs), and POA&Ms—tailored to rapid prototyping and AI systems.
- Assess technical security risks specific to AI/LLM implementations, such as API exposure, vector database access controls, model integration surface area, and software supply chain dependencies.
- Support continuous monitoring (ConMon), technical risk evaluations, and cloud architecture reviews across multi-tenant, multi-classification environments.
- Coordinate with Authorizing Officials (AOs), program managers, and engineering leads to deliver decision-ready risk briefings and ATO recommendations.
- Provide technical input and oversight for cybersecurity engineering and penetration testing activities across prototype projects.
Required Qualifications
Active Top Secret security clearance
- Current DoD 8570/8140 IAM Level II or Level III certification (e.g., Security+, CySA+, CISM, CISSP, CCISO, CAP/CISC)
- 3–5+ years of experience conducting security control assessments, compliance testing, or A&A/RMF activities for DoD or federal information systems
- Solid operational understanding of core AWS cloud services (EC2, S3, IAM, VPCs, Security Groups, Security Hub) and how security controls function within cloud-native and CI/CD pipeline environments.
- Strong working knowledge of NIST SP 800-53 (Rev. 4/5), NIST SP 800-37 (RMF), DoD Cloud Computing SRG, and FedRAMP baselines.
- Demonstrated experience writing and evaluating core RMF artifacts (SSPs, SAPs, SARs, POA&Ms)
- Exceptional written and verbal communication skills, with the ability to articulate technical risk clearly to executive stakeholders, Authorizing Officials, and engineering teams.
- Hands-on experience navigating government GRC repositories, such as eMASS or XACTA.
Desired Qualifications
- Hands-on experience mapping security controls to the NIST AI Risk Management Framework (AI RMF), the OWASP Top 10 for LLM Applications, or the DoD Responsible AI (RAI) Guidelines.
- Familiarity evaluating secure design patterns for autonomous AI Agents (e.g., tool-calling permissions, sandboxing agent execution environments, prompt boundaries, and ReAct/LangGraph architectures).
- Experience assessing cloud-managed AI ecosystems and foundation model platforms (e.g., AWS Bedrock, AWS SageMaker, Hugging Face Enterprise, or self-hosted open-source models).
- Understanding of data protection, access controls, and boundary security for RAG pipelines and vector databases (e.g., OpenSearch Vector Engine, Pinecone, Milvus, or PostgreSQL pgvector).
- Familiarity evaluating risks unique to LLMs—including prompt injection, data poisoning, model inversion, insecure output handling, and open-source supply chain vulnerabilities in AI libraries (PyTorch, LangChain, LlamaIndex).
- Exposure to LLM guardrail platforms, evaluation frameworks, or AI security tools (e.g., Promptfoo, Garak, Giskard, NeMo Guardrails) used to test model robustness and output safety.
- Experience with cATO methodologies, Infrastructure as Code (IaC) templates (Terraform, CloudFormation), and container security (AWS EKS/ECS, Docker).
- Active AWS Certifications (e.g., AWS Certified Security – Specialty or AWS Certified Solutions Architect).
- Background or familiarity with offensive security, penetration testing
- The salary range for this position is estimated to be between $135,000.00 - $150,000.00, commensurate on experience and technical skillset.
- We are proud to be an EEO/AA employer Minorities/Women/Veterans/Disabled and other protected categories.
- In compliance with federal law, all persons hired will be required to verify identity, confirm US Citizenship, and complete the required employment eligibility verification upon hire.
- We are strictly looking for direct, full-time W2 employees. We do not engage with third-party staffing agencies, C2C, or 1099 independent contractors for this role.
