1

Cyber Security Assessor Jobs (NOW HIRING)

Manager, Cyber Security

Reston, VA · Remote

$115K - $156K/yr

Develop, maintain, and coordinate cybersecurity assessment documentation, including FIPS 199 analyses, E-Authentication Risk Assessments, security control implementation statements, and supporting ...

Manager, Cyber Security

Reston, VA · On-site

$115K - $156K/yr

Develop, maintain, and coordinate cybersecurity assessment documentation, including FIPS 199 analyses, E-Authentication Risk Assessments, security control implementation statements, and supporting ...

1. ISO/SAE 21434 Cybersecurity Assessment (Edge Analytics) o Perform a gap assessment of the Edge Analytics solution (device, cloud, data/ML components) against ISO/SAE 21434. o Identify ...

We are seeking a highly skilled Security Control Assessor (SCA) to support independent cybersecurity assessments of systems in accordance with the Risk Management Framework (RMF). This role is ...

Responsibilities : • Perform a variety of cyber security implementation and/or assessment activities involving power plant upgrades and/or new power plant projects. • Assist with planning ...

next page

Showing results 1-20

Cyber Security Assessor information

See salary details

$8

$58

$78

How much do cyber security assessor jobs pay per hour?

As of Jun 16, 2026, the average hourly pay for cyber security assessor in the United States is $58.77, according to ZipRecruiter salary data. Most workers in this role earn between $50.48 and $68.03 per hour, depending on experience, location, and employer.

What is a cyber security assessor?

A cyber security assessor is a professional responsible for evaluating an organization's security measures, identifying vulnerabilities, and ensuring compliance with security standards. They often use tools like vulnerability scanners and may hold certifications such as CISSP or CEH to perform risk assessments and recommend improvements.

What are the key skills and qualifications needed to thrive as a Cyber Security Assessor, and why are they important?

To thrive as a Cyber Security Assessor, you need a robust understanding of cybersecurity frameworks, risk assessments, and information security principles, often backed by a degree in computer science or information security and relevant certifications like CISSP or CISA. Familiarity with vulnerability assessment tools, penetration testing software, and compliance management systems is typically required. Strong analytical thinking, attention to detail, and effective communication skills set top performers apart in this role. These skills and qualifications are crucial for accurately identifying security gaps, advising on remediation, and ensuring organizational compliance with industry standards.

What is the 80 20 rule in cyber security?

In cybersecurity, the 80/20 rule suggests that approximately 80% of security issues are caused by 20% of vulnerabilities or threats. Cybersecurity assessors focus on identifying and mitigating these critical vulnerabilities to improve overall security posture efficiently.

Can you make $500,000 a year in cyber security?

Cyber Security Assessors typically earn salaries ranging from $70,000 to $150,000 annually, depending on experience, certifications, and location. Reaching a $500,000 annual income usually requires advanced roles such as senior security consultants, security architects, or executive positions, often combined with bonuses, profit sharing, or consulting fees. High earnings in cybersecurity generally involve extensive expertise, specialized skills, and leadership responsibilities.

What does a Cyber Security Assessor do?

A Cyber Security Assessor is responsible for evaluating an organization's information systems and networks to identify vulnerabilities, assess risks, and ensure compliance with security standards. They conduct security assessments, audits, and penetration tests to detect potential threats and recommend improvements to strengthen the organization’s cyber defenses. Their work helps organizations protect sensitive data and maintain the integrity, confidentiality, and availability of their digital assets.

Is SOC an entry level job?

A Security Operations Center (SOC) analyst role is often considered an entry-level position in cybersecurity, suitable for individuals with foundational knowledge of security principles, network protocols, and security tools. However, some SOC roles may require prior experience or certifications like CompTIA Security+ or Certified SOC Analyst (CSA).

What is the difference between Cyber Security Assessor vs Cyber Security Analyst?

AspectCyber Security AssessorCyber Security Analyst
CertificationsISO 27001 Lead Auditor, CISSP, CEHCISSP, CompTIA Security+, CEH
Work EnvironmentAudit and compliance settings, consulting firmsSecurity operations centers, IT departments
Employer & IndustryOrganizations seeking compliance, consulting firmsBusinesses with IT security teams, government agencies
Primary FocusAssessing security controls, compliance auditsMonitoring security threats, incident response

The main difference is that a Cyber Security Assessor focuses on evaluating security controls and ensuring compliance with standards, often through audits. In contrast, a Cyber Security Analyst actively monitors and responds to security threats within an organization. Both roles require relevant certifications but serve different functions within cybersecurity teams.

What are some common challenges faced by Cyber Security Assessors during security audits?

Cyber Security Assessors often encounter challenges such as limited access to system documentation, resistance from staff during interviews, or time constraints when performing comprehensive assessments. Navigating complex and rapidly changing IT environments can also make it difficult to identify all vulnerabilities. Successful assessors use strong communication skills to build trust with stakeholders and prioritize findings to ensure critical risks are addressed first.
More about Cyber Security Assessor jobs
What cities are hiring for Cyber Security Assessor jobs? Cities with the most Cyber Security Assessor job openings:
What states have the most Cyber Security Assessor jobs? States with the most job openings for Cyber Security Assessor jobs include:
Infographic showing various Cyber Security Assessor job openings in the United States as of June 2026, with employment types broken down into 97% Full Time, and 3% Contract. Highlights an 92% Physical, 3% Hybrid, and 5% Remote job distribution, with an average salary of $122,236 per year, or $58.8 per hour.
Lead Cybersecurity Assessment Engineer with Security Clearance

Lead Cybersecurity Assessment Engineer with Security Clearance

MITRE Corporation

Lexington Park, MD • Hybrid

Other

Posted 10 days ago


Job description

Why choose between doing meaningful work and having a fulfilling life? At MITRE, you can have both. That's because MITRE people are committed to tackling our nation's toughest challenges-and we're committed to the long-term well-being of our employees. MITRE is different from most technology companies. We are a not-for-profit corporation chartered to work for the public interest, with no commercial conflicts to influence what we do. The R&D centers we operate for the government create lasting impact in fields as diverse as cybersecurity, healthcare, aviation, defense, and enterprise transformation. We're making a difference every day-working for a safer, healthier, and more secure nation and world. Our workplace reflects our values. We offer competitive benefits, exceptional professional development opportunities for career growth, and a culture of innovation that embraces adaptability, collaboration, technical excellence, and people in partnership. If this sounds like the choice you want to make, then choose MITRE - and make a difference with us. The Cyber Solutions Innovation Center creates solutions using threat-informed cybersecurity approaches to enhance the security, safety, and resiliency of critical cyber systems and infrastructure. The Cyber Assessments and Security Automation department serves as MITRE's resource for cyber risk evaluation and security innovation. Our team is dedicated to advancing the field of cybersecurity by combining deep expertise in risk assessment with cutting-edge automation technologies. This dual focus enables us to address the evolving needs of our sponsors, ensuring scalable and effective cybersecurity solutions that meet today's challenges and anticipate tomorrow's threats. Our work is defined by innovation, exemplified through initiatives like SAF, ECHO, and ACT, which demonstrate our commitment to developing transformative tools and methodologies. By leveraging automation, we empower organizations to enhance their security posture efficiently and effectively, positioning them to stay ahead in an increasingly complex cyber landscape. The Cyber Assessments and Security Automation department reflects MITRE's leadership in cybersecurity, making our value clear to sponsors and internal stakeholders alike. We don't just assess risks; we innovate solutions that drive the future of cybersecurity. The Cyber Assessments and Security Automation department within the Cyber Solutions Innovation Center is seeking a Lead level Cybersecurity Assessment Engineer to lead the department's contributions across our portfolios. The department supports all of MITRE by providing a variety of cyber assessment products plus overall cyber engineering skills. The Lead Cybersecurity Assessment Engineer position will be a core member of the department and government technical team and serve as the first-line support for various sponsors. The position requires direct contributions to our diverse work programs. Roles & Responsibilities: * Expertise conducting cybersecurity assessments and workshops for government agencies.
* Develop and implement security strategies, and provide mentorship to junior assessors.
* Cybersecurity Risk Management: Expert knowledge of cybersecurity risk management frameworks and methodologies.
* Vulnerability Assessment & Penetration Testing: Conduct vulnerability assessments, penetration testing, and ethical hacking of applications and systems to identify and remediate security weaknesses.
* Security Controls Assessment: Conduct Security Controls Assessments (SCA), workshops, and audits for internal teams and partner organizations.
* Security Tools Utilization: Utilize a variety of security tools-including Burp Suite, Nessus, Splunk, QRadar, WireShark, eMASS, and others-to support security operations and assessments.
* Contribute technically to one or more Sponsor tasks.
* Collaborate effectively with MITRE, government, and contractors; effectively communicate in writing, presentations, and collaborative discussions; and interface with peers, managers, and sponsors.
* Promote collaboration and integration with other organizational elements within the department and across MITRE. Basic Qualifications: * Requires a minimum of 8 years of related experience with a Bachelor's degree; or 6 years and a Master's degree; or a PhD with 3 years' experience; or equivalent combination of related education and work experience.
* Experience with RMF, NIST SP-800 series, and Security Controls Assessment (SCA).
* Experience in software engineering and systems engineering, including requirements analysis and technical writing.
* Familiarity with Windows, Linux, macOS/Open BSD, and VxWorks/Tornado operating systems.
* Proficiency in programming languages including Java, C#, C++, Python, Perl, Visual Basic, ASP.NET, PHP, COBOL.
* Certifications: CISSP, Certified Ethical Hacker (CEH), Network+, AWS Certified Cloud Practitioner.
* This position requires a minimum of 50% hybrid on-site * Must be able to successfully obtain a Top-Secret clearance within one year of hire.
* Per the U.S. Government's eligibility requirements, you must be a U.S Citizen to be considered for a security clearance Preferred Qualifications: * Active Top Secret Security Clearance.
* Graduate-level degree in a technical discipline (Cybersecurity, Information Assurance, etc.).
* 12 years related experience as a cybersecurity analyst/systems engineer.
* Experience with advanced assessment techniques utilizing Kali Linux, Burp Suite, Wireshark, etc.
* Experience with various Security Information and Event Management (SIEM) platforms (Splunk, QRadar, Tenable products, etc.)
* Experience with offensive and defensive cybersecurity operations, including penetration testing
* Experience with various Information Technology (IT) operations in enterprise environments including system integration, device/network hardening, server administration, network maintenance, etc.
* Certified Information Systems Security Professional (CISSP)
* GIAC Penetration Tester (GPEN), GIAC Certified Intrusion Analyst (GCIA)
* CompTIA Security+, CompTIA Network+, CompTIA Linux+ This requisition requires the candidate to have a minimum of the following clearance(s):
None This requisition requires the hired candidate to have or obtain, within one year from the date of hire, the following clearance(s):
Top Secret Salary compensation range and midpoint:
$158,800 - $198,500 - $238,200 Annual Work Location Type:
Hybrid Commitment to Non-Discrimination All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, local or international law. MITRE intends to maintain a website that is fully accessible to all individuals. If you are unable to search or apply for jobs and would like to request a reasonable accommodation for any part of MITRE's employment process, please email for general support and for intern positions. This service is for individuals requiring reasonable accommodation requests. Please note that vendor solicitations will not receive a reply. Benefits information may be found here . Copyright © 1997-2026, The MITRE Corporation. All rights reserved. MITRE is a registered trademark of The MITRE Corporation. Material on this site may be copied and distributed with permission only.

MITRE logo

About MITRE

Sourced by ZipRecruiter

Why choose between doing meaningful work and having a fulfilling life? At MITRE, you can have both. That's because MITRE people are committed to tackling our nation's toughest challenges-and we're committed to the long-term well-being of our employees. MITRE is different from most technology companies. We are a not-for-profit corporation chartered to work for the public interest, with no commercial conflicts to influence what we do. The R&D centers we operate for the government create lasting impact in fields as diverse as cybersecurity, healthcare, aviation, defense, and enterprise transformation. We're making a difference every day-working for a safer, healthier, and more secure nation and world. Our workplace reflects our values. We offer competitive benefits, exceptional professional development opportunities, and a culture of innovation that embraces diversity, inclusion, flexibility, collaboration, and career growth. If this sounds like the choice you want to make, then choose MITRE-and make a difference with us. MITRE is a trusted operator of federally funded research and development centers and we're on a mission to make the world a safer place-for all of humanity, today and in the future. To deliver on our mission, we need the world's best talent and leaders-groundbreakers and partnership-builders on a global scale in areas like healthcare, artificial intelligence, critical infrastructure resiliency, pandemic management, and cybersecurity. In return, we have the privilege of backing you with thousands of technical experts in diverse fields, a culture of innovation and knowledge sharing, access to data and resources uniquely available to MITRE through our wide-ranging partnerships across government, industry and academia.

Industry

It services

Company size

5,001 - 10,000 Employees

Headquarters location

McLean, VA, US

Year founded

1958

Social media