1

Fisma Security Control Assessor Jobs (NOW HIRING)

Execute a security control assessment plan and update the System Security Plan * Review ... Implement risk management programs by utilizing NIST, FISMA, HIPAA, and PII -- and document ...

Conduct FISMA security control assessments in accordance with NIST SP 800-53 and NIST SP 800-53A * Support system authorization efforts across the RMF lifecycle * Perform control testing, interviews ...

Conduct FISMA security control assessments in accordance with NIST SP 800-53 and NIST SP 800-53A * Support system authorization efforts across the RMF lifecycle * Perform control testing, interviews ...

next page

Showing results 1-20

Fisma Security Control Assessor information

See salary details

$8

$58

$78

How much do fisma security control assessor jobs pay per hour?

As of Sep 15, 2026, the average hourly pay for fisma security control assessor in the United States is $58.77, according to ZipRecruiter salary data. Most workers in this role earn between $50.48 and $68.03 per hour, depending on experience, location, and employer.

What are popular job titles related to Fisma Security Control Assessor jobs?

For Fisma Security Control Assessor jobs, the most frequently searched job titles are:

Infographic showing various Fisma Security Control Assessor job openings in the United States as of August 2026, with employment types broken down into 1% As Needed, 75% Full Time, 20% Part Time, 3% Contract, and 1% Nights. Highlights an 95% Physical, 1% Hybrid, and 4% Remote job distribution, with an average salary of $122,236 per year, or $58.8 per hour.

(736) Security Control Assessor

Arlington, VA • On-site

Arlo Solutions LLC
IT Services • 1 - 10 employees

Full-time

Posted 5 days ago


Job description

Position Description:

The Security Control Assessor (SCA) will be responsible for evaluating and assessing the security controls of Defense Security Cooperation Agency's (DSCA) information systems. This role involves conducting comprehensive assessments to ensure compliance with federal cybersecurity standards and providing recommendations to improve the agency's security posture.

Clearance:  Active Secret Clearance

Work Location:  Arlington, VA

Responsibilities and/or Success Factors: 

  • Conduct thorough assessments of security controls on DSCA's information systems and networks to ensure compliance with federal regulations, including NIST, FISMA, and DoD directives. 
  • Develop and maintain assessment documentation, including Security Assessment Plans (SAPs), Security Assessment Reports (SARs), and Plan of Action and Milestones (POA&Ms). 
  • Perform risk assessments to identify potential security threats and vulnerabilities. 
  • Provide detailed recommendations to mitigate identified risks and enhance the security posture of DSCA's information systems. 
  • Collaborate with system owners, IT staff, and cybersecurity teams to ensure effective implementation of security controls. 
  • Conduct continuous monitoring activities to ensure ongoing compliance with security policies and procedures. 
  • Provide guidance on the security assessment and authorization (A&A) process, including developing and maintaining System Security Plans (SSPs).
  • Assist in the development and delivery of cybersecurity training and awareness programs for DSCA personnel. 
  • Stay current with the latest cybersecurity threats, trends, and technologies to continuously improve assessment methodologies and practices. 
  • Participate in security audits and reviews to ensure adherence to established security standards and best practices.


Minimum Qualifications Including Certificates:

  • Must be a US Citizen. 
  • Must have a Secret Clearance 
  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field (Master's degree preferred). 
  • Minimum of 5 years of experience in information security, with a focus on security control assessment and risk management. 
  • Certifications such as CISSP, CISM, CISA, CAP, or equivalent are highly desirable. 
  • In-depth knowledge of federal cybersecurity regulations and standards, including NIST SP 800 series and FISMA. 
  • Proven experience in conducting security control assessments and developing security assessment documentation. 
  • Excellent analytical, problem-solving, and decision-making skills. 
  • Strong communication and interpersonal skills, with the ability to effectively communicate complex cybersecurity concepts to technical and non-technical stakeholders. 
  • Ability to work independently and collaboratively in a fast-paced environment.

Desired Qualifications: 

  • eMASS, cloud, STIGS experience