1

Lead Security Control Assessor Jobs (NOW HIRING)

Lead Control Implementation Review and Test (CIRT) procedures and system-level security assessments to evaluate the adequacy of technical, operational, and management security controls * Provide ...

We are seeking a highly skilled Security Control Assessor (SCA) to support independent cybersecurity assessments of systems in accordance with the Risk Management Framework (RMF). This role is ...

Security Control Assessor

Arlington, VA · On-site

$110K - $130K/yr

Argo Cyber Systems is seeking a RMF/ Security Control Assessor to support cybersecurity governance, risk, compliance, and modernization activities in federal environments. The selected candidate will ...

Security Control Assessor

Alexandria, VA · On-site

$137K - $152K/yr

M9 Solutions is seeking a Security Control Assessor to work on-site in support of a government contract for a client located in Alexandria, VA . An active Secret clearance is required.

ORA_ON_SITE Description SAIC is seeking a highly skilled and motivated  Senior Security Control Assessor (SCA)  to support the cybersecurity assessment and compliance needs of mission-critical ...

next page

Showing results 1-20

Lead Security Control Assessor information

See salary details

$8

$58

$78

How much do lead security control assessor jobs pay per hour?

As of Aug 21, 2026, the average hourly pay for lead security control assessor in the United States is $58.77, according to ZipRecruiter salary data. Most workers in this role earn between $50.48 and $68.03 per hour, depending on experience, location, and employer.

What is a lead security control assessor?

A Lead Security Control Assessor is a cybersecurity professional responsible for evaluating and validating the effectiveness of security controls within an organization’s information systems. They lead assessment teams, conduct security control assessments, and ensure compliance with relevant frameworks such as NIST RMF (Risk Management Framework). Their work is crucial for identifying vulnerabilities, recommending mitigations, and ensuring that an organization meets federal or industry security requirements. Lead Security Control Assessors also prepare assessment reports and advise stakeholders on improving security posture.

What are the key skills and qualifications needed to thrive as a lead security control assessor?

To thrive as a Lead Security Control Assessor, you need expertise in information security frameworks, risk management, and compliance, typically supported by a bachelor’s degree in cybersecurity or a related field and certifications like CISSP or CISA. Familiarity with assessment tools such as NIST RMF, eMASS, and vulnerability scanning platforms is essential. Strong analytical thinking, attention to detail, and clear communication skills set top assessors apart when evaluating and reporting on security controls. These competencies are crucial for ensuring organizations maintain robust security postures and comply with regulatory requirements.

How does a lead security control assessor typically collaborate with other cybersecurity and compliance teams during an assessment?

A Lead Security Control Assessor frequently works alongside system owners, IT security staff, and compliance officers to evaluate and validate the effectiveness of security controls. Collaboration often involves conducting interviews, reviewing documentation, and coordinating testing activities to ensure all stakeholders are aligned with security requirements. Strong communication and teamwork are essential, as assessors must clearly explain findings, provide actionable recommendations, and support remediation efforts throughout the assessment lifecycle.

What is the difference between Lead Security Control Assessor vs Security Control Assessor?

AspectLead Security Control AssessorSecurity Control Assessor
CertificationsCISA, CISSP, or similarCISA, CISSP, or similar
Work EnvironmentLeads assessment teams, manages projectsPerforms assessments under supervision
Employer & IndustryGovernment agencies, contractorsGovernment agencies, contractors
Search & Comparison IntentUnderstanding leadership roles in assessmentsUnderstanding assessment responsibilities

The main difference is that the Lead Security Control Assessor manages and oversees assessment teams, while the Security Control Assessor performs the assessments. The lead role involves leadership, planning, and coordination, whereas the assessor focuses on executing security evaluations based on established standards.

More about Lead Security Control Assessor jobs

What job categories do people searching Lead Security Control Assessor jobs look for?

The top searched job categories for Lead Security Control Assessor jobs are:

Infographic showing various Lead Security Control Assessor job openings in the United States as of August 2026, with employment types broken down into 88% Full Time, 9% Part Time, and 3% Contract. Highlights an 90% Physical, 3% Hybrid, and 7% Remote job distribution, with an average salary of $122,236 per year, or $58.8 per hour.

Security Control Assessor

Crest Security Assurance

Petersburg, VA • On-site

$90K - $95K/yr

Full-time

Posted 21 days ago


Job description

Support the Defense Contract Management Agency (DCMA) Cybersecurity Support Services (CSS) contract by independently assessing security controls for classified and unclassified information systems. Plan and execute security control assessments in accordance with DoDI 8510.01, the DoD Risk Management Framework (RMF), NIST SP 800-53, and NIST SP 800-53A, and provide objective evidence and risk-based recommendations to support authorization decisions and continuous monitoring.


Responsibilities:

• Develop and execute Security Assessment Plans (SAPs), including assessment scope, methodology, procedures, schedules, and evidence requirements, in coordination with system owners, Information System Security Officers (ISSOs), Information System Security Managers (ISSMs), and Authorizing Official staff.

• Assess implemented technical, operational, and management security controls through documentation review, interviews, observation, testing, and analysis of artifacts such as vulnerability scan results, Security Technical Implementation Guide (STIG) checklists, configuration baselines, and continuous monitoring records.

• Document assessment results, findings, and residual risk in Security Assessment Reports (SARs), Security Control Assessment Reports (SCARs), Risk Assessment Reports (RARs), and related RMF artifacts; validate that findings are accurate, traceable, and supported by sufficient evidence.

• Review Plans of Action and Milestones (POA&Ms) and remediation evidence, evaluate proposed mitigations, and perform closure validation or follow-up testing to confirm that identified weaknesses have been effectively addressed.

• Maintain assessment results, control status, evidence, and authorization documentation in the Enterprise Mission Assurance Support Service (eMASS); track assessment activities and provide status, risk, and performance metrics to DCMA leadership.


Requirements:

• Active Secret security clearance

• At least 5-7 years of related cybersecurity, RMF, security control assessment, or information assurance experience

• DoD IAM III required certification(s) (one of the following):

  • CISM
  • CISSP (or Associate)
  • GSLC
  • CCISO