1

Lead Security Control Assessor Jobs (NOW HIRING)

Lead Control Implementation Review and Test (CIRT) procedures and system-level security assessments to evaluate the adequacy of technical, operational, and management security controls * Provide ...

Execute a security control assessment plan and update the System Security Plan * Review vulnerability scans and remediation * Implement risk management programs by utilizing NIST, FISMA, HIPAA, and ...

Security Control Assessor

Alexandria, VA · On-site

$137K - $152K/yr

M9 Solutions is seeking a Security Control Assessor to work on-site in support of a government contract for a client located in Alexandria, VA . An active Secret clearance is required.

TSA is currently seeking a Senior Security Control Assessor who will serve as a Functional Lead and provide support to our NAVAIR customer in the DC Metro area. Roles/Responsibilities: Leads ...

Security Control Assessor

Monterey, CA · On-site

$65K - $75K/yr

Security Control Assessor Target Salary: $65K to $75K LOCATION: DLIFLC, 1759 Lewis Road, Monterey, CA 93944 Position Overview: The Security Control Assessor is responsible for conducting independent ...

Security Control Assessor

Monterey, CA · On-site

$65K - $75K/yr

Security Control Assessor Target Salary: $65K to $75K LOCATION: DLIFLC, 1759 Lewis Road, Monterey, CA 93944 Position Overview: The Security Control Assessor is responsible for conducting independent ...

Execute a security control assessment plan and update the System Security Plan * Review vulnerability scans and remediation * Implement risk management programs by utilizing NIST, FISMA, HIPAA, and ...

As a Senior Security Control Assessor, you will provide senior-level security control assessment support to a Department of Defense (DoD) customer supporting the F-35 Joint Program Office (JPO ...

Security Control Assessor

Monterey, CA · On-site

$65K - $75K/yr

The Security Control Assessor is responsible for conducting independent, comprehensive assessments of the management, operational, and technical security controls and control enhancements within or ...

Security Control Assessor

Alexandria, VA · On-site

$146K - $234K/yr

Execute a security control assessment plan and update the System Security Plan * Review vulnerability scans and remediation * Implement risk management programs by utilizing NIST, FISMA, HIPAA, and ...

You'll work under a senior assessor and help evaluate security control implementation, validate evidence, and document results in alignment with NIST Risk Management Framework (RMF) and NIST SP 800 ...

Showing results 21-40

Lead Security Control Assessor information

See salary details

$8

$58

$78

How much do lead security control assessor jobs pay per hour?

As of Aug 21, 2026, the average hourly pay for lead security control assessor in the United States is $58.77, according to ZipRecruiter salary data. Most workers in this role earn between $50.48 and $68.03 per hour, depending on experience, location, and employer.

What is a lead security control assessor?

A Lead Security Control Assessor is a cybersecurity professional responsible for evaluating and validating the effectiveness of security controls within an organization’s information systems. They lead assessment teams, conduct security control assessments, and ensure compliance with relevant frameworks such as NIST RMF (Risk Management Framework). Their work is crucial for identifying vulnerabilities, recommending mitigations, and ensuring that an organization meets federal or industry security requirements. Lead Security Control Assessors also prepare assessment reports and advise stakeholders on improving security posture.

What are the key skills and qualifications needed to thrive as a lead security control assessor?

To thrive as a Lead Security Control Assessor, you need expertise in information security frameworks, risk management, and compliance, typically supported by a bachelor’s degree in cybersecurity or a related field and certifications like CISSP or CISA. Familiarity with assessment tools such as NIST RMF, eMASS, and vulnerability scanning platforms is essential. Strong analytical thinking, attention to detail, and clear communication skills set top assessors apart when evaluating and reporting on security controls. These competencies are crucial for ensuring organizations maintain robust security postures and comply with regulatory requirements.

How does a lead security control assessor typically collaborate with other cybersecurity and compliance teams during an assessment?

A Lead Security Control Assessor frequently works alongside system owners, IT security staff, and compliance officers to evaluate and validate the effectiveness of security controls. Collaboration often involves conducting interviews, reviewing documentation, and coordinating testing activities to ensure all stakeholders are aligned with security requirements. Strong communication and teamwork are essential, as assessors must clearly explain findings, provide actionable recommendations, and support remediation efforts throughout the assessment lifecycle.

What is the difference between Lead Security Control Assessor vs Security Control Assessor?

AspectLead Security Control AssessorSecurity Control Assessor
CertificationsCISA, CISSP, or similarCISA, CISSP, or similar
Work EnvironmentLeads assessment teams, manages projectsPerforms assessments under supervision
Employer & IndustryGovernment agencies, contractorsGovernment agencies, contractors
Search & Comparison IntentUnderstanding leadership roles in assessmentsUnderstanding assessment responsibilities

The main difference is that the Lead Security Control Assessor manages and oversees assessment teams, while the Security Control Assessor performs the assessments. The lead role involves leadership, planning, and coordination, whereas the assessor focuses on executing security evaluations based on established standards.

More about Lead Security Control Assessor jobs

What job categories do people searching Lead Security Control Assessor jobs look for?

The top searched job categories for Lead Security Control Assessor jobs are:

Infographic showing various Lead Security Control Assessor job openings in the United States as of August 2026, with employment types broken down into 88% Full Time, 9% Part Time, and 3% Contract. Highlights an 90% Physical, 3% Hybrid, and 7% Remote job distribution, with an average salary of $122,236 per year, or $58.8 per hour.

Security Control Assessor

38North Security

Washington, DC • Remote

Full-time

Posted 5 days ago


Job description

38North Security is the world's most experienced, technically expert, cloud advisory team. Since the inception of cloud computing, we have helped organizations around the world take secure, compliant advantage of the cloud to power modern business. From tech start-ups to Fortune 500 companies, our impressive client portfolio includes government, major healthcare organizations, cloud service providers, and security vendors, with many at the forefront of innovation and disruptive technology. Our goal is to become the preeminent cloud security engineering and compliance advisory team, in the US and internationally, trusted by the world's most demanding cloud centric organizations. At 38North, you will work with the most elite, experienced FedRAMP and cloud security experts in the world. You will be expected to continuously advance your technical and consulting skills while contributing to corporate initiatives that support our rapid growth. In exchange, we offer competitive salaries (commensurate with experience), a fully remote, flexible work environment, and unlike larger companies in this space, reasonable billable hour expectations. Most importantly, you'll be joining a team-focused organization, helmed by leaders who have worked together for decades to advance security and compliance initiatives. Location Remote, but must be available to work Eastern Time hours. About the Role This role will conduct independent security assessments of government environments against NIST SP 800-53 rev 5 security control requirements. Systems assessed could include on premise, AWS cloud (Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and Software as a Service (SaaS) systems) and applications. Experience with assessing the entire control set for systems in the AWS cloud environment is required. Duties and Responsibilities Conduct assessment meetings independently for the entire control set Perform assessment of security controls, as documented in System Security Plan (SSP), for all security control families Conduct risk assessments based on findings of security controls assessments Develop Security Assessment Reports (SAR), document Plans of Action and Milestones (POA&Ms), and develop an Executive Summaries (ES) for each assessment Qualifications Minimum of 3 years of experience for junior-level role, and 8 years of experience for a senior-level, in listed tasks Four-year degree (Bachelor's Degree) from an accredited College or University in Business or Engineering - Education will be verified Minimum of 3 years of experience for junior-level role, and 8 years of experience for a senior-level, in listed tasks Must have or be eligible to obtain a Public Trust Clearance Assessor must be able to conduct assessment independently for all controls in the Low, Moderate, or High baseline. Technical Skills Experience with RMF and applying the NIST Cybersecurity Framework. Experience using JCAM in an RMF Assessor role. Solid understanding and application of NIST Special Publications including SP 800-53, SP 800-137, SP 800-171, and SP 800-37. Experience with Federal Risk and Authorization Management Program (FedRAMP). Experience with assessing systems and applications deployed in local and cloud environments following federal guidelines and best practices. Ability to work with cooperatively and at a technical level with developers, engineers, and managers on system teams. Knowledge of computer networking concepts, protocols, and network security methodologies. Knowledge of risk management processes and tools (e.g., methods and tools for assessing and mitigating risks). Knowledge of laws, regulations, policies, and ethics as they relate to cybersecurity and privacy in a federal environment. Knowledge of current and past cybersecurity threats and vulnerabilities. Familiarity with cloud environments (specifically AWS infrastructure and services) in addition to the AWS Console is a plus. Professional Skills Ability to effectively manage and prioritize multiple tasks and duties simultaneously, while effectively coordinating and ensuring that scheduled delivery dates and milestones are achieved. Able to communicate effectively in an accurate and concise manner through written and verbal means to system teams, and product and cybersecurity leadership. Ability to take initiative on assigned systems and related tasks and work with minimal supervision. Ability to work and collaborate as part of an integrated team with diverse backgrounds. Candidates will be asked to supply 3 references (one of which must be provide by a former or current client) and undergo a background check prior to employment. Candidates must be US citizens. Learn more about 38North at www.38northsecurity.com #J-18808-Ljbffr