1

Lead Security Control Assessor Jobs (NOW HIRING)

You'll work under a senior assessor and help evaluate security control implementation, validate evidence, and document results in alignment with NIST Risk Management Framework (RMF) and NIST SP 800 ...

You'll work under a senior assessor and help evaluate security control implementation, validate evidence, and document results in alignment with NIST Risk Management Framework (RMF) and NIST SP 800 ...

You'll work under a senior assessor and help evaluate security control implementation, validate evidence, and document results in alignment with NIST Risk Management Framework (RMF) and NIST SP 800 ...

You'll work under a senior assessor and help evaluate security control implementation, validate evidence, and document results in alignment with NIST Risk Management Framework (RMF) and NIST SP 800 ...

PR · On-site

Nist Security Control Assessor We are currently seeking a NIST 800-53 Security Control Assessor interested in starting a rewarding career in public accounting by joining our Information Technology ...

Security Control Assessor

Houston, TX · On-site

$61K - $141K/yr

Security Control Assessor The Opportunity: As a cyber mission specialist, you understand the value of hunt-forward operations, and you know that battles are won in the grey. At Booz Allen, you can ...

Security Control Assessor

Arlington, VA · On-site

$110K - $130K/yr

Security Control AssessorLocation: Arlington, VA (On-Site)Citizenship: US onlyClearance: Active TS/SCI (DHS EOD Suitability required)Company: Argo Cyber Systems, LLC - Service-Disabled Veteran-Owned ...

Security Control Assessor (SCA) LOCATION Chantilly, VA 20151 CLEARANCE TS/SCI Full Poly (Please note this position requires full U.S. Citizenship) KEY SUMMARY We are seeking a meticulous and detail ...

Showing results 41-60

Lead Security Control Assessor information

See salary details

$8

$58

$78

How much do lead security control assessor jobs pay per hour?

As of Aug 22, 2026, the average hourly pay for lead security control assessor in the United States is $58.77, according to ZipRecruiter salary data. Most workers in this role earn between $50.48 and $68.03 per hour, depending on experience, location, and employer.

What is a lead security control assessor?

A Lead Security Control Assessor is a cybersecurity professional responsible for evaluating and validating the effectiveness of security controls within an organization’s information systems. They lead assessment teams, conduct security control assessments, and ensure compliance with relevant frameworks such as NIST RMF (Risk Management Framework). Their work is crucial for identifying vulnerabilities, recommending mitigations, and ensuring that an organization meets federal or industry security requirements. Lead Security Control Assessors also prepare assessment reports and advise stakeholders on improving security posture.

What are the key skills and qualifications needed to thrive as a lead security control assessor?

To thrive as a Lead Security Control Assessor, you need expertise in information security frameworks, risk management, and compliance, typically supported by a bachelor’s degree in cybersecurity or a related field and certifications like CISSP or CISA. Familiarity with assessment tools such as NIST RMF, eMASS, and vulnerability scanning platforms is essential. Strong analytical thinking, attention to detail, and clear communication skills set top assessors apart when evaluating and reporting on security controls. These competencies are crucial for ensuring organizations maintain robust security postures and comply with regulatory requirements.

How does a lead security control assessor typically collaborate with other cybersecurity and compliance teams during an assessment?

A Lead Security Control Assessor frequently works alongside system owners, IT security staff, and compliance officers to evaluate and validate the effectiveness of security controls. Collaboration often involves conducting interviews, reviewing documentation, and coordinating testing activities to ensure all stakeholders are aligned with security requirements. Strong communication and teamwork are essential, as assessors must clearly explain findings, provide actionable recommendations, and support remediation efforts throughout the assessment lifecycle.

What is the difference between Lead Security Control Assessor vs Security Control Assessor?

AspectLead Security Control AssessorSecurity Control Assessor
CertificationsCISA, CISSP, or similarCISA, CISSP, or similar
Work EnvironmentLeads assessment teams, manages projectsPerforms assessments under supervision
Employer & IndustryGovernment agencies, contractorsGovernment agencies, contractors
Search & Comparison IntentUnderstanding leadership roles in assessmentsUnderstanding assessment responsibilities

The main difference is that the Lead Security Control Assessor manages and oversees assessment teams, while the Security Control Assessor performs the assessments. The lead role involves leadership, planning, and coordination, whereas the assessor focuses on executing security evaluations based on established standards.

More about Lead Security Control Assessor jobs

What job categories do people searching Lead Security Control Assessor jobs look for?

The top searched job categories for Lead Security Control Assessor jobs are:

Infographic showing various Lead Security Control Assessor job openings in the United States as of August 2026, with employment types broken down into 88% Full Time, 9% Part Time, and 3% Contract. Highlights an 90% Physical, 3% Hybrid, and 7% Remote job distribution, with an average salary of $122,236 per year, or $58.8 per hour.

Security Control Assessor

Boston Government Services, LLC

Oak Ridge, TN • On-site

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Re-posted 24 days ago


Job description

Boston Government Services, LLC. (BGS) has created this Evergreen Talent Pool post for gathering qualified candidates for a position relating to Security Control Assessor to support our clients.

BGS is an engineering, technology, and security firm helping to advance missions of national importance for government programs, national laboratories, national security facilities, nuclear operations, and complex projects. We support clients at every stage, from strategic planning and program management to the execution of engineering and technical activities. We work to attract and retain the best talent because the best talent delivers the best results for our clients. Our capabilities are based on our experience in complex, secure, and highly regulated environments. We leverage our experience and capabilities to provide mission-driven solutions tuned to our client's mission needs and strategic direction.

Work that Matters. People that Matter More. At BGS, we believe meaningful work starts with great people. We foster a culture built on respect, collaboration, and accountability—where employees are empowered to contribute ideas, grow professionally, and make an impact. We care about our employees’ well-being through competitive benefits, clear expectations, and an environment that values both excellence and connection.

If you align with BGS company values and culture, we would love for you to explore opportunities to join our growing team by checking out the job description below!

Responsibilities:

General understanding of cyber requirements. Ability to interpret cyber security plans for vendors to determine compliance with the National Institute of Standards and Technology (NIST) requirements. Ability to communicate with vendor IT and Cyber staff.

Requirements:

  • Working knowledge of NIST 800-171, NIST SP 800-53, NIST SP 800-53A.
  • Ability to assess and document assessment results for NIST SP 800-171 security controls.
  • Ability to aggregate risk for NIST SP 800-171 security controls into an overall risk assessment for a non-federal information system processing Controlled Unclassified Information (CUI) data.
  • Knowledge of cyber controls. Familiarity with Defense Federal Acquisition Regulation Supplement (DFARS) requirements for processing CUI data on non-federal information systems.
  • Must be U.S. citizen.
  • Successful drug screening.
  • Must have an Active Clearance: U.S. Department of Energy (DOE) Q clearance or an equivalent clearance from an agency such as the US Department of Defense (DOD), U.S. Department of State (DOS), U.S. Department of Justice (DOJ) Top Secret Clearance.

Preferred Qualifications:

  • Cybersecurity Maturity Model Certification (CMMC), Certification as Certified CMMC Professional (CCP), Certification as Certified CMMC Assessor (CCA), Training associated with the assessment of NIST security controls.

Location/Work Arrangement:

  • Schedule is full-time, Monday – Friday 40-hour week.


Benefits:

BGS offers a competitive total compensation package to eligible employees. Benefits include Health, Dental, Vision, Life Insurance, Paid Vacation, 401K, Long and Short-Term Disability.

EEO:

BGS is an Equal Opportunity/Affirmative Action employer. All qualified applicants are encouraged to apply and will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, or protected veteran status.

Exclusive Agreement Disclaimer:

BGS has standing contracts with federal agencies throughout the United States. We require an affirmative exclusive agreement to represent all candidates to our clients. By submitting this application, you are consenting to allow BGS to represent you as a candidate for the role in which you are applying.


Schedule is full-time, Monday – Friday 40-hour week.