1

Nist 800 53 Jobs (NOW HIRING)

PR · On-site

Nist Security Control Assessor We are currently seeking a NIST 800-53 Security Control Assessor interested in starting a rewarding career in public accounting by joining our Information Technology ...

• Support the Risk Management Framework (RMF) processes and system authorization lifecycle • Experience with GRC platforms (ServiceNow GRC) • Create systems baseline using NIST 800-53 security ...

We are seeking a skilled Senior Security Assurance Engineer to join our dynamic team and assess compliance to NIST 800-171, NIST 800-53, and CMMC standards. This role involves evaluating our security ...

Perform detailed control assessments in accordance with NIST 800-53 v5 and NIST 800-37 , ensuring compliance with FISMA requirements. * Lead and manage the Security Assessment and Authorization (SA&A ...

Perform detailed control assessments in accordance with NIST 800-53 v5 and NIST 800-37 , ensuring compliance with FISMA requirements. * Lead and manage the Security Assessment and Authorization (SA&A ...

Develop and implement a formal NIST 800.53 control framework. * Expand and refine the Incident Response (IR) Runbook. * Align security strategies with business goals to optimize investments and ...

Senior GRC Analyst

Palo Alto, CA · On-site

$117K - $151K/yr

This role will lead FedRAMP readiness, authorization, and continuous monitoring activities in alignment with NIST 800-53 requirements, while also supporting broader compliance frameworks including ...

next page

Showing results 1-20

Nist 800 53 information

See salary details

$11

$16

$22

How much do nist 800 53 jobs pay per hour?

As of Aug 10, 2026, the average hourly pay for nist 800 53 in the United States is $16.60, according to ZipRecruiter salary data. Most workers in this role earn between $15.14 and $17.31 per hour, depending on experience, location, and employer.

What are some common challenges faced by professionals implementing NIST 800-53 controls in an organization?

Implementing NIST 800-53 controls often involves navigating complex organizational environments, where aligning security requirements with business processes can be challenging. Professionals must work closely with various departments to ensure buy-in and proper integration of controls, which may require significant change management and communication skills. Additionally, maintaining up-to-date documentation and demonstrating ongoing compliance during audits can be time-consuming, requiring attention to detail and strong organizational skills. Success in this role often relies on your ability to adapt controls to fit the unique needs and risk profile of your organization.

What are the key skills and qualifications needed to thrive as a NIST 800-53 security compliance specialist, and why are they important?

To thrive as a NIST 800-53 Security Compliance Specialist, you need a strong understanding of cybersecurity frameworks, risk management, and regulatory compliance, often backed by a degree in information security or a related field. Familiarity with compliance management tools, vulnerability scanning software, and certifications such as CISSP or CISA is typically expected. Attention to detail, analytical thinking, and effective communication are essential soft skills for interpreting controls and collaborating with technical and non-technical teams. These competencies ensure organizations maintain robust security postures and meet federal compliance standards.

What is the difference between Nist 800 53 vs Security Analyst?

AspectNist 800 53Security Analyst
Primary FocusDeveloping and implementing security controls based on NIST standardsMonitoring, analyzing, and responding to security incidents
CertificationsRisk Management Framework (RMF), CISSP, CISA often preferredCompTIA Security+, CISSP, GIAC certifications common
Work EnvironmentGovernment agencies, compliance-focused organizationsPrivate sector, cybersecurity teams
ResponsibilitiesCreating security policies, assessing controls, ensuring complianceThreat detection, incident response, vulnerability management

While Nist 800 53 involves establishing security controls based on federal standards, Security Analysts focus on monitoring and responding to security threats. Both roles require cybersecurity knowledge and certifications, but Nist 800 53 professionals typically work in compliance and policy development, whereas Security Analysts handle day-to-day security operations.

What is NIST 800-53?

NIST 800-53 is a publication from the National Institute of Standards and Technology (NIST) that provides a comprehensive set of security and privacy controls for federal information systems and organizations. Its main goal is to help organizations manage information security risk and ensure compliance with federal regulations. The controls in NIST 800-53 cover a wide range of areas, including access control, incident response, risk assessment, and system and communications protection. While it is primarily intended for U.S. federal agencies, many private sector organizations also use it as a best-practice framework.
More about Nist 800 53 jobs
What states have the most Nist 800 53 jobs? States with the most job openings for Nist 800 53 jobs include:
What job categories do people searching Nist 800 53 jobs look for? The top searched job categories for Nist 800 53 jobs are:
Infographic showing various Nist 800 53 job openings in the United States as of August 2026, with employment types broken down into 91% Full Time, 2% Part Time, and 7% Contract. Highlights an 79% Physical, 7% Hybrid, and 14% Remote job distribution, with an average salary of $34,527 per year, or $16.6 per hour.

NIST Security Control Assessor

Castro & Company, LLC

PR • On-site

Full-time

Re-posted 16 days ago


Job description

Nist Security Control Assessor
We are currently seeking a NIST 800-53 Security Control Assessor interested in starting a rewarding career in public accounting by joining our Information Technology (IT) practice to serve our federal clients. If you are dedicated and eager to grow your auditing career, we will provide you with a supportive team, resources, and training to succeed.
As a Security Control Assessor your responsibilities will include:
  • Perform independent assessments of security controls in accordance with NIST SP 800-53 and NIST SP 800-53A
  • Evaluate the design and operating effectiveness of technical, operational, and management controls across federal information systems
  • Develop and execute Security Assessment Plans (SAPs), including test procedures, sampling approaches, and evidence requirements
  • Conduct control testing activities (interviews, documentation review, and technical validation) in alignment with Risk Management Framework (RMF)
  • Analyze assessment results to identify control deficiencies, gaps, and risk exposures
  • Document findings with clear risk statements, root cause analysis, and recommended remediation actions
  • Prepare Security Assessment Reports (SARs) and present results to Authorizing Officials (AOs), system owners, and stakeholders
  • Support Authorization to Operate (ATO) processes, including control validation and continuous monitoring activities
  • Collaborate with system owners, ISSOs, and engineering teams to validate remediation efforts and perform re-testing
  • Maintain assessment documentation within GRC tools (e.g., ServiceNow)
  • Stay current with evolving federal cybersecurity requirements, including FISMA and OMB/NIST guidance
  • Contribute to audit readiness and compliance initiatives across client environments
Requirements:
  • Must have Bachelor’s Degree in an IT- related degree from an accredited school.
  • Must be able to obtain Security Clearance: Must be able to pass a basic government suitability check (US Citizenship required).
  • Must have 5-8 Years of technical experience NIST 800-53 assessments.
  • Must have strong knowledge and demonstrated understanding of NIST 800-53, security and privacy controls.
  • Must have strong analytical and problem-solving skills
  • Must have experience communicating technical findings to both technical and non-technical stakeholders
  • Must be detail-oriented with strong documentation and reporting skills
  • Must have experience working independently and collaboratively in a team environment
  • Certification (preferred) includes CISSP, Security+, CISA
Castro Puerto Rico is a Professional Services Center headquartered in San Juan, Puerto Rico, delivering advisory, accounting, audit and IT support services to Federal Government clients. We are dedicated to assisting our clients to accomplish their strategic goals while providing our people with a diverse and inclusive environment to thrive and succeed.
Castro Puerto Rico is an Equal Opportunity Employer and considers all qualified applicants without regard to color, religion, sex, sexual orientation, gender identity, national origin, veteran status, disability and any other classification protected by law.