2

Remote Security Control Assessor Jobs in New York

Senior Security Engineer

White Plains, NY · Remote

$118K - $162K/yr

... the remote workforce and field devices. * Reviewing application code, integrations, and system ... control evidence and working with external auditors or assessors. * Working knowledge of HIPAA ...

Senior Corporate Security Engineer

New York, NY · On-site +1

$125K - $171K/yr

This role can either be in-office or remote. Responsibilities Security Engineering & Control Design ... Assess and improve the security posture of corporate SaaS platforms, integrations, APIs and service ...

Manager Application Security

Iselin, NJ · On-site +1

$133K - $190K/yr

... 1 remote in one of the following organizational hubs: Johnston, RI - Westwood OR Boston, MA ... control requirements Partner with engineering leadership to embed security into architecture ...

Manager Application Security

Iselin, NJ · On-site +1

$133K - $190K/yr

... 1 remote in one of the following organizational hubs: Johnston, RI - Westwood OR Boston, MA ... control requirements Partner with engineering leadership to embed security into architecture ...

Security Architect, Product Security

New York, NY · On-site +1

$71 - $92/hr

Work Style Remote Candidates must reside in or be willing to relocate to one of the following ... Assess security risk and provide practical, risk-based remediation guidance to engineering teams.

Security Architect, Product Security

New York, NY · On-site +1

$71 - $92/hr

Work Style Remote Candidates must reside in or be willing to relocate to one of the following ... Assess security risk and provide practical, risk-based remediation guidance to engineering teams.

Job Title: Sr IDAM Security Architect (Remote) * Develop the overall strategy for the migration ... Proven ability to gather and assess business requirements, develop and present solution ...

Security Systems Design Engineer

Monroe, NJ · On-site +1

$105K - $130K/yr

... local, remote for other candidates. This role serves as both a technical expert and project ... Design and engineer access control, video surveillance, and visitor management systems for ...

Showing results 21-40

Remote Security Control Assessor information

See New York salary details

$9

$64

$85

How much do remote security control assessor jobs pay per hour?

As of Sep 6, 2026, the average hourly pay for remote security control assessor in New York is $64.29, according to ZipRecruiter salary data. Most workers in this role earn between $55.24 and $74.42 per hour, depending on experience, location, and employer.

What is a remote security control assessor?

A Remote Security Control Assessor evaluates and ensures that an organization's security controls comply with industry standards and regulations. They perform risk assessments, analyze security policies, and recommend improvements to enhance cybersecurity. Working remotely, they assess systems, review documentation, and collaborate with internal teams and stakeholders. Their goal is to identify vulnerabilities and ensure that security frameworks align with compliance requirements such as NIST, ISO 27001, or FedRAMP.

What does a remote security control assessor do?

A Remote Security Control Assessor typically reviews security policies, analyzes technical controls, and conducts risk assessments to ensure compliance with industry standards and client requirements. Daily tasks often include evaluating documentation, coordinating virtual meetings with stakeholders, preparing assessment reports, and recommending remediation actions for identified vulnerabilities. You’ll collaborate with IT teams, compliance officers, and management to gather evidence and share assessment findings. Strong organizational and communication skills are essential, as much of the work is self-directed and relies on effective remote coordination with clients and internal teams.

What are the key skills and qualifications needed to thrive as a remote security control assessor?

To thrive as a Remote Security Control Assessor, you need expertise in information security frameworks, risk assessment methodologies, and IT auditing, typically supported by a bachelor's degree in cybersecurity or a related field. Familiarity with assessment tools (like Nessus or NIST compliance checklists), experience with GRC (governance, risk, compliance) platforms, and relevant certifications such as CISSP or CISA are highly valued. Excellent analytical skills, attention to detail, and strong written and verbal communication abilities help remote assessors excel, especially when working independently or with cross-functional teams. These skills are critical for accurately evaluating security controls, ensuring regulatory compliance, and communicating findings effectively in a remote work environment.

What are popular job titles related to Remote Security Control Assessor jobs in New York?

For Remote Security Control Assessor jobs in New York, the most frequently searched job titles are:

What job categories do people searching Remote Security Control Assessor jobs in New York look for?

The top searched job categories for Remote Security Control Assessor jobs in New York are:

What cities in New York are hiring for Remote Security Control Assessor jobs?

Cities in New York with the most Remote Security Control Assessor job openings:

Infographic showing various Remote Security Control Assessor job openings in New York as of August 2026, with employment types broken down into 1% As Needed, 75% Full Time, 20% Part Time, 3% Contract, and 1% Nights. Highlights an 94% Physical, 1% Hybrid, and 5% Remote job distribution, with an average salary of $133,730 per year, or $64.3 per hour.

Senior Security Engineer

OnMed

White Plains, NY • Remote

$118K - $162K/yr

Full-time

PTO

Re-posted 11 days ago


Job description

Who We Are and Why Join Us

At OnMed our purpose is simple but powerful...to improve the quality of life and sense of well-being in our communities by bringing access to healthcare to everyone, everywhere. Our path to everywhere has already begun, with our innovative CareStation, a small but mighty, Clinic-in-a-Box, bringing #healthcareaccess anywhere with an outlet to plug it in. Poised to become a key component in America's public health infrastructure, the OnMed CareStation is the only tech-enabled, human-led, hybrid care solution that combines the comprehensive experience, trust and outcomes of a clinic, with the rapid scalability of virtual care.  
At OnMed, every role, everyday, is directly impacting the communities we serve. You'll join a high-performing purpose-driven team, innovating to break down the barriers that keep people from the care they need. 
This is not just a job...it's a movement to bring access to healthcare where and when people need it most. It's healthcare that shows up. 

Who You Are

You are a hands-on, deeply technical Security Engineer who designs, builds, deploys, and operates security across cloud, application, network, and physical infrastructure- not from the sidelines, but with your hands on the tools. You are fluent in the Microsoft Azure and Entra ecosystem, you understand networking and firewall rules cold, and you are just as comfortable reviewing application code as you are tuning detections in an XDR/SIEM console and running an incident to ground. You stay current with emerging threats and technologies, you automate what should be automated, and you have enough compliance grounding to translate technical controls into evidence auditors trust. You thrive in a new, fast-paced, high-demand environment and take direct ownership of the security and resilience of the systems that protect our patients' healthcare data.

Role's Responsibilities

  • Designing, building, deploying, and managing security controls hands-on across OnMed's cloud, application, and network environments- owning the outcomes directly rather than overseeing them from a distance.
  • Architecting and hardening the Microsoft Azure and M365/Entra environment-identity, network security groups, firewall rules, and encryption at-rest and in-transit- along with corporate and CareStation field-device endpoints.
  • Operating and tuning the security stack day to day: XDR/MDR, SIEM, and SOC workflows-building and refining detections, triaging alerts, and working them hands-on.
  • Leading incident response end to end: triage, containment, eradication, root cause analysis, and documentation.
  • Designing, reviewing, and maintaining network and firewall architecture-segmentation, rule sets, VPN, and Zero Trust access for the remote workforce and field devices.
  • Reviewing application code, integrations, and system designs (in-house and vendor-built) for security gaps, and partnering with engineering on remediation.
  • Automating security operations and repetitive tasks through scripting where it strengthens detection, response, or hardening.
  • Administering identity and access in Entra ID- quarterly access reviews, privileged account audits, and MFA/SSO enforcement.
  • Maintaining control evidence for SOC 2, HITRUST, FedRAMP, HIPAA, and related frameworks, supporting auditor and assessor requests, and tracking findings through to remediation.
  • Where a managed security services provider is used, directing and holding them accountable as an extension of the in-house team-while retaining direct ownership of security outcomes.
  • Maintaining security policies, supporting security awareness training, and responding to customer and vendor security questionnaires.

Requirements

Knowledge, Skills & Abilities

Must Have:

  • Deep, hands-on experience designing, developing, deploying, and managing security across multiple technology stacks-engineering the controls yourself, not only directing others.
  • Strong hands-on expertise with Microsoft Azure cloud security and the M365/Entra ID stack-identity, network security, and workload protection.
  • Excellent understanding of networking and firewall rules-segmentation, NGFW and Azure Firewall rule design and administration, VPN, IDS/IPS, and Zero Trust Network Access across remote users and field devices.
  • Application security depth-reviewing code, integrations, and system designs for vulnerabilities, with familiarity with the OWASP Top 10 and SAST/DAST tooling.
  • Hands-on experience operating XDR/MDR, SIEM, and SOC environments-building and tuning detections and working alerts directly.
  • Hands-on incident response experience-triage, containment, root cause analysis, and documentation.
  • Scripting and automation ability (e.g., PowerShell, Python, KQL) to automate detection, response, and hardening-a strong plus where the role calls for it.
  • A working compliance background-practical knowledge of one or more of SOC 2, NIST, CIS, HITRUST, and FedRAMP, including producing control evidence and working with external auditors or assessors.
  • Working knowledge of HIPAA-scoped PHI handling, data classification, Security Rule requirements, and breach notification.
  • Endpoint and device hardening, with encryption at-rest and in-transit across cloud, corporate, and field-deployed devices.
  • Familiarity with AI security: securing AI tools and platforms in use across the organization, and evaluating AI-driven security tooling to defend against AI-enabled threats.
  • Strong written communication-this role writes for engineering peers, auditors, vendors, and non-technical leadership regularly.
  • Comfort supporting and working in a rapidly growing, fast-paced, high-demand environment.

Nice-to-Have:

  • Advanced Security Operations automation (e.g., leveraging Elastic).
  • Hands-on experience with Palo Alto NGFW, Azure Firewall administration, and Cloudflare security services.
  • Experience implementing and managing cloud service provider, SaaS, and PaaS security.
  • Experience securing IoT, embedded devices, and infrastructure deployed in public settings.
  • Vendor risk assessment experience-due diligence, tiering, and ongoing third-party risk tracking-and experience managing an MSSP or MSP relationship.
  • Familiarity with GRC or compliance tracking platforms.
  • Exposure to agentic AI tooling or AI governance programs.
  • Prior healthcare or other regulated-industry experience.

Education & Experience

  • Bachelor's degree in Computer Science, Information Technology, or a related field, or equivalent practical experience.
  • 7+ years of experience in information security with substantial hands-on engineering, preferably in a regulated industry.
  • 5+ years securing cloud (Azure preferred) and on-prem environments hands-on.
  • AZ-500, Security+, GSEC, or CySA+ preferred; OSCP, GCIH, or CISSP/CISM are good nice-to-haves.

Benefits

OnMed provides a competitive salary and benefits package, including unlimited PTO and paid holidays.

The base salary for this role is $130,000 - $140,000 commensurate with the candidate's experience.

OnMed is a proud equal opportunity employer. All qualified applicants will be considered without regard to race, color, creed, religion, gender, sexual orientation, national origin, genetic information, disability, age, marital status, veteran status, or any other category protected by law.

#LI-HYBRID