2

Remote Security Control Assessor Jobs in Oregon (NOW HIRING)

... control, and secure coding practices. * Hands-on experience with security assessment tools and ... Experience working in a remote team or asynchronous work environment where focus, discipline, and ...

Senior Security Compliance Analyst

OR · On-site +1

$110K - $140K/yr

Prepare, coordinate, and manage ISO 27001 audits, including evidence collection, control ... Conduct third-party vendor risk assessments, ensuring compliance with security policies and ...

Lead Security & Compliance Analyst

OR · On-site +1

$80K - $135K/yr

Run third-party/vendor risk assessments and respond to customer security assessments and external ... Deliver HIPAA and security awareness training and measure control effectiveness through internal ...

Oversee Vulnerability Management program including vulnerability assessments, risk scoring and ... Experience acting as technical lead to distributed teams consisting largely of remote engineers.

Conduct threat modeling, design reviews, and security assessments * Contribute to incident response ... There may be remote flexibility for exceptional candidates in the following states: California ...

Senior IT Security Engineer

OR · On-site +1

$130K - $155K/yr

... risk assessments, maintain the risk register, define control owners, and produce compliance ... Though this is a remote position, must be able to work Eastern Time Zone business hours What We ...

Network Security Engineer

OR · On-site +1

$104K - $142K/yr

Oversee vulnerability assessments, penetration testing, and security reviews. * Prioritize and ... Architect secure, low-latency remote access and mesh VPN solutions for intra-fleet communication ...

This is a remote role. We are seeking a hands-on, mid-level Information Security Engineer to help ... Lead the company's SOC 2 compliance program, including readiness, control implementation, evidence ...

Senior Security Engineer, Blue Team

OR · On-site +1

$130K - $185K/yr

Conduct security risk assessments of third parties, evaluating overall maturity, and mapping data ... Remote work with regular in-person bonding experiences sponsored by the company * Competitive ...

Security & Compliance Engineer

OR · On-site +1

$100K - $160K/yr

... control, logging, monitoring, and incident readiness. * Support compliance and assessment ... Use AWS security tooling effectively, support day-to-day security processes, and help translate ...

Senior Application Security Engineer

OR · On-site +1

$58.75 - $78.50/hr

Experience performing threat modelling, security design reviews, and vulnerability assessment ... remote environment. * Self-driven and proactive, comfortable operating in a high-autonomy ...

Executes compliance program activities, including conducting risk assessments, developing work ... Assesses whether export control licenses are required and manages the license process with ...

Assess security risks, monitor processes continuously, and coordinate effective incident response ... Relocation to Bologna (Italy) or remote work. We are a hybrid company. * Italian and English ...

Senior Security Research Engineer

OR · On-site +1

$114K - $156K/yr

Improve the discovery and assessment of vulnerabilities across SIE network, cloud, endpoint ... context, control effectiveness, and remediation considerations. * Lead security validation ...

United States - Remote Clearance: Ability to obtain and maintain a Public Trust LTS is seeking a ... Assess risks associated with prompt injection, jailbreak attempts, indirect prompt attacks, tool ...

next page

Showing results 1-20

Remote Security Control Assessor information

See Oregon salary details

$9

$62

$82

How much do remote security control assessor jobs pay per hour?

As of Aug 25, 2026, the average hourly pay for remote security control assessor in Oregon is $62.13, according to ZipRecruiter salary data. Most workers in this role earn between $53.37 and $71.92 per hour, depending on experience, location, and employer.

What is a remote security control assessor?

A Remote Security Control Assessor evaluates and ensures that an organization's security controls comply with industry standards and regulations. They perform risk assessments, analyze security policies, and recommend improvements to enhance cybersecurity. Working remotely, they assess systems, review documentation, and collaborate with internal teams and stakeholders. Their goal is to identify vulnerabilities and ensure that security frameworks align with compliance requirements such as NIST, ISO 27001, or FedRAMP.

What does a remote security control assessor do?

A Remote Security Control Assessor typically reviews security policies, analyzes technical controls, and conducts risk assessments to ensure compliance with industry standards and client requirements. Daily tasks often include evaluating documentation, coordinating virtual meetings with stakeholders, preparing assessment reports, and recommending remediation actions for identified vulnerabilities. You’ll collaborate with IT teams, compliance officers, and management to gather evidence and share assessment findings. Strong organizational and communication skills are essential, as much of the work is self-directed and relies on effective remote coordination with clients and internal teams.

What are the key skills and qualifications needed to thrive as a remote security control assessor?

To thrive as a Remote Security Control Assessor, you need expertise in information security frameworks, risk assessment methodologies, and IT auditing, typically supported by a bachelor's degree in cybersecurity or a related field. Familiarity with assessment tools (like Nessus or NIST compliance checklists), experience with GRC (governance, risk, compliance) platforms, and relevant certifications such as CISSP or CISA are highly valued. Excellent analytical skills, attention to detail, and strong written and verbal communication abilities help remote assessors excel, especially when working independently or with cross-functional teams. These skills are critical for accurately evaluating security controls, ensuring regulatory compliance, and communicating findings effectively in a remote work environment.

What are popular job titles related to Remote Security Control Assessor jobs in Oregon?

For Remote Security Control Assessor jobs in Oregon, the most frequently searched job titles are:

What job categories do people searching Remote Security Control Assessor jobs in Oregon look for?

The top searched job categories for Remote Security Control Assessor jobs in Oregon are:

Infographic showing various Remote Security Control Assessor job openings in Oregon as of August 2026, with employment types broken down into 1% As Needed, 73% Full Time, 22% Part Time, 3% Contract, and 1% Nights. Highlights an 95% Physical, 1% Hybrid, and 4% Remote job distribution, with an average salary of $129,238 per year, or $62.1 per hour.

Cybersecurity Engineer (COMDO12)

OR • On-site, Remote

Defense Unicorns
Software Development • 11 - 50 employees

Full-time

Re-posted 21 days ago


Job description

EMPLOYER IS A CONTRACTOR FOR THE U.S. GOVERNMENT. THIS POSITION WILL REQUIRE U.S. CITIZENSHIP.

Role Description: 

As a cybersecurity engineer within Delivery at Defense Unicorns, you will own the full lifecycle of achieving and maintaining FedRAMP High authorization for mission-focused platforms and systems. This role requires hands-on experience supporting previous FedRAMP authorization packages. You will be expected to champion modern, continuous security implementations within DoW environments and systems (approval processes). Your perpetual goal will be to accelerate the FedRAMP and ATO process while simultaneously improving our security posture, thus pushing for cultural change away from security theater and towards responsive and resilient systems. While working within the existing FedRAMP processes, you will also work with other engineers to find the best paths forward toward the future with FedRAMP 20x implementation and contribute to Unicorn mission capabilities and open source solutions to further streamline ongoing and future efforts. 

Responsibilities: 

  • Leading the effort to achieve FedRAMP authorization in accordance with Revision 5 requirements, while also working towards FedRAMP 20x implementation requirements
  • Own the development and sustainment of authorization packages for U.S. Government compliance efforts, specifically FedRAMP High, DoD IL5 and IL6 requirements, continuous monitoring, and audit readiness.
  • Collaborating with cross-functional teams including software developers, system architects, and other Government stakeholders to interpret and map compliance requirements to product implementation.
  • Performing security testing and evaluation of our software platform to identify vulnerabilities and weaknesses (STIGs, ACAS, CI/CD security testing, etc.)
  • Preparing and maintaining documentation required for the Authorization process, including System Security Plans (SSPs), Plan of Actions & Milestones (POA&M), Security Assessment Reports (SARs), and other relevant artifacts. 
  • Staying up-to-date with evolving cybersecurity threats, technologies, and regulations to proactively address security challenges and compliance frameworks..
  • Building automation for manual process-driven compliance controls and supporting automated Compliance-as-Code capabilities that continuously evaluate the cybersecurity posture of the tech stack. 
  • Partner with technical teams to shape future product offerings and streamline engineering processes in support of scalable compliance, audit readiness, and authorization outcomes.

The listed responsibilities are not exhaustive and additional responsibilities may be assigned based on the evolving needs of the organization. We are seeking a dynamic individual who is able to adapt and take on new responsibilities as they arise. 

Preferred Experience and Qualifications: 

  • Proven experience in cybersecurity engineering, with a focus on achieving authorization for software systems through FedRAMP with reuse within the DoD. 
  • Proven track record of thinking outside the box and pushing the boundaries of the RMF/FedRAMP/ATO status quo.
  • In-depth knowledge of NIST-800 series standards, particularly NIST-800-53, and experience applying these standards to achieve accreditation. 
  • Skilled at translating technical implementation (infrastructure as code and configuration as code) into verifiable eMASS security control responses that Approving Officials (AOs), and their staffs, can understand. 
  • Strong understanding of cybersecurity principles, technologies, and best practices, including encryption, authentication, access control, and secure coding practices.
  • Hands-on experience with security assessment tools and techniques, such as vulnerability scanning and security analysis. 
  • Familiarity with software development methodologies and practices, particularly Agile and DevSecOps. 
  • Excellent analytical and problem-solving skills, with the ability to assess complex systems and identify security risks. 
  • Effective communication and interpersonal skills, with the ability to collaborate with cross-functional teams and communicate technical concepts to non-technical stakeholders. 
  • Eligibility to obtain and maintain a DoD security clearance. 
  • Eligibility to obtain and maintain privileged access in a Government Cloud Environment (relevant training and/or certifications). 

Desired Experience: 

  • Experience building and supporting platform authorizations for FedRamp High.
  • Experience building and supporting continuous authority to operate (cATO) packages within the DoD 
  • Ability to use machine-readable schemas, such as OSCAL, to manage control implementations, control statements, and compliance evidence as Compliance-as-Code. 
  • Familiarity with the Cloud Computing Security Requirements Guide (CC SRG)
  • Experience working in a remote team or asynchronous work environment where focus, discipline, and comfort navigating/leveraging various communication forms and frequencies to disseminate and prioritize information and keep stakeholders informed 

Travel Expectations/Requirements: 10-15%, up to 3-4 times per year (quarterly)