2

Remote Security Control Assessor Jobs in Frederick, MD

RMF and Authorization Lead

Rockville, MD · On-site +1

$165K - $185K/yr

Coordinate three annual security control assessments and prepare evidence for the independent assessor. * Maintain assessor independence and avoid acting as the assessor of record unless the agency ...

Security Engineer

Rockville, MD · On-site +1

$150K - $170K/yr

Technical writing of security compliance and assessment documentation * Creating Standard Operating ... Office/Remote * Noise level: Low * Work schedule: Schedule is day shift Monday - Friday. May be ...

Security Engineer

Rockville, MD · On-site +1

$50 - $60/hr

Technical writing of security compliance and assessment documentation * Creating Standard Operating ... Office/Remote * Noise level: Low * Work schedule: Part-Time, up to 24 hours per week. Schedule is ...

Remote Insurance Agent

Hagerstown, MD · Remote

$60K - $110K/yr

No lead costs plus No cold calling How to Apply Ready to take control of your career and income ... We may use automated tools, including artificial intelligence (AI), to screen and assess candidates.

next page

Showing results 1-20

Remote Security Control Assessor information

See Frederick, MD salary details

$8

$58

$77

How much do remote security control assessor jobs pay per hour?

As of Aug 25, 2026, the average hourly pay for remote security control assessor in Frederick, MD is $58.43, according to ZipRecruiter salary data. Most workers in this role earn between $50.19 and $67.64 per hour, depending on experience, location, and employer.

What is a remote security control assessor?

A Remote Security Control Assessor evaluates and ensures that an organization's security controls comply with industry standards and regulations. They perform risk assessments, analyze security policies, and recommend improvements to enhance cybersecurity. Working remotely, they assess systems, review documentation, and collaborate with internal teams and stakeholders. Their goal is to identify vulnerabilities and ensure that security frameworks align with compliance requirements such as NIST, ISO 27001, or FedRAMP.

What does a remote security control assessor do?

A Remote Security Control Assessor typically reviews security policies, analyzes technical controls, and conducts risk assessments to ensure compliance with industry standards and client requirements. Daily tasks often include evaluating documentation, coordinating virtual meetings with stakeholders, preparing assessment reports, and recommending remediation actions for identified vulnerabilities. You’ll collaborate with IT teams, compliance officers, and management to gather evidence and share assessment findings. Strong organizational and communication skills are essential, as much of the work is self-directed and relies on effective remote coordination with clients and internal teams.

What are the key skills and qualifications needed to thrive as a remote security control assessor?

To thrive as a Remote Security Control Assessor, you need expertise in information security frameworks, risk assessment methodologies, and IT auditing, typically supported by a bachelor's degree in cybersecurity or a related field. Familiarity with assessment tools (like Nessus or NIST compliance checklists), experience with GRC (governance, risk, compliance) platforms, and relevant certifications such as CISSP or CISA are highly valued. Excellent analytical skills, attention to detail, and strong written and verbal communication abilities help remote assessors excel, especially when working independently or with cross-functional teams. These skills are critical for accurately evaluating security controls, ensuring regulatory compliance, and communicating findings effectively in a remote work environment.

What are popular job titles related to Remote Security Control Assessor jobs in Frederick, MD?

For Remote Security Control Assessor jobs in Frederick, MD, the most frequently searched job titles are:

What job categories do people searching Remote Security Control Assessor jobs in Frederick, MD look for?

The top searched job categories for Remote Security Control Assessor jobs in Frederick, MD are:

What cities near Frederick, MD are hiring for Remote Security Control Assessor jobs?

Cities near Frederick, MD with the most Remote Security Control Assessor job openings:

Infographic showing various Remote Security Control Assessor job openings in Frederick, MD as of August 2026, with employment types broken down into 49% Full Time, 38% Part Time, and 13% Contract. Highlights an 100% Remote job distribution, with an average salary of $121,536 per year, or $58.4 per hour.

Security Assessment and Continuous Monitoring Analyst

Rockville, MD • On-site, Remote

$110K - $120K/yr

Full-time

Medical, Dental, Vision, Retirement, PTO

Posted 4 days ago


Job description

Empower, Innovate, Impact! At Team A-TEK, we EMPOWER people to drive INNOVATION that IMPACTS mission!
A-TEK operates at the intersection of mission and innovation by applying our deep domain expertise across the federal markets. Embracing our digital-first strategy, A-TEK provides enhanced capabilities in application development, digital transformation, enterprise IT, and scientific services. Our solutions are designed to modernize, automate, secure, protect, and enhance the operations of our federal clients, ensuring they stay ahead in a rapidly evolving digital landscape.
Our work is fueled by a passion to serve our clients' needs and to protect the safety and welfare of Americans. That passion shapes how we nurture our most valuable asset - Our Employees. A-TEK actively cultivates the talent that drives our success and fosters a creative, challenging, and mission-driven work environment for current and future employees.
The Security Assessment and Continuous Monitoring Analyst supports annual security assessments, continuous monitoring, POA&M management, cybersecurity documentation, vulnerability and risk tracking, GRC platform updates, and authorization sustainment for an HHS-affiliated agency. This individual collects and validates evidence, maintains accurate records, tracks findings, and keeps authorization packages ready for Government and independent assessor review. Must be able to support hybrid work requirements in the Washington, DC metropolitan area or Research Triangle area.
Responsibilities
  • Support security control assessments for three primary authorization boundaries.
  • Collect, organize, validate, and maintain assessment evidence and control implementation documentation.
  • Coordinate assessment schedules, interviews, demonstrations, evidence requests, and assessor communications.
  • Track findings from identification through remediation, validation, closure, or POA&M acceptance.
  • Update POA&M status in the designated GRC platform within five business days of a status change.
  • Perform continuous monitoring activities and maintain supporting documentation and evidence.
  • Reconcile GRC records against system inventories, authorization artifacts, and operational information.
  • Support the annual review cycle for system documentation and authorization artifacts.
  • Monitor vulnerabilities, configuration changes, control status, and risk indicators.
  • Support security impact analyses within 10 business days after identification of a change request.
  • Prepare risk reports within 10 business days after assessments, major changes, or other triggering events.
  • Support cloud and FedRAMP artifact reviews, control inheritance analysis, and continuous monitoring.
  • Assist with system onboarding, decommissioning, data calls, audits, and cybersecurity reporting.
  • Apply quality checks that promote accurate documentation and 98 percent GRC data accuracy.

Required Experience and Qualifications
  • Demonstrated experience supporting Federal RMF, A&A, security assessments, and continuous monitoring.
  • Knowledge of NIST SP 800-37, NIST SP 800-53, NIST SP 800-53A, FISMA, and POA&M requirements.
  • Experience collecting and evaluating security control evidence.
  • Experience maintaining SSPs, SARs, POA&Ms, risk records, and related cybersecurity artifacts.
  • Understanding of vulnerability management, configuration management, and security impact analysis.
  • Strong analytical, documentation, and stakeholder communication skills.
  • Ability to manage concurrent priorities and meet time sensitive assessment and reporting deadlines.
  • Ability to support hybrid work requirements in the Washington, DC metropolitan area or Research Triangle area.
  • Education and experience that satisfy the proposed GSA labor category.

Preferred Experience and Qualifications
  • Experience supporting HHS or another Federal health agency.
  • Experience using JCAM or a comparable Federal GRC platform.
  • Experience with cloud and FedRAMP artifacts, control inheritance, and shared responsibility models.
  • Experience supporting independent assessors and addressing assessment findings.
  • Experience in maintaining accurate system inventory and authorization data.
  • CAP/CGRC, Security+, CISSP, CISM, or an applicable cloud security certification.

Compensation
Salary Range: $110,000 - $120,000 annually (commensurate with experience)
Benefits: Health, dental, and vision insurance; 401(k) with employer match; paid time off; professional development opportunities.
Why Join Us?
This is an opportunity to make a direct impact on healthcare data processes that support critical regulatory functions. You will collaborate with dedicated professionals, work on meaningful projects, and contribute to improvements in public health systems.
Candidates may use tools (including AI) for proofreading or formatting; however, using any tool to fabricate, exaggerate, or misrepresent qualifications, experience, or work product is not permitted. We may assess application materials for job-related technical depth, internal consistency, and demonstrated hands-on experience, including through follow-up questions, skills assessments, or reference checks. Verification of education may be requested before or during the hiring process.
For security and identity verification purposes, participants may be asked to temporarily disable virtual backgrounds during portions of the call.
Misrepresentation or falsification may result in removal from further consideration. Candidates who need a reasonable accommodation in the application or interview process may request one.
A-TEK, Inc. is an Equal Opportunity/Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, or status as a qualified individual with a disability, or Vietnam era or other protected Veteran status.