2

Remote Security Control Assessor Jobs in Reston, VA

Senior Cybersecurity Analyst

Washington, DC · Remote

$113.30K - $146.20K/yr

The majority of engagements are remote-based and anticipated travel is estimated at less than 20 ... skillsets to lead security control assessments. Duties will include: * Project planning

Remote / Alexandria, VA Clearance: Preferred US Gov Secret or above clearance (not a hard ... Security Control Assessors for ATO package development. * Serve as an internal primary subject ...

Manager, Cyber Security

Reston, VA · Remote

$115.50K - $156.10K/yr

Experience supporting ATO packages, security assessment activities, security control validation ... Remote Office (US99)

Remote / Alexandria, VA Clearance: Preferred US Gov Secret or above clearance (not a hard ... Security Control Assessors for ATO package development. * Serve as an internal primary subject ...

Security Engineer (Senior Level)

Mclean, VA · On-site +1

$115.70K - $158.70K/yr

This is a hybrid -remote role with approximately 5% on-site work at client sites throughout the US ... Participation in quarterly client security posture reviews to assess risk trends and control ...

Security Engineer (Senior Level)

Mclean, VA · On-site +1

$115.70K - $158.70K/yr

This is a hybrid -remote role with approximately 5% on-site work at client sites throughout the US ... Participation in quarterly client security posture reviews to assess risk trends and control ...

Role: Access Management Lead Location: (Local to Reston, VA preferred but will accept remote ... control policies, ensure compliance with security requirements, and coordinate with cross ...

Provide major event safety and security assessment, forecast, and vulnerability reports * Oversee ... and remote working. * Control Risks offers a competitively positioned compensation and benefits ...

next page

Showing results 1-20

Remote Security Control Assessor information

See Reston, VA salary details

$9

$61

$81

How much do remote security control assessor jobs pay per hour?

As of May 30, 2026, the average hourly pay for remote security control assessor in Reston, VA is $61.14, according to ZipRecruiter salary data. Most workers in this role earn between $52.50 and $70.77 per hour, depending on experience, location, and employer.

What is a Remote Security Control Assessor job?

A Remote Security Control Assessor evaluates and ensures that an organization's security controls comply with industry standards and regulations. They perform risk assessments, analyze security policies, and recommend improvements to enhance cybersecurity. Working remotely, they assess systems, review documentation, and collaborate with internal teams and stakeholders. Their goal is to identify vulnerabilities and ensure that security frameworks align with compliance requirements such as NIST, ISO 27001, or FedRAMP.

What are the key skills and qualifications needed to thrive in the Remote Security Control Assessor position, and why are they important?

To thrive as a Remote Security Control Assessor, you need expertise in information security frameworks, risk assessment methodologies, and IT auditing, typically supported by a bachelor's degree in cybersecurity or a related field. Familiarity with assessment tools (like Nessus or NIST compliance checklists), experience with GRC (governance, risk, compliance) platforms, and relevant certifications such as CISSP or CISA are highly valued. Excellent analytical skills, attention to detail, and strong written and verbal communication abilities help remote assessors excel, especially when working independently or with cross-functional teams. These skills are critical for accurately evaluating security controls, ensuring regulatory compliance, and communicating findings effectively in a remote work environment.

What are some typical responsibilities of a Remote Security Control Assessor on a day-to-day basis?

A Remote Security Control Assessor typically reviews security policies, analyzes technical controls, and conducts risk assessments to ensure compliance with industry standards and client requirements. Daily tasks often include evaluating documentation, coordinating virtual meetings with stakeholders, preparing assessment reports, and recommending remediation actions for identified vulnerabilities. You’ll collaborate with IT teams, compliance officers, and management to gather evidence and share assessment findings. Strong organizational and communication skills are essential, as much of the work is self-directed and relies on effective remote coordination with clients and internal teams.
What are popular job titles related to Remote Security Control Assessor jobs in Reston, VA? For Remote Security Control Assessor jobs in Reston, VA, the most frequently searched job titles are:
What job categories do people searching Remote Security Control Assessor jobs in Reston, VA look for? The top searched job categories for Remote Security Control Assessor jobs in Reston, VA are:
What cities near Reston, VA are hiring for Remote Security Control Assessor jobs? Cities near Reston, VA with the most Remote Security Control Assessor job openings:
Infographic showing various Remote Security Control Assessor job openings in Reston, VA as of May 2026, with employment types broken down into 76% Full Time, 20% Part Time, 3% Contract, and 1% Nights. Highlights an 95% Physical, 2% Hybrid, and 3% Remote job distribution, with an average salary of $127,169 per year, or $61.1 per hour.
FCC - Security Engineer / SIEM Engineer

FCC - Security Engineer / SIEM Engineer

cFocus Software Incorporated

Washington, DC • On-site, Remote

Full-time

Posted 25 days ago


Job description

cFocus Software seeks a Security Engineer / SIEM Engineer to join our program supporting the Federal Communications Commission (FCC). This position is remote. This position requires the ability a Public Trust clearance.
Qualifications:
  • Bachelor's degree in cybersecurity, IT, or related field (or equivalent experience)
  • Demonstrated experience in enterprise cybersecurity, SIEM engineering, or monitoring environments
  • Experience supporting systems of similar scale, complexity, or criticality
  • Ability to support engineering, monitoring, and operational cybersecurity functions
  • Experience with enterprise SIEM platforms (e.g., Splunk, Sentinel, QRadar)
  • Strong understanding of log management, event correlation, and telemetry pipelines
  • Knowledge of cybersecurity frameworks (NIST, RMF, FISMA)
  • Experience with cloud and hybrid environments (Azure, AWS, M365)
  • Familiarity with EDR, XDR, and network security tools
  • Ability to analyze large datasets and identify security trends
  • Experience supporting SOC operations and incident response
  • Experience with automation and SOAR platforms
  • Knowledge of Zero Trust Architecture and modern security frameworks
  • Scripting experience (Python, PowerShell)
  • Familiarity with threat intelligence and threat hunting techniques
  • Required Certifications
    • CompTIA Security+
    • Certified Information Systems Security Professional (CISSP) (preferred)
    • GIAC certifications (e.g., GCIA, GCIH)
    • Splunk, Microsoft Sentinel, or other SIEM platform certifications
    • Equivalent certifications demonstrating similar competency may be accepted
Duties:
  • Administer, configure, and optimize SIEM platforms and monitoring tools
  • Integrate and onboard new data sources, ensuring proper normalization and validation
  • Develop and tune detection rules, alerts, and correlation logic to reduce false positives
  • Support log management, telemetry pipelines, and enterprise monitoring architecture
  • Identify gaps in visibility and recommend enhancements to monitoring coverage
  • Collaborate with SOC/NOC teams to improve detection and response capabilities
  • Perform detection engineering and continuous improvement of monitoring outputs
  • Support configuration management and monitoring of security control effectiveness
  • Develop and maintain technical documentation, procedures, and engineering baselines
  • Participate in incident investigations, threat hunting, and root cause analysis.