2

Remote Security Control Assessor Jobs in Silver Spring, MD

Primary work will be performed at the client site in Washington DC and approved remote/telework ... Conduct continuous monitoring activities, including regular security control assessments ...

Primary work will be performed at the client site in Washington DC and approved remote/telework ... Conduct continuous monitoring activities, including regular security control assessments ...

Hands-on authorization package development and security control assessment. Operational experience with a federal GRC platform and an enterprise SIEM. Demonstrated coordination with an agency ...

Support system categorization, security control selection, assessments, authorization, and ... Work Environment This position is primarily remote with occasional on-site meetings or support ...

Support system categorization, security control selection, assessments, authorization, and ... Work Environment This position is primarily remote with occasional on-site meetings or support ...

Showing results 41-60

Remote Security Control Assessor information

See Silver Spring, MD salary details

$9

$60

$80

How much do remote security control assessor jobs pay per hour?

As of Sep 3, 2026, the average hourly pay for remote security control assessor in Silver Spring, MD is $60.75, according to ZipRecruiter salary data. Most workers in this role earn between $52.16 and $70.34 per hour, depending on experience, location, and employer.

What is a remote security control assessor?

A Remote Security Control Assessor evaluates and ensures that an organization's security controls comply with industry standards and regulations. They perform risk assessments, analyze security policies, and recommend improvements to enhance cybersecurity. Working remotely, they assess systems, review documentation, and collaborate with internal teams and stakeholders. Their goal is to identify vulnerabilities and ensure that security frameworks align with compliance requirements such as NIST, ISO 27001, or FedRAMP.

What does a remote security control assessor do?

A Remote Security Control Assessor typically reviews security policies, analyzes technical controls, and conducts risk assessments to ensure compliance with industry standards and client requirements. Daily tasks often include evaluating documentation, coordinating virtual meetings with stakeholders, preparing assessment reports, and recommending remediation actions for identified vulnerabilities. You’ll collaborate with IT teams, compliance officers, and management to gather evidence and share assessment findings. Strong organizational and communication skills are essential, as much of the work is self-directed and relies on effective remote coordination with clients and internal teams.

What are the key skills and qualifications needed to thrive as a remote security control assessor?

To thrive as a Remote Security Control Assessor, you need expertise in information security frameworks, risk assessment methodologies, and IT auditing, typically supported by a bachelor's degree in cybersecurity or a related field. Familiarity with assessment tools (like Nessus or NIST compliance checklists), experience with GRC (governance, risk, compliance) platforms, and relevant certifications such as CISSP or CISA are highly valued. Excellent analytical skills, attention to detail, and strong written and verbal communication abilities help remote assessors excel, especially when working independently or with cross-functional teams. These skills are critical for accurately evaluating security controls, ensuring regulatory compliance, and communicating findings effectively in a remote work environment.

What are popular job titles related to Remote Security Control Assessor jobs in Silver Spring, MD?

For Remote Security Control Assessor jobs in Silver Spring, MD, the most frequently searched job titles are:

What job categories do people searching Remote Security Control Assessor jobs in Silver Spring, MD look for?

The top searched job categories for Remote Security Control Assessor jobs in Silver Spring, MD are:

What cities near Silver Spring, MD are hiring for Remote Security Control Assessor jobs?

Cities near Silver Spring, MD with the most Remote Security Control Assessor job openings:

Infographic showing various Remote Security Control Assessor job openings in Silver Spring, MD as of August 2026, with employment types broken down into 1% As Needed, 76% Full Time, 18% Part Time, 4% Contract, and 1% Nights. Highlights an 94% Physical, 1% Hybrid, and 5% Remote job distribution, with an average salary of $126,365 per year, or $60.8 per hour.

Senior Subject Matter Expert, Equivalency

OneZero Solutions

Washington, DC • Remote

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted 14 days ago


Job description

We are an employee-centric company that truly values our team members and the contributions they make to our customers and the missions they support. We pride ourselves on being forward-leaning thinkers and on building teams that are, and continue to be, technically proficient across a broad range of cyber mission areas. OneZero full-time employees receive a highly competitive benefits package, including health, dental, vision, and life insurance, a 401(k) with company matching, paid time off and holidays, an employee referral program, and educational assistance. Additional details are available on our website: https://www.onezerollc.com/careers/Position Title: Senior Subject Matter Expert, EquivalencyLocation: Remote (United States). Occasional virtual meetings with the Government; no routine on-site requirement.Clearance:No security clearance is required. This work is performed at the Controlled Unclassified Information (CUI) level.S. citizenship is required. All personnel must undergo and successfully pass, at minimum, a Tier 1 background investigation (or equivalent) and be favorably adjudicated.Position SummaryThe Senior SME, Equivalency is the program's senior technical authority for operational technology and industrial control system cybersecurity in the maritime domain. This position conducts the technical review of all equivalency requests submitted under 33 CFR Part 101 Subpart F and assists with complex waiver requests and cybersecurity plan reviews as assigned. This is a designated Key Personnel position; the Government must acknowledge any replacement in writing.Key ResponsibilitiesConduct the detailed technical review of all equivalency requests, evaluating whether the request clearly identifies the regulatory requirement at issue, describes the proposed alternative safeguard, and provides sufficient supporting evidence for Government evaluation.Determine whether the proposed alternative provides a level of security that meets or exceeds the effectiveness of the specified regulatory requirement, and document that analysis so it is technically supportable and traceable.Apply Government-furnished methodologies, checklists, process guides, and decision matrices to produce preliminary recommendations of Approve, Approve with Conditions, or Deny.Prepare consolidated review packages for the USCG representative, including the complete request with supporting documentation, the fully annotated checklist with scoring, and a draft technical analysis.Draft signature-ready correspondence addressed to submitters for USCG review and signature, including supporting justification and any proposed conditions for Government consideration.Assist with complex and novel waiver requests and cybersecurity plan technical reviews as assigned by the Project Manager and Sub-Project Managers.Serve as the senior technical escalation point for OT and ICS questions raised by both review teams.Perform quality control to ensure findings are clearly stated, technically supportable, internally consistent, and traceable to the applicable regulatory requirement or checklist element.Support development and delivery of internal maritime and OT cybersecurity training for review personnel.Recommend improvements to review processes, checklists, and templates for Government consideration, without establishing approval criteria or adjudication standards independent of the Government.Required QualificationsSeven (7) years of hands-on experience focused on OT/ICS cybersecurity.Expert-level knowledge applying cybersecurity frameworks such as NIST CSF and ISA/IEC 62443 specifically to OT/ICS environments.Expert-level understanding of OT network architecture and security controls, with demonstrated capability applying that knowledge to maritime systems such as vessel navigation systems, cargo handling systems, and facility automation.At least one cybersecurity certification satisfying the certification requirement for the DoD 8140 DCWF work role of Security Control Assessor (for example CISSP, CISA, or CISM)At least one advanced OT-focused cybersecurity certification, such as the Global Industrial Cyber Security Professional (GICSP).Must disclose, for organizational conflict of interest screening, any current or prior engagement performed for MTSA-regulated vessel, facility, or Outer Continental Shelf facility owners or operators involving cybersecurity plan development, cybersecurity assessment, or related advisory services.Preferred QualificationsAdditional OT and ICS certifications such as GRID, GCIP, or ISA/IEC 62443 credentials.Prior U.S. Coast Guard, DHS, or MTSA regulatory experience.Experience with Alternative Security Programs (ASPs) in the maritime sector.Experience serving as an independent assessor or auditor against a published control set or checklist.Experience authoring technical justifications or equivalency determinations for a regulator.Technical SkillsOT and ICS network architecture, segmentation, and security control design.Industrial and maritime protocols, including Modbus, DNP3, OPC UA, NMEA 0183/2000.Maritime systems including ECDIS, AIS, GNSS, cargo and ballast control, terminal operating systems, and crane and facility automation.NIST Cybersecurity Framework and NIST SP 800-series risk management guidance.ISA/IEC 62443 series.EducationBachelor's degree in engineering, computer science, cybersecurity, or a related technical field preferred. Equivalent hands-on OT/ICS experience will be considered in lieu of a degree.OneZero Solutions, LLC is an Equal Opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, pregnancy, genetic information, disability, status as a protected veteran, or any other protected category under applicable federal, state, and local laws.To request an accommodation, please contact us at recruiting@onezerollc.com or call (202) 987-2580.
Job Posted by ApplicantPro