2

Remote Security Controls Assessor Jobs in Alabama

High Level Engineer - Controls

Mobile, AL ยท On-site +1

$82K - $107K/yr

This position is REMOTE and can be located anywhere within the US. How you will do it Under general ... Consults with sales and operations team to appropriately assess project financial and execution ...

$130K - $150K/yr

... controls that support the organization's broader security strategy. You'll work closely with ... Risk and compliance oversight - Assess data security risks, review control effectiveness, and ...

$130K - $150K/yr

... controls that support the organization's broader security strategy. You'll work closely with ... Risk and compliance oversight - Assess data security risks, review control effectiveness, and ...

Vulnerability Analyst

AL ยท On-site +1

$55K - $75K/yr

Fully Remote Salary*: $55,000 - $75,000 *Dependent upon qualifications Summit 7 is here to rise ... with security assessments during Red Team operations. * Assist with validating security controls ...

Conduct comprehensive security assessments by analyzing cybersecurity documentation and performing ... Work independently or as part of a client delivery team in a fast-paced, deadline-driven, remote ...

Analyzing processes, controls, and tools to identify opportunities for ServiceNow configuration and ... Includes design of the cyber organization, governance, and risk assessments. Qualifications ...

next page

Showing results 1-20

Remote Security Controls Assessor information

What is the difference between Remote Security Controls Assessor vs Security Analyst?

AspectRemote Security Controls AssessorSecurity Analyst
CertificationsISO 27001 Lead Auditor, CISSP, CISACISSP, Security+
Work EnvironmentRemote or on-site, focusing on compliance assessmentsTypically office-based, analyzing security data and incidents
Employer & IndustryGovernment agencies, consulting firms, large corporationsFinancial institutions, tech companies, healthcare

The Remote Security Controls Assessor primarily evaluates security controls for compliance, often working remotely, while the Security Analyst monitors and analyzes security threats and incidents. Both roles require security certifications, but the assessor focuses on audits and controls, whereas the analyst emphasizes threat detection and response.

What are Remote Security Controls Assessors?

Remote Security Controls Assessors are professionals who evaluate and verify the effectiveness of an organization's security measures, policies, and procedures without being physically present on-site. They use a variety of tools and methods to assess compliance with security standards, identify vulnerabilities, and recommend improvements. Working remotely, these assessors often conduct interviews, review documentation, and perform technical tests to ensure that the organization's information systems are secure and meet regulatory requirements.

What challenges might I face as a Remote Security Controls Assessor, and how can I overcome them?

As a Remote Security Controls Assessor, one common challenge is effectively evaluating technical and administrative controls without being physically present at client sites. This often requires strong communication skills to coordinate with on-site staff, request and interpret evidence remotely, and clarify any ambiguities. Leveraging secure collaboration tools, maintaining clear documentation, and setting regular check-ins with clients can help address these challenges. Additionally, staying up to date with remote assessment methodologies and compliance frameworks will ensure thorough and accurate evaluations.

What are the key skills and qualifications needed to thrive as a Remote Security Controls Assessor, and why are they important?

To thrive as a Remote Security Controls Assessor, you need a solid understanding of information security frameworks, risk management practices, and compliance standards, often supported by a degree in cybersecurity or related certifications like CISSP, CISA, or Security+. Familiarity with security assessment tools, vulnerability scanners, and compliance management platforms is typically required. Strong analytical thinking, attention to detail, and effective written and verbal communication skills help you excel when evaluating controls and reporting findings remotely. These skills are essential to ensure accurate risk identification and maintain regulatory compliance while collaborating efficiently from a distance.
What are popular job titles related to Remote Security Controls Assessor jobs in Alabama? For Remote Security Controls Assessor jobs in Alabama, the most frequently searched job titles are:
What cities in Alabama are hiring for Remote Security Controls Assessor jobs? Cities in Alabama with the most Remote Security Controls Assessor job openings:
Infographic showing various Remote Security Controls Assessor job openings in Alabama as of July 2026, with employment types broken down into 56% Full Time, 6% Part Time, 1% Temporary, 2% Contract, and 35% Nights. Highlights an 89% Physical, 2% Hybrid, and 9% Remote job distribution.

Director of Cybersecurity

EBSCO Industries Inc

Birmingham, AL โ€ข On-site, Remote

Full-time

Posted 7 days ago


Job description

Headquartered in Birmingham, Alabama, Moultrie (www.moultrie.com) is the leader in game feeders and cellular camera innovation, building products used by hunters, property owners, and others for real-time remote monitoring.

We take pride in developing deep user understanding, obsessing about the details, and going the extra mile to show our users we love them. Moultrie is customer-driven โ€“ hardware, software, marketing, and customer success teams collaborate to deliver a quality user experience.

We are guided by the following principles: Customer Obsession.; Excellence is the Standard.; Bias for Action.; Act Boldly.; Deliver Results.; Hire and Develop the Best.; Be Curious and Learn.; Win as a Team

Job Summary

We are looking for a seasoned Director of Cybersecurity to lead and mature our security program across the full breadth of our business. This is a senior leadership role responsible for protecting our subscription products and customer data, securing our software engineering and DevOps pipelines, and building a governance framework that scales with the company.

You will partner closely with Software Engineering, Product, Legal, and Executive leadership to make security an essential part of our business โ€” not just a compliance checkbox.

Job Responsibilities

Subscription Business & Infrastructure Security

โ€ข Own the end-to-end security posture of the companyโ€™s subscription platform, including customerfacing applications, APIs, and underlying cloud infrastructure.

โ€ข Define and enforce security architecture standards for cloud environments (AWS, Azure, GCP), ensuring proper network segmentation, identity and access management (IAM), and data protection controls.

โ€ข Lead vulnerability management, penetration testing, and red team exercises to proactively identify and remediate risk across production systems.

โ€ข Establish and maintain a Security Operations Center (SOC) capability โ€” whether in-house, managed, or hybrid โ€” to ensure continuous monitoring, threat detection, and incident response readiness.

โ€ข Oversee data security controls to protect subscriber PII and payment information in compliance with applicable regulations (PCI-DSS, CCPA, GDPR, etc.).

โ€ข Define and rehearse incident response plans, leading the organization through security events from detection through post-mortem.

Software Development & DevSecOps

โ€ข Embed security throughout the software development lifecycle (SDLC), partnering with Engineering and Product to shift security left without slowing delivery velocity.

โ€ข Own the security of CI/CD build pipelines, including secrets management, pipeline integrity, dependency scanning, and supply chain security controls.

โ€ข Drive adoption of SAST, DAST, SCA, and container/image scanning tools across development teams.

โ€ข Define and maintain secure coding standards, conducting regular developer security training and threat modeling workshops.

โ€ข Establish controls to detect and prevent dependency confusion, code injection, and software supply chain attacks in build and deployment processes.

โ€ข Partner with platform and infrastructure engineering teams to ensure IaC (Terraform, Pulumi, etc.) follows security best practices and is reviewed prior to deployment.

Governance, Risk & Compliance โ€ข Build and maintain a cybersecurity governance framework.

โ€ข Own the companyโ€™s risk register for cybersecurity, providing clear, quantified risk reporting to executive leadership and the board as appropriate.

โ€ข Lead and manage third-party security assessments, customer security questionnaires, and audit responses (SOC 2 Type II, penetration test reports, etc.).

โ€ข Develop and enforce security policies, standards, and procedures across the organization.

โ€ข Drive vendor and third-party risk management, ensuring security requirements are embedded in procurement and contract processes.

โ€ข Maintain awareness of the evolving regulatory landscape and ensure the companyโ€™s practices remain compliant with applicable laws and industry standards.

โ€ข Champion a culture of security awareness through company-wide training programs, phishing simulations, and ongoing communication.

Job Requirements

โ€ข 10+ years of progressive experience in cybersecurity, with at least three years in a leadership role managing security programs and teams.

โ€ข Deep technical expertise in cloud security (AWS, Azure, or GCP) and securing SaaS or subscription-based products.

โ€ข Proven experience implementing DevSecOps practices and securing CI/CD pipelines in modern engineering environments.

โ€ข Hands-on knowledge of security tooling: SIEM, EDR, SAST/DAST, vulnerability scanners, secrets management platforms, and cloud security posture management (CSPM) tools.

โ€ข Strong background in security governance frameworks (NIST CSF, ISO 27001, SOC 2) and working knowledge of compliance requirements (PCI-DSS, GDPR, CCPA).

โ€ข Experience leading incident response efforts, including communication with executives, legal, and external stakeholders.

โ€ข Excellent written and verbal communication skills โ€” able to translate complex technical risk into clear, actionable business language.

Preferred Qualifications

โ€ข Relevant certifications: CISSP, CISM, CISA, AWS Security Specialty, or equivalent.

โ€ข Experience with software supply chain security frameworks (SLSA, SBOM generation, Sigstore, etc.).

โ€ข Familiarity with zero trust architecture and its practical application in enterprise environments. โ€ข Experience working in a subscription or SaaS business where availability and customer trust are directly tied to revenue. โ€ข Background scaling security programs at a growth-stage company.

Essential Job Function

We are an equal opportunity employer and comply with all applicable federal, state, and local fair employment practices laws. We strictly prohibit and do not tolerate discrimination against employees, applicants, or any other covered persons because of race, color, sex, pregnancy status, age, national origin or ancestry, ethnicity, religion, creed, sexual orientation, gender identity, status as a veteran, and basis of disability or any other federal, state or local protected class. This policy applies to all terms and conditions of employment, including, but not limited to, hiring, training, promotion, discipline, compensation, benefits, and termination of employment.

We comply with the Americans with Disabilities Act (ADA), as amended by the ADA Amendments Act, and all applicable state or local law.