1

Security Assessor Jobs in Virginia (NOW HIRING)

The Security Assessor supports security and privacy control assessments for publicsector systems by evaluating control effectiveness, validating evidence, and contributing to formal assessment ...

New

Security Control Assessor (SCA) LOCATION Chantilly, VA 20151 CLEARANCE TS/SCI Full Poly (Please note this position requires full U.S. Citizenship) KEY SUMMARY We are seeking a meticulous and detail ...

Security Control Assessor (SCA) LOCATION Tysons, VA 22182 CLEARANCE TS/SCI Full Poly (Please note this position requires full U.S. Citizenship) KEY SUMMARY We are seeking a meticulous and detail ...

Security Control Assessor (SCA) LOCATION Reston, VA 20190 CLEARANCE TS/SCI Full Poly (Please note this position requires full U.S. Citizenship) KEY SUMMARY We are seeking a meticulous and detail ...

The successful candidate will perform independent assessments of security controls to ensure compliance with federal cybersecurity policies, standards, and frameworks, such as the Risk Management ...

ORA_ON_SITE Description SAIC is seeking a highly skilled and motivated  Senior Security Control Assessor (SCA)  to support the cybersecurity assessment and compliance needs of mission-critical ...

The successful candidate will perform independent assessments of security controls to ensure compliance with federal cybersecurity policies, standards, and frameworks, such as the Risk Management ...

Execute a security control assessment plan and update the System Security Plan * Review vulnerability scans and remediation * Implement risk management programs by utilizing NIST, FISMA, HIPAA, and ...

Execute a security control assessment plan and update the System Security Plan * Review vulnerability scans and remediation * Implement risk management programs by utilizing NIST, FISMA, HIPAA, and ...

Security Control Assessor

Alexandria, VA · On-site

$146K - $234K/yr

Execute a security control assessment plan and update the System Security Plan * Review vulnerability scans and remediation * Implement risk management programs by utilizing NIST, FISMA, HIPAA, and ...

Security Control Assessor

Arlington, VA · On-site

$110K - $130K/yr

Argo Cyber Systems is seeking a RMF/ Security Control Assessor to support cybersecurity governance, risk, compliance, and modernization activities in federal environments. The selected candidate will ...

next page

Showing results 1-20

Security Assessor information

See Virginia salary details

$8

$58

$77

How much do security assessor jobs pay per hour?

As of Aug 14, 2026, the average hourly pay for security assessor in Virginia is $58.26, according to ZipRecruiter salary data. Most workers in this role earn between $50.05 and $67.45 per hour, depending on experience, location, and employer.

How do you become a security assessor?

To become a security assessor, candidates typically need a background in cybersecurity, information technology, or related fields, along with relevant certifications such as Certified Information Systems Security Professional (CISSP) or Certified Information Security Manager (CISM). Gaining experience in security audits, risk assessment, and compliance standards is also important, and some roles may require security clearance or specific industry knowledge.

What are the key skills and qualifications needed to thrive as a security assessor?

To thrive as a Security Assessor, you need a thorough understanding of information security principles, risk assessment methodologies, and compliance frameworks, often supported by a degree in cybersecurity or related fields. Familiarity with tools such as vulnerability scanners, compliance management systems, and certifications like CISSP, CISA, or PCI QSA is typically required. Strong analytical thinking, attention to detail, and clear communication are vital soft skills for accurately identifying risks and conveying findings to stakeholders. These skills ensure that organizations remain compliant, secure, and resilient against evolving cyber threats.

What are some common challenges security assessors face when conducting security audits, and how can they overcome them?

Security Assessors often encounter challenges such as incomplete documentation, resistance from stakeholders, and rapidly changing technology environments. To overcome these, assessors should develop strong communication skills to build trust, encourage transparency, and ensure all relevant parties understand the importance of compliance. Staying current with industry standards and maintaining flexibility in their assessment approach also helps them adapt to new threats and technologies, ensuring thorough and effective audits.

What is a security assessor?

Security Assessors are professionals who evaluate the security measures, policies, and practices of an organization to identify vulnerabilities and ensure compliance with security standards and regulations. They conduct assessments such as penetration testing, risk analysis, and audits to help organizations safeguard their information systems against threats. Security Assessors often work with frameworks like PCI DSS, ISO 27001, and NIST to ensure best practices are followed. Their work is crucial for maintaining the confidentiality, integrity, and availability of sensitive data.

What is the difference between Security Assessor vs Security Analyst?

AspectSecurity AssessorSecurity Analyst
CertificationsISO 27001 Lead Auditor, CISSP, CISACISSP, Security+
Work EnvironmentAudit, compliance, risk assessmentMonitoring, incident response, threat analysis
Employer & IndustryConsulting firms, large organizations, governmentIT departments, security firms, corporations

Security Assessors primarily focus on evaluating security controls, conducting audits, and ensuring compliance with standards like ISO 27001. Security Analysts monitor security systems, analyze threats, and respond to incidents. While both roles require cybersecurity knowledge and certifications, Assessors emphasize compliance and auditing, whereas Analysts focus on threat detection and response.

What are popular job titles related to Security Assessor jobs in Virginia?

For Security Assessor jobs in Virginia, the most frequently searched job titles are:

What job categories do people searching Security Assessor jobs in Virginia look for?

The top searched job categories for Security Assessor jobs in Virginia are:

What cities in Virginia are hiring for Security Assessor jobs?

Cities in Virginia with the most Security Assessor job openings:

Infographic showing various Security Assessor job openings in Virginia as of August 2026, with employment types broken down into 86% Full Time, 12% Part Time, and 2% Contract. Highlights an 92% Physical, 3% Hybrid, and 5% Remote job distribution, with an average salary of $121,188 per year, or $58.3 per hour.

Full-time

Medical, Dental, Vision, Life, Retirement

Posted yesterday

New


Guidehouse rating

7.7

Company rating: 7.7 out of 10

Based on 27 frontline employees who took The Breakroom Quiz

42nd of 72 rated business consultants


Job description

Job Family:

Technology Consulting


Travel Required:

Up to 10%


Clearance Required:

None
What You Will Do:

The Security Assessor supports security and privacy control assessments for publicsector systems by evaluating control effectiveness, validating evidence, and contributing to formal assessment documentation under the direction of a Senior Security Assessor.

This role is primarily focused onassessmentexecution and documentation; however, it also provides exposure to more technical aspects of system architecture and control implementation. Candidates shoulddemonstratecuriosity and interest in expanding their skillset towardsecurity engineering, automation, and emergingAIenabledapproaches to compliance and assessment activities.

This role focuses on assessment execution and documentation, not system engineering or operational security responsibilities.

Key job responsibilities include the following:

  • Perform security and privacy control assessments in accordance with established assessment plans

  • Review security documentation and technical evidence

  • Validate control implementation through:

    • Evidence inspection

    • Architecture and system documentation review

    • Interviews with system owners and technical staff

  • Contribute to assessment artifacts, including:

    • SSP updates

    • SARs

    • ISRAs

    • POA&Ms

  • Document assessment results and clearly articulate control gaps and risks

  • Maintain assessment independence and objectivity

  • Identifyopportunities to improve assessment efficiency throughstandardization, tooling, or automation of evidence collection and validation

  • Support the use ofdata-driven or AI-assisted techniquesto enhance analysis, traceability, and reporting over time


What You Will Need:

  • Minimum of THREE (3) years of overall work experience ideally in supporting security control assessments, audits, or authorization activities

  • Bachelors Degree from an accredited university

  • US Citizenship is contractually required

  • Handson experience contributing to formal security assessment documentation (SSPs, SARs, POA&Ms, or equivalents)

  • Working knowledge of NIST SP 80053 security and privacy controls

  • Understanding of riskbased assessment concepts

  • Ability to analyze assessment evidence and clearly document findings


What Would Be Nice To Have:

  • Experience supporting government or other regulated environments

  • Exposure to CMS, healthcare, or publicsector security compliance frameworks

  • Familiarity with A&A, RMF, or Security Control Assessment processes

  • Relevant certifications (CISA, CISSP, CISM, Security+, or similar)

  • Prior background in or exposure tosecurity engineering, cloud security, or system implementation

  • Familiarity withmodern architectures (cloud platforms, IAM, logging/monitoring, APIs)and how controls are implemented in those environments

  • Exposure toautomation tools, scripting, or GRC platformssupporting assessment or compliance activities

  • Interest in applyingAI/automation to improve audit readiness, evidence analysis, or continuous monitoring processes


What We Offer:

Guidehouse offers a comprehensive, total rewards package that includes competitive compensation and a flexible benefits package that reflects our commitment to creating a diverse and supportive workplace.

Benefits include:

  • Medical, Rx, Dental & Vision Insurance

  • Personal and Family Sick Time & Company Paid Holidays

  • Position may be eligible for a discretionary variable incentive bonus

  • Parental Leave and Adoption Assistance

  • 401(k) Retirement Plan

  • Basic Life & Supplemental Life

  • Health Savings Account, Dental/Vision & Dependent Care Flexible Spending Accounts

  • Short-Term & Long-Term Disability

  • Student Loan PayDown

  • Tuition Reimbursement, Personal Development & Learning Opportunities

  • Skills Development & Certifications

  • Employee Referral Program

  • Corporate Sponsored Events & Community Outreach

  • Emergency Back-Up Childcare Program

  • Mobility Stipend

About Guidehouse

Guidehouse is an Equal Opportunity Employer-Protected Veterans, Individuals with Disabilities or any other basis protected by law, ordinance, or regulation.

Guidehouse will consider for employment qualified applicants with criminal histories in a manner consistent with the requirements of applicable law or ordinance including the Fair Chance Ordinance of Los Angeles and San Francisco.

If you have visited our website for information about employment opportunities, or to apply for a position, and you require an accommodation, please contact Guidehouse Recruiting at 1-571-633-1711 or via email at RecruitingAccommodation@guidehouse.com. All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodation.

All communication regarding recruitment for a Guidehouse position will be sent from Guidehouse email domains including @guidehouse.com or guidehouse@myworkday.com. Correspondence received by an applicant from any other domain should be considered unauthorized and will not be honored by Guidehouse. Note that Guidehouse will never charge a fee or require a money transfer at any stage of the recruitment process and does not collect fees from educational institutions for participation in a recruitment event. Never provide your banking information to a third party purporting to need that information to proceed in the hiring process.

If any person or organization demands money related to a job opportunity with Guidehouse, please report the matter to Guidehouse's Ethics Hotline. If you want to check the validity of correspondence you have received, please contact recruiting@guidehouse.com. Guidehouse is not responsible for losses incurred (monetary or otherwise) from an applicant's dealings with unauthorized third parties.

Guidehouse does not accept unsolicited resumes through or from search firms or staffing agencies. All unsolicited resumes will be considered the property of Guidehouse and Guidehouse will not be obligated to pay a placement fee.


What Guidehouse employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom