1

Security Assurance Management Jobs in Silver Spring, MD

P-1528 As a Staff Security Assurance Engineer within the Security Assurance Team, you will help ... Adopt an ownership mindset to manage the end-to-end delivery of work required for new security ...

New

next page

Showing results 1-20

Security Assurance Management information

See Silver Spring, MD salary details

$31K

$90.1K

$142.1K

How much do security assurance management jobs pay per year?

As of Aug 19, 2026, the average yearly pay for security assurance management in Silver Spring, MD is $90,054.00, according to ZipRecruiter salary data. Most workers in this role earn between $59,400.00 and $106,000.00 per year, depending on experience, location, and employer.

What is security assurance management?

Security Assurance Management refers to the processes and practices used to ensure that an organization's information systems are secure and meet established security standards. This involves assessing risks, implementing security controls, monitoring compliance, and regularly reviewing the effectiveness of security measures. Security Assurance Managers work to identify potential vulnerabilities, coordinate audits, and ensure that both regulatory and internal security requirements are consistently met, helping protect sensitive data and organizational assets.

What are the key skills and qualifications needed to thrive as a security assurance manager?

To thrive as a Security Assurance Manager, you need a deep understanding of risk management, information security frameworks (like ISO 27001 or NIST), and experience with compliance requirements, often supported by a degree in cybersecurity or related fields. Familiarity with security assessment tools, governance risk and compliance (GRC) platforms, and certifications such as CISSP or CISM are highly valued. Strong analytical thinking, attention to detail, and excellent communication skills help in managing stakeholder expectations and guiding teams. These competencies are crucial for ensuring organizational resilience, regulatory compliance, and the effective mitigation of security risks.

What are the main challenges security assurance managers face when coordinating with cross-functional teams?

Security Assurance Managers often work closely with IT, compliance, and business units to ensure organizational security standards are met. A common challenge is aligning security goals with business objectives while managing differing priorities and levels of security awareness across teams. Effective communication and negotiation skills are crucial for building consensus and integrating security controls into diverse workflows. Successfully navigating these dynamics helps foster a strong security culture and ensures compliance without hindering productivity.

What is the difference between Security Assurance Management vs Security Analyst?

AspectSecurity Assurance ManagementSecurity Analyst
CertificationsISO 27001 Lead Auditor, CISSP, CISACISSP, Security+
Work EnvironmentManagement, strategic planning, policy developmentOperational, monitoring, incident response
Employer & Industry UsageOrganizations seeking compliance & risk managementOrganizations monitoring security threats & vulnerabilities

Security Assurance Management focuses on establishing security policies, ensuring compliance, and managing overall security risk. In contrast, Security Analysts primarily monitor security systems, analyze threats, and respond to incidents. Both roles require certifications like CISSP, but their daily tasks and strategic focus differ significantly.

What are popular job titles related to Security Assurance Management jobs in Silver Spring, MD?

For Security Assurance Management jobs in Silver Spring, MD, the most frequently searched job titles are:

What job categories do people searching Security Assurance Management jobs in Silver Spring, MD look for?

The top searched job categories for Security Assurance Management jobs in Silver Spring, MD are:

What cities near Silver Spring, MD are hiring for Security Assurance Management jobs?

Cities near Silver Spring, MD with the most Security Assurance Management job openings:

Infographic showing various Security Assurance Management job openings in Silver Spring, MD as of August 2026, with employment types broken down into 100% Full Time. Highlights an 90% In-person, and 10% Remote job distribution, with an average salary of $90,054 per year, or $43.3 per hour.

Information System Security Officer with Security Clearance

XPECT Solutions, LLC.

Crystal City, VA • On-site

Other

Medical, Dental, Vision, Life, Retirement, PTO

Posted 15 days ago


Job description

Company Overview XPECT Solutions, LLC. has built a strong reputation by supporting our clients in meeting their strategic goals and mission objectives. We provide high quality resources for a wide range of IT and security solutions at best-value pricing. Our success is built on a solid foundation of well-vetted, highly technical personnel, a disciplined project management approach, and an overarching commitment to customer service. We develop, test, deploy, and support exceptional solutions that enhance system functionality, while maximizing reliability and availability, and ensure the tightest security. Job Overview XPECT Solutions seeks an experienced Information Systems Security Officer (ISSO) to lead compliance and security operations for government information systems. In this role, you will navigate the full NIST Risk Management Framework, ensure adherence to NIST 800-53 controls and DHS 4300A requirements, and oversee continuous authorization and monitoring activities. You will partner with Government Security Assurance Management teams, IT Program Managers, and security operations centers to protect critical systems and maintain compliance posture. This role demands deep technical security expertise, regulatory knowledge, and the ability to communicate complex security concepts to diverse stakeholders. Core Responsibilties (to include but not limited to): Risk Management Framework & Authorization * Participate in all phases of the NIST 800-37 Risk Management Framework (Prepare, Categorize, Select, Implement, Assess, Authorize, Monitor) * Ensure systems comply with NIST 800-53 security controls and DHS 4300A requirements * Prepare comprehensive security documentation and collect security artifacts in advance of assessments * Conduct self-assessments and support Security Control Assessment activities Security Compliance & Remediation * Evaluate effectiveness of proposed solutions to audit findings, Security Control Assessments, and other security weaknesses * Perform root cause analysis of audit findings and security incidents * Develop requirements for security control remediation activities * Review vulnerability scans from security assessment tools (Nessus, WebInspect, DbProtect, etc.) * Develop security control implementation statements and review supporting procedures and work instructions Security Documentation & Planning * Review and update the System Security Plan (SSP) and supporting security documentation * Work with Government Security Assurance Management (SAM) on Plan of Action and Milestones (POA&M) closure requests * Prepare status reports on security control accuracy and completeness * Interpret security principles and requirements for remediation plans * Brief Security Assurance Management and support teams on security posture and remediation strategies Configuration & Change Management * Perform security impact analysis of proposed configuration changes * Review security implications of system changes with Government IT Program Managers (ITPMs) and support staff Continuous Monitoringg & Ongoing Operations Once a system is operational, the ISSO performs recurring activities—ad hoc, daily, weekly, monthly, quarterly, and annually—documented in the continuous monitoring plan: * Support all Authorization to Operate (ATO) and continuous authorization activities * Plan of Action and Milestones (POA&M) Management to track identified system weaknesses to resolution * Information Security Vulnerability Management (ISVM)—review system scans at least monthly for new weaknesses, missed patches, unauthorized assets, or configuration changes * Patch Management to ensure all systems are patched regularly and compliance is maintained * Document and monitor any security issues or inconsistencies * Review ISVM findings for applicability and create POA&Ms or take corrective action as required * Audit Log Monitoring and Event Management—periodically review logs for security incidents, unauthorized access attempts, and anomalous activity * Awareness and Training—ensure all system users complete security awareness and role-based security training annually * Work with federal product managers to prioritize security-related POA&Ms or enhancements into active sprints and releases * Provide 24×7 on-call support for security incidents and escalations * Ensure compliance with Zero Trust cybersecurity principles and support agency adoption of zero trust network architectures Requirements: * Must Be Able to Obtain Public Trust Level 6C * Bachelor's Degree in Physics, Mathematics, Information Technology, Computer Science, Business, or related discipline * Minimum of 5 years of professional experience in cybersecurity, information assurance, or related technical roles. * Demonstrable expertise in NIST RMF, NIST 800-53, NIST 800-37, and DHS 4300A requirements * Knowledge and experience of information security practices within federal and/or state government environments. * Excellent written and oral skills * Ability to work on-site in Crystal City, Virginia,1 day per week Preferred Additional Skills and Qualifications: * CISSP, CCSK, GCIH, or other advanced cybersecurity certification * Experience with FedRAMP, FISMA, or other federal compliance frameworks * Hands-on experience with vulnerability assessment tools (Nessus, WebInspect, Qualys, etc.) * Experience in Zero Trust architecture design and implementation * Knowledge of cloud security (AWS, Azure, GCP) and containerized environments * Experience working with Security Operations Centers (SOCs) and incident response teams * Demonstrated success working with Agile/DevSecOps practices and sprint-based development environments Benefits Xpect Solutions, Inc. is a one-of-a-kind employer with a talented team that is cleared at various levels and is certified in dozens of industry-recognized certifications. Our talented staff are the key to our success. They bring the knowledge, experience and technical skills to deliver the best solutions to our customers. We support our team by providing open communication, win-win partnerships with clients and vendors, a team-oriented culture that supports an employee focus on professional development and growth for a long-lasting and happy career. We offer a benefits package that is designed to keep our most important assets – our employees – healthy, happy, energized and moving forward. Our philosophy is simple – empower our employees with the benefits, resources and the financial incentives they need to be successful. Benefits and Perks: * A competitive Medical, Dental, and Vision plan * Retirement Savings Plan * Life Insurance * AD&D Insurance * Short Term and Long Term Disability Insurance * 3 weeks of annual PTO * 11 days of Holiday PTO * Performance Awards * Referral Bonus Plan (of up to $2,500/year) * Education Reimbursement/Training (of up to $2,500/year) #CJ Apply Now Refer to a Friend Copyright 2026 Xpect Solutions. All rights reserved. Powered by ApplicantStack™ Applicant Tracking
Privacy Policy | Terms of Use