1

Security Control Assessor Jobs (NOW HIRING)

We are seeking a highly skilled Security Control Assessor (SCA) to support independent cybersecurity assessments of systems in accordance with the Risk Management Framework (RMF). This role is ...

Security Control Assessor

Arlington, VA · On-site

$110K - $130K/yr

Argo Cyber Systems is seeking a RMF/ Security Control Assessor to support cybersecurity governance, risk, compliance, and modernization activities in federal environments. The selected candidate will ...

ORA_ON_SITE Description SAIC is seeking a highly skilled and motivated Senior Security Control Assessor (SCA) to support the cybersecurity assessment and compliance needs of mission-critical ...

Security Control Assessor

Alexandria, VA · On-site

$137K - $152K/yr

M9 Solutions is seeking a Security Control Assessor to work on-site in support of a government contract for a client located in Alexandria, VA . An active Secret clearance is required.

ORA_ON_SITE Description SAIC is seeking a highly skilled and motivated  Senior Security Control Assessor (SCA)  to support the cybersecurity assessment and compliance needs of mission-critical ...

Description SAIC is seeking a highly skilled and motivated Senior Security Control Assessor (SCA) to support the cybersecurity assessment and compliance needs of mission-critical IT systems for the ...

Execute a security control assessment plan and update the System Security Plan * Review vulnerability scans and remediation * Implement risk management programs by utilizing NIST, FISMA, HIPAA, and ...

Security Control Assessor

Alexandria, VA · On-site

$137K - $152K/yr

M9 Solutions is seeking a Security Control Assessor to work on-site in support of a government contract for a client located in Alexandria, VA . An active Secret clearance is required.

Security Control Assessor

Monterey, CA · On-site

$65K - $75K/yr

Security Control Assessor Target Salary: $65K to $75K LOCATION: DLIFLC, 1759 Lewis Road, Monterey, CA 93944 Position Overview: The Security Control Assessor is responsible for conducting independent ...

next page

Showing results 1-20

Security Control Assessor information

See salary details

$8

$58

$78

How much do security control assessor jobs pay per hour?

As of Aug 22, 2026, the average hourly pay for security control assessor in the United States is $58.77, according to ZipRecruiter salary data. Most workers in this role earn between $50.48 and $68.03 per hour, depending on experience, location, and employer.

What is a security control assessor?

Security Control Assessors (SCAs) are professionals responsible for evaluating the security controls of information systems to ensure they meet required standards and regulations. They conduct assessments, document findings, and provide recommendations to help organizations manage risk and achieve compliance with frameworks such as NIST or FISMA. SCAs play a critical role in maintaining the security and integrity of sensitive data by identifying vulnerabilities and verifying that corrective actions are implemented effectively.

What are the main challenges security control assessors face when evaluating complex information systems?

Security Control Assessors often encounter challenges such as rapidly evolving security threats, integrating new technologies, and ensuring compliance with multiple frameworks (like NIST, FISMA, or RMF). Assessing large, interconnected systems requires attention to detail and strong analytical skills to identify vulnerabilities and recommend effective controls. Collaboration with system owners, IT staff, and auditors is essential to obtain comprehensive documentation and clarify system boundaries, which can be a demanding part of the assessment process.

What are the key skills and qualifications needed to thrive as a security control assessor, and why are they important?

To thrive as a Security Control Assessor, you need expertise in information security principles, risk management frameworks like NIST RMF, and a relevant bachelor's degree or equivalent work experience. Familiarity with security assessment tools, compliance management systems, and certifications such as CISSP, CISA, or CAP is typically required. Strong analytical thinking, attention to detail, and effective communication are crucial for evaluating security controls and reporting findings clearly. These skills ensure accurate risk assessments, regulatory compliance, and robust protection of organizational information assets.

What is the difference between Security Control Assessor vs Security Analyst?

AspectSecurity Control AssessorSecurity Analyst
CertificationsRisk Management Framework (RMF), CISSP, CISACISSP, Security+
Work EnvironmentFederal agencies, DoD, government complianceCorporate, cybersecurity teams, IT departments
ResponsibilitiesAssess security controls, ensure compliance, auditMonitor security, analyze threats, implement security measures

The Security Control Assessor primarily evaluates security controls for compliance and risk management, often within government agencies. In contrast, the Security Analyst focuses on monitoring and analyzing security threats to protect organizational assets. While both roles require cybersecurity knowledge and certifications like CISSP, their focus areas and work environments differ significantly.

How much do security control assessors make?

Security Control Assessors in the federal government or related sectors typically earn between $80,000 and $130,000 annually, depending on experience, certifications, and location. Salaries can vary based on agency, level of clearance, and specific responsibilities, with higher pay often associated with specialized skills and certifications like CISSP or CISA.
More about Security Control Assessor jobs

What cities are hiring for Security Control Assessor jobs?

Cities with the most Security Control Assessor job openings:

What are the most commonly searched types of Security Control Assessor jobs?

The most popular types of Security Control Assessor jobs are:

What states have the most Security Control Assessor jobs?

States with the most job openings for Security Control Assessor jobs include:

Infographic showing various Security Control Assessor job openings in the United States as of August 2026, with employment types broken down into 1% As Needed, 75% Full Time, 20% Part Time, 3% Contract, and 1% Nights. Highlights an 95% Physical, 1% Hybrid, and 4% Remote job distribution, with an average salary of $122,236 per year, or $58.8 per hour.

Security Control Assessor

Crest Security Assurance

Petersburg, VA • On-site

$90K - $95K/yr

Full-time

Posted 23 days ago


Job description

Support the Defense Contract Management Agency (DCMA) Cybersecurity Support Services (CSS) contract by independently assessing security controls for classified and unclassified information systems. Plan and execute security control assessments in accordance with DoDI 8510.01, the DoD Risk Management Framework (RMF), NIST SP 800-53, and NIST SP 800-53A, and provide objective evidence and risk-based recommendations to support authorization decisions and continuous monitoring.


Responsibilities:

• Develop and execute Security Assessment Plans (SAPs), including assessment scope, methodology, procedures, schedules, and evidence requirements, in coordination with system owners, Information System Security Officers (ISSOs), Information System Security Managers (ISSMs), and Authorizing Official staff.

• Assess implemented technical, operational, and management security controls through documentation review, interviews, observation, testing, and analysis of artifacts such as vulnerability scan results, Security Technical Implementation Guide (STIG) checklists, configuration baselines, and continuous monitoring records.

• Document assessment results, findings, and residual risk in Security Assessment Reports (SARs), Security Control Assessment Reports (SCARs), Risk Assessment Reports (RARs), and related RMF artifacts; validate that findings are accurate, traceable, and supported by sufficient evidence.

• Review Plans of Action and Milestones (POA&Ms) and remediation evidence, evaluate proposed mitigations, and perform closure validation or follow-up testing to confirm that identified weaknesses have been effectively addressed.

• Maintain assessment results, control status, evidence, and authorization documentation in the Enterprise Mission Assurance Support Service (eMASS); track assessment activities and provide status, risk, and performance metrics to DCMA leadership.


Requirements:

• Active Secret security clearance

• At least 5-7 years of related cybersecurity, RMF, security control assessment, or information assurance experience

• DoD IAM III required certification(s) (one of the following):

  • CISM
  • CISSP (or Associate)
  • GSLC
  • CCISO