Security Control Assessment: Evaluate baseline security controls (NIST SP 800-53 Rev. 5, CNSSI 1253) across contractor-designed networks, verifying implementation of administrative, operational, and ...
Security Control Assessment: Evaluate baseline security controls (NIST SP 800-53 Rev. 5, CNSSI 1253) across contractor-designed networks, verifying implementation of administrative, operational, and ...
Lead all aspects of the RMF process, from system categorization and security control selection to implementation and assessment. * Security Documentation: Develop, maintain, and update all required ...
Lead all aspects of the RMF process, from system categorization and security control selection to implementation and assessment. * Security Documentation: Develop, maintain, and update all required ...
Advisory Information Security Manager
Huntsville, AL ยท On-site
$120 - $190/hr
Security Control Assessment: Evaluate baseline security controls (NIST SP 800-53 Rev. 5, CNSSI 1253) across contractor-designed networks, verifying implementation of administrative, operational, and ...
New
Advisory Information Security Manager
Huntsville, AL ยท On-site
$120 - $190/hr
Security Control Assessment: Evaluate baseline security controls (NIST SP 800-53 Rev. 5, CNSSI 1253) across contractor-designed networks, verifying implementation of administrative, operational, and ...
New
Cybersecurity Analyst II
Huntsville, AL ยท On-site
ARES Corporation is seeking an experienced senior cybersecurity analyst to join their security control assessment and risk assessment teams supporting the Nation's ballistic missile defense program.
Cybersecurity Analyst II
Huntsville, AL ยท On-site
ARES Corporation is seeking an experienced senior cybersecurity analyst to join their security control assessment and risk assessment teams supporting the Nation's ballistic missile defense program.
Lead all aspects of the RMF process, from system categorization and security control selection to implementation and assessment. * Security Documentation: Develop, maintain, and update all required ...
New
Lead all aspects of the RMF process, from system categorization and security control selection to implementation and assessment. * Security Documentation: Develop, maintain, and update all required ...
New
Lead all aspects of the RMF process, from system categorization and security control selection to implementation and assessment. * Security Documentation: Develop, maintain, and update all required ...
New
Lead all aspects of the RMF process, from system categorization and security control selection to implementation and assessment. * Security Documentation: Develop, maintain, and update all required ...
New
Lead all aspects of the RMF process, from system categorization and security control selection to implementation and assessment. * Security Documentation: Develop, maintain, and update all required ...
New
Quick apply
Lead all aspects of the RMF process, from system categorization and security control selection to implementation and assessment. * Security Documentation: Develop, maintain, and update all required ...
New
Ensure comprehensive security control assessments are planned, executed, and documented to validate the effectiveness of implemented safeguards * Prepare risk management documentation for system ...
Ensure comprehensive security control assessments are planned, executed, and documented to validate the effectiveness of implemented safeguards * Prepare risk management documentation for system ...
Senior Information Systems Security Engineer with Security Clearance
Huntsville, AL ยท On-site
$105K - $143K/yr
... control assessments are planned, executed, and documented to validate the effectiveness of ... of security awareness, providing technical guidance and training to both team members and ...
Senior Information Systems Security Engineer with Security Clearance
Huntsville, AL ยท On-site
$105K - $143K/yr
... control assessments are planned, executed, and documented to validate the effectiveness of ... of security awareness, providing technical guidance and training to both team members and ...
Security Control Assessment: Evaluate baseline security controls (NIST SP 800-53 Rev. 5, CNSSI 1253) across contractor-designed networks, verifying implementation of administrative, operational, and ...
Security Control Assessment: Evaluate baseline security controls (NIST SP 800-53 Rev. 5, CNSSI 1253) across contractor-designed networks, verifying implementation of administrative, operational, and ...
Security Control Assessment: Evaluate baseline security controls (NIST SP 800-53 Rev. 5, CNSSI 1253) across contractor-designed networks, verifying implementation of administrative, operational, and ...
Security Control Assessment: Evaluate baseline security controls (NIST SP 800-53 Rev. 5, CNSSI 1253) across contractor-designed networks, verifying implementation of administrative, operational, and ...
Conduct required IS vulnerability scans according to risk assessment parameters * Manage the risks ... Upload all security control evidence to the Governance, Risk, and Compliance (GRC) application to ...
Conduct required IS vulnerability scans according to risk assessment parameters * Manage the risks ... Upload all security control evidence to the Governance, Risk, and Compliance (GRC) application to ...
Security Control Assessment: Evaluate baseline security controls (NIST SP 800-53 Rev. 5, CNSSI 1253) across contractor-designed networks, verifying implementation of administrative, operational, and ...
Security Control Assessment: Evaluate baseline security controls (NIST SP 800-53 Rev. 5, CNSSI 1253) across contractor-designed networks, verifying implementation of administrative, operational, and ...
Security Control Assessment: Evaluate baseline security controls (NIST SP 800-53 Rev. 5, CNSSI 1253) across contractor-designed networks, verifying implementation of administrative, operational, and ...
Security Control Assessment: Evaluate baseline security controls (NIST SP 800-53 Rev. 5, CNSSI 1253) across contractor-designed networks, verifying implementation of administrative, operational, and ...
Ensure comprehensive security control assessments are planned, executed, and documented to validate the effectiveness of implemented safeguards * Prepare risk management documentation for system ...
Ensure comprehensive security control assessments are planned, executed, and documented to validate the effectiveness of implemented safeguards * Prepare risk management documentation for system ...
... control assessments are planned, executed, and documented to validate the effectiveness of ... security awareness, providing technical guidance and training to both team members and ...
Quick apply
... control assessments are planned, executed, and documented to validate the effectiveness of ... security awareness, providing technical guidance and training to both team members and ...
Ensure comprehensive security control assessments are planned, executed, and documented to validate the effectiveness of implemented safeguards * Prepare risk management documentation for system ...
Ensure comprehensive security control assessments are planned, executed, and documented to validate the effectiveness of implemented safeguards * Prepare risk management documentation for system ...
Team Manager / Information System Security Officer (ISSO) - JWICS Support Modernization
Huntsville, AL ยท On-site
System Security Plans (SSPs) Security Assessment Reports (SARs) Plans of Action and Milestones (POA&Ms) Security control traceability matrices Risk assessments and other RMF artifacts in accordance ...
Team Manager / Information System Security Officer (ISSO) - JWICS Support Modernization
Huntsville, AL ยท On-site
System Security Plans (SSPs) Security Assessment Reports (SARs) Plans of Action and Milestones (POA&Ms) Security control traceability matrices Risk assessments and other RMF artifacts in accordance ...
Security control traceability matrices * Risk assessments and other RMF artifacts in accordance with NIST, DoD, and Army RMF guidance. * Collaborate with the Program ISSM/P-ISSM, AO, AODRs, system ...
New
Security control traceability matrices * Risk assessments and other RMF artifacts in accordance with NIST, DoD, and Army RMF guidance. * Collaborate with the Program ISSM/P-ISSM, AO, AODRs, system ...
New
System Security Plans (SSPs) Security Assessment Reports (SARs) Plans of Action and Milestones (POA&Ms) Security control traceability matrices Risk assessments and other RMF artifacts in accordance ...
System Security Plans (SSPs) Security Assessment Reports (SARs) Plans of Action and Milestones (POA&Ms) Security control traceability matrices Risk assessments and other RMF artifacts in accordance ...
Security Control Assessor information
See Alabama salary details
$8.06 - $13.77
2% of jobs
$13.77 - $19.47
2% of jobs
$19.47 - $25.18
0% of jobs
$25.18 - $30.88
0% of jobs
$30.88 - $36.58
3% of jobs
$36.58 - $42.29
5% of jobs
$45.64 is the 25th percentile. Wages below this are outliers.
$42.29 - $47.99
21% of jobs
The median wage is $52.65 / hr.
$47.99 - $53.70
20% of jobs
$53.70 - $59.40
18% of jobs
$60.73 is the 75th percentile. Wages above this are outliers.
$59.40 - $65.11
15% of jobs
$65.11 - $70.81
14% of jobs
$8
$53
$70
How much do security control assessor jobs pay per hour?
How much do security control assessors make?
What are the key skills and qualifications needed to thrive as a security control assessor, and why are they important?
What is the difference between Security Control Assessor vs Security Analyst?
| Aspect | Security Control Assessor | Security Analyst |
|---|---|---|
| Certifications | Risk Management Framework (RMF), CISSP, CISA | CISSP, Security+ |
| Work Environment | Federal agencies, DoD, government compliance | Corporate, cybersecurity teams, IT departments |
| Responsibilities | Assess security controls, ensure compliance, audit | Monitor security, analyze threats, implement security measures |
The Security Control Assessor primarily evaluates security controls for compliance and risk management, often within government agencies. In contrast, the Security Analyst focuses on monitoring and analyzing security threats to protect organizational assets. While both roles require cybersecurity knowledge and certifications like CISSP, their focus areas and work environments differ significantly.
What are the main challenges security control assessors face when evaluating complex information systems?
What is a security control assessor?

Advisory Information Security Manager (ISSM) with Security Clearance
Huntsville, AL โข On-site
Other
This job post hasย expired today.ย Applications are no longer accepted.
Job description
* On-Site Government Collaboration: Serve as the primary contractor cybersecurity authority operating directly on-site with Army and Navy Organization ISSMs, AODRs, and AOs to facilitate accreditation processes.
* eMASS Package Development & Maintenance: Build, manage, and maintain formal Assessment & Authorization (A&A) packages within eMASS (Enterprise Mission Assurance Support Service) and relevant customer databases, ensuring accurate control allocation and implementation statements.
* Security Control Assessment: Evaluate baseline security controls (NIST SP 800-53 Rev. 5, CNSSI 1253) across contractor-designed networks, verifying implementation of administrative, operational, and technical safeguards.
* Vulnerability & Scan Management: Oversee automated vulnerability assessment tools (ACAS, Nessus, SCAP Compliance Checker), evaluating raw scan results, prioritizing findings, and ensuring required DISA STIGs/SRGs are applied.
* POA&M Ownership: Draft, track, and remediate Plans of Action and Milestones (POA&Ms), negotiating acceptable risk levels and mitigation strategies with government stakeholders.
* Continuous Monitoring (ConMon): Establish and execute ongoing ConMon strategies to maintain authorization boundaries, managing annual security reviews, boundary modification requests, and re-authorization events. * Internal Cybersecurity Hardening & Product Security
* Shift-Left Security Engineering: Collaborate with internal software, network, and systems engineering teams during early development lifecycle phases to embed cybersecurity requirements into company-developed technology before deployment.
* System Hardening Standards: Develop and enforce internal baseline configuration guides, utilizing DISA STIGs and CIS Benchmarks across company-built hardware appliances, software stacks, and operating environments.
* Architecture & Code Review Oversight: Evaluate internal product architectures and software deliverables for security posture, facilitating static/dynamic code analysis, dependency scanning, and zero-trust alignment.
* Best Practices & Governance: Establish company-internal cybersecurity standard operating procedures (SOPs), hardening checklists, and secure development guidelines to ensure consistency across product lines. * Incident Management & Cyber Hygiene
* Vulnerability Response: Lead protective and corrective measures upon discovery of critical vulnerabilities or zero-day threats affecting deployed customer networks or company solutions.
* Incident Handling Support: Coordinate with government security leadership and internal teams to report, contain, investigate, and remediate potential security incidents or policy non-compliance.
* Audit & Inspection Readiness: Coordinate and prepare systems for formal government cybersecurity inspections, and internal quality audits. * Strategic Advisory & Stakeholder Communication
* Leadership Consultation: Advise internal engineering managers and government leadership on security posture, mission risk trade-offs, and emerging cybersecurity threats.
* Technical Interface: Translate complex government compliance requirements (DoDI 8510.01, NIST guidelines) into actionable technical requirements for internal development teams. Education/Qualifications Active TS Clearance (TS/SCI preferred) Must hold a TS security clearance (TS/SCI preferred) DoD 8140/8570 Baseline Certification (Required): * Intermediate Level (Minimum): CompTIA Security+, CompTIA SecurityX (formerly CASP+), Cloud+, GSEC, or equivalent * Advanced Level (Preferred): CISSP (Certified Information Systems Security Professional), CISM (Certified Information Security Manager), GCSA, GCIA, or CISSP-ISSMP. Bachelors in Information Technology, Cybersecurity, Computer Science, Inforamtion Systems, Software Engineering or equivalent +5 years of relevant experience supporting Army or Navy customers in the full RMF lifecycle. Required Technical & Functional Competencies: Government RMF & Compliance Mastery * Demonstrated hands-on experience navigating the complete Risk Management Framework (RMF) lifecycle per DoDI 8510.01, NIST SP 800-53 (Rev. 5), and CNSSI 1253. * Advanced operational capability using eMASS (Enterprise Mission Assurance Support Service) to build, manage, and defend Assessment & Authorization (A&A) packages for Army and/or Navy customers. * Experience managing vulnerability assessment tools (ACAS/Nessus, SCAP Compliance Checker), evaluating raw technical scan data, and applying DISA STIGs / SRGs. * Proven track record drafting, negotiating, and tracking POA&Ms through mitigation to secure ATO, ATO with Conditions, or Interim Authority to Test (IATT). Internal Product Hardening & DevSecOps * Solid working knowledge of system hardening standards across operating systems (Linux/Windows), network infrastructure, containerized environments, and cloud architectures. * Experience embedding cybersecurity requirements into early software/systems engineering workflows (Shift-Left Security / DevSecOps pipelines). * Familiarity with static/dynamic application security testing (SAST/DAST) tools and software bill of materials (SBOM) management. Preferred / Desirable Qualifications * Direct experience supporting Army (eMASS-Army) or Navy (NAVIFOR / NAVSEA / NAVAIR / SPAWAR) program offices and Authorizing Officials (AOs). * Specialized certifications in audit, risk management, or cloud security (e.g., CISA, CRISC, CCSP, AWS/Azure Security Specialties). #LI-EB1 #LI-Onsite
About Frontier Technology
Sourced by ZipRecruiter
Industry
Guided missile and space vehicle manufacturing
Company size
201 - 500 Employees
Headquarters location
Beavercreek, OH, US
Year founded
1985