1

Security Control Assessor Jobs in Colorado (NOW HIRING)

The Security Control Assessor's responsibilities include, but are not limited to, the following: Manage and approve Accreditation Packages. Plan and conduct security authorization reviews and ...

The Security Control Assessor's responsibilities include, but are not limited to, the following: * Manage and approve Accreditation Packages. * Plan and conduct security authorization reviews and ...

The Security Control Assessor's responsibilities include, but are not limited to, the following: * Manage and approve Accreditation Packages. * Plan and conduct security authorization reviews and ...

Security Control Assessor (SCA) LOCATION Aurora, CO 80014 CLEARANCE TS/SCI Full Poly (Please note this position requires full U.S. Citizenship) KEY SUMMARY We are seeking a meticulous and detail ...

Overview VTG is looking for multiple levels (Level 2, 3 & 4) of a Security Control Assessor (SCA) in multiple locations. (Note: position is contingent upon program award and the postions are located ...

next page

Showing results 1-20

Security Control Assessor information

See Colorado salary details

$9

$61

$82

How much do security control assessor jobs pay per hour?

As of Sep 11, 2026, the average hourly pay for security control assessor in Colorado is $61.79, according to ZipRecruiter salary data. Most workers in this role earn between $53.08 and $71.54 per hour, depending on experience, location, and employer.

What is a security control assessor?

Security Control Assessors (SCAs) are professionals responsible for evaluating the security controls of information systems to ensure they meet required standards and regulations. They conduct assessments, document findings, and provide recommendations to help organizations manage risk and achieve compliance with frameworks such as NIST or FISMA. SCAs play a critical role in maintaining the security and integrity of sensitive data by identifying vulnerabilities and verifying that corrective actions are implemented effectively.

What are the main challenges security control assessors face when evaluating complex information systems?

Security Control Assessors often encounter challenges such as rapidly evolving security threats, integrating new technologies, and ensuring compliance with multiple frameworks (like NIST, FISMA, or RMF). Assessing large, interconnected systems requires attention to detail and strong analytical skills to identify vulnerabilities and recommend effective controls. Collaboration with system owners, IT staff, and auditors is essential to obtain comprehensive documentation and clarify system boundaries, which can be a demanding part of the assessment process.

What are the key skills and qualifications needed to thrive as a security control assessor, and why are they important?

To thrive as a Security Control Assessor, you need expertise in information security principles, risk management frameworks like NIST RMF, and a relevant bachelor's degree or equivalent work experience. Familiarity with security assessment tools, compliance management systems, and certifications such as CISSP, CISA, or CAP is typically required. Strong analytical thinking, attention to detail, and effective communication are crucial for evaluating security controls and reporting findings clearly. These skills ensure accurate risk assessments, regulatory compliance, and robust protection of organizational information assets.

What is the difference between Security Control Assessor vs Security Analyst?

AspectSecurity Control AssessorSecurity Analyst
CertificationsRisk Management Framework (RMF), CISSP, CISACISSP, Security+
Work EnvironmentFederal agencies, DoD, government complianceCorporate, cybersecurity teams, IT departments
ResponsibilitiesAssess security controls, ensure compliance, auditMonitor security, analyze threats, implement security measures

The Security Control Assessor primarily evaluates security controls for compliance and risk management, often within government agencies. In contrast, the Security Analyst focuses on monitoring and analyzing security threats to protect organizational assets. While both roles require cybersecurity knowledge and certifications like CISSP, their focus areas and work environments differ significantly.

How much do security control assessors make?

Security Control Assessors in the federal government or related sectors typically earn between $80,000 and $130,000 annually, depending on experience, certifications, and location. Salaries can vary based on agency, level of clearance, and specific responsibilities, with higher pay often associated with specialized skills and certifications like CISSP or CISA.

What are popular job titles related to Security Control Assessor jobs in Colorado?

For Security Control Assessor jobs in Colorado, the most frequently searched job titles are:

What job categories do people searching Security Control Assessor jobs in Colorado look for?

The top searched job categories for Security Control Assessor jobs in Colorado are:

What cities in Colorado are hiring for Security Control Assessor jobs?

Cities in Colorado with the most Security Control Assessor job openings:

What are popular job titles related to Security Control Assessor jobs in CO?

For Security Control Assessor jobs in CO, the most frequently searched job titles are:

Infographic showing various Security Control Assessor job openings in Colorado as of September 2026, with employment types broken down into 100% Full Time. Highlights an 100% In-person job distribution, with an average salary of $128,533 per year, or $61.8 per hour.

Security Control Assessor

Denver, CO • On-site

Calibre Systems
Business Management Consulting • 501 - 1,000 employees

$110K/yr

Other

Posted 16 days ago


Job description

CALIBRE Systems Inc., an employee-owned mission focused solutions and digital transformation company is seeking a Security Control Assessor (Mid-level) who will conduct independent comprehensive assessments of the management, operational, and technical security controls and control enhancements employed within or inherited by an information technology (IT) system to determine the overall effectiveness of the controls (as defined in NIST 800-37). This position has a salary of $110,000. The Security Control Assessor’s responsibilities include, but are not limited to, the following: Manage and approve Accreditation Packages. Plan and conduct security authorization reviews and assurance case development for initial installation of systems and networks. Review authorization and assurance documents to confirm that the level of risk is within acceptable limits for each software application, system, and network. Verify that application software/network/system security postures are implemented as stated, document deviations, and recommend required actions to correct those deviations. Develop security compliance processes and/or audits for external services (e.g., cloud service providers, data centers). Establish acceptable limits for the software application, network, or system. Perform security reviews, identify gaps in security architecture, and develop a security risk management plan. Perform security reviews and identify security gaps in security architecture resulting in recommendations for inclusion in the risk mitigation strategy. Perform risk analysis (e.g., threat, vulnerability, and probability of occurrence) whenever an application or system undergoes a major change. Provide input to the Risk Management Framework (RMF) process activities and related documentation (e.g., system life-cycle support plans, concept of operations, operational procedures, and maintenance training materials). Verify and update security documentation reflecting the application/system security design features. Participate in Risk Governance process to provide security risks, mitigations, and input on other technical risk. Ensure that plans of actions and milestones or remediation plans are in place for vulnerabilities identified during risk assessments, audits, inspections, etc. Assure successful implementation and functionality of security requirements and appropriate information technology (IT) policies and procedures that are consistent with the organization's mission and goals. Define and document how the implementation of a new system or new interfaces between systems impacts the security posture of the current environment. Required Skills All RMF steps as documented in the NIST RMF SP 800-series, with particular emphasis managing the ATO process. Experience planning, developing, implementing, tracking, and maintaining cybersecurity metrics and POA&Ms. Experience with RMF System Continuous Monitoring Plans. Experience performing technical risk and providing reports for accreditation. Usage of tools such as eMASS or XACTA. Usage of DISA STIG Viewer or a similar tool. Desired Skills Proficient with the Microsoft Office suite. Strong verbal and written communication skills. Understanding of DoDIN, DISA Information Assurance Guidance, and FEDRAMP Cloud Computing. required Experience US citizen Active Top Secret/Sensitive Compartmented Information (TS/SCI) clearance, eligible for Counterintelligence (CI) Polygraph. IAM or IAT Level 2 certification. Bachelor’s degree or higher from an accredited college or university in Computer Science, Cyber Security, Information Technology, Software Engineering, Information Systems, or Computer Engineering degree; or a degree in a Mathematics or Engineering field. Possible travel within the Continental United States (CONUS) and Outside CONUS (OCONUS).