1

Security Control Assessor Jobs in Colorado (NOW HIRING)

Security Control Assessor (SCA) LOCATION Aurora, CO 80014 CLEARANCE TS/SCI Full Poly (Please note this position requires full U.S. Citizenship) KEY SUMMARY We are seeking a meticulous and detail ...

Overview VTG is looking for multiple levels (Level 2, 3 & 4) of a Security Control Assessor (SCA) in multiple locations. (Note: position is contingent upon program award and the postions are located ...

next page

Showing results 1-20

Security Control Assessor information

See Colorado salary details

$9

$61

$82

How much do security control assessor jobs pay per hour?

As of Jul 30, 2026, the average hourly pay for security control assessor in Colorado is $61.79, according to ZipRecruiter salary data. Most workers in this role earn between $53.08 and $71.54 per hour, depending on experience, location, and employer.

Can you make $500,000 a year in cyber security?

Security Control Assessors typically earn salaries ranging from $70,000 to $150,000 annually, depending on experience, certifications, and location. Reaching a $500,000 annual salary in cybersecurity generally requires senior roles, specialized expertise, management positions, or consulting work with high-value contracts.

Is SOC an entry level job?

A Security Control Assessor (SOC) role is typically not entry-level; it usually requires prior experience in cybersecurity, knowledge of security frameworks, and relevant certifications such as CISSP or Security+. Entry-level positions in cybersecurity may include roles like Security Analyst or Technician, with SOC roles often requiring more specialized skills and experience. However, some organizations offer junior or trainee SOC positions for those starting their cybersecurity careers.

What are the key skills and qualifications needed to thrive as a Security Control Assessor, and why are they important?

To thrive as a Security Control Assessor, you need expertise in information security principles, risk management frameworks like NIST RMF, and a relevant bachelor's degree or equivalent work experience. Familiarity with security assessment tools, compliance management systems, and certifications such as CISSP, CISA, or CAP is typically required. Strong analytical thinking, attention to detail, and effective communication are crucial for evaluating security controls and reporting findings clearly. These skills ensure accurate risk assessments, regulatory compliance, and robust protection of organizational information assets.

What skills do you need to be a security control assessor?

A security control assessor needs strong knowledge of cybersecurity frameworks, risk management, and security controls. Skills in analyzing security policies, conducting assessments, and familiarity with tools like NIST, ISO standards, and vulnerability scanning are essential. Certifications such as CISSP or CISA can also enhance qualifications.

What is the difference between Security Control Assessor vs Security Analyst?

AspectSecurity Control AssessorSecurity Analyst
CertificationsRisk Management Framework (RMF), CISSP, CISACISSP, Security+
Work EnvironmentFederal agencies, DoD, government complianceCorporate, cybersecurity teams, IT departments
ResponsibilitiesAssess security controls, ensure compliance, auditMonitor security, analyze threats, implement security measures

The Security Control Assessor primarily evaluates security controls for compliance and risk management, often within government agencies. In contrast, the Security Analyst focuses on monitoring and analyzing security threats to protect organizational assets. While both roles require cybersecurity knowledge and certifications like CISSP, their focus areas and work environments differ significantly.

What is the role of a security control assessor?

A security control assessor evaluates the effectiveness of security controls implemented within an organization to ensure they meet security standards and compliance requirements. They review documentation, conduct testing, and provide recommendations for improvement, often working with frameworks like NIST or ISO. Certification such as CISSP or CISA is commonly required for this role.

What are the main challenges Security Control Assessors face when evaluating complex information systems?

Security Control Assessors often encounter challenges such as rapidly evolving security threats, integrating new technologies, and ensuring compliance with multiple frameworks (like NIST, FISMA, or RMF). Assessing large, interconnected systems requires attention to detail and strong analytical skills to identify vulnerabilities and recommend effective controls. Collaboration with system owners, IT staff, and auditors is essential to obtain comprehensive documentation and clarify system boundaries, which can be a demanding part of the assessment process.

What are Security Control Assessors?

Security Control Assessors (SCAs) are professionals responsible for evaluating the security controls of information systems to ensure they meet required standards and regulations. They conduct assessments, document findings, and provide recommendations to help organizations manage risk and achieve compliance with frameworks such as NIST or FISMA. SCAs play a critical role in maintaining the security and integrity of sensitive data by identifying vulnerabilities and verifying that corrective actions are implemented effectively.
What are popular job titles related to Security Control Assessor jobs in Colorado? For Security Control Assessor jobs in Colorado, the most frequently searched job titles are:
What job categories do people searching Security Control Assessor jobs in Colorado look for? The top searched job categories for Security Control Assessor jobs in Colorado are:
What cities in Colorado are hiring for Security Control Assessor jobs? Cities in Colorado with the most Security Control Assessor job openings:
What are popular job titles related to Security Control Assessor jobs in CO? For Security Control Assessor jobs in CO, the most frequently searched job titles are:
Infographic showing various Security Control Assessor job openings in Colorado as of July 2026, with employment types broken down into 2% Locum Tenens, 36% Full Time, 6% Part Time, 1% Temporary, 1% Contract, and 54% Nights. Highlights an 88% Physical, 2% Hybrid, and 10% Remote job distribution, with an average salary of $128,533 per year, or $61.8 per hour.

Security Control Assessor

ITI Solutions, Inc

Colorado Springs, CO • On-site

$90K - $102K/yr

Full-time

Posted 21 days ago


Job description

Location: Peterson SFB, Colorado Springs, Colorado
ITI Solutions is seeking a Security Control Assessor to support an effort to develop, implement, manage, and maintain a Risk Management Framework Cybersecurity Program at Peterson Space Force Base, Colorado. The effort provides cybersecurity services, conducts cybersecurity technical assessments, and participates in cybersecurity technical investigations.
About ITI Solutions, Inc.
ITI Solutions, Inc. is a Service-Disabled Veteran-Owned Small Business (SDVOSB) with a strong track record supporting Department of Defense (DoD) programs, including U.S. Army vehicle production, sustainment, and modernization efforts.
Founded by a Service-Disabled Veteran, we bring mission-driven expertise in engineering support, logistics coordination, and program execution to critical national defense initiatives.
As an Equal Opportunity Employer, ITI Solutions is committed to fostering a diverse, inclusive, and respectful workplace. We do not discriminate in employment decisions on the basis of race, color, religion, national origin, sex, gender, gender identity, sexual orientation, age, disability, protected veteran status, genetic information, or any other characteristic protected by applicable federal, state, or local law. We are dedicated to providing equal employment opportunities to all applicants and employees and maintaining a work environment that is free from discrimination and harassment.
Responsibilities:
  • Analyze, assess, validate, and provide recommendations on cybersecurity RMF packages to support the assessment and accreditation of emerging cybersecurity capabilities and methodologies.
  • Develop and deliver Cyber Risk Assessment reports.
  • Review requests for use of Commercial Internet Service Providers (CISPs) and advise, assist, and provide recommendations to the government on the quality of the submission.
  • Review requests for use of Commercial Satellite Communication and advise, assist, and provide recommendations to the government on the quality of the submission.
  • Schedule and attend meetings and conferences as required to support cybersecurity assessments and processes.
  • Review the Evaluated/Approved Products List (E/APL) to ensure tools requested for use within the Space Authorization Boundary are certified for Space and DoD/US intelligence information systems and applications and provide recommendations to the government.
  • Provide subject matter expertise to analyze the results of system scans and Security Technical Implementation Guides (STIGs) to support the government's management of vulnerabilities and ensure policy compliance.

Experience/Skills:
  • Minimum of 5 years of experience implementing, monitoring, and assessing Risk Management Framework security controls.
  • Strong analytical skills.
  • Excellent verbal and written communication skills.
  • Experience as a Security Control Assessor on behalf of a Department of Defense agency is highly desired.
  • Experience with US Space Force or USAF Space Command systems is highly desirable.

Education:
  • A BS degree in an IT-related field is required.
  • An advanced degree is highly desired

Certifications:
  • Security+ CE or equivalent is required.
  • Other cybersecurity certifications, including CISSP, Certified Ethical Hacker, Certified Authorization Professional, Systems Security Certified Practitioner, etc. are highly desired.

Clearance:
  • Must be a US Citizen and, at a minimum, hold a current Top Secret clearance with TS/SCI eligibility.

Salary Range:
  • The salary will be set based on experience, geographic location and possibly contractual requirements.