1

Security Control Assessor Jobs in Colorado (NOW HIRING)

... control implementation, assessment support, POA&M management, and compliance documentation * Support system hardening, vulnerability assessment, patch management, and security remediation activities

Security Control Assessor training * RMF training * Splunk certifications * Elastic certifications * SIEM platform training * Insider Threat training Overview We are seeking a Watch Officer to join ...

... control implementation, assessment support, POA&M management, and compliance documentation * Support system hardening, vulnerability assessment, patch management, and security remediation activities

... control implementation, assessment support, POA&M management, and compliance documentation * Support system hardening, vulnerability assessment, patch management, and security remediation activities

They are seeking a Mission Security Engineer III to secure national security space systems and ... on control implementation, assessment preparation, and remediation for DoD and IC programs • ...

Advanced proficiency with vulnerability assessment tools, penetration testing methodologies, and automated control verification platforms * Practical application of AI literacy and AI-driven security ...

Showing results 41-60

Security Control Assessor information

See Colorado salary details

$9

$61

$82

How much do security control assessor jobs pay per hour?

As of Aug 7, 2026, the average hourly pay for security control assessor in Colorado is $61.79, according to ZipRecruiter salary data. Most workers in this role earn between $53.08 and $71.54 per hour, depending on experience, location, and employer.

How much do security control assessors make?

Security Control Assessors in the federal government or related sectors typically earn between $80,000 and $130,000 annually, depending on experience, certifications, and location. Salaries can vary based on agency, level of clearance, and specific responsibilities, with higher pay often associated with specialized skills and certifications like CISSP or CISA.

What are the key skills and qualifications needed to thrive as a security control assessor, and why are they important?

To thrive as a Security Control Assessor, you need expertise in information security principles, risk management frameworks like NIST RMF, and a relevant bachelor's degree or equivalent work experience. Familiarity with security assessment tools, compliance management systems, and certifications such as CISSP, CISA, or CAP is typically required. Strong analytical thinking, attention to detail, and effective communication are crucial for evaluating security controls and reporting findings clearly. These skills ensure accurate risk assessments, regulatory compliance, and robust protection of organizational information assets.

What is the difference between Security Control Assessor vs Security Analyst?

AspectSecurity Control AssessorSecurity Analyst
CertificationsRisk Management Framework (RMF), CISSP, CISACISSP, Security+
Work EnvironmentFederal agencies, DoD, government complianceCorporate, cybersecurity teams, IT departments
ResponsibilitiesAssess security controls, ensure compliance, auditMonitor security, analyze threats, implement security measures

The Security Control Assessor primarily evaluates security controls for compliance and risk management, often within government agencies. In contrast, the Security Analyst focuses on monitoring and analyzing security threats to protect organizational assets. While both roles require cybersecurity knowledge and certifications like CISSP, their focus areas and work environments differ significantly.

What are the main challenges security control assessors face when evaluating complex information systems?

Security Control Assessors often encounter challenges such as rapidly evolving security threats, integrating new technologies, and ensuring compliance with multiple frameworks (like NIST, FISMA, or RMF). Assessing large, interconnected systems requires attention to detail and strong analytical skills to identify vulnerabilities and recommend effective controls. Collaboration with system owners, IT staff, and auditors is essential to obtain comprehensive documentation and clarify system boundaries, which can be a demanding part of the assessment process.

What is a security control assessor?

Security Control Assessors (SCAs) are professionals responsible for evaluating the security controls of information systems to ensure they meet required standards and regulations. They conduct assessments, document findings, and provide recommendations to help organizations manage risk and achieve compliance with frameworks such as NIST or FISMA. SCAs play a critical role in maintaining the security and integrity of sensitive data by identifying vulnerabilities and verifying that corrective actions are implemented effectively.
What are popular job titles related to Security Control Assessor jobs in Colorado? For Security Control Assessor jobs in Colorado, the most frequently searched job titles are:
What job categories do people searching Security Control Assessor jobs in Colorado look for? The top searched job categories for Security Control Assessor jobs in Colorado are:
What cities in Colorado are hiring for Security Control Assessor jobs? Cities in Colorado with the most Security Control Assessor job openings:
What are popular job titles related to Security Control Assessor jobs in CO? For Security Control Assessor jobs in CO, the most frequently searched job titles are:
Infographic showing various Security Control Assessor job openings in Colorado as of August 2026, with employment types broken down into 1% As Needed, 77% Full Time, 19% Part Time, and 3% Contract. Highlights an 95% Physical, 1% Hybrid, and 4% Remote job distribution, with an average salary of $128,533 per year, or $61.8 per hour.

Cybersecurity Analyst / Information Systems Security Officer (IS with Security Clearance

KBR

Colorado Springs, CO • On-site

Other

Medical, Dental, Vision, Life, Retirement, PTO

This job post has expired today. Applications are no longer accepted.


KBR rating

8.3

Company rating: 8.3 out of 10

Based on 47 frontline employees who took The Breakroom Quiz

136th of 441 rated engineering


Job description

Title:
Cybersecurity Analyst / Information Systems Security Officer (ISSO) Belong. Connect. Grow. with KBR! KBR's National Security Solutions team provides high-end engineering and advanced technology solutions to our customers in the intelligence and national security communities. In this position, your work will have a profound impact on the country's most critical role - protecting our national security. Why Join Us? * Innovative Projects: KBR's work is at the forefront of engineering, logistics, operations, science, program management, mission IT and cybersecurity solutions.
* Collaborative Environment: Be part of a dynamic team that thrives on collaboration and innovation, fostering a supportive and intellectually stimulating workplace.
* Impactful Work: Your contributions will be pivotal in designing and optimizing defense systems that ensure national security and shape the future of space defense. Job Title: Cybersecurity Analyst / Information Systems Security Officer (ISSO) Job Summary: KBR is seeking a Cybersecurity Analyst / Information Systems Security Officer (ISSO) to join our team at Peterson SFB in Colorado Springs, CO. An active TS/SCI clearance is required. The individual will work in close coordination with current team members to ensure systems are operated, maintained, and disposed of in accordance with applicable security policies and procedures. Duties may include but are not limited to: * Perform activities to convert accreditation packages from DoDRMF Rev. 4 to Rev. 5
* Compiling and tracking vulnerabilities and mitigation results in quantifying program effectiveness, creating and maintaining vulnerability management policies, procedures and training
* Apply security policies to meet security objectives of the system
* Apply updates, patches, and security technical implementation while maintaining control system performance and availability requirements
* Establish and maintain security configuration baseline for the control system(s), including IT components, interconnections, and interfaces * Implement Risk Management Framework (RMF) Assessment requirements for control systems, and document/maintain records for them
* Maintain knowledge of the function and security of control system and IT technologies with which the control systems interface
* Perform asset management and maintain inventory of control system devices and components through physical inspection or logical scans
* Support risk assessments by reviewing and documenting the implementation status of security requirements of control systems
* Mitigate/correct security deficiencies identified during security/certification testing and/or recommend risk acceptance for the appropriate senior leader or authorized representative
* Provide input to the Risk Management Framework process activities and related documentation (e.g., system life-cycle support plans, concept of operations, operational procedures, and maintenance training materials)
* Reviewing and defining requirements for information security solutions, controls compliance and policy development
* Organizing network-based scans to identify possible network security attacks and host-based scans to identify vulnerabilities in workstations, servers and other network hosts determining critical security flaws and figuring out how to fix them
* Conduct audits and assessments focused on uncover vulnerabilities in the networks through scanning tools
* Assist in improving and automating existing vulnerability management lifecycle including but not limited to data ingestion & normalization, compliance metrics and detections on assets
* Assist in partnering with tools and technology teams to troubleshoot, develop, select, implement, and automate appropriate security solutions to keep system data protected from internal and external threats
* Assist in providing support and resolution for scanning and vulnerability remediation reporting issues
* Assist in working to effectively communicate the risks of identified vulnerabilities and make recommendations regarding the selection of cost-effective security controls to mitigate identified risks.
* Stay current with vulnerability information across all the products in the AVAC environment
* Work as part of an integrated team to develop and maintain RMF body of evidence documentation using Enterprise Mission Assurance Support Service (eMASS), XACTA or equivalent products
* Maintain repositories of all body of evidence documentation for systems under your purview
* Develop and execute security control assessment procedures to verify conformance with control requirements as part of ongoing continuous monitoring and authorization assessment activities
* Ensure all security-related vulnerabilities and deficiencies are documented in the Plan of Action and Milestones (POA&M) for each system
* Ensure configuration management policies and procedures for authorizing use of hardware/software are followed and coordinate any system baseline changes with the appropriate stakeholders prior to change
* Assisting with creating and maintaining RMF package documentation for multiple networks
* Advise ISSM of compliance issues, findings and status related to the system packages Required Qualifications: * Active TS/SCI clearance required
* DoD Directive (DoDD) 8140.01certification, Security+
* 2+ years of related experience
* Working knowledge of DoDRMF Rev.4 and/or 5, cyber technologies, NIST standards and DISA STIG governance
* Must have experience in the Agile Lifecycle to include, requirements, design, development, implementation, deployment and remediation
* Excellent technical document preparation and verbal communication skills are required
* Strong working knowledge of Confidentiality, Integrity, and Availability (CIA) concepts such as patch management, multi-factor authentication, host-based security, intrusion detection, security event management and defense-in-depth
* This position requires strong analytical skills for known vulnerabilities and system compliance
* Effective interpersonal skills are required with a demonstrated ability to support complex organizational relationships Desired Qualifications: * Bachelor's Degree (IT or Cybersecurity related) or equivalent related experience
* GSEC, SCNP, SSCP, CISSP or higher
* Experience with RMF controls, eMASS or XACTA, risk assessment, Plan of Actions and Milestones (POAMs), policy and plans documentation, Information Assurance Vulnerability Management (IAVM) and vulnerability assessment for mission systems Work Environment: * Location: Onsite
* Work Hours: Standard Compensation: * For Colorado only, the salary range for this position is approximately $90,000 - $105,000. The offered rate will be based on the selected candidate's knowledge, skills, abilities and/or experience and in consideration of internal parity. Other Compensation: KBR may offer bonuses, commissions, or other forms of compensation to certain job titles or levels, per internal policy or contractual designation. Additional compensation may be in the form of sign on bonus, relocation benefits, short term incentives, long term incentives, or discretionary payments for exceptional performance. KBR Benefits KBR offers a selection of competitive lifestyle benefits which could include 401K plan with company match, medical, dental, vision, life insurance, AD&D, flexible spending account, disability, paid time off, or flexible work schedule. We support career advancement through professional training and development. Ready to Make a Difference? If you're excited about making a significant impact in the field of space defense and working on projects that matter, we encourage you to apply and join our team at KBR. Let's shape the future together. Belong, Connect and Grow at KBR At KBR, we are passionate about our people and our Zero Harm culture. These inform all that we do and are at the heart of our commitment to, and ongoing journey toward being a People First company. That commitment is central to our team of team's philosophy and fosters an environment where everyone can Belong, Connect and Grow. We Deliver - Together. KBR is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, disability, sex, sexual orientation, gender identity or expression, age, national origin, veteran status, genetic information, union status and/or beliefs, or any other characteristic protected by federal, state, or local law.

What KBR employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


KBR logo

About KBR

Sourced by ZipRecruiter

At KBR, we partner with government and industry clients to provide purposeful and comprehensive solutions with an emphasis on efficiency and safety. With a full portfolio of services, proprietary technologies and expertise, our employees are ready to handle projects and missions from planning and design to sustainability and maintenance. Whether at the bottom of the ocean or in outer space, our clients trust us to deliver the impossible on a daily basis.

Industry

It services

Company size

10,000+ Employees

Headquarters location

Houston, TX, US

Year founded

1998