1

Security Control Assessor Jobs in Delaware (NOW HIRING)

$120 - $180/hr

... assessment documentation, validating outputs and ensuring sensitive data is handled appropriately ... control validation, ensuring traceability/auditability and alignment to resiliency and security ...

Security Guard

Wilmington, DE · On-site

$15.50 - $19/hr

Provide access control into the Hospital and specific areas of the Hospital as well as apply ... Provide first responder assessment of threats against staff, patients, and families. Qualifications:

Security Guard

Wilmington, DE · On-site

$15.50 - $19/hr

Provide access control into the Hospital and specific areas of the Hospital as well as apply ... Provide first responder assessment of threats against staff, patients, and families. Qualifications:

... assessment documentation, validating outputs and ensuring sensitive data is handled appropriately ... control validation, ensuring traceability/auditability and alignment to resiliency and security ...

next page

Showing results 1-20

Security Control Assessor information

See Delaware salary details

$8

$58

$78

How much do security control assessor jobs pay per hour?

As of Aug 27, 2026, the average hourly pay for security control assessor in Delaware is $58.82, according to ZipRecruiter salary data. Most workers in this role earn between $50.53 and $68.08 per hour, depending on experience, location, and employer.

What is a security control assessor?

Security Control Assessors (SCAs) are professionals responsible for evaluating the security controls of information systems to ensure they meet required standards and regulations. They conduct assessments, document findings, and provide recommendations to help organizations manage risk and achieve compliance with frameworks such as NIST or FISMA. SCAs play a critical role in maintaining the security and integrity of sensitive data by identifying vulnerabilities and verifying that corrective actions are implemented effectively.

What are the main challenges security control assessors face when evaluating complex information systems?

Security Control Assessors often encounter challenges such as rapidly evolving security threats, integrating new technologies, and ensuring compliance with multiple frameworks (like NIST, FISMA, or RMF). Assessing large, interconnected systems requires attention to detail and strong analytical skills to identify vulnerabilities and recommend effective controls. Collaboration with system owners, IT staff, and auditors is essential to obtain comprehensive documentation and clarify system boundaries, which can be a demanding part of the assessment process.

What are the key skills and qualifications needed to thrive as a security control assessor, and why are they important?

To thrive as a Security Control Assessor, you need expertise in information security principles, risk management frameworks like NIST RMF, and a relevant bachelor's degree or equivalent work experience. Familiarity with security assessment tools, compliance management systems, and certifications such as CISSP, CISA, or CAP is typically required. Strong analytical thinking, attention to detail, and effective communication are crucial for evaluating security controls and reporting findings clearly. These skills ensure accurate risk assessments, regulatory compliance, and robust protection of organizational information assets.

What is the difference between Security Control Assessor vs Security Analyst?

AspectSecurity Control AssessorSecurity Analyst
CertificationsRisk Management Framework (RMF), CISSP, CISACISSP, Security+
Work EnvironmentFederal agencies, DoD, government complianceCorporate, cybersecurity teams, IT departments
ResponsibilitiesAssess security controls, ensure compliance, auditMonitor security, analyze threats, implement security measures

The Security Control Assessor primarily evaluates security controls for compliance and risk management, often within government agencies. In contrast, the Security Analyst focuses on monitoring and analyzing security threats to protect organizational assets. While both roles require cybersecurity knowledge and certifications like CISSP, their focus areas and work environments differ significantly.

How much do security control assessors make?

Security Control Assessors in the federal government or related sectors typically earn between $80,000 and $130,000 annually, depending on experience, certifications, and location. Salaries can vary based on agency, level of clearance, and specific responsibilities, with higher pay often associated with specialized skills and certifications like CISSP or CISA.

What are the most commonly searched types of Security Control Assessor jobs in Delaware?

The most popular types of Security Control Assessor jobs in Delaware are:

What are popular job titles related to Security Control Assessor jobs in Delaware?

For Security Control Assessor jobs in Delaware, the most frequently searched job titles are:

What job categories do people searching Security Control Assessor jobs in Delaware look for?

The top searched job categories for Security Control Assessor jobs in Delaware are:

What are popular job titles related to Security Control Assessor jobs in DE?

For Security Control Assessor jobs in DE, the most frequently searched job titles are:

Infographic showing various Security Control Assessor job openings in Delaware as of August 2026, with employment types broken down into 1% As Needed, 75% Full Time, 20% Part Time, 3% Contract, and 1% Nights. Highlights an 95% Physical, 1% Hybrid, and 4% Remote job distribution, with an average salary of $122,341 per year, or $58.8 per hour.

Cybersecurity Senior ISSO - Principal

EL-Shaddai Technologies Inc

Wilmington, DE • On-site

$97K - $125K/yr

Other

Re-posted 6 days ago


Job description

Cybersecurity Senior ISSO - Principal is responsible for providing strategic cybersecurity oversight and advisory services for assigned Agile Release Trains (ARTs) and business portfolios. This role ensures security requirements are incorporated into technology initiatives through risk assessments, architecture reviews, compliance evaluations, and security governance activities. The Senior ISSO partners with business and technology stakeholders to identify and mitigate cybersecurity risks, support secure solution delivery, and maintain alignment with enterprise policies, regulatory obligations, and industry best practices.

 •          Develop, maintain, and enforce enterprise security requirements, standards, baselines, and governance processes aligned with organizational, regulatory, and industry requirements.

•          Serve as the cybersecurity representative within Agile Release Trains (ARTs), participating in Program Increment (PI) Planning and ensuring security requirements, risks, dependencies, and remediation activities are incorporated into program and team backlogs.

•          Collaborate with Product Management, Product Owners, Release Train Engineers (RTEs), Solution Architects, engineers, and development teams to integrate security-by-design principles and DevSecOps practices throughout the system development lifecycle.

•          Conduct security risk assessments, threat analyses, vulnerability assessments, and security control evaluations for applications, systems, networks, cloud environments, and emerging technologies.

•          Perform security architecture and design reviews to identify security gaps, evaluate risks, and recommend appropriate mitigating and compensating controls.

•          Provide cybersecurity advisory services and risk-based recommendations to business leaders, project teams, architects, and technology stakeholders.

•          Lead and support security governance activities, including security requirements reviews, exception evaluations, risk acceptance decisions, and compliance assessments.

•          Review vulnerability assessment and penetration testing results, prioritize remediation efforts, and track corrective actions through resolution.

•          Partner with Security Operations, Infrastructure, Cloud, Network, and Application teams to address security findings, control deficiencies, incidents, and emerging risks.

•          Support incident response activities by providing security expertise, risk analysis, and guidance for containment, remediation, and lessons learned.

•          Monitor the evolving threat landscape, industry trends, and emerging technologies, and recommend improvements to strengthen the organization''s security posture.

•          Develop and maintain security documentation, including System Security Plans (SSPs), Security Design Reviews, Secure Design Directives (SDDs), risk assessments, exception requests, and remediation plans.

•          Support internal, external, and regulatory audits by validating security control implementation and providing required evidence and documentation.

•          Promote cybersecurity awareness, secure development practices, and risk management principles across the organization.

•          Provide after-hours support for critical security incidents, high-risk vulnerabilities, and business-critical security assessments as required.

•          Work effectively in a multi-office environment and travel as necessary to support security assessments, stakeholder engagements, and strategic initiatives.

•          Enterprise security requirements, standards, baselines, governance recommendations, and Secure Design Directives (SDDs) aligned with organizational, regulatory, and industry frameworks.

•          Security risk assessments, threat models, security impact analyses, and risk treatment recommendations.

•          Security architecture and design review reports identifying security risks, mitigation strategies, and compensating controls.

•          Cybersecurity exception reviews, risk acceptance recommendations, vulnerability assessment reviews, and remediation tracking reports.

•          Security authorization, compliance, and audit artifacts, including System Security Plans (SSPs), risk assessments, security exceptions, and supporting audit evidence.

•          Security governance reports, executive risk summaries, and security posture recommendations supporting business, technology, and Agile delivery initiatives.

•          Demonstrated alignment with NIST RMF, NIST CSF, CIS Controls, UCF, and applicable organizational security standards.

•          10+ years of experience in cybersecurity, information security, security architecture, engineering, risk management, or related security disciplines.

•          Demonstrated experience performing security architecture reviews, risk assessments, threat modeling, vulnerability management, and security control evaluations across applications, infrastructure, networks, and cloud environments.

•          Strong knowledge of cybersecurity frameworks and standards, including NIST RMF, NIST CSF, CIS Controls, UCF, and other applicable industry and regulatory frameworks.

•          Experience supporting Agile delivery methodologies, including Agile Release Trains (ARTs), Program Increment (PI) Planning, and DevSecOps practices.

•          In-depth understanding of secure architecture principles and the ability to translate business requirements into security requirements and technical controls.

•          Knowledge of common cyber threats, attack techniques, vulnerabilities, and risk mitigation strategies.

•          Experience with vulnerability assessment, security testing, and risk analysis tools such as Nessus, Checkmarx, Nmap, Burp Suite, Tenable, Qualys, or equivalent solutions.

•          Familiarity with security technologies and concepts, including network security, cloud security, firewalls, SIEM platforms, identity and access management, vulnerability management, and security monitoring.

•          Proven ability to document and communicate security risks, findings, remediation recommendations, and compliance requirements to technical and executive stakeholders.

•          Strong analytical, problem-solving, stakeholder management, and written/verbal communication skills.

•          CISSP (Certified Information Systems Security Professional) required.

•          Experience supporting cybersecurity engineering projects for a large enterprise

•          Experience implementing automation in cybersecurity toolchains

•          Any of the industry standard cybersecurity certifications such as CISM, CISA, CRISC, GCIH, GPEN, CEH, CHFI, Security+, CASP, OSCP, etc.