1

Security Control Assessor Jobs in Florida (NOW HIRING)

... control assessments - Proficiency in Microsoft Office (Project, PowerPoint, Excel, Word ... Certified Information Systems Auditor (CISA), Certified Information Security Manager (CISM ...

Well-versed in National Institute of Standards and Technology (NIST) security control guidance to build Security Control Traceability Matrix (SCTM) features and to assess the vulnerability of various ...

Cyber Lead

Tampa, FL · On-site

$109K - $147K/yr

Experience conducting security control assessments, log reviews, vulnerability analysis, compliance audits, risk assessments, and root-cause investigations to identify and remediate cybersecurity ...

Cyber Security SME

Orlando, FL · Hybrid

$135K - $165K/yr

Conduct PO security control assessments of System Integrator/developer submitted A&A documentation to ensure compliance with RMF requirements * Generate and submit PO A&A documentation required for ...

Showing results 21-40

Security Control Assessor information

See Florida salary details

$6

$43

$58

How much do security control assessor jobs pay per hour?

As of Aug 12, 2026, the average hourly pay for security control assessor in Florida is $43.92, according to ZipRecruiter salary data. Most workers in this role earn between $37.74 and $50.82 per hour, depending on experience, location, and employer.

How much do security control assessors make?

Security Control Assessors in the federal government or related sectors typically earn between $80,000 and $130,000 annually, depending on experience, certifications, and location. Salaries can vary based on agency, level of clearance, and specific responsibilities, with higher pay often associated with specialized skills and certifications like CISSP or CISA.

What are the key skills and qualifications needed to thrive as a security control assessor, and why are they important?

To thrive as a Security Control Assessor, you need expertise in information security principles, risk management frameworks like NIST RMF, and a relevant bachelor's degree or equivalent work experience. Familiarity with security assessment tools, compliance management systems, and certifications such as CISSP, CISA, or CAP is typically required. Strong analytical thinking, attention to detail, and effective communication are crucial for evaluating security controls and reporting findings clearly. These skills ensure accurate risk assessments, regulatory compliance, and robust protection of organizational information assets.

What is the difference between Security Control Assessor vs Security Analyst?

AspectSecurity Control AssessorSecurity Analyst
CertificationsRisk Management Framework (RMF), CISSP, CISACISSP, Security+
Work EnvironmentFederal agencies, DoD, government complianceCorporate, cybersecurity teams, IT departments
ResponsibilitiesAssess security controls, ensure compliance, auditMonitor security, analyze threats, implement security measures

The Security Control Assessor primarily evaluates security controls for compliance and risk management, often within government agencies. In contrast, the Security Analyst focuses on monitoring and analyzing security threats to protect organizational assets. While both roles require cybersecurity knowledge and certifications like CISSP, their focus areas and work environments differ significantly.

What are the main challenges security control assessors face when evaluating complex information systems?

Security Control Assessors often encounter challenges such as rapidly evolving security threats, integrating new technologies, and ensuring compliance with multiple frameworks (like NIST, FISMA, or RMF). Assessing large, interconnected systems requires attention to detail and strong analytical skills to identify vulnerabilities and recommend effective controls. Collaboration with system owners, IT staff, and auditors is essential to obtain comprehensive documentation and clarify system boundaries, which can be a demanding part of the assessment process.

What is a security control assessor?

Security Control Assessors (SCAs) are professionals responsible for evaluating the security controls of information systems to ensure they meet required standards and regulations. They conduct assessments, document findings, and provide recommendations to help organizations manage risk and achieve compliance with frameworks such as NIST or FISMA. SCAs play a critical role in maintaining the security and integrity of sensitive data by identifying vulnerabilities and verifying that corrective actions are implemented effectively.
What are the most commonly searched types of Security Control Assessor jobs in Florida? The most popular types of Security Control Assessor jobs in Florida are:
What are popular job titles related to Security Control Assessor jobs in Florida? For Security Control Assessor jobs in Florida, the most frequently searched job titles are:
What job categories do people searching Security Control Assessor jobs in Florida look for? The top searched job categories for Security Control Assessor jobs in Florida are:
What cities in Florida are hiring for Security Control Assessor jobs? Cities in Florida with the most Security Control Assessor job openings:
What are popular job titles related to Security Control Assessor jobs in FL? For Security Control Assessor jobs in FL, the most frequently searched job titles are:
Infographic showing various Security Control Assessor job openings in Florida as of August 2026, with employment types broken down into 1% As Needed, 76% Full Time, 18% Part Time, 4% Contract, and 1% Nights. Highlights an 96% Physical, 1% Hybrid, and 3% Remote job distribution, with an average salary of $91,346 per year, or $43.9 per hour.

Information System Security Manager (ISSM)

Zachary Piper Solutions

Orlando, FL • On-site

$140 - $185/hr

Other

Posted 6 days ago


Job description

Zachary Piper Solutions is seeking an experienced Cybersecurity Information System Security Manager (ISSM) to support a U.S. Army customer in Orlando, FL (100% onsite). The Cybersecurity Information System Security Manager (ISSM) will serve as the primary lead responsible for managing the RMF lifecycle, ATO activities, & overall cybersecurity posture for multiple Army information systems supporting both CUI & classified environments. This role will partner closely with Government leadership, engineers, system owners, Authorizing Officials, & security assessors to ensure secure, compliant, & mission-ready systems throughout their lifecycle.

Responsibilities of the Cybersecurity Information System Security Manager (ISSM) include:
  • Serve as the ISSM supporting 3–7 U.S. Army information systems across classified & unclassified environments
  • Lead all phases of the DOD RMF lifecycle, including system authorization, continuous monitoring, & reauthorization activities
  • Develop, maintain, & manage RMF authorization packages including SSPs, POA&Ms, security categorization documentation, Body of Evidence artifacts, and ConMon documentation
  • Coordinate ATO, IATT, ATO-C, & system reauthorization efforts
  • Manage ConMon, vulnerability management, STIG compliance, ACAS scan reviews, cybersecurity reporting, & corrective action tracking
  • Conduct cybersecurity risk assessments and provide recommendations supporting AO risk decisions
  • Coordinate SCAs & oversee remediation of assessment findings to maintain RMF compliance
  • Review system architectures, authorization boundaries, network diagrams, data flows, and engineering changes to ensure continued cybersecurity compliance
  • Provide cybersecurity guidance and compliance support to system owners, engineers, administrators, and Government leadership
  • Prepare executive briefings, cybersecurity status reports, risk assessments, & authorization recommendations for senior Government stakeholders
  • Support implementation of ZTA, cloud security initiatives, & secure system engineering best practices where applicable
Qualifications of the Cybersecurity Information System Security Manager (ISSM) include:
  • 8+ years of experience supporting DOD cybersecurity programs
  • 5+ years of experience managing RMF & A&A activities within DOD environments
  • Experience serving as an ISSM/ISSO supporting U.S. Army or DOD information systems
  • Demonstrated experience managing multiple RMF authorization packages simultaneously through the full system lifecycle
  • Strong knowledge of DOD RMF, AR 25-2, NETCOM RMF Business Rules, & cybersecurity compliance requirements
  • Experience developing and maintaining SSPs, POA&Ms, Body of Evidence documentation, ConMon artifacts, and authorization packages
  • Hands-on experience with vulnerability management, STIG implementation, ACAS, SCAs, and cybersecurity compliance reporting
  • Experience using eMASS, Xacta, or similar GRC tools
  • Working knowledge of Microsoft Windows, Linux, virtualization technologies, enterprise networking, and cloud security principles
  • Experience supporting ZTA, FedRAMP, or DoD Cloud SRG environments preferred
  • Certifications preferred: CISSP, CISM, CASP+, or CCSP
  • Active Top Secret security clearance required (SCI eligibility preferred)
  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Engineering, or related field
Keywords:

Information System Security Manager, ISSM, Information System Security Officer, ISSO, Cybersecurity, Risk Management Framework, RMF, Assessment and Authorization, A&A, Authorization to Operate, ATO, IATT, ATO-C, Continuous Monitoring, ConMon, System Security Plan, SSP, Plans of Action and Milestones, POA&M, eMASS, Xacta, Governance Risk and Compliance, GRC, Security Control Assessment, SCA, Vulnerability Management, STIG, ACAS, Security Technical Implementation Guide, DoD, Department of Defense, U.S. Army, Army Regulation 25-2, AR 25-2, NETCOM, Cybersecurity Compliance, Security Controls, Authorizing Official, AO, Body of Evidence, CUI, Classified Systems, Zero Trust, Zero Trust Architecture, ZTA, Cloud Security, FedRAMP, DoD Cloud SRG, Windows, Linux, Virtualization, Enterprise Networking, CISSP, CISM, CASP+, CCSP, DoD 8140, Orlando, Florida, Top Secret, TS, TS/SCI, Defense, Federal Government

#LI-SW1 #LI-ONSITE

#J-18808-Ljbffr