1

Security Control Assessor Jobs in Florida (NOW HIRING)

Well-versed in National Institute of Standards and Technology (NIST) security control guidance to build Security Control Traceability Matrix (SCTM) features and to assess the vulnerability of various ...

Prepare and manage Assessment and Authorization documentation using RMF and derivative processes (e ... Understanding of security control inheritance in cloud-based systems.) Familiarity with STIG/SRG ...

Showing results 21-40

Security Control Assessor information

See Florida salary details

$6

$43

$58

How much do security control assessor jobs pay per hour?

As of Sep 11, 2026, the average hourly pay for security control assessor in Florida is $43.92, according to ZipRecruiter salary data. Most workers in this role earn between $37.74 and $50.82 per hour, depending on experience, location, and employer.

What is a security control assessor?

Security Control Assessors (SCAs) are professionals responsible for evaluating the security controls of information systems to ensure they meet required standards and regulations. They conduct assessments, document findings, and provide recommendations to help organizations manage risk and achieve compliance with frameworks such as NIST or FISMA. SCAs play a critical role in maintaining the security and integrity of sensitive data by identifying vulnerabilities and verifying that corrective actions are implemented effectively.

What are the main challenges security control assessors face when evaluating complex information systems?

Security Control Assessors often encounter challenges such as rapidly evolving security threats, integrating new technologies, and ensuring compliance with multiple frameworks (like NIST, FISMA, or RMF). Assessing large, interconnected systems requires attention to detail and strong analytical skills to identify vulnerabilities and recommend effective controls. Collaboration with system owners, IT staff, and auditors is essential to obtain comprehensive documentation and clarify system boundaries, which can be a demanding part of the assessment process.

What are the key skills and qualifications needed to thrive as a security control assessor, and why are they important?

To thrive as a Security Control Assessor, you need expertise in information security principles, risk management frameworks like NIST RMF, and a relevant bachelor's degree or equivalent work experience. Familiarity with security assessment tools, compliance management systems, and certifications such as CISSP, CISA, or CAP is typically required. Strong analytical thinking, attention to detail, and effective communication are crucial for evaluating security controls and reporting findings clearly. These skills ensure accurate risk assessments, regulatory compliance, and robust protection of organizational information assets.

What is the difference between Security Control Assessor vs Security Analyst?

AspectSecurity Control AssessorSecurity Analyst
CertificationsRisk Management Framework (RMF), CISSP, CISACISSP, Security+
Work EnvironmentFederal agencies, DoD, government complianceCorporate, cybersecurity teams, IT departments
ResponsibilitiesAssess security controls, ensure compliance, auditMonitor security, analyze threats, implement security measures

The Security Control Assessor primarily evaluates security controls for compliance and risk management, often within government agencies. In contrast, the Security Analyst focuses on monitoring and analyzing security threats to protect organizational assets. While both roles require cybersecurity knowledge and certifications like CISSP, their focus areas and work environments differ significantly.

How much do security control assessors make?

Security Control Assessors in the federal government or related sectors typically earn between $80,000 and $130,000 annually, depending on experience, certifications, and location. Salaries can vary based on agency, level of clearance, and specific responsibilities, with higher pay often associated with specialized skills and certifications like CISSP or CISA.

What are the most commonly searched types of Security Control Assessor jobs in Florida?

The most popular types of Security Control Assessor jobs in Florida are:

What are popular job titles related to Security Control Assessor jobs in Florida?

For Security Control Assessor jobs in Florida, the most frequently searched job titles are:

What job categories do people searching Security Control Assessor jobs in Florida look for?

The top searched job categories for Security Control Assessor jobs in Florida are:

What cities in Florida are hiring for Security Control Assessor jobs?

Cities in Florida with the most Security Control Assessor job openings:

What are popular job titles related to Security Control Assessor jobs in FL?

For Security Control Assessor jobs in FL, the most frequently searched job titles are:

Infographic showing various Security Control Assessor job openings in Florida as of September 2026, with employment types broken down into 62% Full Time, 31% Part Time, and 7% Contract. Highlights an 94% In-person, 2% Hybrid, and 4% Remote job distribution, with an average salary of $91,346 per year, or $43.9 per hour.

Information System Security Officer (ISSO)

FL • On-site

Astrion
5 - 10K employees

Full-time

Re-posted 19 days ago


Job description

Overview
Information System Security Officer (ISSO) - Mid-Level
LOCATION: Eglin AFB, FL
JOB STATUS: Full-time
CLEARANCE: Active Top Secret
CERTIFICATION:DoD 8140.03 Information Assurance Technical (IAT) Level II
TRAVEL: 20%
Astrion has an exciting opportunity for an SE-3 Information System Security Officer (ISSO). This position will provide support to the 46 Test Squadron Advanced Datalink Test Lab implementing multiple programs, performing cybersecurity duties at Eglin AFB.
REQUIRED QUALIFICATIONS / SKILLS
  • Bachelor's Degree and 3- 10 years of relevant experience. Additional experience may be substituted for education.
  • Active Top Secret Clearance is required.Must be able to obtain and maintain a DoD TS/SCI clearance (i.e. DCID 6/4 eligibility)
    Eligibility for access to Special Access Program (SAP) Information
  • US Citizenship required
  • In-depth knowledge of RMF with the ability to write all supporting documentation.
  • Able to produce Assess and Authorize (A&A) packages with extensive experience in building, configuring, and adapting DoD Information System (IS) RMF documentation to meet test requirements.
  • Well-versed in National Institute of Standards and Technology (NIST) security control guidance to build Security Control Traceability Matrix (SCTM) features and to assess the vulnerability of various operating systems within the physical operating environment.
  • Self-starter, able to multi-task and perform effectively in a highly-dynamic, fast-paced environment with very little supervision.
  • Able to deploy CONUS/OCONUS and possess a strong ability to work independently.
  • Extensive experience in reviewing Microsoft and Linux audit reports; ensuring audit records are collected, reviewed, and documented (to include any anomalies).
  • Ensure all IS security-related documentation is current and accessible to properly authorized individuals
  • Conducts periodic reviews of IS and Continuous Monitoring plans to ensure compliance with the System Security Plan (SSP).
  • Able to assist in the design, procurement, buildup, and support of mobile and fixed Information Systems.
  • Able to identify and initiate corrective actions when a security incident or vulnerability is discovered in accordance with incidence response plan.
  • Understanding of Configuration Management processes for hardware/software to ensure systems are maintained and documented, and system changes are coordinated with the ISSM and Authorizing Official.
  • Able to perform standard OSHA single person lifting (approx. 40 lbs.) to assist with setup of site equipment.

PREFERRED QUALIFICATIONS / SKILLS
  • Experience using Security Content Automation Protocol (SCAP) Compliance Checker or Evaluate STIG to perform scans of standalone and networked systems.
  • Interpersonal skills (written and verbal) necessary to deal courteously and effectively with a diverse group of individuals.
  • Able to provide current Advanced Program references.

RESPONSIBILITIES
  • Will primarily perform duties of an Information Systems Security Officer (ISSO) in an Advanced Programs Developmental Test, and Evaluation laboratory.
  • Requires the production of a high volume of written documentation throughout the Risk Management Framework (RMF) life cycle for a numerus systems in multiple operating locations.
  • Conducts technical and non-technical reviews and audits as prescribed by the Information System Security Manager (ISSM).