1

Security Control Assessor Jobs in Georgia (NOW HIRING)

Conduct vulnerability assessments using Tenable tools and track remediation efforts. * Support ... Maintain and update System Security Plans (SSPs) to reflect security control implementations.

Showing results 21-40

Security Control Assessor information

See Georgia salary details

$7

$49

$65

How much do security control assessor jobs pay per hour?

As of Sep 12, 2026, the average hourly pay for security control assessor in Georgia is $49.62, according to ZipRecruiter salary data. Most workers in this role earn between $42.64 and $57.45 per hour, depending on experience, location, and employer.

What is a security control assessor?

Security Control Assessors (SCAs) are professionals responsible for evaluating the security controls of information systems to ensure they meet required standards and regulations. They conduct assessments, document findings, and provide recommendations to help organizations manage risk and achieve compliance with frameworks such as NIST or FISMA. SCAs play a critical role in maintaining the security and integrity of sensitive data by identifying vulnerabilities and verifying that corrective actions are implemented effectively.

What are the main challenges security control assessors face when evaluating complex information systems?

Security Control Assessors often encounter challenges such as rapidly evolving security threats, integrating new technologies, and ensuring compliance with multiple frameworks (like NIST, FISMA, or RMF). Assessing large, interconnected systems requires attention to detail and strong analytical skills to identify vulnerabilities and recommend effective controls. Collaboration with system owners, IT staff, and auditors is essential to obtain comprehensive documentation and clarify system boundaries, which can be a demanding part of the assessment process.

What are the key skills and qualifications needed to thrive as a security control assessor, and why are they important?

To thrive as a Security Control Assessor, you need expertise in information security principles, risk management frameworks like NIST RMF, and a relevant bachelor's degree or equivalent work experience. Familiarity with security assessment tools, compliance management systems, and certifications such as CISSP, CISA, or CAP is typically required. Strong analytical thinking, attention to detail, and effective communication are crucial for evaluating security controls and reporting findings clearly. These skills ensure accurate risk assessments, regulatory compliance, and robust protection of organizational information assets.

What is the difference between Security Control Assessor vs Security Analyst?

AspectSecurity Control AssessorSecurity Analyst
CertificationsRisk Management Framework (RMF), CISSP, CISACISSP, Security+
Work EnvironmentFederal agencies, DoD, government complianceCorporate, cybersecurity teams, IT departments
ResponsibilitiesAssess security controls, ensure compliance, auditMonitor security, analyze threats, implement security measures

The Security Control Assessor primarily evaluates security controls for compliance and risk management, often within government agencies. In contrast, the Security Analyst focuses on monitoring and analyzing security threats to protect organizational assets. While both roles require cybersecurity knowledge and certifications like CISSP, their focus areas and work environments differ significantly.

How much do security control assessors make?

Security Control Assessors in the federal government or related sectors typically earn between $80,000 and $130,000 annually, depending on experience, certifications, and location. Salaries can vary based on agency, level of clearance, and specific responsibilities, with higher pay often associated with specialized skills and certifications like CISSP or CISA.

What are popular job titles related to Security Control Assessor jobs in Georgia?

For Security Control Assessor jobs in Georgia, the most frequently searched job titles are:

What job categories do people searching Security Control Assessor jobs in Georgia look for?

The top searched job categories for Security Control Assessor jobs in Georgia are:

What cities in Georgia are hiring for Security Control Assessor jobs?

Cities in Georgia with the most Security Control Assessor job openings:

What are popular job titles related to Security Control Assessor jobs in GA?

For Security Control Assessor jobs in GA, the most frequently searched job titles are:

Infographic showing various Security Control Assessor job openings in Georgia as of August 2026, with employment types broken down into 1% As Needed, 78% Full Time, 18% Part Time, 2% Contract, and 1% Nights. Highlights an 95% Physical, 1% Hybrid, and 4% Remote job distribution, with an average salary of $103,214 per year, or $49.6 per hour.

Business Impact & Information Security Analyst

Atlanta, GA • On-site

Stefanini Group
IT Services • 10K+ employees

$60 - $65/hr

Contractor

Posted 17 days ago


Job description

Details:
Stefanini Group is hiring!
Stefanini is looking for Business Impact & Information Security Analyst in Atlanta, GA
For quick apply, please contact Sudhanshu Shrivastava; Ph: 248 582 6510
Sudhanshu.shrivastava@stefanini.com
W2 Candidates Only!
About Role:
We are seeking a versatile Business Impact & Information Security Analyst to join our enterprise risk management team. This dual-focused role combines business continuity planning with cybersecurity operations, making it ideal for a well-rounded contractor who can bridge operational resilience and information security. The successful candidate will assess organizational vulnerabilities from both business impact and security threat perspectives, ensuring comprehensive protection of critical assets and operations.
Key Responsibilities:
Organizational Risk & Impact Assessment
  • Lead structured interviews and collaborative workshops with department heads and key stakeholders to identify critical business functions, security requirements, and risk exposure
  • Map critical business functions, workflows, technical dependencies, and security control touchpoints across the organization
  • Document operational interdependencies, assess security control effectiveness, and identify single points of failure from both continuity and security perspectives
  • Research and analyze emerging cyber threats, vulnerabilities, and attack vectors; assess relevance to organizational operations and business continuity

Impact Quantification & Risk Analysis
  • Evaluate and assign severity scores to potential disruption scenarios resulting from system failures, supply chain outages, or security incidents
  • Assess financial, operational, legal, and reputational consequences tied to business disruptions and security breaches
  • Develop integrated risk matrices and impact classification frameworks that address both continuity and security risks
  • Correlate security events and threat intelligence with business impact scenarios
  • Contribute to threat modeling exercises for critical systems and functions

Security Controls & Recovery Planning
  • Evaluate effectiveness of existing security controls and countermeasures through testing aligned with frameworks (NIST, ISO 27001, CIS)
  • Review system configurations against security baselines and hardening standards
  • Assess cloud security configurations and compliance (AWS, Azure, GCP)
  • Define Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO) for core applications and business units, factoring in security restoration requirements
  • Establish prioritization criteria for recovery sequencing that incorporates security validation steps
  • Collaborate with IT, operations, and security teams to validate feasibility of recovery targets and security controls

Compliance, Governance & Reporting
  • Assist with security and business continuity audits; provide evidence of control implementation
  • Maintain comprehensive documentation including policies, procedures, runbooks, security controls, and business impact profiles
  • Track and report on security metrics, business continuity KPIs, and integrated risk indicators
  • Synthesize analytical findings into executive-ready dashboards and presentations
  • Deliver integrated continuity strategies and security recommendations to senior leadership
  • Maintain updated documentation in alignment with organizational and regulatory standards

Job Requirements
Details:
Required Qualifications and Skills:
Education
  • Bachelor's Degree or 4 years equivalent experience; Bachelor's Degree preferred in Business Administration, Information Technology, Cybersecurity, Risk Management, Data Science, or related field
  • Master's degree or additional certifications preferred

Experience
  • 3-5 years of experience

Core Competencies:
Business Continuity:
  • Proven proficiency in business impact analysis methodologies and frameworks
  • Strong understanding of risk assessment principles and practices
  • Experience with supply chain dependency analysis

Information Security:
  • Solid understanding of cybersecurity principles, frameworks, and best practices
  • Knowledge of common attack vectors, vulnerabilities, and mitigation techniques
  • Experience with security incident investigation and response procedures
  • Understanding of network protocols, system architecture, and security technologies

Universal Skills:
  • Exceptional analytical and critical thinking abilities
  • Outstanding communication and stakeholder management skills
  • Ability to facilitate productive workshops with diverse audiences
  • Strong problem-solving skills and attention to detail
  • Ability to translate technical concepts for non-technical audiences

Technical Tools:
Business Continuity:
* Experience with enterprise continuity software (ServiceNow BCM or similar platforms)
* Proficiency with advanced data collection frameworks and survey tools
* Strong command of relational databases, SQL, and advanced spreadsheet functions
Information Security:
* Knowledge of firewall, IDS/IPS, and network security tools
* Experience with cloud security tools and CSPM platforms
Certifications:
Business Continuity (Preferred):
  • Certified Business Continuity Professional (CBCP)
  • CBCI, MBCI, or similar

Information Security (One or more):
  • Certified Information Systems Security Professional (CISSP)
  • GIAC Security Essentials (GSEC)
  • Certified Information Security Manager (CISM)
  • Cloud security certifications (AWS Security Specialty, Azure Security Engineer)

Experience
  • 3-5 years of combined experience in business continuity, risk management, and/or information security
  • Demonstrated experience conducting business impact analyses
  • Experience working in regulated industries (finance, healthcare, government) a plus
  • Previous contractor or consulting experience beneficial

Ideal Candidate:
The perfect candidate for this role brings a unique combination of business acumen and technical security expertise. You should be equally comfortable:
  • Facilitating executive workshops on business continuity strategies
  • Presenting risk findings to C-level stakeholders
  • Responding to security incidents
  • Documenting complex workflows and dependencies
  • Implementing security controls and conducting assessments
  • This position offers an excellent opportunity for a versatile professional seeking to make impact across both operational resilience and cybersecurity domains.

#LI-SS3
#LI-HYBRID
Stefanini takes pride in hiring top talent and developing relationships with our future employees. Our talent acquisition teams will never make an offer of employment without having a phone conversation with you. Those face-to-face conversations will involve a description of the job for which you have applied. We also speak with you about the process including interviews and job offers.
About Stefanini Group:
The Stefanini Group is a global provider of offshore, onshore and near shore outsourcing, IT digital consulting, systems integration, application, and strategic staffing services to Fortune 1000 enterprises around the world. Our presence is in countries like the Americas, Europe, Africa, and Asia, and more than four hundred clients across a broad spectrum of markets, including financial services, manufacturing, telecommunications, chemical services, technology, public sector, and utilities. Stefanini is a CMM level 5, IT consulting company with a global presence. We are CMM Level 5 company
Pay Range:
$ 60.00 - $ 65.00