1

Security Control Assessor Jobs in Illinois (NOW HIRING)

Senior Security Engineer

Chicago, IL · On-site

$118K - $161K/yr

Role: Sr. Security Engineer Location: Chicago, IL - Locals (Hybrid) Exp: 10+ Years * Security ... Partner with technology owners to assess compliance and remediate gaps. * Support control selection ...

IL · On-site

Provide the Certification Memo and test results to HQ CCC for submission to the AF Security Control Assessor for certification and inclusion in the AF EPL. Use the AF EPL SharePoint site to monitor ...

Provide the Certification Memo and test results to HQ CCC for submission to the AF Security Control Assessor for certification and inclusion in the AF EPL. Use the AF EPL SharePoint site to monitor ...

Responsibilities : • Lead all aspects of the RMF process, from system categorization and security control selection to implementation and assessment. • Develop, maintain, and update all required ...

Showing results 21-40

Security Control Assessor information

See Illinois salary details

$8

$56

$75

How much do security control assessor jobs pay per hour?

As of Sep 3, 2026, the average hourly pay for security control assessor in Illinois is $56.95, according to ZipRecruiter salary data. Most workers in this role earn between $48.89 and $65.91 per hour, depending on experience, location, and employer.

What is a security control assessor?

Security Control Assessors (SCAs) are professionals responsible for evaluating the security controls of information systems to ensure they meet required standards and regulations. They conduct assessments, document findings, and provide recommendations to help organizations manage risk and achieve compliance with frameworks such as NIST or FISMA. SCAs play a critical role in maintaining the security and integrity of sensitive data by identifying vulnerabilities and verifying that corrective actions are implemented effectively.

What are the main challenges security control assessors face when evaluating complex information systems?

Security Control Assessors often encounter challenges such as rapidly evolving security threats, integrating new technologies, and ensuring compliance with multiple frameworks (like NIST, FISMA, or RMF). Assessing large, interconnected systems requires attention to detail and strong analytical skills to identify vulnerabilities and recommend effective controls. Collaboration with system owners, IT staff, and auditors is essential to obtain comprehensive documentation and clarify system boundaries, which can be a demanding part of the assessment process.

What are the key skills and qualifications needed to thrive as a security control assessor, and why are they important?

To thrive as a Security Control Assessor, you need expertise in information security principles, risk management frameworks like NIST RMF, and a relevant bachelor's degree or equivalent work experience. Familiarity with security assessment tools, compliance management systems, and certifications such as CISSP, CISA, or CAP is typically required. Strong analytical thinking, attention to detail, and effective communication are crucial for evaluating security controls and reporting findings clearly. These skills ensure accurate risk assessments, regulatory compliance, and robust protection of organizational information assets.

What is the difference between Security Control Assessor vs Security Analyst?

AspectSecurity Control AssessorSecurity Analyst
CertificationsRisk Management Framework (RMF), CISSP, CISACISSP, Security+
Work EnvironmentFederal agencies, DoD, government complianceCorporate, cybersecurity teams, IT departments
ResponsibilitiesAssess security controls, ensure compliance, auditMonitor security, analyze threats, implement security measures

The Security Control Assessor primarily evaluates security controls for compliance and risk management, often within government agencies. In contrast, the Security Analyst focuses on monitoring and analyzing security threats to protect organizational assets. While both roles require cybersecurity knowledge and certifications like CISSP, their focus areas and work environments differ significantly.

How much do security control assessors make?

Security Control Assessors in the federal government or related sectors typically earn between $80,000 and $130,000 annually, depending on experience, certifications, and location. Salaries can vary based on agency, level of clearance, and specific responsibilities, with higher pay often associated with specialized skills and certifications like CISSP or CISA.

What are the most commonly searched types of Security Control Assessor jobs in Illinois?

The most popular types of Security Control Assessor jobs in Illinois are:

What are popular job titles related to Security Control Assessor jobs in Illinois?

For Security Control Assessor jobs in Illinois, the most frequently searched job titles are:

What job categories do people searching Security Control Assessor jobs in Illinois look for?

The top searched job categories for Security Control Assessor jobs in Illinois are:

What cities in Illinois are hiring for Security Control Assessor jobs?

Cities in Illinois with the most Security Control Assessor job openings:

What are popular job titles related to Security Control Assessor jobs in IL?

For Security Control Assessor jobs in IL, the most frequently searched job titles are:

Infographic showing various Security Control Assessor job openings in Illinois as of August 2026, with employment types broken down into 1% As Needed, 72% Full Time, 24% Part Time, 2% Contract, and 1% Nights. Highlights an 95% Physical, 1% Hybrid, and 4% Remote job distribution, with an average salary of $118,450 per year, or $56.9 per hour.

Senior RMF Specialist / Information System Security Officer (ISSO) - JWICS Support Modernization

Technology, Automation, and Management, Inc.

Rock Island, IL • On-site

Full-time

Posted 29 days ago


Job description

Pending Contract Award

Mission Objectives ? The Senior RMF Specialist/ISSO is responsible for the day-to-day execution of the Risk Management Framework (RMF) lifecycle for AMC?s JWICS systems and enclaves. This position ensures that all required controls are implemented, assessed, documented, and monitored in eMASS to support AO risk decisions and maintain AMC?s JWICS Authorization to Operate.

Position Responsibility Summary

  • Lead the comprehensive RMF lifecycle management for assigned JWICS systems within the AMC eMASS portfolio, covering categorization, control selection/implementation, assessment, authorization, and continuous monitoring.
  • Develop, maintain, and update system security documentation (e.g., SSPs, SARs, POA&Ms, security control traceability matrices, risk assessments) in accordance with DoD and Army RMF guidance.
  • Collaborate with the P-ISSM, AO, AODRs, system owners, and ISSOs to optimize RMF workflows and coordinate approvals for system changes, boundary updates, and new capabilities.
  • Implement and manage a robust continuous monitoring strategy, including vulnerability scanning, configuration management, control assessments, and security log reviews; ensure results are captured in eMASS and associated tools.
  • Support cybersecurity assessments of JWICS computing environments to identify vulnerabilities and non-compliance with IA standards; recommend and track mitigations.
  • Provide RMF and security engineering input to mission mapping and cyberspace terrain mapping activities, helping define authorization boundaries and risk posture.
  • Produce timely RMF/eMASS updates and risk reports that enable AMC to meet QASP measures (e.g., =95% of priority systems with current eMASS status, =95% of identified gaps with recommended actions within 5 business days).
  • Provide RMF and IA guidance to JWICS system administrators, Tier 1 support staff, and other technical personnel to ensure security considerations are built into day-to-day operations.
  • Support cyber exercises and inspections/assessments (e.g., CCRIs, inspections by higher headquarters) by preparing RMF artifacts, responding to findings, and tracking corrective actions.