1

Security Control Assessor Jobs in Michigan (NOW HIRING)

Facilitate Security Control Assessment (SCA) and Continuous Monitoring Activities (Plans of Action and Milestones (POA&M) , Corrective Action Plans (CAP) with State of Michigan Applications. To be ...

... assessment process and identify gaps in security control environment and compliance requirements. * Perform gap analysis of security requirements implemented within the agency application(s ...

... Control Management * Execute analysis and remediation efforts for the global vulnerability management program and IT security tools/controls across manufacturing environments. * Assess, report, and ...

... Control Management * Execute analysis and remediation efforts for the global vulnerability management program and IT security tools/controls across manufacturing environments. * Assess, report, and ...

... security assessments and backlog acceleration; help teams prioritize security work without stalling delivery. * Define metrics, reporting, and dashboards (e.g., delivery throughput, control ...

next page

Showing results 1-20

Security Control Assessor information

See Michigan salary details

$7

$51

$68

How much do security control assessor jobs pay per hour?

As of Jul 26, 2026, the average hourly pay for security control assessor in Michigan is $51.22, according to ZipRecruiter salary data. Most workers in this role earn between $43.99 and $59.28 per hour, depending on experience, location, and employer.

Can you make $500,000 a year in cyber security?

Security Control Assessors typically earn salaries ranging from $70,000 to $150,000 annually, depending on experience, certifications, and location. Reaching a $500,000 annual salary in cybersecurity generally requires senior roles, specialized expertise, management positions, or consulting work with high-value contracts.

Is SOC an entry level job?

A Security Control Assessor (SOC) role is typically not entry-level; it usually requires prior experience in cybersecurity, knowledge of security frameworks, and relevant certifications such as CISSP or Security+. Entry-level positions in cybersecurity may include roles like Security Analyst or Technician, with SOC roles often requiring more specialized skills and experience. However, some organizations offer junior or trainee SOC positions for those starting their cybersecurity careers.

What are the key skills and qualifications needed to thrive as a Security Control Assessor, and why are they important?

To thrive as a Security Control Assessor, you need expertise in information security principles, risk management frameworks like NIST RMF, and a relevant bachelor's degree or equivalent work experience. Familiarity with security assessment tools, compliance management systems, and certifications such as CISSP, CISA, or CAP is typically required. Strong analytical thinking, attention to detail, and effective communication are crucial for evaluating security controls and reporting findings clearly. These skills ensure accurate risk assessments, regulatory compliance, and robust protection of organizational information assets.

What skills do you need to be a security control assessor?

A security control assessor needs strong knowledge of cybersecurity frameworks, risk management, and security controls. Skills in analyzing security policies, conducting assessments, and familiarity with tools like NIST, ISO standards, and vulnerability scanning are essential. Certifications such as CISSP or CISA can also enhance qualifications.

What is the difference between Security Control Assessor vs Security Analyst?

AspectSecurity Control AssessorSecurity Analyst
CertificationsRisk Management Framework (RMF), CISSP, CISACISSP, Security+
Work EnvironmentFederal agencies, DoD, government complianceCorporate, cybersecurity teams, IT departments
ResponsibilitiesAssess security controls, ensure compliance, auditMonitor security, analyze threats, implement security measures

The Security Control Assessor primarily evaluates security controls for compliance and risk management, often within government agencies. In contrast, the Security Analyst focuses on monitoring and analyzing security threats to protect organizational assets. While both roles require cybersecurity knowledge and certifications like CISSP, their focus areas and work environments differ significantly.

What is the role of a security control assessor?

A security control assessor evaluates the effectiveness of security controls implemented within an organization to ensure they meet security standards and compliance requirements. They review documentation, conduct testing, and provide recommendations for improvement, often working with frameworks like NIST or ISO. Certification such as CISSP or CISA is commonly required for this role.

What are the main challenges Security Control Assessors face when evaluating complex information systems?

Security Control Assessors often encounter challenges such as rapidly evolving security threats, integrating new technologies, and ensuring compliance with multiple frameworks (like NIST, FISMA, or RMF). Assessing large, interconnected systems requires attention to detail and strong analytical skills to identify vulnerabilities and recommend effective controls. Collaboration with system owners, IT staff, and auditors is essential to obtain comprehensive documentation and clarify system boundaries, which can be a demanding part of the assessment process.

What are Security Control Assessors?

Security Control Assessors (SCAs) are professionals responsible for evaluating the security controls of information systems to ensure they meet required standards and regulations. They conduct assessments, document findings, and provide recommendations to help organizations manage risk and achieve compliance with frameworks such as NIST or FISMA. SCAs play a critical role in maintaining the security and integrity of sensitive data by identifying vulnerabilities and verifying that corrective actions are implemented effectively.
What are popular job titles related to Security Control Assessor jobs in Michigan? For Security Control Assessor jobs in Michigan, the most frequently searched job titles are:
What job categories do people searching Security Control Assessor jobs in Michigan look for? The top searched job categories for Security Control Assessor jobs in Michigan are:
What cities in Michigan are hiring for Security Control Assessor jobs? Cities in Michigan with the most Security Control Assessor job openings:
What are popular job titles related to Security Control Assessor jobs in MI? For Security Control Assessor jobs in MI, the most frequently searched job titles are:
Infographic showing various Security Control Assessor job openings in Michigan as of July 2026, with employment types broken down into 2% Locum Tenens, 37% Full Time, 4% Part Time, 1% Temporary, 2% Contract, and 54% Nights. Highlights an 88% Physical, 3% Hybrid, and 9% Remote job distribution, with an average salary of $106,540 per year, or $51.2 per hour.
Information Systems Security Officer (ISSO)

Information Systems Security Officer (ISSO)

Contact Government Services, LLC

Detroit, MI

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted yesterday


Job description

ISSO
Employment Type: Full-Time, Experienced 
Department: Information Technology 

CGS is seeking an Information Systems Security Officer (ISSO) with DIACAP and/or RMF experience who has deep expertise in security assessment documentation to support Dept. of Commerce systems and efforts to achieve their Authorization to Operate (ATO). This position is located at the client site in the Herbert Hoover building in Washington, DC. The scope of this position includes full life-cycle Assessment and Authorization (A&A) management through all 6 Steps of the RMF process in support of the Government ISSM.In this role, you'll conduct security assessment, and information system security oversight activities in accordance with NIST 800.53 that support systems from the perspective RMF requirements.  

CGS brings motivated, highly skilled, and creative people together to solve the government's most dynamic problems with cutting-edge technology. To carry out our mission, we are seeking candidates who are excited to contribute to government innovation, appreciate collaboration, and can anticipate the needs of others. Here at CGS, we offer an environment in which our employees feel supported, and we encourage professional growth through various learning opportunities. 

Skills and attributes for success:
- Review systems to identify potential security weaknesses and recommend improvements to amend vulnerabilities, implement changes, and document upgrades. 
- Maintain responsibility for managing cybersecurity risk from an organizational perspective. 
- Identify organizational risks, prioritize those risks, and maintain a risk registry for escalating and presenting those risks to senior leadership.
- Provide security guidance and IS validation using the National Institute of Standards and Technology (NIST) RMF, DoC, and local security policies.
- Providing configuration management (CM) recommendations for information system security software, hardware, and firmware and coordinating changes and modifications with the ISSM, Security Control Assessor (SCA), and Authorizing Official (AO).
- Maintain vulnerability scanning tool compliance, such as HBSS or ACAS, and patch management, such as IAVM to ensure IT staff pushes patches to all systems in an effort to maintain compliance with all applicable directives, manage system changes, and assess the security impact of those changes.
- Support security authorization activities, including transitioning from the legacy Information Assurance Certification and Accreditation Process (DIACAP) to compliance with the DoC RMF.
- Provide subject matter expertise for cyber security and trusted system technology. 
- Apply advanced technical knowledge and analysis of specialized functional areas in task requirements to develop solutions to complex problems.
- Research, write, review, disposition feedback, and finalize recommendations regarding cyber security policy, assessment and authorization assessments (A&As), security test and evaluation reports, and security engineering practices and processes. 
- Conduct research and write risk assessment reports to include risk thresholds, evaluation, and scoring.
- Support analysis of the findings and provide expert technical guidance for mitigation strategies, including implementation advice on the cyber security risk findings, and other complex problems. 

Qualifications:
- Bachelor's Degree.
- A minimum of five (5) years experience as an Information Assurance (IA) Analyst, ISSE, ISSO, or similar role in ATO package development, including generating security documentation for requirements, security control assessment, STIG and IAVA compliance, Standard Operating Procedures, test results, etc.
- eMASS experience.
- Professional security certification such as: CCNA Security, CySA+, GICSP, GSEC, CompTIA Security+ CE, SSCP, or higher.
- Strong desktop publishing skills using Microsoft Word and Excel.
- Experience with industry writing styles such as grammar, sentence form, and structure.
- Ability to multi-task in a deadline-oriented environment.

Ideally, you will also have:
- CISSP, CASP, or a similar certificate is preferred.
- Master's Degree in Cybersecurity or related field.
- Strong initiative, detail orientation, organizational skills, and aptitude for analytical thinking.
- Demonstrated ability to work well independently and as a part of a team.
- Excellent work ethic and a high commitment to quality.

Our Commitment:
Contact Government Services (CGS) strives to simplify and enhance government bureaucracy through the optimization of human, technical, and financial resources. We combine cutting-edge technology with world-class personnel to deliver customized solutions that fit our client's specific needs. We are committed to solving the most challenging and dynamic problems.

For the past seven years, we've been growing our government contracting portfolio, and along the way, we've created valuable partnerships by demonstrating a commitment to honesty, professionalism, and quality work.

Here at CGS we value honesty through hard work and self-awareness, professionalism in all we do, and to deliver the best quality to our consumers mending those relations for years to come.

We care about our employees. Therefore, we offer a comprehensive benefits package.
Health, Dental, and Vision
Life Insurance
401k
Flexible Spending Account (Health, Dependent Care, and Commuter)
Paid Time Off and Observance of State/Federal Holidays

Contact Government Services, LLC is an Equal Opportunity Employer. Applicants will be considered without regard to their race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.

Join our team and become part of government innovation!
Explore additional job opportunities with CGS on our Job Board:
https://cgsfederal.com/join-our-team/
For more information about CGS please visit: https://www.cgsfederal.com or contact:
Email: [email protected]

#CJ
$92,213.33 - $125,146.66 a year
We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
apply for this job