1

Security Control Assessor Jobs in Rhode Island (NOW HIRING)

Evaluate vendor security programs, control effectiveness, and governance, along with deep-dive assessment of the specific product being implemented including solution architecture, data flows, and ...

Evaluate vendor security programs, control effectiveness, and governance, along with deep-dive assessment of the specific product being implemented including solution architecture, data flows, and ...

Perform continuous threat monitoring, log analysis, vulnerability assessments, and execute ... control systems (Kerri). * Participate in $24\times7\times365$ emergency threat responses and ...

next page

Showing results 1-20

Security Control Assessor information

See Rhode Island salary details

$8

$57

$76

How much do security control assessor jobs pay per hour?

As of Aug 8, 2026, the average hourly pay for security control assessor in Rhode Island is $57.55, according to ZipRecruiter salary data. Most workers in this role earn between $49.42 and $66.63 per hour, depending on experience, location, and employer.

How much do security control assessors make?

Security Control Assessors in the federal government or related sectors typically earn between $80,000 and $130,000 annually, depending on experience, certifications, and location. Salaries can vary based on agency, level of clearance, and specific responsibilities, with higher pay often associated with specialized skills and certifications like CISSP or CISA.

What are the key skills and qualifications needed to thrive as a security control assessor, and why are they important?

To thrive as a Security Control Assessor, you need expertise in information security principles, risk management frameworks like NIST RMF, and a relevant bachelor's degree or equivalent work experience. Familiarity with security assessment tools, compliance management systems, and certifications such as CISSP, CISA, or CAP is typically required. Strong analytical thinking, attention to detail, and effective communication are crucial for evaluating security controls and reporting findings clearly. These skills ensure accurate risk assessments, regulatory compliance, and robust protection of organizational information assets.

What is the difference between Security Control Assessor vs Security Analyst?

AspectSecurity Control AssessorSecurity Analyst
CertificationsRisk Management Framework (RMF), CISSP, CISACISSP, Security+
Work EnvironmentFederal agencies, DoD, government complianceCorporate, cybersecurity teams, IT departments
ResponsibilitiesAssess security controls, ensure compliance, auditMonitor security, analyze threats, implement security measures

The Security Control Assessor primarily evaluates security controls for compliance and risk management, often within government agencies. In contrast, the Security Analyst focuses on monitoring and analyzing security threats to protect organizational assets. While both roles require cybersecurity knowledge and certifications like CISSP, their focus areas and work environments differ significantly.

What are the main challenges security control assessors face when evaluating complex information systems?

Security Control Assessors often encounter challenges such as rapidly evolving security threats, integrating new technologies, and ensuring compliance with multiple frameworks (like NIST, FISMA, or RMF). Assessing large, interconnected systems requires attention to detail and strong analytical skills to identify vulnerabilities and recommend effective controls. Collaboration with system owners, IT staff, and auditors is essential to obtain comprehensive documentation and clarify system boundaries, which can be a demanding part of the assessment process.

What is a security control assessor?

Security Control Assessors (SCAs) are professionals responsible for evaluating the security controls of information systems to ensure they meet required standards and regulations. They conduct assessments, document findings, and provide recommendations to help organizations manage risk and achieve compliance with frameworks such as NIST or FISMA. SCAs play a critical role in maintaining the security and integrity of sensitive data by identifying vulnerabilities and verifying that corrective actions are implemented effectively.
What are popular job titles related to Security Control Assessor jobs in Rhode Island? For Security Control Assessor jobs in Rhode Island, the most frequently searched job titles are:
What job categories do people searching Security Control Assessor jobs in Rhode Island look for? The top searched job categories for Security Control Assessor jobs in Rhode Island are:
What are popular job titles related to Security Control Assessor jobs in RI? For Security Control Assessor jobs in RI, the most frequently searched job titles are:
Infographic showing various Security Control Assessor job openings in Rhode Island as of August 2026, with employment types broken down into 1% As Needed, 75% Full Time, 19% Part Time, 4% Contract, and 1% Nights. Highlights an 95% Physical, 1% Hybrid, and 4% Remote job distribution, with an average salary of $119,707 per year, or $57.6 per hour.

Information System Security Specialist III

STAHL

Newport, RI • On-site

Contractor

Re-posted 10 days ago


Job description

Information System Security Specialist III

WHO WE ARE:
STAHL Companies provides the Program Management for its Channel of Commercial Technology companies in Government that consist of Small Businesses and New Technology start-ups.
STAHL advocates for policies that can improve government services and maintain our government's competitive advantage, by bringing more technology into government programs.
STAHL Companies advocates on behalf of our nation's innovative, new technology and small businesses looking to work with the U.S. government. We do this by aligning the voice of our small business members with advocacy for change in federal policy that will make the government market more accessible to small businesses and the commercial technology ecosystem.
The Channel's founding Technical Board Members include former government leaders and IT executives passionate about bringing best-of-breed technology to the government.
We are seeking a skilled and experienced Information System Security Specialist III to join our team!
The Information System Security Specialist III is responsible for supporting cybersecurity and information assurance (IA) activities to ensure compliance with Department of Defense (DoD) and Department of the Navy (DON) security requirements. This role focuses on safeguarding information systems, supporting authorization processes, and implementing security controls across systems and environments.
Responsibilities

Cybersecurity & Information Assurance: 
         Implement and maintain security controls in compliance with DoD and DON policies 
         Support system security posture and continuous monitoring activities 
Assessment & Authorization (A&A): 
         Assist in the development and maintenance of A&A packages 
         Support RMF processes, including system categorization, control selection, and authorization 
Security Tools & Compliance: 
         Utilize tools such as eMASS and ACAS to track, assess, and report system vulnerabilities 
         Ensure systems meet compliance standards and address identified risks 
Risk Management: 
         Identify, assess, and mitigate cybersecurity risks and vulnerabilities 
         Recommend corrective actions and track remediation efforts 
Documentation & Reporting: 
         Prepare and maintain security documentation, including System Security Plans (SSPs) 
         Provide reports on system security status and compliance metrics 
Collaboration & Support: 
         Work with engineers, program managers, and stakeholders to integrate security into system lifecycle 
         Support audits, inspections, and security assessments
Qualifications
Minimum Qualifications:
         Information Assurance Technician (IAT) Level I certification (minimum requirement) 
         Completion of required training in accordance with: 
o    SECNAV M-5239.2 
o    DoD 8570.01-M
 (Dates of most recent training completion must be provided)

Education Requirements:
         Bachelor's degree in a technical or managerial discipline, OR 
         High school diploma (or equivalent) with additional years of relevant experience 
Experience Requirements:
         5+ years of relevant experience in: 
o    Cybersecurity 
o    Systems engineering 
o    Test & Evaluation (T&E) 
o    Assessment & Authorization (A&A), formerly Certification & Accreditation (C&A) 
         7+ years of experience required in lieu of a college degree 
Desired Qualifications:
         Experience with Information Assurance and cybersecurity tools, including: 
o    DISA Enterprise Mission Assurance Support Service (eMASS) 
o    Assured Compliance Assessment Solution (ACAS) 
         Familiarity with Risk Management Framework (RMF) processes 
         May be required to hold or obtain Security Control Assessor (SCA) qualification 


*Position is contingent upon award.

Location: Newport, Rhode Island, United States
To know more about the company, visit Stahl Companies (stahlusa.us)
The Information System Security Specialist III is responsible for supporting cybersecurity and information assurance (IA) activities to ensure compliance with Department of Defense (DoD) and Department of the Navy (DON) security requirements. This role focuses on safeguarding information systems, supporting authorization processes, and implementing security controls across systems and environments.