1

Security Control Assessor Jobs in Virginia (NOW HIRING)

Overview VTG is looking for multiple levels (Level 2, 3 & 4) of a Security Control Assessor (SCA) in multiple locations. (Note: position is contingent upon program award and the postions are located ...

Overview VTG is looking for multiple levels (Level 2, 3 & 4) of a Security Control Assessor (SCA) in multiple locations. (Note: position is contingent upon program award and the postions are located ...

Overview VTG is looking for multiple levels (Level 2, 3 & 4) of a Security Control Assessor (SCA) in multiple locations. (Note: position is contingent upon program award and the postions are located ...

Conduct FISMA security control assessments in accordance with NIST SP 800-53 and NIST SP 800-53A * Support system authorization efforts across the RMF lifecycle * Perform control testing, interviews ...

Conduct FISMA security control assessments in accordance with NIST SP 800-53 and NIST SP 800-53A * Support system authorization efforts across the RMF lifecycle * Perform control testing, interviews ...

Showing results 41-60

Security Control Assessor information

See Virginia salary details

$8

$58

$77

How much do security control assessor jobs pay per hour?

As of Sep 12, 2026, the average hourly pay for security control assessor in Virginia is $58.26, according to ZipRecruiter salary data. Most workers in this role earn between $50.05 and $67.45 per hour, depending on experience, location, and employer.

What is a security control assessor?

Security Control Assessors (SCAs) are professionals responsible for evaluating the security controls of information systems to ensure they meet required standards and regulations. They conduct assessments, document findings, and provide recommendations to help organizations manage risk and achieve compliance with frameworks such as NIST or FISMA. SCAs play a critical role in maintaining the security and integrity of sensitive data by identifying vulnerabilities and verifying that corrective actions are implemented effectively.

What are the main challenges security control assessors face when evaluating complex information systems?

Security Control Assessors often encounter challenges such as rapidly evolving security threats, integrating new technologies, and ensuring compliance with multiple frameworks (like NIST, FISMA, or RMF). Assessing large, interconnected systems requires attention to detail and strong analytical skills to identify vulnerabilities and recommend effective controls. Collaboration with system owners, IT staff, and auditors is essential to obtain comprehensive documentation and clarify system boundaries, which can be a demanding part of the assessment process.

What are the key skills and qualifications needed to thrive as a security control assessor, and why are they important?

To thrive as a Security Control Assessor, you need expertise in information security principles, risk management frameworks like NIST RMF, and a relevant bachelor's degree or equivalent work experience. Familiarity with security assessment tools, compliance management systems, and certifications such as CISSP, CISA, or CAP is typically required. Strong analytical thinking, attention to detail, and effective communication are crucial for evaluating security controls and reporting findings clearly. These skills ensure accurate risk assessments, regulatory compliance, and robust protection of organizational information assets.

What is the difference between Security Control Assessor vs Security Analyst?

AspectSecurity Control AssessorSecurity Analyst
CertificationsRisk Management Framework (RMF), CISSP, CISACISSP, Security+
Work EnvironmentFederal agencies, DoD, government complianceCorporate, cybersecurity teams, IT departments
ResponsibilitiesAssess security controls, ensure compliance, auditMonitor security, analyze threats, implement security measures

The Security Control Assessor primarily evaluates security controls for compliance and risk management, often within government agencies. In contrast, the Security Analyst focuses on monitoring and analyzing security threats to protect organizational assets. While both roles require cybersecurity knowledge and certifications like CISSP, their focus areas and work environments differ significantly.

How much do security control assessors make?

Security Control Assessors in the federal government or related sectors typically earn between $80,000 and $130,000 annually, depending on experience, certifications, and location. Salaries can vary based on agency, level of clearance, and specific responsibilities, with higher pay often associated with specialized skills and certifications like CISSP or CISA.

What are popular job titles related to Security Control Assessor jobs in Virginia?

For Security Control Assessor jobs in Virginia, the most frequently searched job titles are:

What job categories do people searching Security Control Assessor jobs in Virginia look for?

The top searched job categories for Security Control Assessor jobs in Virginia are:

What cities in Virginia are hiring for Security Control Assessor jobs?

Cities in Virginia with the most Security Control Assessor job openings:

What are popular job titles related to Security Control Assessor jobs in VA?

For Security Control Assessor jobs in VA, the most frequently searched job titles are:

Infographic showing various Security Control Assessor job openings in Virginia as of September 2026, with employment types broken down into 100% Full Time. Highlights an 86% In-person, and 14% Remote job distribution, with an average salary of $121,188 per year, or $58.3 per hour.

Security Control Assessor (SCA)

Chantilly, VA • On-site

Cyber Defense Technologies
Real Estate • 11 - 50 employees

$120K - $145K/yr

Full-time

Medical, Dental, Retirement

Re-posted 17 days ago


Job description

Overview: CDT is looking to add an experienced Security Control Assessor (mid to senior) to support a government customer in Chantilly, VA.
Clearance: An active Top Secret/SCI clearance with CI Poly is required. Candidates who do not meet these clearance requirements will not be considered.
Qualifications:
  • Master's Degree and 3 years work experience, Bachelor's Degree and 5 years of work experience or equivalent; Associates Degree or High School/GED and 7 years work experience or equivalent.
Preferred Qualification:
  • Practical experience performing information systems assessment and authorization (A&A) as defined in applicable ICDs and guidance.
  • Practical experience performing the processes involved in developing and implementing security related directives and guidance for Information Assurance, Information Technology, and Information Management.
  • Practical experience utilizing risk management strategies for information technology solutions.
  • Technical understanding of emerging technologies and their implementation within Government system and network environments.
  • Knowledge of information technology concepts used in the evaluation of security performance and integrity of state-of-the-art applications, communications systems, hardware, software, satellite control systems, and information processing systems.
  • Technical understanding of information technology systems, software, and networks.
  • Ability to effectively coordinate A&A activities of industry and Government information systems to meet acquisition milestone requirements; and
  • Effective technical report and general correspondence writing ability.
  • Ability to manage and track systems or programs involved in the A&A process.
  • Experience developing and implementing security related directives and guidance for Information Assurance, Information Technology, and Information Management; and
  • Experience working with a mixed skill level team to ensure that appropriate knowledge and skill transfer occurs.
Travel:
  • Travel will be required about 25% depending on program needs.
Why Join Cyber Defense Technologies?
At CDT, we offer a collaborative and inclusive work environment where your expertise in A&A can help shape the future of cybersecurity and engineering solutions.
Compensation and Benefits:
  • Competitive salary based on experience.
  • Comprehensive benefits package, including health, dental, and retirement plans.
  • Opportunities for professional development and career advancement.
CDT is committed to hiring and retaining a diverse workforce. We are an Equal Opportunity employer making decisions without regard to race, color, religion, creed, sex, sexual orientation, gender identity, marital status, national origin, age, veteran status, disability, or any other protected class.
Apply Now:
If you are a proactive SCA and thrive in dynamic environments, we encourage you to apply and join the CDT team!
Salary Range: $120,000 - $145,000 based on experience