1

Security Control Assessor Jobs in Washington (NOW HIRING)

Security Control Assessor

Arlington, VA · On-site

$140K - $160K/yr

Security Control Assessor Location: On Site in Arlington, VA Department: Cyber Security Services Reports To: Management FLSA Status: Full Time/Non-exempt Job Purpose: The security control assessor ...

Security Control Assessor

Arlington, VA · On-site

$140K - $160K/yr

Security Control Assessor Location: On Site in Arlington, VA Department: Cyber Security Services Reports To: Management FLSA Status: Full Time/Non-exempt Job Purpose: The security control assessor ...

Job#: 3044387 Security Control Assessor Location: Alexandria, Virginia (Onsite) Role Overview We are seeking a skilled and detail-oriented Security Control Assessor to join our team. The successful ...

Security Control Assessor

Arlington, VA · On-site

$140K - $160K/yr

Security Control Assessor Location: On Site in Arlington, VA Department: Cyber Security Services Reports To: Management FLSA Status: Full Time/Non-exempt Job Purpose: The security control assessor ...

Execute a security control assessment plan and update the System Security Plan * Review vulnerability scans and remediation * Implement risk management programs by utilizing NIST, FISMA, HIPAA, and ...

Execute a security control assessment plan and update the System Security Plan * Review vulnerability scans and remediation * Implement risk management programs by utilizing NIST, FISMA, HIPAA, and ...

Security Control Assessor

Alexandria, VA · On-site

$146K - $234K/yr

Execute a security control assessment plan and update the System Security Plan * Review vulnerability scans and remediation * Implement risk management programs by utilizing NIST, FISMA, HIPAA, and ...

You'll work under a senior assessor and help evaluate security control implementation, validate evidence, and document results in alignment with NIST Risk Management Framework (RMF) and NIST SP 800 ...

You'll work under a senior assessor and help evaluate security control implementation, validate evidence, and document results in alignment with NIST Risk Management Framework (RMF) and NIST SP 800 ...

You'll work under a senior assessor and help evaluate security control implementation, validate evidence, and document results in alignment with NIST Risk Management Framework (RMF) and NIST SP 800 ...

You'll work under a senior assessor and help evaluate security control implementation, validate evidence, and document results in alignment with NIST Risk Management Framework (RMF) and NIST SP 800 ...

You'll work under a senior assessor and help evaluate security control implementation, validate evidence, and document results in alignment with NIST Risk Management Framework (RMF) and NIST SP 800 ...

next page

Showing results 1-20

Security Control Assessor information

See Washington salary details

$10

$66

$88

How much do security control assessor jobs pay per hour?

As of Sep 11, 2026, the average hourly pay for security control assessor in Washington is $66.56, according to ZipRecruiter salary data. Most workers in this role earn between $57.16 and $77.07 per hour, depending on experience, location, and employer.

What is a security control assessor?

Security Control Assessors (SCAs) are professionals responsible for evaluating the security controls of information systems to ensure they meet required standards and regulations. They conduct assessments, document findings, and provide recommendations to help organizations manage risk and achieve compliance with frameworks such as NIST or FISMA. SCAs play a critical role in maintaining the security and integrity of sensitive data by identifying vulnerabilities and verifying that corrective actions are implemented effectively.

What are the main challenges security control assessors face when evaluating complex information systems?

Security Control Assessors often encounter challenges such as rapidly evolving security threats, integrating new technologies, and ensuring compliance with multiple frameworks (like NIST, FISMA, or RMF). Assessing large, interconnected systems requires attention to detail and strong analytical skills to identify vulnerabilities and recommend effective controls. Collaboration with system owners, IT staff, and auditors is essential to obtain comprehensive documentation and clarify system boundaries, which can be a demanding part of the assessment process.

What are the key skills and qualifications needed to thrive as a security control assessor, and why are they important?

To thrive as a Security Control Assessor, you need expertise in information security principles, risk management frameworks like NIST RMF, and a relevant bachelor's degree or equivalent work experience. Familiarity with security assessment tools, compliance management systems, and certifications such as CISSP, CISA, or CAP is typically required. Strong analytical thinking, attention to detail, and effective communication are crucial for evaluating security controls and reporting findings clearly. These skills ensure accurate risk assessments, regulatory compliance, and robust protection of organizational information assets.

What is the difference between Security Control Assessor vs Security Analyst?

AspectSecurity Control AssessorSecurity Analyst
CertificationsRisk Management Framework (RMF), CISSP, CISACISSP, Security+
Work EnvironmentFederal agencies, DoD, government complianceCorporate, cybersecurity teams, IT departments
ResponsibilitiesAssess security controls, ensure compliance, auditMonitor security, analyze threats, implement security measures

The Security Control Assessor primarily evaluates security controls for compliance and risk management, often within government agencies. In contrast, the Security Analyst focuses on monitoring and analyzing security threats to protect organizational assets. While both roles require cybersecurity knowledge and certifications like CISSP, their focus areas and work environments differ significantly.

How much do security control assessors make?

Security Control Assessors in the federal government or related sectors typically earn between $80,000 and $130,000 annually, depending on experience, certifications, and location. Salaries can vary based on agency, level of clearance, and specific responsibilities, with higher pay often associated with specialized skills and certifications like CISSP or CISA.

What are popular job titles related to Security Control Assessor jobs in Washington?

For Security Control Assessor jobs in Washington, the most frequently searched job titles are:

What job categories do people searching Security Control Assessor jobs in Washington look for?

The top searched job categories for Security Control Assessor jobs in Washington are:

What cities in Washington are hiring for Security Control Assessor jobs?

Cities in Washington with the most Security Control Assessor job openings:

What are popular job titles related to Security Control Assessor jobs in WA?

For Security Control Assessor jobs in WA, the most frequently searched job titles are:

Infographic showing various Security Control Assessor job openings in Washington as of September 2026, with employment types broken down into 1% As Needed, 73% Full Time, 21% Part Time, 4% Contract, and 1% Nights. Highlights an 92% Physical, 1% Hybrid, and 7% Remote job distribution, with an average salary of $138,444 per year, or $66.6 per hour.

Security Control Assessor

Arlington, VA • On-site

$140K - $160K/yr

Full-time

Posted 21 days ago


Key responsibilities

  • Evaluate the effectiveness of implemented security controls and identify weaknesses using automated tools, manual techniques, and specialized testing methodologies.

  • Assess security documentation, determine risk levels, and develop plans such as Security Assessment Reports and continuous monitoring strategies.

  • Advise system owners and support the development and execution of security assessment and authorization processes, including initial remediation actions.


Job description

Description:

Job Title: Security Control Assessor  

Location: On Site in Arlington, VA  

Department: Cyber Security Services  

Reports To: Management 

FLSA Status: Full Time/Non-exempt  

Job Purpose: 

The security control assessor (SCAs) supports a critical, objective role to evaluate the effectiveness of implemented controls in mitigating security risks. The SCA will support a critical mission within the intelligence community. In the role as a SCA, you are expected to use automated scanning tools, manual techniques, and specialized testing methodologies to identify weaknesses and vulnerabilities. The SCA is expected to be a collaborative member of the RMF program of the organization, to provide intelligent input to system security architectures in order to align with RMF principles and guidelines. This includes ensuring to guide the RMF process so that security controls are integrated seamlessly into system designs to provide comprehensive protection against threats and vulnerabilities. 

Duties & Responsibilities: 

The SCA's specific duties include: 

  • Advise the Information System Owner (ISO) concerning the impact levels for Confidentiality, Integrity, and Availability for the information on systems. 
  • Ensure security assessments are completed for each IS. 
  • Initiate a POA&M with identified weaknesses and suspense dates for each IS based on findings and recommendations from the SAR. 
  • Evaluate security assessment documentation and provide written recommendations for security authorization to the CISO and AO. 
  • Assess proposed changes to Information Systems, their environment of operation, and mission needs that could affect system authorization. 
  • Serve as a cybersecurity technical advisor to the CISO and AO under their purview. 
  • Be integral to the development of the monitoring strategy. The system-level continuous monitoring strategy must conform to all applicable published DoD enterprise-level or DoD Component-level continuous monitoring strategies. 
  • Determine and document in the SAR a risk level for every noncompliant security control in the system baseline. 
  • Determine and document in the SAR an aggregate level of risk to the system and identify the key drivers for the assessment. The SCA's risk assessment considers threats, vulnerabilities, and potential impacts as well as existing and planned risk mitigation. 
  • Develop the continuous monitoring plan specific to the information system. 

The SCA is responsible for the RMF deliverables associated with Step 4 of DOD and IC RMF Policies for assigned systems. This includes, but is not limited to:  

  • Security Assessment Plans tailored to specific systems control requirements 
  • Security control assessment input, which includes narratives for the review of controls and artifacts 
  • Security Assessment Reports 
  • ATO recommendations or ATO with Condition Memorandums 
  • Conduct initial remediation actions once a security assessment has been completed to ensure proper hand off to the ISSM and ISSOs.  
  • Assessment of selected controls IAW continuous monitoring strategy 

The SCA is expected to have additional duties as assigned in support of corporate cyber security services. Additional details are reviewed in accordance with company policies.  

Requirements:

Required Skills & Experience: 

  • Strong knowledge of Risk Management Framework (RMF) 800-37 and continuous monitoring 800-137 
  • Expert knowledge and hands-on experience with FISMA Systems, NIST 800-series guidelines, FIPS, Security Assessment & Authorization (SA&A) requirements and processes, Continuous Monitoring Framework experience and its tools, Plan of Action & Milestones (POA&M) policies, and vulnerability/patch management, risk management, project management, proficient with Microsoft products - Word, Excel, PowerPoint. 
  • Proficient with vulnerability and scanning tools and well-versed in interpreting risk posture resulting from assessment reports. Experience in project management and tracking, and the Microsoft suite of office products 
  • Experience of assessing cloud-based security authorizations (FedRamp, AWS & Azure) as well as the NIST control responsibilities 
  • Experience with SAP/JSIG 
  • Expert with documenting and or reviewing of security materials such as; system security plans (SSP), Security Assessment Report (SAR), and Security Assessment Plan (SAP), and other documents per NIST 800 guidelines. 
  • Experience supporting cloud-based security authorizations (FedRamp, AWS, & Azure) 
  • Experience creating Security Assessment Plans, Security Assessment Reports, and Executive-level briefings 

Qualifications: 

  • Bachelor's Degree in Computer Science or a related technical discipline  
  • Master's Degree preferred. 
  • Minimum 6-10 years of experience.  
  • Must currently possess an active TS/SCI with the ability to obtain and maintain a CI polygraph. 
  • DOD 8140 IAM Level II (CAP, CASP, CISM, CISSP, GSLC, CCISO) is required 
  • Systems Security Engineering background preferred.  
  • Effective communication skills to collaborate with cross-functional teams and stakeholders on implementing security measures organization-wide. 
  • Strong analytical skills for identifying system vulnerabilities and documenting control remediation recommendations through collaboration on System Impact Analysis and Documented Risk Acceptance.  
  • Detail-oriented with the ability to manage multiple tasks and prioritize effectively. 
  • Comprehensive knowledge of RMF activities at a senior level (ability to articulate to Executive audiences preferred). 
  • Familiarity with federal regulatory requirements, contractual obligations, and industry standards related to information security. Evaluate adherence to standards such as Privacy, GDPR, and HIPAA 

Other: 

This is typical office or administrative work, and there is no exposure to adverse environmental conditions. 

This position requires sedentary work. Sedentary work is defined as: Exerting up to 10 pounds of force occasionally and/or a negligible amount of force frequently or constantly to lift, carry, push, pull or otherwise move objects, including the human body. Sedentary work involves sitting most of the time. Jobs are sedentary if walking and standing are required only occasionally, and all other sedentary criteria are met.