1

Security Control Assessor Jobs in Washington (NOW HIRING)

ORA_ON_SITE Description SAIC is seeking a highly skilled and motivated Senior Security Control Assessor (SCA) to support the cybersecurity assessment and compliance needs of mission-critical ...

ORA_ON_SITE Description SAIC is seeking a highly skilled and motivated  Senior Security Control Assessor (SCA)  to support the cybersecurity assessment and compliance needs of mission-critical ...

Description SAIC is seeking a highly skilled and motivated Senior Security Control Assessor (SCA) to support the cybersecurity assessment and compliance needs of mission-critical IT systems for the ...

We are looking for a SME Security Control Assessor that supports security control assessment activities for HHS-ACF information systems by applying NIST security controls and frameworks to evaluate ...

We are looking for a SME Security Control Assessor that supports security control assessment activities for HHS-ACF information systems by applying NIST security controls and frameworks to evaluate ...

We are looking for a SME Security Control Assessor that supports security control assessment activities for HHS-ACF information systems by applying NIST security controls and frameworks to evaluate ...

Senior Security Control Assessor Overview: TSA is currently seeking a Senior Security Control Assessor who will serve as a Functional Lead and provide support to our NAVAIR customer in the DC Metro ...

We are looking for a SME Security Control Assessor that supports security control assessment activities for HHS-ACF information systems by applying NIST security controls and frameworks to evaluate ...

next page

Showing results 1-20

Security Control Assessor information

See Washington salary details

$10

$66

$88

How much do security control assessor jobs pay per hour?

As of Jul 30, 2026, the average hourly pay for security control assessor in Washington is $66.56, according to ZipRecruiter salary data. Most workers in this role earn between $57.16 and $77.07 per hour, depending on experience, location, and employer.

Can you make $500,000 a year in cyber security?

Security Control Assessors typically earn salaries ranging from $70,000 to $150,000 annually, depending on experience, certifications, and location. Reaching a $500,000 annual salary in cybersecurity generally requires senior roles, specialized expertise, management positions, or consulting work with high-value contracts.

Is SOC an entry level job?

A Security Control Assessor (SOC) role is typically not entry-level; it usually requires prior experience in cybersecurity, knowledge of security frameworks, and relevant certifications such as CISSP or Security+. Entry-level positions in cybersecurity may include roles like Security Analyst or Technician, with SOC roles often requiring more specialized skills and experience. However, some organizations offer junior or trainee SOC positions for those starting their cybersecurity careers.

What are the key skills and qualifications needed to thrive as a Security Control Assessor, and why are they important?

To thrive as a Security Control Assessor, you need expertise in information security principles, risk management frameworks like NIST RMF, and a relevant bachelor's degree or equivalent work experience. Familiarity with security assessment tools, compliance management systems, and certifications such as CISSP, CISA, or CAP is typically required. Strong analytical thinking, attention to detail, and effective communication are crucial for evaluating security controls and reporting findings clearly. These skills ensure accurate risk assessments, regulatory compliance, and robust protection of organizational information assets.

What skills do you need to be a security control assessor?

A security control assessor needs strong knowledge of cybersecurity frameworks, risk management, and security controls. Skills in analyzing security policies, conducting assessments, and familiarity with tools like NIST, ISO standards, and vulnerability scanning are essential. Certifications such as CISSP or CISA can also enhance qualifications.

What is the difference between Security Control Assessor vs Security Analyst?

AspectSecurity Control AssessorSecurity Analyst
CertificationsRisk Management Framework (RMF), CISSP, CISACISSP, Security+
Work EnvironmentFederal agencies, DoD, government complianceCorporate, cybersecurity teams, IT departments
ResponsibilitiesAssess security controls, ensure compliance, auditMonitor security, analyze threats, implement security measures

The Security Control Assessor primarily evaluates security controls for compliance and risk management, often within government agencies. In contrast, the Security Analyst focuses on monitoring and analyzing security threats to protect organizational assets. While both roles require cybersecurity knowledge and certifications like CISSP, their focus areas and work environments differ significantly.

What is the role of a security control assessor?

A security control assessor evaluates the effectiveness of security controls implemented within an organization to ensure they meet security standards and compliance requirements. They review documentation, conduct testing, and provide recommendations for improvement, often working with frameworks like NIST or ISO. Certification such as CISSP or CISA is commonly required for this role.

What are the main challenges Security Control Assessors face when evaluating complex information systems?

Security Control Assessors often encounter challenges such as rapidly evolving security threats, integrating new technologies, and ensuring compliance with multiple frameworks (like NIST, FISMA, or RMF). Assessing large, interconnected systems requires attention to detail and strong analytical skills to identify vulnerabilities and recommend effective controls. Collaboration with system owners, IT staff, and auditors is essential to obtain comprehensive documentation and clarify system boundaries, which can be a demanding part of the assessment process.

What are Security Control Assessors?

Security Control Assessors (SCAs) are professionals responsible for evaluating the security controls of information systems to ensure they meet required standards and regulations. They conduct assessments, document findings, and provide recommendations to help organizations manage risk and achieve compliance with frameworks such as NIST or FISMA. SCAs play a critical role in maintaining the security and integrity of sensitive data by identifying vulnerabilities and verifying that corrective actions are implemented effectively.
What are popular job titles related to Security Control Assessor jobs in Washington? For Security Control Assessor jobs in Washington, the most frequently searched job titles are:
What job categories do people searching Security Control Assessor jobs in Washington look for? The top searched job categories for Security Control Assessor jobs in Washington are:
What cities in Washington are hiring for Security Control Assessor jobs? Cities in Washington with the most Security Control Assessor job openings:
What are popular job titles related to Security Control Assessor jobs in WA? For Security Control Assessor jobs in WA, the most frequently searched job titles are:
Infographic showing various Security Control Assessor job openings in Washington as of July 2026, with employment types broken down into 1% Locum Tenens, 36% Full Time, 4% Part Time, 2% Contract, 56% Nights, and 1% Summer. Highlights an 89% Physical, 2% Hybrid, and 9% Remote job distribution, with an average salary of $138,444 per year, or $66.6 per hour.

Security Control Assessor

SAIC

Springfield, VA • On-site

Other

Posted 5 days ago


SAIC rating

7.9

Company rating: 7.9 out of 10

Based on 79 frontline employees who took The Breakroom Quiz

76th of 230 rated it services


Job description

Job ID: 2614940
Location: Springfield, VA, US
Date Posted: 2026-07-24
Category: Cyber
Subcategory: Cyberspace Ops
Schedule: Full-Time
Shift: Day Job
Travel: Yes - 10% of the time
Minimum Clearance Required: Top_Secret
Clearance Level Must Be Able to Obtain: TS/SCI with Poly
Potential for Remote Work: ORA_ON_SITE
Description
SAIC is seeking a highly skilled and motivated Senior Security Control Assessor (SCA) to support the cybersecurity assessment and compliance needs of mission-critical IT systems for the MAJESTIC Joint Program Office (JPO) Team. The successful candidate will perform independent assessments of security controls to ensure compliance with federal cybersecurity policies, standards, and frameworks, such as the Risk Management Framework (RMF), NIST SP 800-53, and others, to manage and mitigate risks to sensitive and classified systems.
This role will require working closely with Information System Security Managers (ISSMs), Information System Owners (ISOs), and system administrators to conduct technical reviews, evaluate security controls, and assist with Authorization and Accreditation (A&A) efforts. This role requires on-site support in Springfield, VA.
Key Responsibilities:
  • Conduct independent, objective, and robust assessments of IT systems to validate compliance with security control requirements in alignment with NIST 800-53, RMF, DoD 8510.01, and other applicable federal cybersecurity regulations
  • Review and assess Authorization Boundary Diagrams (ABDs), Risk Assessment Reports (RARs), Security Plan Packages (SSPs), STIG checklists, vulnerability scan results, POA&Ms, and other security artifacts required for A&A efforts
  • Lead Control Implementation Review and Test (CIRT) procedures and system-level security assessments to evaluate the adequacy of technical, operational, and management security controls
  • Provide formal recommendations on system authorization status to Authorizing Officials (AOs), based on assessment results, residual risks, and system compliance to applicable policies
  • Analyze and interpret vulnerability scan results (e.g., from ACAS, Nessus, or Qualys) and assist in presenting the organization's vulnerability management posture to relevant stakeholders
  • Perform continuous monitoring assessments of information systems to identify risks, ensure ongoing compliance, and document changes impacting the security posture of systems
  • Assess and validate security hardening practices using the DISA STIGs or CIS Benchmarks across systems, applications, and networks
  • Conduct risk analysis and recommend risk mitigation strategies and control adjustments to minimize threats to system operations and data integrity
  • Interface with system engineers, ISSOs, and stakeholders to resolve identified vulnerabilities and ensure timely remediation of risks
  • Provide recommendations to improve current processes, tools, and documentation for security control assessments
  • Compile and present comprehensive reports, including Security Assessment Reports (SARs) and risk assessment summaries, to senior stakeholders for decision-making
  • Maintain up-to-date expertise on cybersecurity threats, technologies, regulatory frameworks, and compliance best practices

Qualifications
Required Qualifications:
Certifications (CWF Requirements):
  • Candidates must satisfy Cybersecurity Workforce Framework (CWF) ID 612 (Security Control Assessor) requirements, as outlined by Navy COOL
    This requirement can be met by possessing one or more of the following qualifying certifications:
  • Certified in Governance Risk and Compliance (CGRC)
  • Certified Information Systems Security Officer (C)ISSO-A)
  • CompTIA Cloud+
  • CompTIA PenTest+
  • CompTIA Security+
  • CompTIA SecurityX (formerly CASP+)
  • Federal IT Security Professional-Auditor-NG (FITSP-A)
  • GIAC Cloud Security Automation (GCSA)
  • GIAC Security Essentials Certification (GSEC)
  • Certified Chief Information Security Officer (CCISO)
  • Certified Information Security Manager (CISM)
  • Certified Information Systems Auditor (CISA)
  • Certified Information Systems Security Professional (CISSP)
  • CompTIA Cybersecurity Analyst (CySA+)
  • GIAC Security Leadership Certification (GSLC)
  • GIAC Systems and Network Auditor (GSNA)
  • Information Systems Security Engineering Professional (ISSEP)
    OR This requirement can be met through:
  • A Bachelor's Degree in Cybersecurity, Computer Science, IT, or a related field

Experience:
  • 5-9 years of professional experience managing and supporting enterprise-level IT environments

Technical Skills:
  • Familiarity with IT environments running enterprise systems, such as Windows Server 2019, MS SQL databases, and Linux distributions (RHEL preferred)
  • Knowledge of incident response functions, security architecture, and penetration testing frameworks (e.g., METASPLOIT, Kali Linux)
  • Strong analytical and documentation skills, with the ability to author comprehensive Security Assessment Reports (SARs) and other system artifacts

Preferred Qualifications:
  • Familiarity with IT environments running enterprise systems, such as Windows Server 2019, MS SQL databases, and Linux distributions (RHEL preferred)
  • Knowledge of incident response functions, security architecture, and penetration testing frameworks (e.g., METASPLOIT, Kali Linux)
  • Strong analytical and documentation skills, with the ability to author comprehensive Security Assessment Reports (SARs) and other system artifacts

Clearance Requirement:
  • Active TS/SCI clearance with the ability to obtain and maintain a TS/SCI with Poly

Work Environment and Notes:
  • On-Site Work: All work must be conducted on-site in Springfield, VA
  • Program Scope: Supports on-premises enterprise IT environments, including virtualized Windows servers, MS SQL Server databases, and networking layers
  • Subcontractor Role: Responsibilities and compensation vary based on the subcontract agreement, with a competitive salary aligned to market rates and role-specific requirements

Target salary range: $120,001 - $160,000. The estimate displayed represents the typical salary range for this position based on experience and other factors.
SAIC is a premier technology integrator providing full life cycle services and solutions in the technical, engineering, intelligence, and enterprise information technology markets. SAIC is Redefining Ingenuity through its deep customer and domain knowledge to enable the delivery of systems engineering and integration offerings for large, complex projects. SAIC's approximately 15,000 employees are driven by integrity and mission focus to serve customers in the U.S. federal government. Headquartered in Reston, Virginia, SAIC has annual revenues of approximately $4.5 billion. For more information, visit saic.com. For information on the benefits SAIC offers, see .

What SAIC employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom