1

Security Control Assessor Jobs in Atlanta, GA (NOW HIRING)

Security Control Assessor (SCA) 1- This is a future position that may come open in the future. We are currently building our pipeline! Responsible for conducting a comprehensive assessment of the ...

Sr. Security Engineer

Atlanta, GA · On-site

$45 - $50/hr

Proven experience in IT security programs, audits, controls, assessments, risk assessments, or remediation management. * Strong knowledge of industry-standard security control frameworks, including ...

Conduct vulnerability assessments using Tenable tools and track remediation efforts. * Support ... Maintain and update System Security Plans (SSPs) to reflect security control implementations.

next page

Showing results 1-20

Security Control Assessor information

See Atlanta, GA salary details

$8

$56

$75

How much do security control assessor jobs pay per hour?

As of Aug 23, 2026, the average hourly pay for security control assessor in Atlanta, GA is $56.51, according to ZipRecruiter salary data. Most workers in this role earn between $48.56 and $65.43 per hour, depending on experience, location, and employer.

What is a security control assessor?

Security Control Assessors (SCAs) are professionals responsible for evaluating the security controls of information systems to ensure they meet required standards and regulations. They conduct assessments, document findings, and provide recommendations to help organizations manage risk and achieve compliance with frameworks such as NIST or FISMA. SCAs play a critical role in maintaining the security and integrity of sensitive data by identifying vulnerabilities and verifying that corrective actions are implemented effectively.

What are the main challenges security control assessors face when evaluating complex information systems?

Security Control Assessors often encounter challenges such as rapidly evolving security threats, integrating new technologies, and ensuring compliance with multiple frameworks (like NIST, FISMA, or RMF). Assessing large, interconnected systems requires attention to detail and strong analytical skills to identify vulnerabilities and recommend effective controls. Collaboration with system owners, IT staff, and auditors is essential to obtain comprehensive documentation and clarify system boundaries, which can be a demanding part of the assessment process.

What are the key skills and qualifications needed to thrive as a security control assessor, and why are they important?

To thrive as a Security Control Assessor, you need expertise in information security principles, risk management frameworks like NIST RMF, and a relevant bachelor's degree or equivalent work experience. Familiarity with security assessment tools, compliance management systems, and certifications such as CISSP, CISA, or CAP is typically required. Strong analytical thinking, attention to detail, and effective communication are crucial for evaluating security controls and reporting findings clearly. These skills ensure accurate risk assessments, regulatory compliance, and robust protection of organizational information assets.

What is the difference between Security Control Assessor vs Security Analyst?

AspectSecurity Control AssessorSecurity Analyst
CertificationsRisk Management Framework (RMF), CISSP, CISACISSP, Security+
Work EnvironmentFederal agencies, DoD, government complianceCorporate, cybersecurity teams, IT departments
ResponsibilitiesAssess security controls, ensure compliance, auditMonitor security, analyze threats, implement security measures

The Security Control Assessor primarily evaluates security controls for compliance and risk management, often within government agencies. In contrast, the Security Analyst focuses on monitoring and analyzing security threats to protect organizational assets. While both roles require cybersecurity knowledge and certifications like CISSP, their focus areas and work environments differ significantly.

How much do security control assessors make?

Security Control Assessors in the federal government or related sectors typically earn between $80,000 and $130,000 annually, depending on experience, certifications, and location. Salaries can vary based on agency, level of clearance, and specific responsibilities, with higher pay often associated with specialized skills and certifications like CISSP or CISA.

What are the most commonly searched types of Security Control Assessor jobs in Atlanta, GA?

The most popular types of Security Control Assessor jobs in Atlanta, GA are:

What are popular job titles related to Security Control Assessor jobs in Atlanta, GA?

For Security Control Assessor jobs in Atlanta, GA, the most frequently searched job titles are:

What job categories do people searching Security Control Assessor jobs in Atlanta, GA look for?

The top searched job categories for Security Control Assessor jobs in Atlanta, GA are:

What cities near Atlanta, GA are hiring for Security Control Assessor jobs?

Cities near Atlanta, GA with the most Security Control Assessor job openings:

Infographic showing various Security Control Assessor job openings in Atlanta, GA as of August 2026, with employment types broken down into 1% As Needed, 75% Full Time, 19% Part Time, 4% Contract, and 1% Nights. Highlights an 95% Physical, 1% Hybrid, and 4% Remote job distribution, with an average salary of $117,549 per year, or $56.5 per hour.

Risk Management Framework (RMF) Support/Senior with Security Clearance

Koniag Government Services

Smyrna, GA • On-site

Other

Medical, Dental, Vision, Retirement, PTO

Posted 9 days ago


Koniag Government Services rating

8.6

Company rating: 8.6 out of 10

Based on 6 frontline employees who took The Breakroom Quiz

57th of 495 rated business services


Job description

Koniag IT Systems, LLC, a Koniag Government Services company, is seeking a Risk Management Framework (RMF) Support/Senior with a Secret security clearance to support KITS and our government customer in Smyrna, GA. This position is for a Future New Business Opportunity. We offer competitive compensation and an extraordinary benefits package including health, dental and vision insurance, 401K with company matching, flexible spending accounts, paid holidays, three weeks paid time off, and more. Koniag IT Systems, a Koniag Government Services company, is seeking an experienced Risk Management Framework (RMF) Support/Senior professional to serve as the RMF Lead supporting our government customer. The ideal candidate is a seasoned cybersecurity professional with deep expertise in the RMF process, security control assessments, and risk management within federal government environments. The successful candidate will perform dual functions as both a Team Lead and Senior Functional Expert, serving as the single point of contact for government stakeholders on all RMF-related activities. An active ADP-II/Secret clearance is required for this position. The RMF Support/Senior will serve as the RMF Lead, integrating security and risk management activities into the system development life cycle while applying a risk-based approach to security control selection and specification. Principal responsibilities will include but are not limited to: * Serve as the RMF Lead and primary single point of contact for the Government Task Monitor (GTM) and the Assessment & Authorization (A&A) government lead. * Perform dual functions as Team Lead and Senior Functional Expert, providing guidance, oversight, and expertise to team members supporting RMF activities. * Conduct and oversee all activities that integrate security and risk management into the system development life cycle (SDLC), ensuring alignment with applicable laws, directives, Executive Orders, policies, standards, and regulations. * Apply a risk-based approach to security control selection and specification, considering effectiveness, efficiency, and applicable constraints. * Lead and perform security control assessments and residual risk determinations across all steps of the RMF process. * Oversee the preparation, review, and maintenance of A&A documentation packages, including System Security Plans (SSPs), Security Assessment Reports (SARs), Plans of Action and Milestones (POA&Ms), and Risk Assessment Reports. * Coordinate with system owners, information system security officers (ISSOs), and other stakeholders to ensure continuous monitoring and compliance with security requirements. * Provide expert guidance on RMF process steps including Categorize, Select, Implement, Assess, Authorize, and Monitor. * Identify and communicate security risks, recommend mitigation strategies, and support the development of risk acceptance decisions. * Ensure compliance with most current DoW guidance and other applicable federal cybersecurity frameworks and directives. * Mentor and provide technical direction to junior team members engaged in RMF and A&A activities. Education and Experience:
Required: * Bachelor's Degree with an emphasis in Information Technology Security, Cybersecurity, or a related field from an accredited college or university. Extensive experience in the required discipline may serve as a substitution for the Bachelor's Degree requirement. * Minimum of 7 years of experience in the certification and accreditation process of Information Systems within the U.S. Federal Government. * Without a Bachelor's Degree, a minimum of 10+ years of experience in the certification and accreditation process of Information Systems within the U.S. Federal Government is required. * Certified in accordance with most current DoW guidance as an IAM Level III. Required Skills and Competencies: * Exceptional communication skills in English - both written and oral - with the ability to effectively communicate complex security and risk concepts to both technical and non-technical stakeholders. * In-depth knowledge and expertise across all steps of the RMF process as defined by NIST SP 800-37 and related publications. * Extensive experience conducting security control assessments and residual risk determinations. * Strong knowledge of NIST Special Publications, including SP 800-53, SP 800-53A, SP 800-30, and SP 800-137. * Experience preparing and reviewing A&A documentation packages including SSPs, SARs, POA&Ms, and Risk Assessment Reports. * Proficiency in applying a risk-based approach to security control selection and specification in compliance with applicable laws, Executive Orders, directives, policies, and regulations. * Demonstrated experience serving as a team lead or senior subject matter expert in a federal government IT security environment. * Strong understanding of the System Development Life Cycle (SDLC) and how security and risk management activities integrate throughout each phase. * Ability to act as the primary point of contact and liaison between technical teams and government stakeholders on all RMF-related matters. * Experience with continuous monitoring strategies and tools to ensure ongoing system authorization and compliance. * Active ADP-II/Secret clearance. Desired Skills and Competencies: * Experience supporting DoD or other federal agency A&A efforts using tools such as eMASS (Enterprise Mission Assurance Support Service) or similar platforms. * Familiarity with additional cybersecurity frameworks such as FISMA, FedRAMP, or CMMC. * Experience with cloud security assessments and the application of RMF within cloud environments. * IAM Level III certifications such as CISM, CISSP, or GSLC. * Knowledge of zero trust architecture principles and their application within federal environments. * Experience supporting or leading teams in a government contracting environment. * Familiarity with vulnerability management tools and techniques, including STIG compliance and SCAP scanning. Our Equal Employment Opportunity Policy The company is an equal opportunity employer. The company shall not discriminate against any employee or applicant because of race, color, religion, creed, ethnicity, sex, sexual orientation, gender or gender identity (except where gender is a bona fide occupational qualification), national origin or ancestry, age, disability, citizenship, military/veteran status, marital status, genetic information or any other characteristic protected by applicable federal, state, or local law. We are committed to equal employment opportunity in all decisions related to employment, promotion, wages, benefits, and all other privileges, terms, and conditions of employment. The company is dedicated to seeking all qualified applicants. If you require an accommodation to navigate or apply for a position on our website, please get in touch with Heaven Wood via e-mail at or by calling 703-488-9377 to request accommodations. Koniag Government Services (KGS) is an Alaska Native Owned corporation supporting the values and traditions of our native communities through an agile employee and corporate culture that delivers Enterprise Solutions, Professional Services and Operational Management to Federal Government Agencies. As a wholly owned subsidiary of Koniag, we apply our proven commercial solutions to a deep knowledge of Defense and Civilian missions to provide forward leaning technical, professional, and operational solutions. KGS enables successful mission outcomes for our customers through solution-oriented business partnerships and a commitment to exceptional service delivery. We ensure long-term success with a continuous improvement approach while balancing the collective interests of our customers, employees, and native communities. For more information, please visit www.koniag-gs.com. Equal Opportunity Employer/Veterans/Disabled. Shareholder Preference in accordance with Public Law 88-352

What Koniag Government Services employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom