1

Security Control Assessor Jobs in Austin, TX (NOW HIRING)

Conduct security control assessments, risk assessments, and gap analyses , mapping findings to applicable compliance requirements. * Prepare and maintain privacy and security documentation, including ...

This role is critical to ensuring organizational systems achieve and maintain an Authorization to Operate (ATO) by supporting security categorization, control selection, implementation, assessment ...

New

... assessments & evaluate in alignment to the supplier security control framework Ensure effectiveness of approved controls and drive risk remediations or changes from previous audit for existing ...

... security control assessments, gap analyses, and compliance reviews • Map assessment findings to applicable security and compliance requirements • Prepare privacy documentation including Privacy ...

Risk Manager II - AMZ10108334

Austin, TX · On-site

$78K - $129K/yr

... assessments for data center security controls and evaluating control applicability between the organization and third-party providers; tracking milestones and reporting status. For vendors, evaluates ...

... reactive assessments to proactive, automated protection at global scale. Security Engineers are ... You'll apply threat modeling, architecture analysis, and enterprise security control knowledge to ...

... reactive assessments to proactive, automated protection at global scale. Security Engineers are ... You'll apply threat modeling, architecture analysis, and enterprise security control knowledge to ...

You'll apply threat modeling, architecture analysis, and enterprise security control knowledge to ... in risk assessment and enabling organizations to make security decisions - 2+ years of ...

next page

Showing results 1-20

Security Control Assessor information

See Austin, TX salary details

$8

$58

$77

How much do security control assessor jobs pay per hour?

As of Aug 28, 2026, the average hourly pay for security control assessor in Austin, TX is $58.25, according to ZipRecruiter salary data. Most workers in this role earn between $50.05 and $67.45 per hour, depending on experience, location, and employer.

What is a security control assessor?

Security Control Assessors (SCAs) are professionals responsible for evaluating the security controls of information systems to ensure they meet required standards and regulations. They conduct assessments, document findings, and provide recommendations to help organizations manage risk and achieve compliance with frameworks such as NIST or FISMA. SCAs play a critical role in maintaining the security and integrity of sensitive data by identifying vulnerabilities and verifying that corrective actions are implemented effectively.

What are the main challenges security control assessors face when evaluating complex information systems?

Security Control Assessors often encounter challenges such as rapidly evolving security threats, integrating new technologies, and ensuring compliance with multiple frameworks (like NIST, FISMA, or RMF). Assessing large, interconnected systems requires attention to detail and strong analytical skills to identify vulnerabilities and recommend effective controls. Collaboration with system owners, IT staff, and auditors is essential to obtain comprehensive documentation and clarify system boundaries, which can be a demanding part of the assessment process.

What are the key skills and qualifications needed to thrive as a security control assessor, and why are they important?

To thrive as a Security Control Assessor, you need expertise in information security principles, risk management frameworks like NIST RMF, and a relevant bachelor's degree or equivalent work experience. Familiarity with security assessment tools, compliance management systems, and certifications such as CISSP, CISA, or CAP is typically required. Strong analytical thinking, attention to detail, and effective communication are crucial for evaluating security controls and reporting findings clearly. These skills ensure accurate risk assessments, regulatory compliance, and robust protection of organizational information assets.

What is the difference between Security Control Assessor vs Security Analyst?

AspectSecurity Control AssessorSecurity Analyst
CertificationsRisk Management Framework (RMF), CISSP, CISACISSP, Security+
Work EnvironmentFederal agencies, DoD, government complianceCorporate, cybersecurity teams, IT departments
ResponsibilitiesAssess security controls, ensure compliance, auditMonitor security, analyze threats, implement security measures

The Security Control Assessor primarily evaluates security controls for compliance and risk management, often within government agencies. In contrast, the Security Analyst focuses on monitoring and analyzing security threats to protect organizational assets. While both roles require cybersecurity knowledge and certifications like CISSP, their focus areas and work environments differ significantly.

How much do security control assessors make?

Security Control Assessors in the federal government or related sectors typically earn between $80,000 and $130,000 annually, depending on experience, certifications, and location. Salaries can vary based on agency, level of clearance, and specific responsibilities, with higher pay often associated with specialized skills and certifications like CISSP or CISA.

What are the most commonly searched types of Security Control Assessor jobs in Austin, TX?

The most popular types of Security Control Assessor jobs in Austin, TX are:

What are popular job titles related to Security Control Assessor jobs in Austin, TX?

For Security Control Assessor jobs in Austin, TX, the most frequently searched job titles are:

What job categories do people searching Security Control Assessor jobs in Austin, TX look for?

The top searched job categories for Security Control Assessor jobs in Austin, TX are:

What cities near Austin, TX are hiring for Security Control Assessor jobs?

Cities near Austin, TX with the most Security Control Assessor job openings:

Infographic showing various Security Control Assessor job openings in Austin, TX as of August 2026, with employment types broken down into 1% As Needed, 76% Full Time, 19% Part Time, 3% Contract, and 1% Nights. Highlights an 94% Physical, 1% Hybrid, and 5% Remote job distribution, with an average salary of $121,162 per year, or $58.3 per hour.

Security Compliance Specialist

Austin, TX • On-site

Apexon
IT Services • 5 - 10K employees

Other

Posted 10 days ago


Job description

Job Summary

We are seeking a Security Compliance Specialist with strong experience in cybersecurity compliance, risk management, vulnerability management, and security documentation. The ideal candidate will have advanced knowledge of NIST SP 800-53, System Security Plans (SSPs), Cyber Assessments, and NIST Risk Management Framework (RMF).

The candidate will support State Government client systems by developing and maintaining compliance documentation, conducting security control assessments, supporting ATO activities, managing POA&Ms, and ensuring systems remain audit-ready.

Key Responsibilities
  • Develop, update, and maintain System Security Plans (SSPs) for State Government client systems.
  • Apply NIST SP 800-53, NIST RMF, and related security frameworks such as FedRAMP, StateRAMP, and CJIS.
  • Conduct security control assessments, risk assessments, and gap analyses, mapping findings to applicable compliance requirements.
  • Prepare and maintain privacy and security documentation, including Privacy Impact Assessments (PIAs) and data-handling policies.
  • Support Authorization to Operate (ATO) packages and coordinate with System Owners, ISSOs, auditors, and other stakeholders.
  • Create, track, and maintain Plans of Action and Milestones (POA&Ms) and monitor remediation activities through closure.
  • Maintain audit-ready documentation and evidence repositories for internal and external compliance reviews.
  • Review vulnerability assessment results from tools such as Nessus, Qualys, Tenable, and Veracode.
  • Analyze vulnerability findings, determine risk ratings, and translate findings into appropriate POA&M and remediation activities.
  • Support security compliance documentation for cloud environments, including Azure Government and AWS GovCloud.
  • Use GitHub or similar version-control/collaboration tools to manage documentation changes and work with technical teams.
  • Work closely with Development, IT, Infrastructure, Security, and Project teams to gather system information and maintain accurate compliance documentation.
  • Clearly document security findings, procedures, risks, remediation plans, and compliance requirements for both technical and non-technical stakeholders.
  • Participate in discovery sessions, project meetings, and Agile/Sprint planning to assess compliance and security impacts.
  • Mentor junior team members on security compliance and documentation best practices.
  • Stay current with evolving NIST, cybersecurity, privacy, and compliance frameworks.
  • Leverage AI-assisted tools to research, troubleshoot, and support technical and compliance-related activities.
Required Qualifications
  • Strong professional experience in Cybersecurity, Security Compliance, GRC, or Information Security.
  • Advanced hands-on experience with NIST SP 800-53.
  • Advanced experience developing and maintaining System Security Plans (SSPs).
  • Strong experience with Cybersecurity Assessments and Security Control Assessments.
  • Strong understanding of NIST Risk Management Framework (RMF).
  • Experience with Vulnerability and Patch Management.
  • Experience with POA&M management, risk remediation, and compliance tracking.
  • Experience supporting ATO processes and security authorization packages.
  • Experience with security and privacy documentation, including PIAs.
  • Working knowledge of Cloud Security, preferably Azure Government or AWS GovCloud.
  • Strong technical documentation and communication skills.
  • Ability to work effectively with technical teams, business stakeholders, auditors, ISSOs, and system owners.
Preferred Qualifications
  • Experience supporting State Government / Public Sector cybersecurity programs.
  • Experience with FedRAMP, StateRAMP, and CJIS compliance.
  • Experience with vulnerability management tools such as Nessus, Qualys, Tenable, or Veracode.
  • Experience with GitHub/GitHub Copilot or similar development and collaboration tools.
  • Familiarity with Agile/Scrum environments and participation in sprint planning.
  • Experience mentoring junior security or compliance professionals.
  • Experience working with Azure Government and/or AWS GovCloud environments.