1

Security Control Assessor Jobs in Hanover, MD (NOW HIRING)

Responsibilities Peraton is seeking a Security Control Assessor in our Linthicum, MD office in support of our Department of Defense (DoD) customer as part of a highly talented, highly motivated, and ...

Responsibilities Peraton is seeking a Security Control Assessor in our Linthicum, MD office in support of our Department of Defense (DoD) customer as part of a highly talented, highly motivated, and ...

Security Control Assessor

Linthicum, MD · On-site

$135K - $216K/yr

Responsibilities Peraton is seeking a Security Control Assessor in our Linthicum, MD office in support of our Department of Defense (DoD) customer as part of a highly talented, highly motivated, and ...

You'll work under a senior assessor and help evaluate security control implementation, validate evidence, and document results in alignment with NIST Risk Management Framework (RMF) and NIST SP 800 ...

You'll work under a senior assessor and help evaluate security control implementation, validate evidence, and document results in alignment with NIST Risk Management Framework (RMF) and NIST SP 800 ...

You'll work under a senior assessor and help evaluate security control implementation, validate evidence, and document results in alignment with NIST Risk Management Framework (RMF) and NIST SP 800 ...

You'll work under a senior assessor and help evaluate security control implementation, validate evidence, and document results in alignment with NIST Risk Management Framework (RMF) and NIST SP 800 ...

You'll work under a senior assessor and help evaluate security control implementation, validate evidence, and document results in alignment with NIST Risk Management Framework (RMF) and NIST SP 800 ...

You'll work under a senior assessor and help evaluate security control implementation, validate evidence, and document results in alignment with NIST Risk Management Framework (RMF) and NIST SP 800 ...

You'll work under a senior assessor and help evaluate security control implementation, validate evidence, and document results in alignment with NIST Risk Management Framework (RMF) and NIST SP 800 ...

You'll work under a senior assessor and help evaluate security control implementation, validate evidence, and document results in alignment with NIST Risk Management Framework (RMF) and NIST SP 800 ...

next page

Showing results 1-20

Security Control Assessor information

See Hanover, MD salary details

$8

$58

$77

How much do security control assessor jobs pay per hour?

As of Sep 4, 2026, the average hourly pay for security control assessor in Hanover, MD is $58.47, according to ZipRecruiter salary data. Most workers in this role earn between $50.24 and $67.69 per hour, depending on experience, location, and employer.

What is a security control assessor?

Security Control Assessors (SCAs) are professionals responsible for evaluating the security controls of information systems to ensure they meet required standards and regulations. They conduct assessments, document findings, and provide recommendations to help organizations manage risk and achieve compliance with frameworks such as NIST or FISMA. SCAs play a critical role in maintaining the security and integrity of sensitive data by identifying vulnerabilities and verifying that corrective actions are implemented effectively.

What are the main challenges security control assessors face when evaluating complex information systems?

Security Control Assessors often encounter challenges such as rapidly evolving security threats, integrating new technologies, and ensuring compliance with multiple frameworks (like NIST, FISMA, or RMF). Assessing large, interconnected systems requires attention to detail and strong analytical skills to identify vulnerabilities and recommend effective controls. Collaboration with system owners, IT staff, and auditors is essential to obtain comprehensive documentation and clarify system boundaries, which can be a demanding part of the assessment process.

What are the key skills and qualifications needed to thrive as a security control assessor, and why are they important?

To thrive as a Security Control Assessor, you need expertise in information security principles, risk management frameworks like NIST RMF, and a relevant bachelor's degree or equivalent work experience. Familiarity with security assessment tools, compliance management systems, and certifications such as CISSP, CISA, or CAP is typically required. Strong analytical thinking, attention to detail, and effective communication are crucial for evaluating security controls and reporting findings clearly. These skills ensure accurate risk assessments, regulatory compliance, and robust protection of organizational information assets.

What is the difference between Security Control Assessor vs Security Analyst?

AspectSecurity Control AssessorSecurity Analyst
CertificationsRisk Management Framework (RMF), CISSP, CISACISSP, Security+
Work EnvironmentFederal agencies, DoD, government complianceCorporate, cybersecurity teams, IT departments
ResponsibilitiesAssess security controls, ensure compliance, auditMonitor security, analyze threats, implement security measures

The Security Control Assessor primarily evaluates security controls for compliance and risk management, often within government agencies. In contrast, the Security Analyst focuses on monitoring and analyzing security threats to protect organizational assets. While both roles require cybersecurity knowledge and certifications like CISSP, their focus areas and work environments differ significantly.

How much do security control assessors make?

Security Control Assessors in the federal government or related sectors typically earn between $80,000 and $130,000 annually, depending on experience, certifications, and location. Salaries can vary based on agency, level of clearance, and specific responsibilities, with higher pay often associated with specialized skills and certifications like CISSP or CISA.

What are popular job titles related to Security Control Assessor jobs in Hanover, MD?

For Security Control Assessor jobs in Hanover, MD, the most frequently searched job titles are:

What job categories do people searching Security Control Assessor jobs in Hanover, MD look for?

The top searched job categories for Security Control Assessor jobs in Hanover, MD are:

What cities near Hanover, MD are hiring for Security Control Assessor jobs?

Cities near Hanover, MD with the most Security Control Assessor job openings:

Infographic showing various Security Control Assessor job openings in Hanover, MD as of August 2026, with employment types broken down into 1% As Needed, 76% Full Time, 18% Part Time, 1% Temporary, 3% Contract, and 1% Nights. Highlights an 94% Physical, 1% Hybrid, and 5% Remote job distribution, with an average salary of $121,625 per year, or $58.5 per hour.

Security Control Assessor

Peraton

Linthicum, MD • On-site

Full-time

Posted 10 days ago


Peraton rating

8.3

Company rating: 8.3 out of 10

Based on 56 frontline employees who took The Breakroom Quiz

52nd of 226 rated it services


Job description

Responsibilities

Peraton is seeking a Security Control Assessor in our Linthicum, MD office in support of our Department of Defense (DoD) customer as part of a highly talented, highly motivated, and high-performing team. This position offers a unique opportunity to work at the forefront of cyber investigations, digital forensics, cyber threat analysis, and mission support in a dynamic and collaborative environment. The successful candidate will contribute to protecting national security interests by leveraging technical expertise, analytical skills, and innovative problem-solving to address complex cyber challenges. Individuals who are passionate about cybersecurity, committed to excellence, and eager to make a meaningful impact are encouraged to apply.

In this role you will accomplish the following:

  • Conduct assessments and facilitate risk mitigation planning.
  • Provide Assessment and Authorization (A&A) for the ARCYBER cloud infrastructure.
  • Execute a security control assessment plan and update the System Security Plan.
  • Review vulnerability scans and remediation.
  • Implement risk management programs by utilizing NIST, FISMA, HIPAA, and PII -- and document solutions.
  • Monitor the privacy landscape regarding all data (privacy, protection, classification, and residency).
  • Assist clients with identifying gaps within existing privacy programs and designing solutions to help address those challenges.
  • Scan, test, and validate systems/networks/applications to obtain/maintain an ATO under NIST/FISMA guidelines.
Qualifications

Required Qualifications:

  • Bachelor's degree and 8+ years of experience, or Master's and 6+ years of experience, or PhD and 3+ years of experience. A degree in one of the following fields of study is highly desired: Information Technology, Computer Science, Cybersecurity, Information Systems, Software Engineering, or Data Science. An additional 4 years of experience or specialized training may be considered in lieu of Bachelor's degree.
  • Active TS clearance with SCI eligibility.
  • Active CompTIA Security+ certification.
  • Active IAM level III certification (such as CISM).
  • Must have knowledge of enterprise solutions across multiple cloud operating environments (JWICS, SIPRNET, NIPRNET, and commercial Internet).
  • Must have eMASS, ACAS, and ISC2 Certified Cloud Computing Professional (CCSP) or CompTIA Cloud+ experience.
  • Must have knowledge in the following areas:
    • Knowledge of computer networking and/or cloud computing concepts and protocols, and network security methodologies.
    • Knowledge of cyber threats and vulnerabilities in a virtualized environment.
    • Knowledge of national and international laws, regulations, policies, and ethics as they relate to cybersecurity.
    • Knowledge of risk management framework processes (e.g., methods for assessing and mitigating risk).
    • Knowledge of specific operational impacts of cybersecurity lapses.
    • Knowledge of industry methods for evaluating, implementing, and disseminating Information Technology (IT) security assessment, monitoring, detection, and remediation tools and procedures using standards-based concepts and capabilities.
    • Knowledge of cyber defense and vulnerability assessment tools, including opensource tools, and their capabilities.
    • Knowledge of cybersecurity principles and organizational requirements (relevant to confidentiality, integrity, availability, authentication, non-repudiation).
    • Knowledge of cybersecurity principles used to manage risks related to the use, processing, storage, and transmission of information or data in a cloud environment.
    • Knowledge of IT and cloud computing security principles and methods (e.g., firewalls, demilitarized zones, encryption).
    • Knowledge of known vulnerabilities from alerts, advisories, errata, and bulletins.
    • Knowledge of network and/or cloud computing environment security architecture concepts including topology, protocols, components, and principles (e.g., application of defense-in-depth).
    • Knowledge of penetration testing principles, tools, and techniques..
    • Knowledge of system and application security threats and vulnerabilities (e.g., buffer overflow, mobile code, cross-site scripting, Procedural Language/Structured Query Language [PL/SQL] and injections, race conditions, covert channel, replay, returnoriented attacks, malicious code).
    • Knowledge of the Security Assessment and Authorization process.
    • Skill in determining how a security and/or cloud computing security system should work (including its resilience and dependability capabilities) and how changes in conditions, operations, or the environment will affect these outcomes.
    • Skill in discerning the protection needs (i.e., security controls) of information systems and networks and those relating to cloud computing.
    • Knowledge of local specialized system requirements (e.g., critical infrastructure systems that may not use standard IT) for safety, performance, and reliability.
    • Knowledge of new and emerging IT and cybersecurity technologies and/or those technologies specific to cloud computing.
Peraton Overview

Peraton is a next-generation national security company that drives missions of consequence spanning the globe and extending to the farthest reaches of the galaxy. As the world's leading mission capability integrator and transformative enterprise IT provider, we deliver trusted, highly differentiated solutions and technologies to protect our nation and allies. Peraton operates at the critical nexus between traditional and nontraditional threats across all domains: land, sea, space, air, and cyberspace. The company serves as a valued partner to essential government agencies and supports every branch of the U.S. armed forces. Each day, our employees do the can't be done by solving the most daunting challenges facing our customers. Visit peraton.com to learn how we're keeping people around the world safe and secure.

Target Salary Range$135,000 - $216,000. This represents the typical salary range for this position. Salary is determined by various factors, including but not limited to, the scope and responsibilities of the position, the individual's experience, education, knowledge, skills, and competencies, as well as geographic location and business and contract considerations. Depending on the position, employees may be eligible for overtime, shift differential, and a discretionary bonus in addition to base pay.EEOEEO: Equal opportunity employer, including disability and protected veterans, or other characteristics protected by law.Employment Type: FULL_TIME

What Peraton employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


Peraton logo

About Peraton

Sourced by ZipRecruiter

At Peraton, we re at the forefront of delivering the next big thing every day. We re the partner of choice to help solve some of the world s most daunting challenges, delivering bold, new solutions to keep people around the world safer and more secure.

Industry

It services

Company size

10,000+ Employees

Headquarters location

Herndon, VA, US

Year founded

2017