1

Security Control Assessor Jobs in Hanover, MD (NOW HIRING)

Security Control Accessor

Washington, DC · On-site

$100K - $130K/yr

The Security Control Assessor will serve as an independent technical evaluator responsible for planning, executing, and reporting on security and privacy controls assessments for assigned systems and ...

The Security Control Assessor will serve as an independent technical evaluator responsible for planning, executing, and reporting on security and privacy controls assessments for assigned systems and ...

The Security Control Assessor will serve as an independent technical evaluator responsible for planning, executing, and reporting on security and privacy controls assessments for assigned systems and ...

... is a senior security-control assessor responsible for conducting independent assessments of federal information systems. This position leads technical and compliance assessments, tests the ...

Showing results 41-60

Security Control Assessor information

See Hanover, MD salary details

$8

$58

$77

How much do security control assessor jobs pay per hour?

As of Sep 6, 2026, the average hourly pay for security control assessor in Hanover, MD is $58.47, according to ZipRecruiter salary data. Most workers in this role earn between $50.24 and $67.69 per hour, depending on experience, location, and employer.

What is a security control assessor?

Security Control Assessors (SCAs) are professionals responsible for evaluating the security controls of information systems to ensure they meet required standards and regulations. They conduct assessments, document findings, and provide recommendations to help organizations manage risk and achieve compliance with frameworks such as NIST or FISMA. SCAs play a critical role in maintaining the security and integrity of sensitive data by identifying vulnerabilities and verifying that corrective actions are implemented effectively.

What are the main challenges security control assessors face when evaluating complex information systems?

Security Control Assessors often encounter challenges such as rapidly evolving security threats, integrating new technologies, and ensuring compliance with multiple frameworks (like NIST, FISMA, or RMF). Assessing large, interconnected systems requires attention to detail and strong analytical skills to identify vulnerabilities and recommend effective controls. Collaboration with system owners, IT staff, and auditors is essential to obtain comprehensive documentation and clarify system boundaries, which can be a demanding part of the assessment process.

What are the key skills and qualifications needed to thrive as a security control assessor, and why are they important?

To thrive as a Security Control Assessor, you need expertise in information security principles, risk management frameworks like NIST RMF, and a relevant bachelor's degree or equivalent work experience. Familiarity with security assessment tools, compliance management systems, and certifications such as CISSP, CISA, or CAP is typically required. Strong analytical thinking, attention to detail, and effective communication are crucial for evaluating security controls and reporting findings clearly. These skills ensure accurate risk assessments, regulatory compliance, and robust protection of organizational information assets.

What is the difference between Security Control Assessor vs Security Analyst?

AspectSecurity Control AssessorSecurity Analyst
CertificationsRisk Management Framework (RMF), CISSP, CISACISSP, Security+
Work EnvironmentFederal agencies, DoD, government complianceCorporate, cybersecurity teams, IT departments
ResponsibilitiesAssess security controls, ensure compliance, auditMonitor security, analyze threats, implement security measures

The Security Control Assessor primarily evaluates security controls for compliance and risk management, often within government agencies. In contrast, the Security Analyst focuses on monitoring and analyzing security threats to protect organizational assets. While both roles require cybersecurity knowledge and certifications like CISSP, their focus areas and work environments differ significantly.

How much do security control assessors make?

Security Control Assessors in the federal government or related sectors typically earn between $80,000 and $130,000 annually, depending on experience, certifications, and location. Salaries can vary based on agency, level of clearance, and specific responsibilities, with higher pay often associated with specialized skills and certifications like CISSP or CISA.

What are popular job titles related to Security Control Assessor jobs in Hanover, MD?

For Security Control Assessor jobs in Hanover, MD, the most frequently searched job titles are:

What job categories do people searching Security Control Assessor jobs in Hanover, MD look for?

The top searched job categories for Security Control Assessor jobs in Hanover, MD are:

What cities near Hanover, MD are hiring for Security Control Assessor jobs?

Cities near Hanover, MD with the most Security Control Assessor job openings:

Infographic showing various Security Control Assessor job openings in Hanover, MD as of August 2026, with employment types broken down into 1% As Needed, 76% Full Time, 18% Part Time, 1% Temporary, 3% Contract, and 1% Nights. Highlights an 94% Physical, 1% Hybrid, and 5% Remote job distribution, with an average salary of $121,625 per year, or $58.5 per hour.

Security Control Assessor - TS/SCI with Polygraph

General Dynamics Information Technology

Bethesda, MD • On-site

$142K - $187K/yr

Full-time

Retirement, PTO

Posted 9 days ago


Key responsibilities

  • Conduct Security Control Assessments of IC information systems, evaluating Zero Trust maturity across various domains.

  • Review and validate technical evidence of Zero Trust capability implementation and distinguish verified controls from self-reported claims.

  • Communicate assessment results to technical teams and executive stakeholders.


General Dynamics Information Technology rating

7.8

Company rating: 7.8 out of 10

Based on 63 frontline employees who took The Breakroom Quiz

89th of 226 rated it services


Job description

Share
REQ#: RQ227263Public Trust: None Requisition Type: Regular Your Impact

Own your opportunity to serve as a critical component of our nations safety and security. Make an impact by using your expertise to protect our country from threats.

Job Description

OWN YOUR OPPORTUNITY
Explore a career in cyber at GDIT and youll find endless opportunities to grow alongside colleagues who share your focus on defending and protecting what matters.

Advance your career while impacting our national security in cyber as a Security Control Assessor (Zero Trust Architect Principal) at GDIT. Here, technologists have many paths to grow a meaningful career supporting cyber missions and operations across the federal government.
MEANINGFUL WORK AND PERSONAL IMPACT

  • Conduct Security Control Assessments of IC information systems, with specialized expertise evaluating Zero Trust maturity across identity, device, network, application, data, and analytics domains.
  • Review and validate technical evidence of Zero Trust capability implementation, distinguishing verified, testable controls from self-reported claims.
  • Apply hands-on technical knowledge of identity/access management, network segmentation, endpoint detection, data protection, and security monitoring to assess real-world implementation maturity.
  • Identify capability gaps and documents risk-based findings that hold up to senior leadership review.
  • Communicates assessment results clearly to both technical teams and executive stakeholders.
  • Stays current on Zero Trust architecture standards and evolving assessment methodologies.

WHAT YOULL NEED TO SUCCEED

  • Bachelors degree in computer engineering, Computer Science, Electrical Engineering, Information systems, Information Technology, Cybersecurity, or a closely related discipline.
  • Four (4) years of additional demonstrated work experience in Security Control Assessor (SCA) and Defensive Cyber Operations (DCO)Testing will be accepted in lieu of a bachelors degree.
  • A Masters degree in an applicable discipline be substituted for three years of demonstrated work experience
  • Three (3) years of cybersecurity experience with at least one year of experience conducting SCAs under ICD 503/CNSSI 1253 NIST Cybersecurity Framework, Risk Management Framework (RMF), or a similar framework.
  • One full year of SCA experiences within the last three calendar years.
  • One full year supporting cloud environment and experience performing security assessments in a cloud environment (AWS, Google, IBM, Azure, and Oracle).
  • Must meet Department of War (DOW) 8570.01-M baseline certification requirement for Information Assurances Technical (IAT) Level III CASP+CE, CCNP Security, CISA, or CISSP or Associate, GCED, GCIH, or CCSP.
  • Knowledge of Independent Verification & Validation (IV&V) of security controls.
  • Knowledge of general attack strategies (e.g., MITRE ATT&CK Framework).
  • Knowledge of NISPOM, ICD 503, NIST SP 800-53, ICD 705, and other ICDs as appropriate.
  • Skill in conducting vulnerability scans and recognizing vulnerability in security systems (e.g., Cloud Environments) ASW, Google, IBM, Azure, and Oracle.
  • Make recommendations to the IC CISO or designee for improving TTPS for better cyber threat protection.
  • Clearance: TS/SCI with Polygraph

GDIT IS YOUR PLACE

  • At GDIT, the mission is our purpose, and our people are at the center of everything we do.
  • Growth: AI-powered career tool that identifies career steps and learning opportunities
  • Support: An internal mobility team focused on helping you achieve your career goals
  • Rewards: Comprehensive benefits and wellness packages, 401K with company match, and competitive pay and paid time off
  • Community: Award-winning culture of innovation and a military-friendly workplace

#WeAreGDIT
#JET
#VA_2026Alumni

Work Requirements
Years of Experience

8 + years of related experience

* may vary based on technical training, certification(s), or degree

Certification
Travel Required

Less than 10%

Citizenship

U.S. Citizenship Required

Salary and Benefit Information

The likely salary range for this position is $142,792 - $187,709. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.
View information about benefits and our total rewards program.

Our Identity Verification Process

As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during virtual interviews. We reserve the right to take your picture to verify your identity and prevent fraud. By proceeding, you authorize the collection, processing, and use of your biometric data for identity verification and security purposes.

About Our Work

We are GDIT. A global technology and professional services company that delivers technology solutions and mission services to every major agency across the U.S. government, defense and intelligence community. Our 26,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. We operate across 50+ countries worldwide, offering leading mission-ready capabilities in AI, cloud, cyber and software development.

Join our Talent Community to stay up to date on our career opportunities and events at gdit.com/tc.

Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans


What General Dynamics Information Technology employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


General Dynamics Information Technology logo

About General Dynamics Information Technology

Sourced by ZipRecruiter

GDIT is a global technology and professional services company that delivers technology solutions and mission services to every major agency across the U.S. government, defense, and intelligence community. Its 30,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. The company operates across 50+ countries worldwide, offering leading capabilities in digital modernization, AI/ML, cloud, cyber, and application development.

Industry

It services

Company size

10,000+ Employees

Headquarters location

Falls Church, VA, US