1

Security Control Assessor Jobs in Reston, VA (NOW HIRING)

Security Control Assessor (SCA) LOCATION Tysons, VA 22182 CLEARANCE TS/SCI Full Poly (Please note this position requires full U.S. Citizenship) KEY SUMMARY We are seeking a meticulous and detail ...

Security Control Assessor (SCA) LOCATIONReston, VA 20190 CLEARANCETS/SCI Full Poly (Please note this position requires full U.S. Citizenship) KEY SUMMARYWe are seeking a meticulous and detail ...

Traveling Security Control Assessor

Alexandria, VA · Hybrid

$87.10K - $157.45K/yr

POSITION OVERVIEW As a Security Control Assessor, you will play a key role in conducting Security Control Assessments at various government sites, with approximately 85% of your time on travel ...

Security Control Assessor (SCA) LOCATION Reston, VA 20190 CLEARANCE TS/SCI Full Poly (Please note this position requires full U.S. Citizenship) KEY SUMMARY We are seeking a meticulous and detail ...

Security Control Assessor (SCA) LOCATION Chantilly, VA 20151 CLEARANCE TS/SCI Full Poly (Please note this position requires full U.S. Citizenship) KEY SUMMARY We are seeking a meticulous and detail ...

Security Control Assessor (SCA) LOCATIONChantilly, VA 20151 CLEARANCETS/SCI Full Poly (Please note this position requires full U.S. Citizenship) KEY SUMMARYWe are seeking a meticulous and detail ...

next page

Showing results 1-20

Security Control Assessor information

See Reston, VA salary details

$9

$62

$82

How much do security control assessor jobs pay per hour?

As of May 31, 2026, the average hourly pay for security control assessor in Reston, VA is $62.11, according to ZipRecruiter salary data. Most workers in this role earn between $53.37 and $71.88 per hour, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a Security Control Assessor, and why are they important?

To thrive as a Security Control Assessor, you need expertise in information security principles, risk management frameworks like NIST RMF, and a relevant bachelor's degree or equivalent work experience. Familiarity with security assessment tools, compliance management systems, and certifications such as CISSP, CISA, or CAP is typically required. Strong analytical thinking, attention to detail, and effective communication are crucial for evaluating security controls and reporting findings clearly. These skills ensure accurate risk assessments, regulatory compliance, and robust protection of organizational information assets.

What are the main challenges Security Control Assessors face when evaluating complex information systems?

Security Control Assessors often encounter challenges such as rapidly evolving security threats, integrating new technologies, and ensuring compliance with multiple frameworks (like NIST, FISMA, or RMF). Assessing large, interconnected systems requires attention to detail and strong analytical skills to identify vulnerabilities and recommend effective controls. Collaboration with system owners, IT staff, and auditors is essential to obtain comprehensive documentation and clarify system boundaries, which can be a demanding part of the assessment process.

What are Security Control Assessors?

Security Control Assessors (SCAs) are professionals responsible for evaluating the security controls of information systems to ensure they meet required standards and regulations. They conduct assessments, document findings, and provide recommendations to help organizations manage risk and achieve compliance with frameworks such as NIST or FISMA. SCAs play a critical role in maintaining the security and integrity of sensitive data by identifying vulnerabilities and verifying that corrective actions are implemented effectively.

What is the difference between Security Control Assessor vs Security Analyst?

AspectSecurity Control AssessorSecurity Analyst
CertificationsRisk Management Framework (RMF), CISSP, CISACISSP, Security+
Work EnvironmentFederal agencies, DoD, government complianceCorporate, cybersecurity teams, IT departments
ResponsibilitiesAssess security controls, ensure compliance, auditMonitor security, analyze threats, implement security measures

The Security Control Assessor primarily evaluates security controls for compliance and risk management, often within government agencies. In contrast, the Security Analyst focuses on monitoring and analyzing security threats to protect organizational assets. While both roles require cybersecurity knowledge and certifications like CISSP, their focus areas and work environments differ significantly.

What are the most commonly searched types of Security Control Assessor jobs in Reston, VA? The most popular types of Security Control Assessor jobs in Reston, VA are:
What are popular job titles related to Security Control Assessor jobs in Reston, VA? For Security Control Assessor jobs in Reston, VA, the most frequently searched job titles are:
What job categories do people searching Security Control Assessor jobs in Reston, VA look for? The top searched job categories for Security Control Assessor jobs in Reston, VA are:
What cities near Reston, VA are hiring for Security Control Assessor jobs? Cities near Reston, VA with the most Security Control Assessor job openings:
Security Control Assessor - Journeyman

Security Control Assessor - Journeyman

SMS Data Products Group, Inc.

Springfield, VA

Full-time

Posted 17 days ago


Job description

SMS is seeking a skilled and detail-oriented Security Control Assessor and Validator to join our team. The successful candidate will be responsible for evaluating, testing, and validating the effectiveness of security controls within our organization's information systems and networks, with a strong emphasis on applying the Risk Management Framework (RMF). 

As a dynamic systems integrator, SMS offers proven solutions in engineering, operations, cybersecurity, and digital transformation. With expertise in modernizing and optimizing legacy infrastructure and systems, ensuring operational efficiency, and designing, implementing, and managing secure environments, SMS supports business and mission goals with proficiency, quality, and integrity.

SMS has been serving the advanced information technology needs of the federal government since 1976, delivering talented teams and innovative, cost-effective solutions and services to support our customers’ missions for more than 40 years. SMS is headquartered in McLean, Virginia, with offices and on-site operations at customer locations throughout the United States. For additional information on SMS, visit www.sms.com.

Submit your resume today.


The Security Control Assessor, you will be responsible for the following:

  • Provide the United States Coast Guard (USCG) with tailored documentation to support their security authorization.
  • Independent assessor for Risk Management Framework Steps 0 to 7.
  • Plan and execute security control assessments for various information systems within the organization.
  • Develop and maintain assessment procedures and methodologies aligned with NIST guidelines and other relevant frameworks.
  • Analyze and evaluate the effectiveness of implemented security controls.
  • Identify vulnerabilities, weaknesses, and potential risks in information systems and infrastructure.
  • Prepare detailed Security Assessment Reports (SARs) documenting findings and recommendations.
  • Collaborate with system owners, ISSOs, and other stakeholders throughout the assessment process.
  • Verify the implementation of remediation actions and conduct follow-up assessments as needed.
  • Provide expert advice on the development and maintenance of System Security Plans (SSPs) and Plans of Action and Milestones (POA&Ms).
  • Stay current with evolving cybersecurity threats, technologies, and best practices.
  • Validate security control implementation and provide test results.
  • Hands-on experience in assessing RMF Step 4 and performing continuous monitoring.
  • Examine security control weaknesses and determine if they are producing the desired intent.
  • Deep understanding of Vulnerability Management practices.

Required Qualifications:

  • Intimate understanding of NIST RMF implementation guidance.
  • Hands-on experience with using eMASS or similar Information Assurance tools.
  • Well-developed understanding of Federal Civilian or DHS Security Assessment and Authorization (SA&A) processes.
  • In-depth understanding of the relevance of NIST Security Controls and Control Implementation methodologies to the SA&A process.
  • Experience analyzing vulnerability scans and STIG implementations.
  • Can demonstrate understanding of critical documentation required in Security Authorization (SA) Packages.
  • Ability to understand and support Privacy Compliance Activities to include the development of Privacy Impact Analysis (PIA), Privacy Threshold Analysis (PTA), and Statement of Record Notices (SORN).
  • At least one of the DOD 8750 IAT II certifications:  CCNA Security, CySA+, GICSP, GSEC, Security + CE, CND, or SSCP.
  • CSSP-AU certification - must obtain within 60days of employment.
  • Knowledge/Familiarity with DoD 8500, DoD 8510, DHS 4300 A and B, NIST SP 800-18, 60, 70, 53, 53A, 137, IACS, CMRS, COAMS, JIMS, Swimlane, Governance, Risk, and Compliance, POA&M (i.e., Management, Assessment, etc.), ERS, FISMA, Knowledge Service, ACAS, Tanium, Power BI, Project/Program Management, TASKORD (i.e., FRAGO, CTO, etc.), and Data Calls (i.e., OIG Audit, etc.) 

Desired Qualifications:

  • Well-developed understanding of Systems Development Lifecycle (SDLC) and ideally the DHS Systems Engineering Lifecycle (SELC) process as it relates to Security Assessment and Authorization (SA&A).
  • Relevant DOD, DHS or .gov Cyber Security Information Assurance focused experience with specific current hands-on experience researching, writing, and submitting complete A&A documentation packages for new system authorizations.

Clearance Requirement:

  • Active DOD Secret security clearance required

Certifications Requirement:

  • IAT Level II: Security+ CE, CySA+, CCNA Security, GICSP, GSEC, CND, SSCP
  • CSSP-AU: CEH, CySA+, CISA, PenTest+, GSNA, CFR . Within 60 days of hire. 

SMS is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.