1

Security Control Assessor Jobs in Reston, VA (NOW HIRING)

Security Control Assessor (SCA) LOCATION Tysons, VA 22182 CLEARANCE TS/SCI Full Poly (Please note this position requires full U.S. Citizenship) KEY SUMMARY We are seeking a meticulous and detail ...

Security Control Assessor (SCA) LOCATION Reston, VA 20190 CLEARANCE TS/SCI Full Poly (Please note this position requires full U.S. Citizenship) KEY SUMMARY We are seeking a meticulous and detail ...

Security Control Assessor (SCA) LOCATION Chantilly, VA 20151 CLEARANCE TS/SCI Full Poly (Please note this position requires full U.S. Citizenship) KEY SUMMARY We are seeking a meticulous and detail ...

Security Control Assessor (SCA) LOCATION Tysons, VA 22182 CLEARANCE TS/SCI Full Poly (Please note this position requires full U.S. Citizenship) KEY SUMMARY We are seeking a meticulous and detail ...

Security Control Assessor (SCA) LOCATION Reston, VA 20190 CLEARANCE TS/SCI Full Poly (Please note this position requires full U.S. Citizenship) KEY SUMMARY We are seeking a meticulous and detail ...

POSITION OVERVIEW As a Security Control Assessor, you will play a key role in conducting Security Control Assessments at various government sites, with approximately 85% of your time on travel ...

Security Control Assessor, Junior Conduct independent security control testing and assessments of the management, operational, and technical security controls to determine the overall effectiveness ...

next page

Showing results 1-20

Security Control Assessor information

See Reston, VA salary details

$9

$61

$81

How much do security control assessor jobs pay per hour?

As of Jun 14, 2026, the average hourly pay for security control assessor in Reston, VA is $61.14, according to ZipRecruiter salary data. Most workers in this role earn between $52.50 and $70.77 per hour, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a Security Control Assessor, and why are they important?

To thrive as a Security Control Assessor, you need expertise in information security principles, risk management frameworks like NIST RMF, and a relevant bachelor's degree or equivalent work experience. Familiarity with security assessment tools, compliance management systems, and certifications such as CISSP, CISA, or CAP is typically required. Strong analytical thinking, attention to detail, and effective communication are crucial for evaluating security controls and reporting findings clearly. These skills ensure accurate risk assessments, regulatory compliance, and robust protection of organizational information assets.

What is the difference between Security Control Assessor vs Security Analyst?

AspectSecurity Control AssessorSecurity Analyst
CertificationsRisk Management Framework (RMF), CISSP, CISACISSP, Security+
Work EnvironmentFederal agencies, DoD, government complianceCorporate, cybersecurity teams, IT departments
ResponsibilitiesAssess security controls, ensure compliance, auditMonitor security, analyze threats, implement security measures

The Security Control Assessor primarily evaluates security controls for compliance and risk management, often within government agencies. In contrast, the Security Analyst focuses on monitoring and analyzing security threats to protect organizational assets. While both roles require cybersecurity knowledge and certifications like CISSP, their focus areas and work environments differ significantly.

What are the main challenges Security Control Assessors face when evaluating complex information systems?

Security Control Assessors often encounter challenges such as rapidly evolving security threats, integrating new technologies, and ensuring compliance with multiple frameworks (like NIST, FISMA, or RMF). Assessing large, interconnected systems requires attention to detail and strong analytical skills to identify vulnerabilities and recommend effective controls. Collaboration with system owners, IT staff, and auditors is essential to obtain comprehensive documentation and clarify system boundaries, which can be a demanding part of the assessment process.

What are Security Control Assessors?

Security Control Assessors (SCAs) are professionals responsible for evaluating the security controls of information systems to ensure they meet required standards and regulations. They conduct assessments, document findings, and provide recommendations to help organizations manage risk and achieve compliance with frameworks such as NIST or FISMA. SCAs play a critical role in maintaining the security and integrity of sensitive data by identifying vulnerabilities and verifying that corrective actions are implemented effectively.
What are the most commonly searched types of Security Control Assessor jobs in Reston, VA? The most popular types of Security Control Assessor jobs in Reston, VA are:
What are popular job titles related to Security Control Assessor jobs in Reston, VA? For Security Control Assessor jobs in Reston, VA, the most frequently searched job titles are:
What job categories do people searching Security Control Assessor jobs in Reston, VA look for? The top searched job categories for Security Control Assessor jobs in Reston, VA are:
What cities near Reston, VA are hiring for Security Control Assessor jobs? Cities near Reston, VA with the most Security Control Assessor job openings:
Infographic showing various Security Control Assessor job openings in Reston, VA as of June 2026, with employment types broken down into 78% Full Time, and 22% Contract. Highlights an 49% In-person, and 51% Remote job distribution, with an average salary of $127,169 per year, or $61.1 per hour.

Security Control Assessor (SCA)

Novul Solutions

Arlington, VA

Other

Medical, Dental, Vision, Retirement, PTO

Posted 26 days ago


Job description

Job Description
We are seeking an experienced Security Control Assessor to support the assessment, validation, and authorization of DoD information systems. This role requires a strong background in the Risk Management Framework (RMF) process, security control assessment, and cybersecurity compliance. The ideal candidate will be skilled in evaluating how security controls are implemented, measuring their resilience and reliability, and determining how changes in operational or environmental conditions may affect system security.
Key Responsibilities:
  • Conduct in-depth security control assessments for DoD information systems in accordance with NIST SP 800-53, NIST SP 800-37, DoD RMF, and JSIG requirements.
  • Communicate government-approved mitigation and remediation guidance to system owners in support of the RMF process.
  • Assess and validate the implementation of security controls, including how they support system resilience, reliability, and overall cybersecurity posture.
  • Apply and interpret the Confidentiality, Integrity, and Availability (CIA) triad and related categorization impact levels (High, Moderate, Low) for assigned systems and programs.
  • Validate inherited security controls from hosted, interconnected, or external systems.
  • Evaluate program compliance with controls related to Ports, Protocols, and Services (PP&S), including proper handling, management, and review of log files.
  • Lead the review, preparation, and quality assurance of Authorization to Operate (ATO) packages and supporting documentation.
  • Identify control gaps, document findings, and provide actionable recommendations for remediation.
  • Coordinate with stakeholders, system owners, engineers, and cybersecurity teams to ensure security requirements are properly addressed.
  • Support assessment activities, artifact reviews, interviews, and technical validations required for authorization decisions.
Requirements
  • 8+ years of experience in cybersecurity.
  • 5+ years of experience in Certification and Accreditation (C&A), Assessment and Authorization (A&A), or closely related cybersecurity compliance functions.
  • Demonstrated expertise with the Risk Management Framework (RMF).
  • Strong knowledge of NIST SP 800-37, NIST SP 800-53, and CNSSI 1253.
  • Experience supporting DoD security authorization efforts and control validation activities.
  • Proven ability to review and assess system security documentation for completeness and accuracy.
  • Previous leadership or team lead experience.
  • Strong written and verbal communication skills, with the ability to explain assessment findings and remediation actions to technical and non-technical stakeholders.
  • Bachelor's Degree required.
Benefits
Core Benefits:
  • Paid Time OffPTO):TEN (10) Paid days off & FIVE (5) Floating days off.
  • Holidays: 11 Paid Holidays. Flex time can be utilized instead of holiday time usage.
  • Payroll: Paid Bi-Monthly.
  • 401(k): Partnered with the SECOND LARGEST Retirement plan provider in the U.S. Guaranteed 3% match. Eligibility - 21 years of age or older, after 3 months of employment
  • Individual or company-wide performance and recognition awards (Quarterly
Health Benefits:
  • UNITED HEALTHCARE PPO, extensive national coverage.
  • INCLUDES: Medical/Dental/Vision/HSA.
  • Eligible on the first of the month, immediately after the start date.
  • Submit the enrollment form within 30 days of your start date otherwise, you will have to wait until October for the new year enrollment.
Quality of Life Benefits:
  • Training & Career Development Reimbursement of Tuition and training needed to support career development.
  • $150 monthly reimbursement contribution paid monthly towards parking expenses.
  • Receipts must be submitted by the close of business on the 25th of each month.
  • Reimbursements will be paid on the first payroll AFTER reimbursements are submitted each month.
Special Benefits:
  • Performance bonus - Project-based
  • Yearly bonus - Company based