1

Security Control Assessor Jobs in Silver Spring, MD

You'll work under a senior assessor and help evaluate security control implementation, validate evidence, and document results in alignment with NIST Risk Management Framework (RMF) and NIST SP 800 ...

You'll work under a senior assessor and help evaluate security control implementation, validate evidence, and document results in alignment with NIST Risk Management Framework (RMF) and NIST SP 800 ...

You'll work under a senior assessor and help evaluate security control implementation, validate evidence, and document results in alignment with NIST Risk Management Framework (RMF) and NIST SP 800 ...

You'll work under a senior assessor and help evaluate security control implementation, validate evidence, and document results in alignment with NIST Risk Management Framework (RMF) and NIST SP 800 ...

You'll work under a senior assessor and help evaluate security control implementation, validate evidence, and document results in alignment with NIST Risk Management Framework (RMF) and NIST SP 800 ...

Security Control Assessor (SCA) LOCATION Chantilly, VA 20151 CLEARANCE TS/SCI Full Poly (Please note this position requires full U.S. Citizenship) KEY SUMMARY We are seeking a meticulous and detail ...

Security Control Assessor

Arlington, VA · On-site

$110K - $130K/yr

Security Control AssessorLocation: Arlington, VA (On-Site)Citizenship: US onlyClearance: Active TS/SCI (DHS EOD Suitability required)Company: Argo Cyber Systems, LLC - Service-Disabled Veteran-Owned ...

Showing results 21-40

Security Control Assessor information

See Silver Spring, MD salary details

$9

$60

$80

How much do security control assessor jobs pay per hour?

As of Aug 15, 2026, the average hourly pay for security control assessor in Silver Spring, MD is $60.75, according to ZipRecruiter salary data. Most workers in this role earn between $52.16 and $70.34 per hour, depending on experience, location, and employer.

How much do security control assessors make?

Security Control Assessors in the federal government or related sectors typically earn between $80,000 and $130,000 annually, depending on experience, certifications, and location. Salaries can vary based on agency, level of clearance, and specific responsibilities, with higher pay often associated with specialized skills and certifications like CISSP or CISA.

What are the key skills and qualifications needed to thrive as a security control assessor, and why are they important?

To thrive as a Security Control Assessor, you need expertise in information security principles, risk management frameworks like NIST RMF, and a relevant bachelor's degree or equivalent work experience. Familiarity with security assessment tools, compliance management systems, and certifications such as CISSP, CISA, or CAP is typically required. Strong analytical thinking, attention to detail, and effective communication are crucial for evaluating security controls and reporting findings clearly. These skills ensure accurate risk assessments, regulatory compliance, and robust protection of organizational information assets.

What is the difference between Security Control Assessor vs Security Analyst?

AspectSecurity Control AssessorSecurity Analyst
CertificationsRisk Management Framework (RMF), CISSP, CISACISSP, Security+
Work EnvironmentFederal agencies, DoD, government complianceCorporate, cybersecurity teams, IT departments
ResponsibilitiesAssess security controls, ensure compliance, auditMonitor security, analyze threats, implement security measures

The Security Control Assessor primarily evaluates security controls for compliance and risk management, often within government agencies. In contrast, the Security Analyst focuses on monitoring and analyzing security threats to protect organizational assets. While both roles require cybersecurity knowledge and certifications like CISSP, their focus areas and work environments differ significantly.

What are the main challenges security control assessors face when evaluating complex information systems?

Security Control Assessors often encounter challenges such as rapidly evolving security threats, integrating new technologies, and ensuring compliance with multiple frameworks (like NIST, FISMA, or RMF). Assessing large, interconnected systems requires attention to detail and strong analytical skills to identify vulnerabilities and recommend effective controls. Collaboration with system owners, IT staff, and auditors is essential to obtain comprehensive documentation and clarify system boundaries, which can be a demanding part of the assessment process.

What is a security control assessor?

Security Control Assessors (SCAs) are professionals responsible for evaluating the security controls of information systems to ensure they meet required standards and regulations. They conduct assessments, document findings, and provide recommendations to help organizations manage risk and achieve compliance with frameworks such as NIST or FISMA. SCAs play a critical role in maintaining the security and integrity of sensitive data by identifying vulnerabilities and verifying that corrective actions are implemented effectively.

What are the most commonly searched types of Security Control Assessor jobs in Silver Spring, MD?

The most popular types of Security Control Assessor jobs in Silver Spring, MD are:

What are popular job titles related to Security Control Assessor jobs in Silver Spring, MD?

For Security Control Assessor jobs in Silver Spring, MD, the most frequently searched job titles are:

What job categories do people searching Security Control Assessor jobs in Silver Spring, MD look for?

The top searched job categories for Security Control Assessor jobs in Silver Spring, MD are:

What cities near Silver Spring, MD are hiring for Security Control Assessor jobs?

Cities near Silver Spring, MD with the most Security Control Assessor job openings:

Infographic showing various Security Control Assessor job openings in Silver Spring, MD as of August 2026, with employment types broken down into 1% As Needed, 73% Full Time, 21% Part Time, 4% Contract, and 1% Nights. Highlights an 96% Physical, 1% Hybrid, and 3% Remote job distribution, with an average salary of $126,365 per year, or $60.8 per hour.

Contractor

Re-posted 6 days ago


Job description

Position Overview

A Cybersecurity Subject Matter Expert provides expert-level cybersecurity analysis, engineering, and assessment services for complex, multi-domain systems. This role acts as a senior technical advisor and Security Control Assessor (SCA), specializing in integrating security throughout the system lifecycle, translating technical risks into mission-impact statements, and guiding the implementation of advanced security architectures.

Principal Duties and Responsibilities:

  • Provides strategic cybersecurity guidance and participates in technical reviews (e.g., SRR, PDR, CDR) to ensure security is integrated from the initial design phase and throughout the system development lifecycle.
  • Executes the Risk Management Framework (RMF) process, providing risk determinations and recommendations to the Authorizing Official (AO).
  • As a Security Control Assessor (SCA), executes the Risk Management Framework (RMF) process across Federal, DoD, and IC policies. Provides continuous risk determinations and actionable recommendations directly to the Authorizing Official (AO).
  • Conducts deep technical validation of security controls by reviewing vulnerability scans (e.g., ACAS/Nessus), STIG checklists, and penetration test reports to correlate findings with operational mission risk.
  • Evaluates the security performance, integrity, and residual risk of diverse and complex architectures, including Platform Information Technology (PIT), cloud environments, communication networks, and satellite control systems.
  • Guides the adoption and implementation of DoD Zero Trust principles and provides specialized expertise in the design and evaluation of Cross Domain Solutions (CDS).
  • Functions as a technical liaison between engineering teams, program leadership, and external government and industry partners.

Required Skills (Knowledge, Skills, Abilities):

  • Requires a minimum of twelve (12) years of demonstrated experience in IT, cybersecurity engineering, and/or Assessment & Authorization (A&A).
  • Certification:Must hold a current certification compliant with DoD 8140.01 for IAT Level III or IAM Level III (e.g., CISSP, CISM, GSLC, CASP+ CE).
  • Technical Expertise:Must have proven hands-on experience with systems integration, enterprise networks, cloud computing systems, or Platform IT architectures.
  • Ample experience with Special Access Program (SAP) and Sensitive Compartmentalized Information (SCI) Systems preferred.

Travel Requirements

  • Some travel is required for this position.
  • Ability to travel to CONUS and/or OCONUS locations
  • Must have active US passport for OCONUS travel requirements

Clearance

  • Clearance:Must possess an active Top-Secret clearance with eligibility for SCI and SAP access.

Additional Information

  • This job description is not designed to cover or contain all job duties required of the employee. There may be additional activities, duties and/or responsibilities that are required for this position that are not listed in this job description.
  • In compliance with federal law, all persons hired will be required to verify identity and eligibility to work in the United States and to complete the required employment eligibility verification document form upon hire.
  • System High is a Military friendly employer. Our extensive work on behalf of the U.S. government offers those who have served in uniform an opportunity to continue to serve their country in a new and exciting way while enjoying a successful civilian career.
  • System High values the power and strength of diverse backgrounds on the culture and performance of our company. We strive to maintain an inclusive culture to encourage each employee to bring their whole self to the mission.
  • System High Corporation is committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender, gender identity or expression, veteran status, or any other characteristic protected by law. We are proud to be an equal opportunity workplace.
  • If you require a reasonable accommodation to apply for a position with us, please emailrecruiting@systemhigh.com.
  • Legal notices can be viewed on the following PDFs:Know Your Rights: Workplace Discrimination is Illegal;EPPA Notice;FMLA Notice

Warning:Beware of recruitment scams: System High will never request money or personal purchases during the hiring process. Verify all communications come from a systemhigh.com or msg.paycomonline.com email address.