1

Security Control Assessor Jobs in Springfield, VA

Job#: 3044387 Security Control Assessor Location: Alexandria, Virginia (Onsite) Role Overview We are seeking a skilled and detail-oriented Security Control Assessor to join our team. The successful ...

Security Control Assessor

Arlington, VA ยท On-site

$140K - $160K/yr

Security Control Assessor Location: On Site in Arlington, VA Department: Cyber Security Services Reports To: Management FLSA Status: Full Time/Non-exempt Job Purpose: The security control assessor ...

Security Control Assessor

Arlington, VA ยท On-site

$140K - $160K/yr

Security Control Assessor Location: On Site in Arlington, VA Department: Cyber Security Services Reports To: Management FLSA Status: Full Time/Non-exempt Job Purpose: The security control assessor ...

Security Control Assessor

Alexandria, VA ยท On-site

$137K - $152K/yr

M9 Solutions is seeking a Security Control Assessor to work on-site in support of a government contract for a client located in Alexandria, VA . An active Secret clearance is required.

Security Control Assessor

Alexandria, VA ยท On-site

$137K - $152K/yr

M9 Solutions is seeking a Security Control Assessor to work on-site in support of a government contract for a client located in Alexandria, VA . An active Secret clearance is required.

Execute a security control assessment plan and update the System Security Plan * Review vulnerability scans and remediation * Implement risk management programs by utilizing NIST, FISMA, HIPAA, and ...

Security Control Assessor

Alexandria, VA ยท On-site

$146K - $234K/yr

Execute a security control assessment plan and update the System Security Plan * Review vulnerability scans and remediation * Implement risk management programs by utilizing NIST, FISMA, HIPAA, and ...

Execute a security control assessment plan and update the System Security Plan * Review vulnerability scans and remediation * Implement risk management programs by utilizing NIST, FISMA, HIPAA, and ...

Junior Security Control Assessor

Bethesda, MD ยท Remote

$100K - $115K/yr

You'll work under a senior assessor and help evaluate security control implementation, validate evidence, and document results in alignment with NIST Risk Management Framework (RMF) and NIST SP 800 ...

Senior Security Control Assessor

Arlington, VA ยท On-site

$130K - $150K/yr

Senior Security Control Assessor Overview: TSA is currently seeking a Senior Security Control Assessor who will serve as a Functional Lead and provide support to our NAVAIR customer in the DC Metro ...

Junior Security Control Assessor

Bethesda, MD ยท Remote

$100K - $115K/yr

You'll work under a senior assessor and help evaluate security control implementation, validate evidence, and document results in alignment with NIST Risk Management Framework (RMF) and NIST SP 800 ...

next page

Showing results 1-20

Security Control Assessor information

See Springfield, VA salary details

$9

$61

$81

How much do security control assessor jobs pay per hour?

As of Sep 2, 2026, the average hourly pay for security control assessor in Springfield, VA is $61.38, according to ZipRecruiter salary data. Most workers in this role earn between $52.74 and $71.06 per hour, depending on experience, location, and employer.

What is a security control assessor?

Security Control Assessors (SCAs) are professionals responsible for evaluating the security controls of information systems to ensure they meet required standards and regulations. They conduct assessments, document findings, and provide recommendations to help organizations manage risk and achieve compliance with frameworks such as NIST or FISMA. SCAs play a critical role in maintaining the security and integrity of sensitive data by identifying vulnerabilities and verifying that corrective actions are implemented effectively.

What are the main challenges security control assessors face when evaluating complex information systems?

Security Control Assessors often encounter challenges such as rapidly evolving security threats, integrating new technologies, and ensuring compliance with multiple frameworks (like NIST, FISMA, or RMF). Assessing large, interconnected systems requires attention to detail and strong analytical skills to identify vulnerabilities and recommend effective controls. Collaboration with system owners, IT staff, and auditors is essential to obtain comprehensive documentation and clarify system boundaries, which can be a demanding part of the assessment process.

What are the key skills and qualifications needed to thrive as a security control assessor, and why are they important?

To thrive as a Security Control Assessor, you need expertise in information security principles, risk management frameworks like NIST RMF, and a relevant bachelor's degree or equivalent work experience. Familiarity with security assessment tools, compliance management systems, and certifications such as CISSP, CISA, or CAP is typically required. Strong analytical thinking, attention to detail, and effective communication are crucial for evaluating security controls and reporting findings clearly. These skills ensure accurate risk assessments, regulatory compliance, and robust protection of organizational information assets.

What is the difference between Security Control Assessor vs Security Analyst?

AspectSecurity Control AssessorSecurity Analyst
CertificationsRisk Management Framework (RMF), CISSP, CISACISSP, Security+
Work EnvironmentFederal agencies, DoD, government complianceCorporate, cybersecurity teams, IT departments
ResponsibilitiesAssess security controls, ensure compliance, auditMonitor security, analyze threats, implement security measures

The Security Control Assessor primarily evaluates security controls for compliance and risk management, often within government agencies. In contrast, the Security Analyst focuses on monitoring and analyzing security threats to protect organizational assets. While both roles require cybersecurity knowledge and certifications like CISSP, their focus areas and work environments differ significantly.

How much do security control assessors make?

Security Control Assessors in the federal government or related sectors typically earn between $80,000 and $130,000 annually, depending on experience, certifications, and location. Salaries can vary based on agency, level of clearance, and specific responsibilities, with higher pay often associated with specialized skills and certifications like CISSP or CISA.

What are the most commonly searched types of Security Control Assessor jobs in Springfield, VA?

The most popular types of Security Control Assessor jobs in Springfield, VA are:

What are popular job titles related to Security Control Assessor jobs in Springfield, VA?

For Security Control Assessor jobs in Springfield, VA, the most frequently searched job titles are:

What job categories do people searching Security Control Assessor jobs in Springfield, VA look for?

The top searched job categories for Security Control Assessor jobs in Springfield, VA are:

What cities near Springfield, VA are hiring for Security Control Assessor jobs?

Cities near Springfield, VA with the most Security Control Assessor job openings:

Infographic showing various Security Control Assessor job openings in Springfield, VA as of August 2026, with employment types broken down into 1% As Needed, 72% Full Time, 23% Part Time, 3% Contract, and 1% Nights. Highlights an 94% Physical, 1% Hybrid, and 5% Remote job distribution, with an average salary of $128,387 per year, or $61.7 per hour.

Security Control Assessor

Novul Solutions

Arlington, VA โ€ข On-site

Full-time

Medical, Dental, Vision, Retirement, PTO

Re-posted 14 days ago


Job description


Position Overview
We are seeking an experienced Security Control Assessor to support cybersecurity assessment and authorization activities for Department of Defense information systems. This role is responsible for conducting in-depth security control assessments, validating control implementation, reviewing system security documentation, and supporting the development and maintenance of complete and accurate Authorization to Operate packages.
The ideal candidate will bring extensive experience with the Risk Management Framework, NIST security standards, DoD cybersecurity policies, and the Joint Special Access Program Implementation Guide. The individual must be capable of communicating assessment findings, remediation requirements, and government-approved mitigation strategies to system owners and technical stakeholders.
Key Responsibilities:
  • Conduct comprehensive security control assessments of DoD information systems in accordance with NIST SP 800-53, DoD RMF policies, CNSSI 1253, and the JSIG.
  • Evaluate the implementation and effectiveness of security controls and document assessment findings, risks, deficiencies, and recommended corrective actions.
  • Communicate government-approved mitigation and remediation requirements to system owners, cybersecurity personnel, and technical stakeholders in support of the RMF process.
  • Apply the cybersecurity principles of confidentiality, integrity, and availability when evaluating system categorization and impact levels, including High, Moderate, and Low classifications.
  • Validate security controls identified as inherited from hosting environments, connected systems, enterprise services, or other authorized systems.
  • Assess program compliance with security controls associated with registered Ports, Protocols, and Services, including the proper generation, retention, protection, and handling of system log files.
  • Review system security documentation and supporting evidence for accuracy, completeness, consistency, and alignment with applicable cybersecurity requirements.
  • Lead the review, preparation, and quality assurance of Authorization to Operate packages and related RMF documentation.
  • Identify control gaps, weaknesses, and areas of noncompliance and provide clear, actionable recommendations for remediation.
  • Coordinate with system owners, information system security personnel, engineers, program leadership, and government stakeholders throughout the assessment and authorization lifecycle.
  • Support the development, review, and validation of Plans of Action and Milestones and other risk-management documentation.
  • Provide leadership and technical guidance to assessment teams and support the resolution of complex cybersecurity compliance issues.

Requirements
Required Qualifications:
  • Bachelor's degree in cybersecurity, information technology, computer science, information systems, engineering, or a related field.
  • Eight or more years of professional experience in cybersecurity.
  • Five or more years of experience supporting Certification and Accreditation or Assessment and Authorization activities.
  • Expert-level knowledge of the DoD Risk Management Framework.
  • Strong working knowledge of NIST SP 800-37, NIST SP 800-53, CNSSI 1253, and the JSIG.
  • Experience conducting security control assessments and evaluating technical, operational, and management controls.
  • Experience reviewing and preparing ATO packages and supporting documentation.
  • Experience validating inherited controls and assessing Ports, Protocols, and Services requirements.
  • Demonstrated leadership experience, including previous experience serving in a lead or senior assessment role.
  • Strong written and verbal communication skills, with the ability to clearly explain technical findings, risks, and remediation requirements to system owners and government stakeholders.

Preferred Qualifications
  • Experience supporting DoD Special Access Programs or other highly classified environments.
  • Experience working directly with system owners, ISSOs, ISSMs, security engineers, and Authorizing Official representatives.
  • Familiarity with security assessment reports, risk assessment reports, system security plans, POA&Ms, and continuous-monitoring documentation.
  • Experience leading assessment teams or overseeing multiple system authorization efforts.
  • Strong analytical, documentation-review, and quality-assurance skills.

Benefits
Core Benefits:
  • Paid Time OffPTO):TEN (10) Paid days off & FIVE (5) Floating days off.
  • Holidays: 11 Paid Holidays. Flex time can be utilized instead of holiday time usage.
  • Payroll: Paid Bi-Monthly.
  • 401(k): Partnered with the SECOND LARGEST Retirement plan provider in the U.S. Guaranteed 3% match. Eligibility - 21 years of age or older, after 3 months of employment
  • Individual or company-wide performance and recognition awards (Quarterly)

Health Benefits:
  • UNITED HEALTHCARE PPO, extensive national coverage.
  • INCLUDES: Medical/Dental/Vision/HSA.
  • Eligible on the first of the month, immediately after the start date.
  • Submit the enrollment form within 30 days of your start date otherwise, you will have to wait until October for the new year enrollment.

Quality of Life Benefits:
  • Training & Career Development Reimbursement of Tuition and training needed to support career development.
  • $150 monthly reimbursement contribution paid monthly towards parking expenses.
  • Receipts must be submitted by the close of business on the 25th of each month.
  • Reimbursements will be paid on the first payroll AFTER reimbursements are submitted each month.

Special Benefits:
  • Performance bonus - Project-based
  • Yearly bonus - Company based