1

Security Control Assessor Jobs in Springfield, VA

Security Control Assessor

Washington, DC ยท On-site

$165K - $185K/yr

Job Title Security Control Assessor The most security-conscious organizations trust Telos Corporation to protect their vital IT assets. The reputation of our company rests on the quality of our ...

Security Control Assessor (SCA) LOCATION Chantilly, VA 20151 CLEARANCE TS/SCI Full Poly (Please note this position requires full U.S. Citizenship) KEY SUMMARY We are seeking a meticulous and detail ...

Security Control Assessor (SCA) LOCATION Reston, VA 20190 CLEARANCE TS/SCI Full Poly (Please note this position requires full U.S. Citizenship) KEY SUMMARY We are seeking a meticulous and detail ...

Security Control Assessor (SCA) LOCATION Tysons, VA 22182 CLEARANCE TS/SCI Full Poly (Please note this position requires full U.S. Citizenship) KEY SUMMARY We are seeking a meticulous and detail ...

POSITION OVERVIEW As a Security Control Assessor, you will play a key role in conducting Security Control Assessments at various government sites, with approximately 85% of your time on travel ...

Security Control Assessor

Washington, DC ยท On-site

$165K - $185K/yr

Conduct ongoing assessments of information systems security requirements, perform STIG analysis Highly motivated self-starter that can run objectives to completion on their own Define metrics and ...

Security Control Assessor

Arlington, VA ยท On-site

$110K - $130K/yr

Security Control AssessorLocation: Arlington, VA (On-Site)Citizenship: US onlyClearance: Active TS/SCI (DHS EOD Suitability required)Company: Argo Cyber Systems, LLC - Service-Disabled Veteran-Owned ...

Security Control Assessor (SCA) Belong. Connect. Grow. with KBR! KBR's National Security Solutions team provides high-end engineering and advanced technology solutions to our customers in the ...

New

Extensive experience with the NIST RMF and independently leading security control assessments from start to finish using the NIST Framework. * Experience in several of the following areas is required ...

next page

Showing results 1-20

Security Control Assessor information

See Springfield, VA salary details

$9

$61

$82

How much do security control assessor jobs pay per hour?

As of Jul 20, 2026, the average hourly pay for security control assessor in Springfield, VA is $61.72, according to ZipRecruiter salary data. Most workers in this role earn between $53.03 and $71.44 per hour, depending on experience, location, and employer.

Can you make $500,000 a year in cyber security?

Security Control Assessors typically earn salaries ranging from $70,000 to $150,000 annually, depending on experience, certifications, and location. Reaching a $500,000 annual salary in cybersecurity generally requires senior roles, specialized expertise, management positions, or consulting work with high-value contracts.

Is SOC an entry level job?

A Security Control Assessor (SOC) role is typically not entry-level; it usually requires prior experience in cybersecurity, knowledge of security frameworks, and relevant certifications such as CISSP or Security+. Entry-level positions in cybersecurity may include roles like Security Analyst or Technician, with SOC roles often requiring more specialized skills and experience. However, some organizations offer junior or trainee SOC positions for those starting their cybersecurity careers.

What are the key skills and qualifications needed to thrive as a Security Control Assessor, and why are they important?

To thrive as a Security Control Assessor, you need expertise in information security principles, risk management frameworks like NIST RMF, and a relevant bachelor's degree or equivalent work experience. Familiarity with security assessment tools, compliance management systems, and certifications such as CISSP, CISA, or CAP is typically required. Strong analytical thinking, attention to detail, and effective communication are crucial for evaluating security controls and reporting findings clearly. These skills ensure accurate risk assessments, regulatory compliance, and robust protection of organizational information assets.

What skills do you need to be a security control assessor?

A security control assessor needs strong knowledge of cybersecurity frameworks, risk management, and security controls. Skills in analyzing security policies, conducting assessments, and familiarity with tools like NIST, ISO standards, and vulnerability scanning are essential. Certifications such as CISSP or CISA can also enhance qualifications.

What is the difference between Security Control Assessor vs Security Analyst?

AspectSecurity Control AssessorSecurity Analyst
CertificationsRisk Management Framework (RMF), CISSP, CISACISSP, Security+
Work EnvironmentFederal agencies, DoD, government complianceCorporate, cybersecurity teams, IT departments
ResponsibilitiesAssess security controls, ensure compliance, auditMonitor security, analyze threats, implement security measures

The Security Control Assessor primarily evaluates security controls for compliance and risk management, often within government agencies. In contrast, the Security Analyst focuses on monitoring and analyzing security threats to protect organizational assets. While both roles require cybersecurity knowledge and certifications like CISSP, their focus areas and work environments differ significantly.

What is the role of a security control assessor?

A security control assessor evaluates the effectiveness of security controls implemented within an organization to ensure they meet security standards and compliance requirements. They review documentation, conduct testing, and provide recommendations for improvement, often working with frameworks like NIST or ISO. Certification such as CISSP or CISA is commonly required for this role.

What are the main challenges Security Control Assessors face when evaluating complex information systems?

Security Control Assessors often encounter challenges such as rapidly evolving security threats, integrating new technologies, and ensuring compliance with multiple frameworks (like NIST, FISMA, or RMF). Assessing large, interconnected systems requires attention to detail and strong analytical skills to identify vulnerabilities and recommend effective controls. Collaboration with system owners, IT staff, and auditors is essential to obtain comprehensive documentation and clarify system boundaries, which can be a demanding part of the assessment process.

What are Security Control Assessors?

Security Control Assessors (SCAs) are professionals responsible for evaluating the security controls of information systems to ensure they meet required standards and regulations. They conduct assessments, document findings, and provide recommendations to help organizations manage risk and achieve compliance with frameworks such as NIST or FISMA. SCAs play a critical role in maintaining the security and integrity of sensitive data by identifying vulnerabilities and verifying that corrective actions are implemented effectively.
What are the most commonly searched types of Security Control Assessor jobs in Springfield, VA? The most popular types of Security Control Assessor jobs in Springfield, VA are:
What are popular job titles related to Security Control Assessor jobs in Springfield, VA? For Security Control Assessor jobs in Springfield, VA, the most frequently searched job titles are:
What job categories do people searching Security Control Assessor jobs in Springfield, VA look for? The top searched job categories for Security Control Assessor jobs in Springfield, VA are:
What cities near Springfield, VA are hiring for Security Control Assessor jobs? Cities near Springfield, VA with the most Security Control Assessor job openings:
Infographic showing various Security Control Assessor job openings in Springfield, VA as of July 2026, with employment types broken down into 2% Locum Tenens, 35% Full Time, 6% Part Time, 2% Contract, 54% Nights, and 1% Summer. Highlights an 88% Physical, 2% Hybrid, and 10% Remote job distribution, with an average salary of $128,387 per year, or $61.7 per hour.
Security Control Assessor

Security Control Assessor

Pueo Business Solutions LLC

Mclean, VA โ€ข On-site

Full-time

Posted 4 days ago

New


Job description

The Security Control Assessor (SCA) conducts comprehensive assessments of security controls employed by, or inherited within, information systems to determine their overall effectiveness and compliance with applicable security requirements. The SCA develops and submits the complete Body of Evidence (BoE), including the System Security Plan (SSP), Security Assessment Report (SAR), Plan of Action and Milestones (POA&M), and draft Authorization to Operate (ATO) letter, to the Authorizing Official (AO) or Delegated Authorizing Official (DAO) for review and authorization determination.
The SCA serves as a trusted advisor to key stakeholders, including Program Offices, Data Owners, Information System Security Officers (ISSOs), and Authorizing Officials/Delegated Authorizing Officials, providing guidance on system security categorization and determining appropriate confidentiality, integrity, and availability impact levels in accordance with Risk Management Framework (RMF) requirements.
Knowledge, Skills and Abilities
  • Excellent interpersonal, verbal, and written communication skills, with experience collaborating across mixed technical teams and engaging diverse stakeholders.
  • Expert-level experience reviewing, analyzing, and interpreting compliance and vulnerability assessment results from tools such as Xacta, STIG Viewer, ACAS, Prisma, Splunk, Trellix (HBSS), and other vulnerability scanners.
  • Ability to lead or support security projects and initiatives, manage competing priorities, and contribute effectively in a team-oriented environment.

Required Qualifications:
  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field. A Bachelor's degree may be substituted with an additional four (4) years of directly related experience, for a total of sixteen (16) years of relevant experience.
  • Twelve (12) years of experience supporting cybersecurity, Information Assurance, Risk Management Framework (RMF), and Assessment & Authorization (A&A) activities.
  • Obtain and maintain an IAT Level III certification in accordance with DoD 8570.01-M and DoD Directive 8140 Cyberspace Workforce Management requirements.
  • Acceptable certifications include: CompTIA Advanced Security Practitioner (CASP+ CE), Cisco Certified Network Professional Security (CCNP Security), Certified Information Systems Auditor (CISA), Certified Information Systems Security Professional (CISSP) or CISSP Associate, GIAC Certified Enterprise Defender (GCED), GIAC Certified Incident Handler (GCIH), and Certified Cloud Security Professional (CCSP).

Clearance:
  • Hold a Top Secret Security Clearance with SCI eligibility. Ability to Pass CI Poly.

Pueo is an equal employment opportunity employer and affirmative action employer. All interested individuals will receive consideration and will not be discriminated against on the basis of race, color, religion, sex, national origin, disability, age, sexual orientation, gender identity, genetic information, or protected veteran status. Pueo takes affirmative action in support of its policy to advance diversity and inclusion of individuals who are minorities, women, protected veterans, and individuals with disabilities.