1

Security Control Assessor Jobs (NOW HIRING)

Security Control Assessor

Monterey, CA ยท On-site

$65K - $75K/yr

Security Control Assessor Target Salary: $65K to $75K LOCATION: DLIFLC, 1759 Lewis Road, Monterey, CA 93944 Position Overview: The Security Control Assessor is responsible for conducting independent ...

Execute a security control assessment plan and update the System Security Plan * Review vulnerability scans and remediation * Implement risk management programs by utilizing NIST, FISMA, HIPAA, and ...

Senior Security Control Assessor

Arlington, VA ยท On-site

$130K - $150K/yr

Senior Security Control Assessor Overview: TSA is currently seeking a Senior Security Control Assessor who will serve as a Functional Lead and provide support to our NAVAIR customer in the DC Metro ...

As a Senior Security Control Assessor, you will provide senior-level security control assessment support to a Department of Defense (DoD) customer supporting the F-35 Joint Program Office (JPO ...

Security Control Assessor

Monterey, CA ยท On-site

$65K - $75K/yr

The Security Control Assessor is responsible for conducting independent, comprehensive assessments of the management, operational, and technical security controls and control enhancements within or ...

Security Control Assessor

Alexandria, VA ยท On-site

$146K - $234K/yr

Execute a security control assessment plan and update the System Security Plan * Review vulnerability scans and remediation * Implement risk management programs by utilizing NIST, FISMA, HIPAA, and ...

Junior Security Control Assessor

Bethesda, MD ยท On-site

$100K - $115K/yr

You'll work under a senior assessor and help evaluate security control implementation, validate evidence, and document results in alignment with NIST Risk Management Framework (RMF) and NIST SP 800 ...

Junior Security Control Assessor

Bethesda, MD ยท Remote

$100K - $115K/yr

You'll work under a senior assessor and help evaluate security control implementation, validate evidence, and document results in alignment with NIST Risk Management Framework (RMF) and NIST SP 800 ...

Junior Security Control Assessor

Bethesda, MD ยท Remote

$100K - $115K/yr

You'll work under a senior assessor and help evaluate security control implementation, validate evidence, and document results in alignment with NIST Risk Management Framework (RMF) and NIST SP 800 ...

Junior Security Control Assessor

Bethesda, MD ยท Remote

$100K - $115K/yr

You'll work under a senior assessor and help evaluate security control implementation, validate evidence, and document results in alignment with NIST Risk Management Framework (RMF) and NIST SP 800 ...

Junior Security Control Assessor

Bethesda, MD ยท Remote

$100K - $115K/yr

You'll work under a senior assessor and help evaluate security control implementation, validate evidence, and document results in alignment with NIST Risk Management Framework (RMF) and NIST SP 800 ...

Showing results 21-40

Security Control Assessor information

See salary details

$8

$58

$78

How much do security control assessor jobs pay per hour?

As of Aug 22, 2026, the average hourly pay for security control assessor in the United States is $58.77, according to ZipRecruiter salary data. Most workers in this role earn between $50.48 and $68.03 per hour, depending on experience, location, and employer.

What is a security control assessor?

Security Control Assessors (SCAs) are professionals responsible for evaluating the security controls of information systems to ensure they meet required standards and regulations. They conduct assessments, document findings, and provide recommendations to help organizations manage risk and achieve compliance with frameworks such as NIST or FISMA. SCAs play a critical role in maintaining the security and integrity of sensitive data by identifying vulnerabilities and verifying that corrective actions are implemented effectively.

What are the main challenges security control assessors face when evaluating complex information systems?

Security Control Assessors often encounter challenges such as rapidly evolving security threats, integrating new technologies, and ensuring compliance with multiple frameworks (like NIST, FISMA, or RMF). Assessing large, interconnected systems requires attention to detail and strong analytical skills to identify vulnerabilities and recommend effective controls. Collaboration with system owners, IT staff, and auditors is essential to obtain comprehensive documentation and clarify system boundaries, which can be a demanding part of the assessment process.

What are the key skills and qualifications needed to thrive as a security control assessor, and why are they important?

To thrive as a Security Control Assessor, you need expertise in information security principles, risk management frameworks like NIST RMF, and a relevant bachelor's degree or equivalent work experience. Familiarity with security assessment tools, compliance management systems, and certifications such as CISSP, CISA, or CAP is typically required. Strong analytical thinking, attention to detail, and effective communication are crucial for evaluating security controls and reporting findings clearly. These skills ensure accurate risk assessments, regulatory compliance, and robust protection of organizational information assets.

What is the difference between Security Control Assessor vs Security Analyst?

AspectSecurity Control AssessorSecurity Analyst
CertificationsRisk Management Framework (RMF), CISSP, CISACISSP, Security+
Work EnvironmentFederal agencies, DoD, government complianceCorporate, cybersecurity teams, IT departments
ResponsibilitiesAssess security controls, ensure compliance, auditMonitor security, analyze threats, implement security measures

The Security Control Assessor primarily evaluates security controls for compliance and risk management, often within government agencies. In contrast, the Security Analyst focuses on monitoring and analyzing security threats to protect organizational assets. While both roles require cybersecurity knowledge and certifications like CISSP, their focus areas and work environments differ significantly.

How much do security control assessors make?

Security Control Assessors in the federal government or related sectors typically earn between $80,000 and $130,000 annually, depending on experience, certifications, and location. Salaries can vary based on agency, level of clearance, and specific responsibilities, with higher pay often associated with specialized skills and certifications like CISSP or CISA.
More about Security Control Assessor jobs

What cities are hiring for Security Control Assessor jobs?

Cities with the most Security Control Assessor job openings:

What are the most commonly searched types of Security Control Assessor jobs?

The most popular types of Security Control Assessor jobs are:

What states have the most Security Control Assessor jobs?

States with the most job openings for Security Control Assessor jobs include:

Infographic showing various Security Control Assessor job openings in the United States as of August 2026, with employment types broken down into 1% As Needed, 75% Full Time, 20% Part Time, 3% Contract, and 1% Nights. Highlights an 95% Physical, 1% Hybrid, and 4% Remote job distribution, with an average salary of $122,236 per year, or $58.8 per hour.

Security Control Assessor

LinTech Global

Monterey, CA โ€ข On-site

$65K - $75K/yr

Full-time

Medical, Life, Retirement, PTO

Posted 19 days ago


Job description

Security Control Assessor

Target Salary: $65K to $75K

LOCATION: DLIFLC, 1759 Lewis Road, Monterey, CA 93944


Position Overview:

The Security Control Assessor is responsible for conducting independent, comprehensive assessments of the management, operational, and technical security controls and control enhancements within or inherited by an information technology (IT) system. The primary objective is to determine the overall effectiveness of these controls, as defined in NIST 800- 37.

Job Duties:

  • Conduct comprehensive assessments of management, operational, and technical security controls.
  • Evaluate compliance with NIST SP 800-53, NIST RMF, FedRAMP, DoD RMF, and agency-specific requirements.
  • Develop Security Assessment Plans (SAPs).
  • Execute control testing and validation activities.
  • Review system documentation, architectures, and security artifacts.
  • Assess cybersecurity risks and determine residual risk levels.
  • Identify control deficiencies and recommend remediation actions.
  • Validate Plans of Action & Milestones (POA&Ms).
  • Support Authorization to Operate (ATO) decisions.
  • Ensure compliance with federal and regulatory requirements.
  • Document findings, vulnerabilities, and risk determinations.
  • Present assessment results to system owners, ISSOs, ISSMs, and Authorizing Officials.
  • Track remediation efforts and reassessment activities.

Job Requirements:

  • Educational requirements include AA/AS from an accredited college or university or substitute with 3+ years of equivalent technical related experience.
  • Must have following relevant Skills: ACAS, Microsoft Defender, STIGs, Microsoft 365, SaaS Security, RHEL, Windows Server, MacOS, and eMASS.
  • Must be able to evaluate Security Controls: Perform thorough evaluations to ensure compliance with NIST 800- 37 and related standards.
  • Must be able to identify and Recommend Improvements: Assess control effectiveness, identify vulnerabilities, and recommend enhancements.
  • Must be able to document and Report Findings: Provide detailed reports and communicate findings to stakeholders.
  • Must be able to collaborate with Teams: Work with IT and security teams to implement recommended measures.

Required to Start Qualifications:

  • IAT Level II Certification is required to Start (CCNA Security, CSA+, GICSP, GSEC, Security+ CE, or SSCP) Certification
  • A NACLC Public Trust Clearance is required to Start.

Company Description

Dexian Government Solutions is an award-winning, ISO 9001:2015 certified, business and GSA contract holder providing diversified Information Technology services to both Civilian and Defense agencies. Services include Software Development, Systems Integration, Data Management, Project Management, Operations & Maintenance, Cybersecurity, and Training and Audio/Visual (AV) Solutions. Dexian Government Solutions has received several recognitions, including rankings on "Top 50 Companies to Watch", Washington Technology's Annual "FAST 50", and Inc. 500's List of "Fastest Growing Private Companies". The Dexian Government Solutions team is comprised of individuals who are dedicated to the success and sustainability of our customers and their missions. Our combination of technical expertise, big business experience, and small business agility allows us to promptly provide our customers with exceptional IT and engineering solutions.

Benefits

Our robust benefits package includes Open Paid Time Off, 11 Federal Paid Holidays & 5 Paid Sick Days, Company-paid Life/AD&D, Company-paid Short Term and Long-Term Disability, Health Insurance with Company Contribution, 401k Plan with Company Match, Employee Recognition Program, opportunity for Employee Referral Bonus, opportunity for annual Performance Bonus and much more!

EEO Statement

Dexian Government Solutions is proud to be an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. All employment is decided based on qualifications, merit, and business need.

All applicants will be considered for employment without attention to race, religion, color, national origin, ancestry, physical or mental disability, medical condition, pregnancy (including childbirth, lactation and related medical conditions), marital status, genetic information (including characteristics and testing), gender, sexual orientation, gender identity or expression, military and veteran status, or any other status protected under federal, state, or local law in the locations where we operate.

If you are an individual with a disability and would like to request a reasonable accommodation as part of the employment selection process, please contact Human Resources. The Company invites any applicant and/or employee to review the Company's written Affirmative Action Plan. This plan is available for inspection upon request.

http://Lintechglobal.com/wp-content/uploads/2017/09/poster_screen_reader_optimized.pdf

#DICE

#LI-LM1



This role requires customer approval, suitability to hold a public trust and successful completion of a preemployment background screening.ย ย