1

Security Control Assessor Jobs (NOW HIRING)

PR ยท On-site

Nist Security Control Assessor We are currently seeking a NIST 800-53 Security Control Assessor interested in starting a rewarding career in public accounting by joining our Information Technology ...

Security Control Assessor

Houston, TX ยท On-site

$61K - $141K/yr

Security Control Assessor The Opportunity: As a cyber mission specialist, you understand the value of hunt-forward operations, and you know that battles are won in the grey. At Booz Allen, you can ...

Security Control Assessor (SCA) LOCATION San Antonio, TX 78208 CLEARANCE TS/SCI Full Poly (Please note this position requires full U.S. Citizenship) KEY SUMMARY We are seeking a meticulous and detail ...

Security Control Assessor

Arlington, VA ยท On-site

$110K - $130K/yr

Security Control AssessorLocation: Arlington, VA (On-Site)Citizenship: US onlyClearance: Active TS/SCI (DHS EOD Suitability required)Company: Argo Cyber Systems, LLC - Service-Disabled Veteran-Owned ...

Security Control Assessor (SCA) LOCATION Chantilly, VA 20151 CLEARANCE TS/SCI Full Poly (Please note this position requires full U.S. Citizenship) KEY SUMMARY We are seeking a meticulous and detail ...

Security Control Assessor (SCA) LOCATION Aurora, CO 80014 CLEARANCE TS/SCI Full Poly (Please note this position requires full U.S. Citizenship) KEY SUMMARY We are seeking a meticulous and detail ...

Showing results 41-60

Security Control Assessor information

See salary details

$8

$58

$78

How much do security control assessor jobs pay per hour?

As of Aug 22, 2026, the average hourly pay for security control assessor in the United States is $58.77, according to ZipRecruiter salary data. Most workers in this role earn between $50.48 and $68.03 per hour, depending on experience, location, and employer.

What is a security control assessor?

Security Control Assessors (SCAs) are professionals responsible for evaluating the security controls of information systems to ensure they meet required standards and regulations. They conduct assessments, document findings, and provide recommendations to help organizations manage risk and achieve compliance with frameworks such as NIST or FISMA. SCAs play a critical role in maintaining the security and integrity of sensitive data by identifying vulnerabilities and verifying that corrective actions are implemented effectively.

What are the main challenges security control assessors face when evaluating complex information systems?

Security Control Assessors often encounter challenges such as rapidly evolving security threats, integrating new technologies, and ensuring compliance with multiple frameworks (like NIST, FISMA, or RMF). Assessing large, interconnected systems requires attention to detail and strong analytical skills to identify vulnerabilities and recommend effective controls. Collaboration with system owners, IT staff, and auditors is essential to obtain comprehensive documentation and clarify system boundaries, which can be a demanding part of the assessment process.

What are the key skills and qualifications needed to thrive as a security control assessor, and why are they important?

To thrive as a Security Control Assessor, you need expertise in information security principles, risk management frameworks like NIST RMF, and a relevant bachelor's degree or equivalent work experience. Familiarity with security assessment tools, compliance management systems, and certifications such as CISSP, CISA, or CAP is typically required. Strong analytical thinking, attention to detail, and effective communication are crucial for evaluating security controls and reporting findings clearly. These skills ensure accurate risk assessments, regulatory compliance, and robust protection of organizational information assets.

What is the difference between Security Control Assessor vs Security Analyst?

AspectSecurity Control AssessorSecurity Analyst
CertificationsRisk Management Framework (RMF), CISSP, CISACISSP, Security+
Work EnvironmentFederal agencies, DoD, government complianceCorporate, cybersecurity teams, IT departments
ResponsibilitiesAssess security controls, ensure compliance, auditMonitor security, analyze threats, implement security measures

The Security Control Assessor primarily evaluates security controls for compliance and risk management, often within government agencies. In contrast, the Security Analyst focuses on monitoring and analyzing security threats to protect organizational assets. While both roles require cybersecurity knowledge and certifications like CISSP, their focus areas and work environments differ significantly.

How much do security control assessors make?

Security Control Assessors in the federal government or related sectors typically earn between $80,000 and $130,000 annually, depending on experience, certifications, and location. Salaries can vary based on agency, level of clearance, and specific responsibilities, with higher pay often associated with specialized skills and certifications like CISSP or CISA.
More about Security Control Assessor jobs

What cities are hiring for Security Control Assessor jobs?

Cities with the most Security Control Assessor job openings:

What are the most commonly searched types of Security Control Assessor jobs?

The most popular types of Security Control Assessor jobs are:

What states have the most Security Control Assessor jobs?

States with the most job openings for Security Control Assessor jobs include:

Infographic showing various Security Control Assessor job openings in the United States as of August 2026, with employment types broken down into 1% As Needed, 75% Full Time, 20% Part Time, 3% Contract, and 1% Nights. Highlights an 95% Physical, 1% Hybrid, and 4% Remote job distribution, with an average salary of $122,236 per year, or $58.8 per hour.

NIST Security Control Assessor

Castro & Company, LLC

PR โ€ข On-site

Full-time

Re-posted 29 days ago


Job description

Nist Security Control Assessor
We are currently seeking a NIST 800-53 Security Control Assessor interested in starting a rewarding career in public accounting by joining our Information Technology (IT) practice to serve our federal clients. If you are dedicated and eager to grow your auditing career, we will provide you with a supportive team, resources, and training to succeed.
As a Security Control Assessor your responsibilities will include:
  • Perform independent assessments of security controls in accordance with NIST SP 800-53 and NIST SP 800-53A
  • Evaluate the design and operating effectiveness of technical, operational, and management controls across federal information systems
  • Develop and execute Security Assessment Plans (SAPs), including test procedures, sampling approaches, and evidence requirements
  • Conduct control testing activities (interviews, documentation review, and technical validation) in alignment with Risk Management Framework (RMF)
  • Analyze assessment results to identify control deficiencies, gaps, and risk exposures
  • Document findings with clear risk statements, root cause analysis, and recommended remediation actions
  • Prepare Security Assessment Reports (SARs) and present results to Authorizing Officials (AOs), system owners, and stakeholders
  • Support Authorization to Operate (ATO) processes, including control validation and continuous monitoring activities
  • Collaborate with system owners, ISSOs, and engineering teams to validate remediation efforts and perform re-testing
  • Maintain assessment documentation within GRC tools (e.g., ServiceNow)
  • Stay current with evolving federal cybersecurity requirements, including FISMA and OMB/NIST guidance
  • Contribute to audit readiness and compliance initiatives across client environments
Requirements:
  • Must have Bachelorโ€™s Degree in an IT- related degree from an accredited school.
  • Must be able to obtain Security Clearance: Must be able to pass a basic government suitability check (US Citizenship required).
  • Must have 5-8 Years of technical experience NIST 800-53 assessments.
  • Must have strong knowledge and demonstrated understanding of NIST 800-53, security and privacy controls.
  • Must have strong analytical and problem-solving skills
  • Must have experience communicating technical findings to both technical and non-technical stakeholders
  • Must be detail-oriented with strong documentation and reporting skills
  • Must have experience working independently and collaboratively in a team environment
  • Certification (preferred) includes CISSP, Security+, CISA
Castro Puerto Rico is a Professional Services Center headquartered in San Juan, Puerto Rico, delivering advisory, accounting, audit and IT support services to Federal Government clients. We are dedicated to assisting our clients to accomplish their strategic goals while providing our people with a diverse and inclusive environment to thrive and succeed.
Castro Puerto Rico is an Equal Opportunity Employer and considers all qualified applicants without regard to color, religion, sex, sexual orientation, gender identity, national origin, veteran status, disability and any other classification protected by law.โ€ฏโ€ฏ