1

Security Control Jobs in Maryland (NOW HIRING)

We are seeking a highly skilled Security Control Assessor (SCA) to support independent cybersecurity assessments of systems in accordance with the Risk Management Framework (RMF). This role is ...

You'll work under a senior assessor and help evaluate security control implementation, validate evidence, and document results in alignment with NIST Risk Management Framework (RMF) and NIST SP 800 ...

POSITION OVERVIEW As a Security Control Assessor, you will play a key role in conducting Security Control Assessments at various government sites, with approximately 85% of your time on travel ...

POSITION OVERVIEW As a Security Control Assessor, you will play a key role in conducting Security Control Assessments at various government sites, with approximately 85% of your time on travel ...

Extensive experience with the NIST RMF and independently leading security control assessments from start to finish using the NIST Framework. * Experience in several of the following areas is required ...

Yes SECURITY CONTROL ASSESSOR (SCA) II ~ EVERGREEN The Security Control Assessor (SCA) II is responsible for conducting a comprehensive assessment of the management, operational, and technical ...

next page

Showing results 1-20

Security Control information

What is the difference between Security Control vs Security Analyst?

AspectSecurity ControlSecurity Analyst
CertificationsCompTIA Security+, CISSP, CISACompTIA Security+, CISSP, GIAC
Work EnvironmentImplementing and managing security measures, often in security operations centers or IT departmentsMonitoring, analyzing, and responding to security incidents, often in security operations or cybersecurity teams
Employer & Industry UsageUsed across industries to establish security policies and controlsCommonly employed in cybersecurity teams to analyze threats and vulnerabilities

Security Control professionals focus on implementing and managing security measures to protect organizational assets, while Security Analysts monitor and analyze security events to identify and respond to threats. Both roles are essential in cybersecurity, often working together within security teams to ensure comprehensive protection.

Infographic showing various Security Control job openings in Maryland as of July 2026, with employment types broken down into 1% As Needed, 73% Full Time, 23% Part Time, 2% Contract, and 1% Nights. Highlights an 96% Physical, 1% Hybrid, and 3% Remote job distribution.

Other

Re-posted 23 days ago


Job description

Job Description We are seeking a highly skilled Security Control Assessor (SCA) to support independent cybersecurity assessments of systems in accordance with the Risk Management Framework (RMF). This role is responsible for evaluating the implementation and effectiveness of security controls, assessing residual risk, and providing actionable recommendations to support authorization decisions. The ideal candidate brings deep DoD cybersecurity experience, strong analytical judgment, and the ability to communicate technical risk clearly to both cybersecurity and senior mission stakeholders.

This is a high-visibility role supporting mission-critical systems in a dynamic national security environment. Key Responsibilities Perform independent security control assessments of information systems in support of RMF authorization and continuous monitoring activities Evaluate the implementation, effectiveness, and compliance of security controls in accordance with NIST SP 800-53 and DoD cybersecurity requirements Review technical artifacts, system documentation, test results, and evidence to determine control inheritance, applicability, and residual risk Document assessment findings, vulnerabilities, recommendations, and risk impacts in clear and concise language Develop Security Assessment Reports (SARs), risk summaries, and briefing materials for Authorizing Officials and senior stakeholders Coordinate with system owners, ISSMs, engineers, and cybersecurity teams to validate findings and support remediation planning Assess cloud, hybrid, enclave, and enterprise architectures for cybersecurity compliance and security posture Support high-priority authorization decisions while ensuring alignment with mission execution and operational requirements Required Qualifications 7+ years of experience in cybersecurity, RMF, information assurance, or related information security roles Demonstrated experience performing security control assessments, compliance reviews, or cybersecurity audits Strong knowledge of Risk Management Framework (RMF), NIST SP 800-53, and security assessment methodologies Experience analyzing technical evidence and articulating cybersecurity risk to technical and non-technical stakeholders Prior experience supporting complex DoD or enterprise IT systems Active Secret Clearance (or higher) required Ability to work onsite at Joint Base Andrews, MD two days per week Prior DoD cybersecurity experience required CISSP certification required Preferred Qualifications Previous experience serving as a Security Control Assessor (SCA) or SCA-Validator Experience supporting Air Force systems or A4 mission environments Familiarity with cloud, hybrid, and enclave architectures Strong briefing, customer engagement, and stakeholder communication skills Additional certifications such as CISM or CISA preferredIdeal Candidate Profile Critical thinker with strong attention to technical detail Comfortable operating in mission-focused, high-visibility DoD environments Able to balance cybersecurity rigor with operational mission requirements Effective collaborator with engineers, program teams, and senior leadership Passionate about improving security posture and supporting national security missions