Evaluate security controls, assess their impact on systems, and develop mitigation strategies where necessary. Requirements: * 5 yrs experience supporting RMF-based ATO processes. * Hands-on ...
Quick apply
Evaluate security controls, assess their impact on systems, and develop mitigation strategies where necessary. Requirements: * 5 yrs experience supporting RMF-based ATO processes. * Hands-on ...
Quick apply
Evaluate security controls, assess their impact on systems, and develop mitigation strategies where necessary. Requirements: * 5 yrs experience supporting RMF-based ATO processes. * Hands-on ...
Evaluate security controls, assess their impact on systems, and develop mitigation strategies where necessary. Requirements * 5 yrs experience supporting RMF-based ATO processes. * Hands-on ...
Evaluate security controls, assess their impact on systems, and develop mitigation strategies where necessary. Requirements * 5 yrs experience supporting RMF-based ATO processes. * Hands-on ...
The selected candidate will assess security controls, support Security Assessment and Authorization (SA&A) efforts, and develop accreditation documentation to ensure compliance with federal and DoD ...
The selected candidate will assess security controls, support Security Assessment and Authorization (SA&A) efforts, and develop accreditation documentation to ensure compliance with federal and DoD ...
The selected candidate will assist in evaluating security controls, supporting Security Assessment and Authorization (SA&A) efforts, and maintaining compliance with applicable cybersecurity ...
The selected candidate will assist in evaluating security controls, supporting Security Assessment and Authorization (SA&A) efforts, and maintaining compliance with applicable cybersecurity ...
Evaluate security controls, assess their impact on systems, and develop mitigation strategies where necessary. Requirements * 5 yrs experience supporting RMF-based ATO processes. * Hands-on ...
Evaluate security controls, assess their impact on systems, and develop mitigation strategies where necessary. Requirements * 5 yrs experience supporting RMF-based ATO processes. * Hands-on ...
The selected candidate will assess security controls, support Security Assessment and Authorization (SA&A) efforts, and develop accreditation documentation to ensure compliance with federal and DoD ...
Quick apply
The selected candidate will assess security controls, support Security Assessment and Authorization (SA&A) efforts, and develop accreditation documentation to ensure compliance with federal and DoD ...
The selected candidate will assess security controls, support Security Assessment and Authorization (SA&A) efforts, and develop accreditation documentation to ensure compliance with federal and DoD ...
The selected candidate will assess security controls, support Security Assessment and Authorization (SA&A) efforts, and develop accreditation documentation to ensure compliance with federal and DoD ...
The selected candidate will assist in evaluating security controls, supporting Security Assessment and Authorization (SA&A) efforts, and maintaining compliance with applicable cybersecurity ...
The selected candidate will assist in evaluating security controls, supporting Security Assessment and Authorization (SA&A) efforts, and maintaining compliance with applicable cybersecurity ...
Assess security controls based on cybersecurity principles and frameworks including NIST SP 800-53 and the Cybersecurity Framework. * Support Security Assessment & Authorization (SA&A) processes and ...
Assess security controls based on cybersecurity principles and frameworks including NIST SP 800-53 and the Cybersecurity Framework. * Support Security Assessment & Authorization (SA&A) processes and ...
The selected candidate will assist in evaluating security controls, supporting Security Assessment and Authorization (SA&A) efforts, and maintaining compliance with applicable cybersecurity ...
Quick apply
The selected candidate will assist in evaluating security controls, supporting Security Assessment and Authorization (SA&A) efforts, and maintaining compliance with applicable cybersecurity ...
Indianapolis, IN ยท On-site
$62 - $80.25/hr
... assessments by evaluating compliance gaps, developing remediation plans, and supporting implementation of required security controls. * Review and monitor firm systems to ensure compliance with ...
Indianapolis, IN ยท On-site
$62 - $80.25/hr
... assessments by evaluating compliance gaps, developing remediation plans, and supporting implementation of required security controls. * Review and monitor firm systems to ensure compliance with ...
Assess security controls based on cybersecurity principles and frameworks including NIST SP 800-53 and the Cybersecurity Framework. * Support Security Assessment & Authorization (SA&A) processes and ...
Assess security controls based on cybersecurity principles and frameworks including NIST SP 800-53 and the Cybersecurity Framework. * Support Security Assessment & Authorization (SA&A) processes and ...
Assess security controls based on cybersecurity principles and frameworks including NIST SP 800-53 and the Cybersecurity Framework. * Support Security Assessment & Authorization (SA&A) processes and ...
Assess security controls based on cybersecurity principles and frameworks including NIST SP 800-53 and the Cybersecurity Framework. * Support Security Assessment & Authorization (SA&A) processes and ...
Assess and evaluate security controls based on cybersecurity principles and frameworks including NIST SP 800-53 and the Cybersecurity Framework. * Support Security Assessment & Authorization (SA&A ...
Assess and evaluate security controls based on cybersecurity principles and frameworks including NIST SP 800-53 and the Cybersecurity Framework. * Support Security Assessment & Authorization (SA&A ...
Assess and evaluate security controls based on cybersecurity principles and frameworks including NIST SP 800-53 and the Cybersecurity Framework. * Support Security Assessment & Authorization (SA&A ...
Assess and evaluate security controls based on cybersecurity principles and frameworks including NIST SP 800-53 and the Cybersecurity Framework. * Support Security Assessment & Authorization (SA&A ...
Assess and evaluate security controls based on cybersecurity principles and frameworks including NIST SP 800-53 and the Cybersecurity Framework. * Support Security Assessment & Authorization (SA&A ...
Assess and evaluate security controls based on cybersecurity principles and frameworks including NIST SP 800-53 and the Cybersecurity Framework. * Support Security Assessment & Authorization (SA&A ...
Indianapolis, IN ยท On-site
$109K - $150K/yr
Security Controls & Hardening: Establish baselines and implement preventive and detective security ... Further assessment of candidates beyond this initial phase within Vaco/Highspring will be otherwise ...
Indianapolis, IN ยท On-site
$109K - $150K/yr
Security Controls & Hardening: Establish baselines and implement preventive and detective security ... Further assessment of candidates beyond this initial phase within Vaco/Highspring will be otherwise ...
Assess security controls based on cybersecurity principles and frameworks including NIST SP 800-53 and the Cybersecurity Framework. * Support Security Assessment & Authorization (SA&A) processes and ...
Assess security controls based on cybersecurity principles and frameworks including NIST SP 800-53 and the Cybersecurity Framework. * Support Security Assessment & Authorization (SA&A) processes and ...
Assess security controls based on cybersecurity principles and frameworks including NIST SP 800-53 and the Cybersecurity Framework. * Support Security Assessment & Authorization (SA&A) processes and ...
Assess security controls based on cybersecurity principles and frameworks including NIST SP 800-53 and the Cybersecurity Framework. * Support Security Assessment & Authorization (SA&A) processes and ...
Assess security controls based on cybersecurity principles and frameworks including NIST SP 800-53 and the Cybersecurity Framework. * Support Security Assessment & Authorization (SA&A) processes and ...
Quick apply
Assess security controls based on cybersecurity principles and frameworks including NIST SP 800-53 and the Cybersecurity Framework. * Support Security Assessment & Authorization (SA&A) processes and ...
$8.46 - $14.45
2% of jobs
$14.45 - $20.44
2% of jobs
$20.44 - $26.43
0% of jobs
$26.43 - $32.42
0% of jobs
$32.42 - $38.41
3% of jobs
$38.41 - $44.40
5% of jobs
$47.92 is the 25th percentile. Wages below this are outliers.
$44.40 - $50.39
21% of jobs
The median wage is $55.27 / hr.
$50.39 - $56.37
20% of jobs
$56.37 - $62.36
18% of jobs
$63.75 is the 75th percentile. Wages above this are outliers.
$62.36 - $68.35
15% of jobs
$68.35 - $74.34
14% of jobs
$8
$55
$74
A security controls assessor (SCA) evaluates the security controls within network systems to identify vulnerabilities and recommend actions to correct problems, working either alone or as part of a team. As a security controls assessor, your duties begin with conducting an in-depth assessment of the management, operations, and technical security controls. You must analyze information and prepare reports describing the vulnerability level of the network with specific detail as to what compromises data systems. You then develop a plan to address vulnerabilities and continue to monitor the security of network systems.
| Aspect | Security Controls Assessor | Security Analyst |
|---|---|---|
| Certifications | ISO 27001 Lead Auditor, CISSP, CISA | CISSP, Security+ |
| Work Environment | Assessing security controls, compliance audits | Monitoring security systems, incident response |
| Employer & Industry | Government agencies, compliance firms | Corporate IT, cybersecurity teams |
The Security Controls Assessor primarily evaluates and verifies security controls for compliance, often in government or regulated environments. In contrast, a Security Analyst focuses on monitoring, analyzing, and responding to security threats within organizations. While both roles require security certifications and involve cybersecurity, their core responsibilities and work settings differ significantly.

Full-time
Re-posted 26 days ago
We are seeking an experienced Information System Security Specialist II to support the security authorization, compliance, and continuous monitoring activities of mission-critical information systems. The successful candidate will create and maintain IA artifacts, support Authority to Operate (ATO) efforts using the Risk Management Framework (RMF), perform compliance scanning and patch management activities, and collaborate with system owners, ISSMs, and technical teams to ensure systems remain secure and compliant.
Key Responsibilities:
About TRISTAR
TRISTAR is an SBA certified Service-Disabled Veteran-Owned professional services company supporting the U.S. Department of War programs. Our core competencies include Electronic Warfare, Enterprise Management, Full Spectrum Cybersecurity, Information Technology, Digital Transformation, Software Engineering and Development, Maritime Modernization and Engineering, and Technical Solutions.
TRISTAR was founded in March 1995 and has built an employee-focused collaborative environment which enables our team of professionals to create and deliver customized solutions to meet our customers’ mission critical challenges.
TRISTAR’s core capabilities support customers with end-to-end solutions. For over 30 years, TRISTAR has demonstrated and perfected our ability to successfully manage any task, small or large no matter how difficult or complex.
TRISTAR is proud to serve the Department of War and other Federal Agencies.
TRISTAR provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws. This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation and training.