1

Security Controls Assessor Jobs in Indiana (NOW HIRING)

In alignment with the Risk Management Framework (RMF), implement security controls, document ... assessments, subject matter expert input to proposals, technical interchange meetings, status ...

Architect, Security Products

Carmel, IN ยท Remote

$61.50 - $79.50/hr

The Architect works to assess, design, develop, build, and validate solutions by leveraging in ... controls based on the concepts the group will define as key use cases to explore for OT security ...

In alignment with the Risk Management Framework (RMF), implement security controls, document ... assessments, subject matter expert input to proposals, technical interchange meetings, status ...

Architect, Security Products

Carmel, IN ยท On-site

$61.50 - $79.50/hr

The Architect works to assess, design, develop, build, and validate solutions by leveraging in ... controls based on the concepts the group will define as key use cases to explore for OT security ...

Lead build/buy/partner assessments; support M&A and partnership diligence from a security market ... security controls, EU CRA / NIS2 themes, sector-specific requirements where applicable)

Lead build/buy/partner assessments; support M&A and partnership diligence from a security market ... CIP security controls, EU CRA / NIS2 themes, sector-specific requirements where applicable)

Showing results 41-60

Security Controls Assessor information

See Indiana salary details

$8

$55

$74

How much do security controls assessor jobs pay per hour?

As of Aug 8, 2026, the average hourly pay for security controls assessor in Indiana is $55.92, according to ZipRecruiter salary data. Most workers in this role earn between $48.03 and $64.71 per hour, depending on experience, location, and employer.

What is a security controls assessor?

Security Controls Assessors are professionals responsible for evaluating and validating the effectiveness of security controls within an organization's information systems. They conduct assessments to ensure compliance with regulatory standards, such as NIST, FISMA, or other security frameworks. Their work helps organizations identify vulnerabilities, manage risks, and maintain the confidentiality, integrity, and availability of critical data. Security Controls Assessors often provide recommendations for remediation and support efforts to achieve or maintain security certifications.

What are the key skills and qualifications needed to thrive as a security controls assessor, and why are they important?

To thrive as a Security Controls Assessor, you need expertise in information security frameworks, risk assessment methodologies, and compliance requirements, often supported by a degree in cybersecurity or related fields and certifications like CISSP, CISA, or CAP. Familiarity with tools such as vulnerability scanners, security assessment platforms, and compliance management systems is typically required. Strong analytical thinking, attention to detail, and effective communication skills help you identify risks and clearly report findings to stakeholders. These skills ensure that organizations maintain robust security postures and meet regulatory requirements to protect critical assets.

What are some common challenges security controls assessors face when evaluating compliance across multiple systems?

Security Controls Assessors often encounter challenges with inconsistent documentation, varying system configurations, and differing interpretations of compliance standards across departments. Coordinating with multiple teams to collect evidence and clarify control implementations can be time-consuming, especially in large organizations. Staying current with evolving regulations and ensuring all systems meet the latest requirements also demands continuous learning and adaptability. Building strong communication channels with system owners and IT staff helps overcome these hurdles and ensures thorough, accurate assessments.

What does a security controls assessor do?

A security controls assessor (SCA) evaluates the security controls within network systems to identify vulnerabilities and recommend actions to correct problems, working either alone or as part of a team. As a security controls assessor, your duties begin with conducting an in-depth assessment of the management, operations, and technical security controls. You must analyze information and prepare reports describing the vulnerability level of the network with specific detail as to what compromises data systems. You then develop a plan to address vulnerabilities and continue to monitor the security of network systems.

What is the difference between Security Controls Assessor vs Security Analyst?

AspectSecurity Controls AssessorSecurity Analyst
CertificationsISO 27001 Lead Auditor, CISSP, CISACISSP, Security+
Work EnvironmentAssessing security controls, compliance auditsMonitoring security systems, incident response
Employer & IndustryGovernment agencies, compliance firmsCorporate IT, cybersecurity teams

The Security Controls Assessor primarily evaluates and verifies security controls for compliance, often in government or regulated environments. In contrast, a Security Analyst focuses on monitoring, analyzing, and responding to security threats within organizations. While both roles require security certifications and involve cybersecurity, their core responsibilities and work settings differ significantly.

What are popular job titles related to Security Controls Assessor jobs in Indiana? For Security Controls Assessor jobs in Indiana, the most frequently searched job titles are:
What job categories do people searching Security Controls Assessor jobs in Indiana look for? The top searched job categories for Security Controls Assessor jobs in Indiana are:
What are popular job titles related to Security Controls Assessor jobs in IN? For Security Controls Assessor jobs in IN, the most frequently searched job titles are:
Infographic showing various Security Controls Assessor job openings in Indiana as of August 2026, with employment types broken down into 85% Full Time, 5% Part Time, 5% Temporary, and 5% Contract. Highlights an 86% In-person, and 14% Remote job distribution, with an average salary of $116,315 per year, or $55.9 per hour.

Information Systems Security Engineer (ISSE)

Precise Systems

Crane, IN โ€ข On-site

Full-time

Re-posted 4 days ago


Job description

Precise Systems delivers integrated, mission-ready solutions that advance warfighter readiness and strengthen our nationโ€™s most critical defense programs. Through the power of our combined capabilities, we provide deep expertise in Advanced Engineering; Digital Transformation; Electromagnetic Warfare; Interactive Training & Simulation; Physical Sciences Research; Platform Lifecycle Support; and Foreign Military Sales. Unified by decades of trusted performance and expanded through strategic growth, our team applies innovative technologies, engineering rigor, and customer-focused execution to solve complex challenges and accelerate mission success. Guided by our commitment to partnership, precision, and performance, we deliver the scalable solutions and technical excellence our customers depend onโ€”today and into the future.

We are seeking an Information Systems Security Engineer (ISSE) to support our customer in Crane, Indiana. This position provides cybersecurity engineering support for tactical information systems, applications, networks, and platform systems supporting Expeditionary Electromagnetic Warfare Division efforts. The ISSE will support the engineering, documentation, assessment, and authorization activities required to establish and maintain compliant, operationally effective systems in accordance with DoD and Navy cybersecurity requirements. This role is ideal for a candidate who understands both the technical and procedural sides of cybersecurity. The successful candidate will help engineer and document security controls, support RMF package development and submission, assess vulnerabilities, manage POA&Ms, and sustain systems through authorization and continuous monitoring. The position requires strong judgment, initiative, organization, and the ability to operate effectively in a fast-paced environment with sensitive information and mission-critical systems.

This role requires in-person support. 

Duties:

  • Provide cybersecurity engineering support for tactical information systems that are not owned by NSWC Crane or NMCI, including applications, networks, and platform systems.
  • Develop, update, and maintain cybersecurity documentation required for the certification, accreditation, authorization, and sustainment of information systems. Core artifacts may include the System Security Plan (SSP), Risk Assessment Report (RAR), Security Assessment Plan (SAP), Security Assessment Report (SAR), POA&M, Incident Response Plan (IRP), Contingency Plan, SOPs, Remediation Plans, and Configuration Management Plan (CMP).
  • Support the Risk Management Framework (RMF) process and demonstrate working knowledge of the RMF submission flow, including:
    • System categorization and boundary definition 
    • Security control selection and tailoring 
    • Control implementation and technical evidence collection 
    • Package development and submission for assessment 
    • Support to security control assessment and adjudication 
    • Development and maintenance of POA&Ms 
    • Authorization package updates in support of ATO decisions
    • Transition to continuous monitoring and reauthorization support as required.
  • Perform technical efforts required for the certification, accreditation, and authorization of tactical systems, including vulnerability assessment using Tenable Nessus, SCAP Compliance Checker (SCC), STIG evaluation, and manual checklist development.
  • Analyze system, network, database, cloud, and application security posture and recommend cost-effective safeguards and remediation strategies.
  • Proactively create, monitor, and update POA&Ms to ensure identified weaknesses are tracked and resolved within required timelines.
  • Assist with development and maintenance of the information systemโ€™s authorization to operate (ATO) and overall compliance posture.
  • Maintain hardware and software inventories, support configuration management, and assess impacts of proposed changes to maintain security posture.
  • Support incident response and contingency planning activities, including documentation updates and technical coordination.
  • Ensure systems are maintained in DITPR-DON and that software applications are properly registered in DADMS, as applicable.
  • Support continuous monitoring of vulnerabilities through patching, security updates, policy changes, mitigation development, and security status reporting to stakeholders.
  • Participate in configuration control and change-review activities affecting cybersecurity posture, in coordination with program, engineering, and security personnel.

Desired Education:

  • Bachelorโ€™s degree in Cybersecurity, Information Technology, Computer Science, Computer Engineering, Information Systems, or a related technical field.

Desired Experience:

  • 3+ years of information assurance, cybersecurity engineering, ISSO/ISSE, or related DoD cyber compliance experience.
  • Experience supporting the Risk Management Framework (RMF) for DoD information systems.
  • Experience developing or updating RMF/security authorization documentation such as SSP, RAR, SAP, SAR, POA&M, IRP, CP, SOPs, and CMPs.
  • Working knowledge of FISMA, FIPS, NIST, DoDI 8510.01, DoDI 8500.01, and related cybersecurity guidance.
  • Experience performing or supporting vulnerability scanning, STIG review, assessment, and remediation analysis.
  • Familiarity with tools such as Tenable Nessus, SCC, and related assessment/compliance tooling.
  • Ability to assess evolving threats, communicate technical risk clearly, and support practical remediation in an operational environment.
  • Strong written and verbal communication skills and ability to work effectively with engineers, ISSOs, ISSMs, administrators, and Government stakeholders.

Preferred Qualifications:

  • Current experience providing DoD ISSO/ISSE support in a Navy or tactical systems environment.
  • Experience supporting systems hosted in cloud, Agile, or DevSecOps environments.
  • Familiarity with DITPR-DON, DADMS, eMASS-equivalent workflows, and Navy authorization package routing.
  • Experience supporting continuous monitoring, patch management, configuration management, and ATO sustainment activities.
  • One or more of the following certifications:
    • CISSP
    • CASP+
    • CISA
    • CEH
    • CISM

Must be able to obtain and maintain a Secret security clearance. Due to the sensitivity of customer related requirements, U.S. Citizenship is required.

Precise Systems is dedicated to a shared vision and core values of Integrity, Respect, and Responsibility, which foster innovation and drive our continued success in the global marketplace. Precise Systems and its subsidiaries are Equal Opportunity /Affirmative Action Employers. All qualified applicants will receive consideration for employment without regard to race, color, religion, age, sex, sexual orientation, gender identity, national origin, protected veteran status, status as an individual with a disability, or any legally protected status under federal, state, or local law. Visit www.GoPrecise.com for a listing of current openings and our comprehensive, employee friendly benefits summary.  Precise Systems participates in E-Verify.


Required Skills
Required Experience