Continuously assess effectiveness of enterprise security controls as the ecosystem expands and the threat landscape evolves, supplement or extend coverage accordingly. * Proactively partner with ...
Continuously assess effectiveness of enterprise security controls as the ecosystem expands and the threat landscape evolves, supplement or extend coverage accordingly. * Proactively partner with ...
Conduct cyber threat assessments and recommend solutions for identified deficiencies. * Support ... Translate security controls into system requirements and verify threat mitigations. * Participate ...
Conduct cyber threat assessments and recommend solutions for identified deficiencies. * Support ... Translate security controls into system requirements and verify threat mitigations. * Participate ...
Application Security Analyst
Auburn Hills, MI ยท On-site
$55.50 - $74.25/hr
Integrate security controls into development workflows WAF & Security Controls * Lead Web ... Conduct security assessments using standard tools * Track and report: * Risks * Milestones
Application Security Analyst
Auburn Hills, MI ยท On-site
$55.50 - $74.25/hr
Integrate security controls into development workflows WAF & Security Controls * Lead Web ... Conduct security assessments using standard tools * Track and report: * Risks * Milestones
Security Engineer
Auburn Hills, MI ยท On-site
Lead and manage all cybersecurity audits, including ISO 27001 and TISAX assessments * Own audit ... Partner with IT and business teams to ensure controls are implemented and operating effectively ...
Security Engineer
Auburn Hills, MI ยท On-site
Lead and manage all cybersecurity audits, including ISO 27001 and TISAX assessments * Own audit ... Partner with IT and business teams to ensure controls are implemented and operating effectively ...
Security Engineer
Auburn Hills, MI ยท On-site
Lead and manage all cybersecurity audits, including ISO 27001 and TISAX assessments * Own audit ... Partner with IT and business teams to ensure controls are implemented and operating effectively ...
Security Engineer
Auburn Hills, MI ยท On-site
Lead and manage all cybersecurity audits, including ISO 27001 and TISAX assessments * Own audit ... Partner with IT and business teams to ensure controls are implemented and operating effectively ...
Conduct cyber threat assessments and recommend solutions for identified deficiencies. * Support ... Translate security controls into system requirements and verify threat mitigations. * Participate ...
Conduct cyber threat assessments and recommend solutions for identified deficiencies. * Support ... Translate security controls into system requirements and verify threat mitigations. * Participate ...
Perform risk assessments and provide responses for security controls. * Continuously monitor plans of action and milestones and corrective action plans as they relate to the SSPs in collaboration ...
Perform risk assessments and provide responses for security controls. * Continuously monitor plans of action and milestones and corrective action plans as they relate to the SSPs in collaboration ...
... cyber threat assessments and recommend solutions for identified deficiencies. โข Support ... security controls into system requirements and verify threat mitigations. โข Participate in ...
... cyber threat assessments and recommend solutions for identified deficiencies. โข Support ... security controls into system requirements and verify threat mitigations. โข Participate in ...
Assess threats and vulnerabilities regarding information assets and recommend the appropriate information security controls and measures. Develop and implement strategies to align information ...
Assess threats and vulnerabilities regarding information assets and recommend the appropriate information security controls and measures. Develop and implement strategies to align information ...
Design, implement, and manage security controls, leveraging Microsoft 365 E5 Security and ... Conduct regular security assessments, vulnerability scans, and penetration tests to identify and ...
Quick apply
Design, implement, and manage security controls, leveraging Microsoft 365 E5 Security and ... Conduct regular security assessments, vulnerability scans, and penetration tests to identify and ...
Application Security Analyst
$55.50 - $74.25/hr
Integrate security controls into development workflows WAF & Security Controls * Lead Web ... Conduct security assessments using standard tools * Track and report: * Risks * Milestones
Application Security Analyst
$55.50 - $74.25/hr
Integrate security controls into development workflows WAF & Security Controls * Lead Web ... Conduct security assessments using standard tools * Track and report: * Risks * Milestones
Conduct cyber threat assessments and recommend solutions for identified deficiencies. * Support ... Translate security controls into system requirements and verify threat mitigations. * Participate ...
Conduct cyber threat assessments and recommend solutions for identified deficiencies. * Support ... Translate security controls into system requirements and verify threat mitigations. * Participate ...
Associate Security Engineer
Wyoming, MI ยท Hybrid
... controls. * Contribute to the management and maintenance of security tools and technologies, ensuring optimal performance and effectiveness. * Participate in security audits and assessments ...
Associate Security Engineer
Wyoming, MI ยท Hybrid
... controls. * Contribute to the management and maintenance of security tools and technologies, ensuring optimal performance and effectiveness. * Participate in security audits and assessments ...
IT Security Analyst
Lansing, MI ยท On-site
Monitor and advise on information security issues related to the systems & workflow @ an agency to ... NIST controls. Ability to lead small, less complex system assessments independently Ability to ...
IT Security Analyst
Lansing, MI ยท On-site
Monitor and advise on information security issues related to the systems & workflow @ an agency to ... NIST controls. Ability to lead small, less complex system assessments independently Ability to ...
Information Technology Security Manager
Grand Rapids, MI ยท On-site
$121K - $133K/yr
Supports audits, assessments, and remediation activities. * Identifies and mitigates security risks across systems. * Maintains documentation of controls and security posture. * Develops, implements ...
Quick apply
Information Technology Security Manager
Grand Rapids, MI ยท On-site
$121K - $133K/yr
Supports audits, assessments, and remediation activities. * Identifies and mitigates security risks across systems. * Maintains documentation of controls and security posture. * Develops, implements ...
Sr Prin Security Engineer
$104K - $142K/yr
Conduct threat modeling and risk assessments to identify vulnerabilities, recommend mitigation strategies, and design effective security controls. * Collaborate with cross-functional teams, including ...
Sr Prin Security Engineer
$104K - $142K/yr
Conduct threat modeling and risk assessments to identify vulnerabilities, recommend mitigation strategies, and design effective security controls. * Collaborate with cross-functional teams, including ...
Sr Prin Security Engineer
$104K - $142K/yr
Conduct threat modeling and risk assessments to identify vulnerabilities, recommend mitigation strategies, and design effective security controls. * Collaborate with cross-functional teams, including ...
Sr Prin Security Engineer
$104K - $142K/yr
Conduct threat modeling and risk assessments to identify vulnerabilities, recommend mitigation strategies, and design effective security controls. * Collaborate with cross-functional teams, including ...
Sr Prin Security Engineer
Jackson, MI ยท On-site
$102K - $140K/yr
Conduct threat modeling and risk assessments to identify vulnerabilities, recommend mitigation strategies, and design effective security controls. * Collaborate with cross-functional teams, including ...
Sr Prin Security Engineer
Jackson, MI ยท On-site
$102K - $140K/yr
Conduct threat modeling and risk assessments to identify vulnerabilities, recommend mitigation strategies, and design effective security controls. * Collaborate with cross-functional teams, including ...
Sr Prin Security Engineer
Jackson, MI ยท On-site
$104K - $142K/yr
Conduct threat modeling and risk assessments to identify vulnerabilities, recommend mitigation strategies, and design effective security controls. * Collaborate with cross-functional teams, including ...
Sr Prin Security Engineer
Jackson, MI ยท On-site
$104K - $142K/yr
Conduct threat modeling and risk assessments to identify vulnerabilities, recommend mitigation strategies, and design effective security controls. * Collaborate with cross-functional teams, including ...
Security Auditor
Lansing, MI ยท On-site
... assessments. This position is not a member of the Security Operations Center, rather it is ... Security Controls, Cloud Security Alliance, SafeCode etc.) * 3+ years with both compiled and ...
Security Auditor
Lansing, MI ยท On-site
... assessments. This position is not a member of the Security Operations Center, rather it is ... Security Controls, Cloud Security Alliance, SafeCode etc.) * 3+ years with both compiled and ...
Security Controls Assessor information
See Michigan salary details
$7.75 - $13.24
2% of jobs
$13.24 - $18.72
2% of jobs
$18.72 - $24.21
0% of jobs
$24.21 - $29.69
0% of jobs
$29.69 - $35.18
3% of jobs
$35.18 - $40.67
5% of jobs
$43.89 is the 25th percentile. Wages below this are outliers.
$40.67 - $46.15
21% of jobs
The median wage is $50.63 / hr.
$46.15 - $51.64
20% of jobs
$51.64 - $57.12
18% of jobs
$58.40 is the 75th percentile. Wages above this are outliers.
$57.12 - $62.61
15% of jobs
$62.61 - $68.09
14% of jobs
$7
$51
$68
How much do security controls assessor jobs pay per hour?
What are Security Controls Assessors?
What are the key skills and qualifications needed to thrive as a Security Controls Assessor, and why are they important?
What are some common challenges Security Controls Assessors face when evaluating compliance across multiple systems?
What Does a Security Controls Assessor Do?
A security controls assessor (SCA) evaluates the security controls within network systems to identify vulnerabilities and recommend actions to correct problems, working either alone or as part of a team. As a security controls assessor, your duties begin with conducting an in-depth assessment of the management, operations, and technical security controls. You must analyze information and prepare reports describing the vulnerability level of the network with specific detail as to what compromises data systems. You then develop a plan to address vulnerabilities and continue to monitor the security of network systems.
What is the difference between Security Controls Assessor vs Security Analyst?
| Aspect | Security Controls Assessor | Security Analyst |
|---|---|---|
| Certifications | ISO 27001 Lead Auditor, CISSP, CISA | CISSP, Security+ |
| Work Environment | Assessing security controls, compliance audits | Monitoring security systems, incident response |
| Employer & Industry | Government agencies, compliance firms | Corporate IT, cybersecurity teams |
The Security Controls Assessor primarily evaluates and verifies security controls for compliance, often in government or regulated environments. In contrast, a Security Analyst focuses on monitoring, analyzing, and responding to security threats within organizations. While both roles require security certifications and involve cybersecurity, their core responsibilities and work settings differ significantly.

Other
Posted 10 days ago
Job description
Posting Type
Remote/Hybrid
Job Overview
The Advanced Security Engineer is a technically deep, hands-on practitioner who forms the operational backbone of the enterprise security function. Operating within a layered defense-in-depth program, this engineer owns the design, deployment, implementation and optimization of AI-enabled security technologies at all layers. With the goal of enabling automated orchestration of security operations into day-to-day detection and response capabilities, hardening rigor, and rapid response. This role works closely with the Senior Manager of Enterprise Security and cross-functional engineering teams to reduce the organization's attack surface, enable threat landscape adaptability, and improve detection and response times across Relativity's technical ecosystem.Job Description and Requirements
- As applicable, design, deploy and optimize security controls that span perimeter, network, host, application, identity and data layers, ensuring and maintaining effectiveness of controls at each layer.
- Collaborate cross-functionally to ensure controls are aligned to industry recognized frameworks.
- Validate that telemetry from each layer feeds the central analytics platforms and supports 360-degree visibility and appropriate attack surface coverage.
- Continuously assess effectiveness of enterprise security controls as the ecosystem expands and the threat landscape evolves, supplement or extend coverage accordingly.
- Proactively partner with IT, Engineering and other stakeholders to embed security controls natively.
- Periodically provide recommendations on technical design of security controls aligned to vulnerabilities, risks, issues and/or events.
- Support purple-team exercises and control-efficacy testing to verify depth and resilience under attack conditions.
- Ensure redundant, complementary security capabilities to prevent bypasses and ensure failure redundancy through all security layers.
Endpoint Security & Hardening
- Deploy, integrate, optimize and manage EDR/XDR platforms and periodically define custom detections and automated response actions across security tooling.
- Establish and enforce endpoint and image hardening baselines, configuration standards, and application control baselines.
- Integrate endpoint telemetry into the central analytics platform (or SIEM) to support security context and cross-domain correlation; ensure SIEM coverage is adequate and effective.
- Collaborate cross-functionally to ensure security events, exposures, vulnerabilities and alerts are remediated within appropriate SLA's.
- Investigate endpoint-based alerts and incidents through to root cause: perform triage, forensic artifact collection (memory, disk, logs), timeline reconstruction, and containment/eradication actions.
Threat Hunting
- Collaborate cross-functionally to support purple team exercises and analyze security telemetry to surface anomalous and malicious behavior to the relevant stakeholders.
- Develop, execute and document structured hunts mapped to MITRE ATT&CK and ATLAS techniques and current threat intelligence.
- Perform exposure analysis on identified vulnerabilities, zero-day, alert telemetry, threat intelligence feeds and notifications from partners and customers and conclude on exploitability risk and/or exposure.
- Maintain awareness of the evolving threat landscape, adversary TTP's, and emerging vulnerabilities and their relevance to Relativity's technical ecosystem and organizational trajectory.
- Standardize and document hunt methodology, hypotheses, and outcomes and collaborate with security stakeholders to mature threat hunting program over time.
- Convert successful hunts, exposure analysis, purple team findings and alerts into durable, automated detections and containment logic and improved coverage.
AI-Enabled Security Operations
- Build and maintain SOAR workflows that automate enrichment, triage, containment, and routine response actions.
- Measure and continuously improve the impact of automation on time-based detection, containment and response to reduce threat actor dwell time.
- Identify, evaluate and operationalize AI/ML capabilities for semantic anomaly detection, behavioral analytics, alert triage, and prioritization.
Data Security
- Implement data classification, discovery, and data security posture management across cloud and on-premises stores.
- Deploy and tune data loss prevention controls across endpoints, network, email, cloud and SaaS surfaces.
- Investigate data key risk indicators associated with data access, exfiltration, and integrating data telemetry into central analytics (SIEM).
Minimum Qualifications:
- Bachelor's in Computer Science, Information Security, or equivalent experience.
- 5+ years of hands-on experience in enterprise security engineering, with a focus on network and/or endpoint security domains (or) Master's Degree in Cybersecurity or relevant field.
- Hands-on experience with common security tools such as EDR, XDR, SIEM, CNAPP, CSPM, CWP, etc. and intermediate knowledge of applicable security technologies at all layers of the OSI model.
- Threat hunting, digital forensics, and/or detection engineering experience and writing automation scripts and rules for security enforcement and/or observability.
- Basic knowledge of industry standard common security benchmarks and frameworks (e.g., MITRE, NIST, etc.)
- Proficiency in at least one scripting/automation language (Python, Bash, or PowerShell) applied to modern containerized services, CLI based commands, and/or security specific use cases.
- Ability to communicate technical findings clearly to both engineering peers and non-technical stakeholders.
Preferred Qualifications:
- Familiarity with AI-enabled SecOps (e.g., detection: UEBA, ML-based alert prioritization, or AI-assisted threat hunting workflows)
- Basic knowledge of common cloud environments such as AWS, Azure or GCP.
- Working knowledge of software development lifecycle, software engineering practices or infrastructure as code environments: contributing endpoint or network security controls to CI/CD pipelines.
- Experience supporting compliance and audit requirements (SOC 2, ISO 27001, HIPAA) from a technical control perspective.
- Relevant certifications such as SEC+, CISSP, CISA, GCIH, GCFA, GCIA, GPEN, OSCP, CySA+, or equivalent.
Relativity is committed to competitive, fair, and equitable compensation practices.
This position is eligible for total compensation which includes a competitive base salary, an annual performance bonus, and long-term incentives.
The expected salary range for this role is between following values:
$104,000 and $156,000The final offered salary will be based on several factors, including but not limited to the candidate's depth of experience, skill set, qualifications, and internal pay equity. Hiring at the top end of the range would not be typical, to allow for future meaningful salary growth in this position.
Required Skills:
Endpoint Security, Network Security, Penetration Testing, Security Architecture Design, Security Automation, Security Information, Security Information and Event Management (SIEM), Security Operations, Threat Modeling, Vulnerability Management