1

Security Controls Assessor Jobs in Michigan (NOW HIRING)

IT Security Analyst

Lansing, MI · Hybrid

$27.59 - $47.59/hr

The ideal candidate will have experience with security governance, NIST security controls, Governance, Risk, and Compliance (GRC) tools, risk assessments, and security documentation, along with ...

Application Security Analyst

Auburn Hills, MI · On-site

$55.50 - $74.25/hr

Integrate security controls into development workflows WAF & Security Controls * Lead Web ... Conduct security assessments using standard tools * Track and report: * Risks * Milestones

Design, implement, and manage security controls, leveraging Microsoft 365 E5 Security and ... Conduct regular security assessments, vulnerability scans, and penetration tests to identify and ...

Knowledge of NIST, System Security Plans (SSP), Governance, Risk & Compliance (GRC), and security controls. * Experience performing risk assessments, vulnerability remediation, and compliance ...

Knowledge of NIST, System Security Plans (SSP), Governance, Risk & Compliance (GRC), and security controls. * Experience performing risk assessments, vulnerability remediation, and compliance ...

Application Security Analyst

Auburn Hills, MI

$55.50 - $74.25/hr

Integrate security controls into development workflows WAF & Security Controls * Lead Web ... Conduct security assessments using standard tools * Track and report: * Risks * Milestones

Monitor and advise on information security issues related to the systems & workflow @ an agency to ... NIST controls. Ability to lead small, less complex system assessments independently Ability to ...

next page

Showing results 1-20

Security Controls Assessor information

See Michigan salary details

$7

$51

$68

How much do security controls assessor jobs pay per hour?

As of Aug 16, 2026, the average hourly pay for security controls assessor in Michigan is $51.22, according to ZipRecruiter salary data. Most workers in this role earn between $43.99 and $59.28 per hour, depending on experience, location, and employer.

What is a security controls assessor?

Security Controls Assessors are professionals responsible for evaluating and validating the effectiveness of security controls within an organization's information systems. They conduct assessments to ensure compliance with regulatory standards, such as NIST, FISMA, or other security frameworks. Their work helps organizations identify vulnerabilities, manage risks, and maintain the confidentiality, integrity, and availability of critical data. Security Controls Assessors often provide recommendations for remediation and support efforts to achieve or maintain security certifications.

What are the key skills and qualifications needed to thrive as a security controls assessor, and why are they important?

To thrive as a Security Controls Assessor, you need expertise in information security frameworks, risk assessment methodologies, and compliance requirements, often supported by a degree in cybersecurity or related fields and certifications like CISSP, CISA, or CAP. Familiarity with tools such as vulnerability scanners, security assessment platforms, and compliance management systems is typically required. Strong analytical thinking, attention to detail, and effective communication skills help you identify risks and clearly report findings to stakeholders. These skills ensure that organizations maintain robust security postures and meet regulatory requirements to protect critical assets.

What are some common challenges security controls assessors face when evaluating compliance across multiple systems?

Security Controls Assessors often encounter challenges with inconsistent documentation, varying system configurations, and differing interpretations of compliance standards across departments. Coordinating with multiple teams to collect evidence and clarify control implementations can be time-consuming, especially in large organizations. Staying current with evolving regulations and ensuring all systems meet the latest requirements also demands continuous learning and adaptability. Building strong communication channels with system owners and IT staff helps overcome these hurdles and ensures thorough, accurate assessments.

What does a security controls assessor do?

A security controls assessor (SCA) evaluates the security controls within network systems to identify vulnerabilities and recommend actions to correct problems, working either alone or as part of a team. As a security controls assessor, your duties begin with conducting an in-depth assessment of the management, operations, and technical security controls. You must analyze information and prepare reports describing the vulnerability level of the network with specific detail as to what compromises data systems. You then develop a plan to address vulnerabilities and continue to monitor the security of network systems.

What is the difference between Security Controls Assessor vs Security Analyst?

AspectSecurity Controls AssessorSecurity Analyst
CertificationsISO 27001 Lead Auditor, CISSP, CISACISSP, Security+
Work EnvironmentAssessing security controls, compliance auditsMonitoring security systems, incident response
Employer & IndustryGovernment agencies, compliance firmsCorporate IT, cybersecurity teams

The Security Controls Assessor primarily evaluates and verifies security controls for compliance, often in government or regulated environments. In contrast, a Security Analyst focuses on monitoring, analyzing, and responding to security threats within organizations. While both roles require security certifications and involve cybersecurity, their core responsibilities and work settings differ significantly.

What are popular job titles related to Security Controls Assessor jobs in Michigan?

For Security Controls Assessor jobs in Michigan, the most frequently searched job titles are:

What job categories do people searching Security Controls Assessor jobs in Michigan look for?

The top searched job categories for Security Controls Assessor jobs in Michigan are:

What cities in Michigan are hiring for Security Controls Assessor jobs?

Cities in Michigan with the most Security Controls Assessor job openings:

What are popular job titles related to Security Controls Assessor jobs in MI?

For Security Controls Assessor jobs in MI, the most frequently searched job titles are:

Infographic showing various Security Controls Assessor job openings in Michigan as of August 2026, with employment types broken down into 83% Full Time, 12% Part Time, 1% Temporary, and 4% Contract. Highlights an 92% Physical, 3% Hybrid, and 5% Remote job distribution, with an average salary of $106,540 per year, or $51.2 per hour.

IT Security Analyst

KēSTA I.T.

Lansing, MI • Hybrid

$27.59 - $47.59/hr

Full-time

Retirement, PTO

Posted 11 days ago


Job description

Come build, innovate, disrupt, and thrive!

KēSTA I.T is actively seeking a IT Security Analyst for an immediate contract engagement with our government client.

Work Location: This position is Hybrid

Job Description:

We Are Seeking an IT Security Analyst to support enterprise security compliance, governance, and risk management initiatives by developing, maintaining, and validating System Security Plans (SSPs) for new and existing information systems. This role is responsible for collaborating with cross-functional technical and business teams to ensure systems comply with security standards, regulatory requirements, and organizational policies. The ideal candidate will have experience with security governance, NIST security controls, Governance, Risk, and Compliance (GRC) tools, risk assessments, and security documentation, along with strong analytical, communication, and problem-solving skills.

Responsibilities:

·         Develop, maintain, and update System Security Plans (SSPs) for new and existing enterprise applications and systems.

·         Collaborate with project managers, system owners, security administrators, technical leads, product owners, and business stakeholders to establish and document security processes and controls.

·         Support Authority to Operate (ATO) activities and ensure compliance with organizational security accreditation processes.

·         Create and maintain security documentation within Governance, Risk, and Compliance (GRC) platforms.

·         Coordinate system registration activities and maintain required security documentation throughout the system lifecycle.

·         Perform risk assessments and document responses for security control implementation.

·         Identify security vulnerabilities and collaborate with technical teams to develop remediation plans.

·         Validate security controls to ensure compliance with NIST standards, organizational policies, and applicable regulatory requirements.

·         Lead security testing, vulnerability scanning, and system assessment activities.

·         Monitor Plans of Action and Milestones (POA&Ms) and Corrective Action Plans (CAPs) to ensure timely remediation of identified risks.

·         Coordinate security scanning and assessment activities with internal security teams, project teams, and business stakeholders.

·         Lead data classification activities as part of the SSP and ATO processes.

·         Collect, review, and validate security artifacts required for compliance assessments and audits.

·         Develop recommendations to strengthen system security posture and improve compliance with security standards.

·         Maintain technical documentation and provide ongoing support for enterprise security governance initiatives.

Required Skills:

Required Qualifications

·         Bachelor's degree in Information Technology, Computer Science, Cybersecurity, Computer Information Systems, Mathematics, or a related field, or an associate degree with qualifying technical coursework and relevant professional experience, or a high school diploma (or equivalent) with qualifying information technology experience, or an industry-recognized IT or Cybersecurity certification.

·         1–3 years of experience in information security, cybersecurity, compliance, governance, risk management, or a related field.

·         Knowledge of System Security Plans (SSPs), security governance, and compliance processes.

·         Familiarity with Governance, Risk, and Compliance (GRC) tools and security documentation.

·         Understanding of NIST security frameworks, security controls, and cybersecurity best practices.

·         Experience supporting security assessments, risk assessments, vulnerability management, and compliance initiatives.

·         Knowledge of Authority to Operate (ATO), Plans of Action and Milestones (POA&Ms), and Corrective Action Plans (CAPs).

·         Experience coordinating with technical teams, business stakeholders, and security personnel to implement security requirements.

·         Strong analytical, troubleshooting, and problem-solving skills.

·         Excellent written and verbal communication skills with the ability to create clear technical documentation.

·         Ability to manage multiple priorities while working independently and collaboratively in a team environment.

Preferred Qualifications

·         Experience using Keylight or similar Governance, Risk, and Compliance (GRC) platforms.

·         Experience supporting enterprise application security compliance initiatives.

·         Knowledge of Secure Application Development Life Cycle (SADLC) practices.

·         Experience with vulnerability scanning, security testing, and security accreditation processes.

·         Familiarity with data classification methodologies and enterprise security governance.

·         Experience working within regulated or large enterprise IT environments.

 

Available Benefits:

·         Medical Benefits (Platinum level plans available)

·         Work from home / Hybrid / Onsite options

·         PTO

·         Holiday Pay

·         VTO

·         401K

·         Charitable Match

·         Training reimbursement

About KēSTA I.T.:

Our name says it all; KēSTA I.T. (Keys-to-I.T.) AND our people are our keys to our success!

 

KēSTA I.T. is a premier Utah-based technical staffing and consulting services firm. We specialize in temporary and permanent placement of Software, Hardware, Network, Cloud, CRM/ERP, Data, End-User support, Web and Executive / leadership-based positions on a full time and consulting basis.

If you're interested in a role where top performance is rewarded, personal time is valued, and excellence is demanded at every level we want to talk to you today! 

 

Where do you want to go? We've got the keys! ~ KēSTA I.T.

 

WWW.KeSTAIT.COM