1

Security Controls Assessor Jobs in Rhode Island (NOW HIRING)

next page

Showing results 1-20

Security Controls Assessor information

See Rhode Island salary details

$8

$57

$76

How much do security controls assessor jobs pay per hour?

As of Aug 8, 2026, the average hourly pay for security controls assessor in Rhode Island is $57.55, according to ZipRecruiter salary data. Most workers in this role earn between $49.42 and $66.63 per hour, depending on experience, location, and employer.

What is a security controls assessor?

Security Controls Assessors are professionals responsible for evaluating and validating the effectiveness of security controls within an organization's information systems. They conduct assessments to ensure compliance with regulatory standards, such as NIST, FISMA, or other security frameworks. Their work helps organizations identify vulnerabilities, manage risks, and maintain the confidentiality, integrity, and availability of critical data. Security Controls Assessors often provide recommendations for remediation and support efforts to achieve or maintain security certifications.

What are the key skills and qualifications needed to thrive as a security controls assessor, and why are they important?

To thrive as a Security Controls Assessor, you need expertise in information security frameworks, risk assessment methodologies, and compliance requirements, often supported by a degree in cybersecurity or related fields and certifications like CISSP, CISA, or CAP. Familiarity with tools such as vulnerability scanners, security assessment platforms, and compliance management systems is typically required. Strong analytical thinking, attention to detail, and effective communication skills help you identify risks and clearly report findings to stakeholders. These skills ensure that organizations maintain robust security postures and meet regulatory requirements to protect critical assets.

What are some common challenges security controls assessors face when evaluating compliance across multiple systems?

Security Controls Assessors often encounter challenges with inconsistent documentation, varying system configurations, and differing interpretations of compliance standards across departments. Coordinating with multiple teams to collect evidence and clarify control implementations can be time-consuming, especially in large organizations. Staying current with evolving regulations and ensuring all systems meet the latest requirements also demands continuous learning and adaptability. Building strong communication channels with system owners and IT staff helps overcome these hurdles and ensures thorough, accurate assessments.

What does a security controls assessor do?

A security controls assessor (SCA) evaluates the security controls within network systems to identify vulnerabilities and recommend actions to correct problems, working either alone or as part of a team. As a security controls assessor, your duties begin with conducting an in-depth assessment of the management, operations, and technical security controls. You must analyze information and prepare reports describing the vulnerability level of the network with specific detail as to what compromises data systems. You then develop a plan to address vulnerabilities and continue to monitor the security of network systems.

What is the difference between Security Controls Assessor vs Security Analyst?

AspectSecurity Controls AssessorSecurity Analyst
CertificationsISO 27001 Lead Auditor, CISSP, CISACISSP, Security+
Work EnvironmentAssessing security controls, compliance auditsMonitoring security systems, incident response
Employer & IndustryGovernment agencies, compliance firmsCorporate IT, cybersecurity teams

The Security Controls Assessor primarily evaluates and verifies security controls for compliance, often in government or regulated environments. In contrast, a Security Analyst focuses on monitoring, analyzing, and responding to security threats within organizations. While both roles require security certifications and involve cybersecurity, their core responsibilities and work settings differ significantly.

What are the most commonly searched types of Security Controls Assessor jobs in Rhode Island? The most popular types of Security Controls Assessor jobs in Rhode Island are:
What are popular job titles related to Security Controls Assessor jobs in Rhode Island? For Security Controls Assessor jobs in Rhode Island, the most frequently searched job titles are:
What job categories do people searching Security Controls Assessor jobs in Rhode Island look for? The top searched job categories for Security Controls Assessor jobs in Rhode Island are:
What are popular job titles related to Security Controls Assessor jobs in RI? For Security Controls Assessor jobs in RI, the most frequently searched job titles are:
Infographic showing various Security Controls Assessor job openings in Rhode Island as of August 2026, with employment types broken down into 85% Full Time, 5% Part Time, 5% Temporary, and 5% Contract. Highlights an 86% In-person, and 14% Remote job distribution, with an average salary of $119,707 per year, or $57.6 per hour.

Information Systems Security Officer

Philadelphia Media Network, Pbc

Middletown, RI

Full-time

Posted 10 days ago


Job description

We are seeking an experienced Information Systems Security Officer (ISSO) to support cybersecurity compliance and accreditation activities supporting a Department of Defense (DoD) cloud environment. The ideal candidate will possess extensive experience navigating the Navy Authorization to Operate (ATO) process and will serve as a cybersecurity resource responsible for guiding the system through the DoD Risk Management Framework (RMF) lifecycle. This position will work closely with government stakeholders, engineering teams, cloud architects, and program leadership to achieve and maintain authorization while ensuring compliance with DoD cybersecurity requirements.

Primary Responsibilities: Lead cybersecurity activities throughout the DoD Risk Management Framework (RMF) lifecycle. Manage the development, review, and maintenance of RMF artifacts and authorization documentation. Serve as the primary ISSO supporting the achievement of a Navy Authorization to Operate (ATO).

Coordinate directly with government Authorizing Officials (AO), Information System Security Managers (ISSM), validators, and cybersecurity representatives. Build and maintain effective working relationships with Navy cybersecurity organizations to facilitate the authorization process. Utilize eMASS to manage security controls, documentation, findings, and authorization packages.

Coordinate Security Technical Implementation Guide (STIG) implementation and validation across Windows, Linux, networking, and cloud environments. Conduct security control assessments against NIST SP 800-53 requirements. Support vulnerability management, POA&M development, and continuous monitoring activities.

Collaborate with engineering teams to implement secure cloud architectures within Azure Government and/or AWS GovCloud. Assist with DoD Cloud Security Requirements Guide (SRG) compliance activities. Support future Secret-level accreditation efforts and classified system expansion.

Provide cybersecurity guidance throughout system design, implementation, and operational phases. Develop executive-level status reports and communicate cybersecurity risks to technical and non-technical stakeholders.Active Secret Security Clearance Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related discipline (or equivalent experience) 5+ years supporting DoD cybersecurity programs Demonstrated experience implementing the DoD Risk Management Framework (RMF) Extensive experience with Navy Authorization to Operate (ATO) processes Strong working knowledge of: NIST SP 800-53 DoD RMF Security Controls Assessment process POA&M management Continuous Monitoring Experience using eMASS Active DoD CAC (preferred) or ability to obtain eMASS access Experience implementing and remediating Security Technical Implementation Guides (STIGs) Familiarity with Microsoft Azure Government and/or AWS GovCloud Understanding of FedRAMP security requirements and cloud compliance Working knowledge of the DoD Cloud Computing Security Requirements Guide (Cloud SRG) Excellent communication and documentation skills Highly Desired Qualifications: Extensive experience obtaining Navy ATOs Existing relationships within Navy cybersecurity organizations Current Navy CAC with Flank Speed access Ability to access SIPRNet on a regular basis Experience supporting Secret or higher classified information systems Xacta experience TS/SCI Security Clearance CISSP, CAP, Security+, CASP+, or equivalent DoD 8570/8140 certificationsActive Secret Security Clearance Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related discipline (or equivalent experience) 5+ years supporting DoD cybersecurity programs Demonstrated experience implementing the DoD Risk Management Framework (RMF) Extensive experience with Navy Authorization to Operate (ATO) processes Strong working knowledge of: NIST SP 800-53 DoD RMF Security Controls Assessment process POA&M management Continuous Monitoring Experience using eMASS Active DoD CAC (preferred) or ability to obtain eMASS access Experience implementing and remediating Security Technical Implementation Guides (STIGs) Familiarity with Microsoft Azure Government and/or AWS GovCloud Understanding of FedRAMP security requirements and cloud compliance Working knowledge of the DoD Cloud Computing Security Requirements Guide (Cloud SRG) Excellent communication and documentation skills Highly Desired Qualifications: Extensive experience obtaining Navy ATOs Existing relationships within Navy cybersecurity organizations Current Navy CAC with Flank Speed access Ability to access SIPRNet on a regular basis Experience supporting Secret or higher classified information systems Xacta experience TS/SCI Security Clearance CISSP, CAP, Security+, CASP+, or equivalent DoD 8570/8140 certifications.