NIST SP 800-53 DoD RMF Security Controls Assessment process POA&M management Continuous Monitoring Experience using eMASS Active DoD CAC (preferred) or ability to obtain eMASS access Experience ...
NIST SP 800-53 DoD RMF Security Controls Assessment process POA&M management Continuous Monitoring Experience using eMASS Active DoD CAC (preferred) or ability to obtain eMASS access Experience ...
DoD RMF * Security Controls Assessment process * POA&M management * Continuous Monitoring * Experience using eMASS * Active DoD CAC (preferred) or ability to obtain eMASS access * Experience ...
DoD RMF * Security Controls Assessment process * POA&M management * Continuous Monitoring * Experience using eMASS * Active DoD CAC (preferred) or ability to obtain eMASS access * Experience ...
DoD RMF * Security Controls Assessment process * POA&M management * Continuous Monitoring * Experience using eMASS * Active DoD CAC (preferred) or ability to obtain eMASS access * Experience ...
DoD RMF * Security Controls Assessment process * POA&M management * Continuous Monitoring * Experience using eMASS * Active DoD CAC (preferred) or ability to obtain eMASS access * Experience ...
NIST SP 800-53 DoD RMF Security Controls Assessment process POA&M management Continuous Monitoring Experience using eMASS Active DoD CAC (preferred) or ability to obtain eMASS access Experience ...
NIST SP 800-53 DoD RMF Security Controls Assessment process POA&M management Continuous Monitoring Experience using eMASS Active DoD CAC (preferred) or ability to obtain eMASS access Experience ...
... controls in compliance with DoD and DON policies • Support system security posture and continuous monitoring activities Assessment & Authorization (A&A): • Assist in the development and ...
... controls in compliance with DoD and DON policies • Support system security posture and continuous monitoring activities Assessment & Authorization (A&A): • Assist in the development and ...
Implement and maintain security controls in compliance with DoD and DON policies Support system security posture and continuous monitoring activities Assessment & Authorization (A&A): Assist in the ...
Implement and maintain security controls in compliance with DoD and DON policies Support system security posture and continuous monitoring activities Assessment & Authorization (A&A): Assist in the ...
... controls in compliance with DoD and DON policies · Support system security posture and continuous monitoring activities Assessment & Authorization (A&A): · Assist in the development and maintenance ...
Quick apply
... controls in compliance with DoD and DON policies · Support system security posture and continuous monitoring activities Assessment & Authorization (A&A): · Assist in the development and maintenance ...
Information Systems Security Engineer with Security Clearance
Newport, RI · On-site
$100K - $130K/yr
Working knowledge of the DoD Risk Management Framework and Assessment and Authorization processes. * Knowledge of security controls, compliance documentation, vulnerability management, and ...
Information Systems Security Engineer with Security Clearance
Newport, RI · On-site
$100K - $130K/yr
Working knowledge of the DoD Risk Management Framework and Assessment and Authorization processes. * Knowledge of security controls, compliance documentation, vulnerability management, and ...
Conduct risk assessments and vulnerability analyses on AI models and cloud infrastructure * Develop ... Collaborate with engineering teams to integrate security controls into AI workflows * Lead security ...
Conduct risk assessments and vulnerability analyses on AI models and cloud infrastructure * Develop ... Collaborate with engineering teams to integrate security controls into AI workflows * Lead security ...
Conduct risk assessments and vulnerability analyses on AI models and cloud infrastructure * Develop ... Collaborate with engineering teams to integrate security controls into AI workflows * Lead security ...
Conduct risk assessments and vulnerability analyses on AI models and cloud infrastructure * Develop ... Collaborate with engineering teams to integrate security controls into AI workflows * Lead security ...
Information Systems Security Engineer
Newport, RI · On-site
$100K - $130K/yr
Working knowledge of the DoD Risk Management Framework and Assessment and Authorization processes. * Knowledge of security controls, compliance documentation, vulnerability management, and ...
Information Systems Security Engineer
Newport, RI · On-site
$100K - $130K/yr
Working knowledge of the DoD Risk Management Framework and Assessment and Authorization processes. * Knowledge of security controls, compliance documentation, vulnerability management, and ...
DevSecOps Engineer, Staff with Security Clearance
Middletown, RI · On-site
$82K - $131K/yr
Manage system services, networking, access controls, logging, and system monitoring on Linux ... Participate in technical reviews, risk assessments, and planning sessions with program stakeholders ...
DevSecOps Engineer, Staff with Security Clearance
Middletown, RI · On-site
$82K - $131K/yr
Manage system services, networking, access controls, logging, and system monitoring on Linux ... Participate in technical reviews, risk assessments, and planning sessions with program stakeholders ...
Information Security Controls and Process Analysis, Application & Security Risk Assessments as well as Identity & Access Management. Tested and implemented administrator/root passwords from a variety ...
Information Security Controls and Process Analysis, Application & Security Risk Assessments as well as Identity & Access Management. Tested and implemented administrator/root passwords from a variety ...
Build and operationalize security controls that protect AI applications, models, agents, prompts ... Integrate automated security validation, adversarial testing, and model robustness assessments into ...
Build and operationalize security controls that protect AI applications, models, agents, prompts ... Integrate automated security validation, adversarial testing, and model robustness assessments into ...
Build and operationalize security controls that protect AI applications, models, agents, prompts ... Integrate automated security validation, adversarial testing, and model robustness assessments into ...
Build and operationalize security controls that protect AI applications, models, agents, prompts ... Integrate automated security validation, adversarial testing, and model robustness assessments into ...
Build and operationalize security controls that protect AI applications, models, agents, prompts ... Integrate automated security validation, adversarial testing, and model robustness assessments into ...
Build and operationalize security controls that protect AI applications, models, agents, prompts ... Integrate automated security validation, adversarial testing, and model robustness assessments into ...
Build and operationalize security controls that protect AI applications, models, agents, prompts ... Integrate automated security validation, adversarial testing, and model robustness assessments into ...
Build and operationalize security controls that protect AI applications, models, agents, prompts ... Integrate automated security validation, adversarial testing, and model robustness assessments into ...
Build and operationalize security controls that protect AI applications, models, agents, prompts ... Integrate automated security validation, adversarial testing, and model robustness assessments into ...
Build and operationalize security controls that protect AI applications, models, agents, prompts ... Integrate automated security validation, adversarial testing, and model robustness assessments into ...
Build and operationalize security controls that protect AI applications, models, agents, prompts ... Integrate automated security validation, adversarial testing, and model robustness assessments into ...
Build and operationalize security controls that protect AI applications, models, agents, prompts ... Integrate automated security validation, adversarial testing, and model robustness assessments into ...
Build and operationalize security controls that protect AI applications, models, agents, prompts ... Integrate automated security validation, adversarial testing, and model robustness assessments into ...
Build and operationalize security controls that protect AI applications, models, agents, prompts ... Integrate automated security validation, adversarial testing, and model robustness assessments into ...
Security Controls Assessor information
See Rhode Island salary details
$8.71 - $14.87
2% of jobs
$14.87 - $21.04
2% of jobs
$21.04 - $27.20
0% of jobs
$27.20 - $33.36
0% of jobs
$33.36 - $39.53
3% of jobs
$39.53 - $45.69
5% of jobs
$49.31 is the 25th percentile. Wages below this are outliers.
$45.69 - $51.85
21% of jobs
The median wage is $56.88 / hr.
$51.85 - $58.02
20% of jobs
$58.02 - $64.18
18% of jobs
$65.61 is the 75th percentile. Wages above this are outliers.
$64.18 - $70.35
15% of jobs
$70.35 - $76.51
14% of jobs
$8
$57
$76
How much do security controls assessor jobs pay per hour?
What is a security controls assessor?
What are the key skills and qualifications needed to thrive as a security controls assessor, and why are they important?
What are some common challenges security controls assessors face when evaluating compliance across multiple systems?
What does a security controls assessor do?
A security controls assessor (SCA) evaluates the security controls within network systems to identify vulnerabilities and recommend actions to correct problems, working either alone or as part of a team. As a security controls assessor, your duties begin with conducting an in-depth assessment of the management, operations, and technical security controls. You must analyze information and prepare reports describing the vulnerability level of the network with specific detail as to what compromises data systems. You then develop a plan to address vulnerabilities and continue to monitor the security of network systems.
What is the difference between Security Controls Assessor vs Security Analyst?
| Aspect | Security Controls Assessor | Security Analyst |
|---|---|---|
| Certifications | ISO 27001 Lead Auditor, CISSP, CISA | CISSP, Security+ |
| Work Environment | Assessing security controls, compliance audits | Monitoring security systems, incident response |
| Employer & Industry | Government agencies, compliance firms | Corporate IT, cybersecurity teams |
The Security Controls Assessor primarily evaluates and verifies security controls for compliance, often in government or regulated environments. In contrast, a Security Analyst focuses on monitoring, analyzing, and responding to security threats within organizations. While both roles require security certifications and involve cybersecurity, their core responsibilities and work settings differ significantly.

Full-time
Posted 10 days ago
Job description
We are seeking an experienced Information Systems Security Officer (ISSO) to support cybersecurity compliance and accreditation activities supporting a Department of Defense (DoD) cloud environment. The ideal candidate will possess extensive experience navigating the Navy Authorization to Operate (ATO) process and will serve as a cybersecurity resource responsible for guiding the system through the DoD Risk Management Framework (RMF) lifecycle. This position will work closely with government stakeholders, engineering teams, cloud architects, and program leadership to achieve and maintain authorization while ensuring compliance with DoD cybersecurity requirements.
Primary Responsibilities: Lead cybersecurity activities throughout the DoD Risk Management Framework (RMF) lifecycle. Manage the development, review, and maintenance of RMF artifacts and authorization documentation. Serve as the primary ISSO supporting the achievement of a Navy Authorization to Operate (ATO).
Coordinate directly with government Authorizing Officials (AO), Information System Security Managers (ISSM), validators, and cybersecurity representatives. Build and maintain effective working relationships with Navy cybersecurity organizations to facilitate the authorization process. Utilize eMASS to manage security controls, documentation, findings, and authorization packages.
Coordinate Security Technical Implementation Guide (STIG) implementation and validation across Windows, Linux, networking, and cloud environments. Conduct security control assessments against NIST SP 800-53 requirements. Support vulnerability management, POA&M development, and continuous monitoring activities.
Collaborate with engineering teams to implement secure cloud architectures within Azure Government and/or AWS GovCloud. Assist with DoD Cloud Security Requirements Guide (SRG) compliance activities. Support future Secret-level accreditation efforts and classified system expansion.
Provide cybersecurity guidance throughout system design, implementation, and operational phases. Develop executive-level status reports and communicate cybersecurity risks to technical and non-technical stakeholders.Active Secret Security Clearance Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related discipline (or equivalent experience) 5+ years supporting DoD cybersecurity programs Demonstrated experience implementing the DoD Risk Management Framework (RMF) Extensive experience with Navy Authorization to Operate (ATO) processes Strong working knowledge of: NIST SP 800-53 DoD RMF Security Controls Assessment process POA&M management Continuous Monitoring Experience using eMASS Active DoD CAC (preferred) or ability to obtain eMASS access Experience implementing and remediating Security Technical Implementation Guides (STIGs) Familiarity with Microsoft Azure Government and/or AWS GovCloud Understanding of FedRAMP security requirements and cloud compliance Working knowledge of the DoD Cloud Computing Security Requirements Guide (Cloud SRG) Excellent communication and documentation skills Highly Desired Qualifications: Extensive experience obtaining Navy ATOs Existing relationships within Navy cybersecurity organizations Current Navy CAC with Flank Speed access Ability to access SIPRNet on a regular basis Experience supporting Secret or higher classified information systems Xacta experience TS/SCI Security Clearance CISSP, CAP, Security+, CASP+, or equivalent DoD 8570/8140 certificationsActive Secret Security Clearance Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related discipline (or equivalent experience) 5+ years supporting DoD cybersecurity programs Demonstrated experience implementing the DoD Risk Management Framework (RMF) Extensive experience with Navy Authorization to Operate (ATO) processes Strong working knowledge of: NIST SP 800-53 DoD RMF Security Controls Assessment process POA&M management Continuous Monitoring Experience using eMASS Active DoD CAC (preferred) or ability to obtain eMASS access Experience implementing and remediating Security Technical Implementation Guides (STIGs) Familiarity with Microsoft Azure Government and/or AWS GovCloud Understanding of FedRAMP security requirements and cloud compliance Working knowledge of the DoD Cloud Computing Security Requirements Guide (Cloud SRG) Excellent communication and documentation skills Highly Desired Qualifications: Extensive experience obtaining Navy ATOs Existing relationships within Navy cybersecurity organizations Current Navy CAC with Flank Speed access Ability to access SIPRNet on a regular basis Experience supporting Secret or higher classified information systems Xacta experience TS/SCI Security Clearance CISSP, CAP, Security+, CASP+, or equivalent DoD 8570/8140 certifications.