1

Security Controls Assessor Jobs in Utah (NOW HIRING)

Yes The SCA is responsible for conducting a comprehensive assessment of the management, operational, and technical security controls employed within or inherited by an IS to determine the overall ...

Sr AI Security Engineer

Layton, UT · On-site

$120 - $194/hr

Help ensure AI systems handling sensitive healthcare and enterprise information are designed with appropriate security and privacy controls. * Assess how PHI, PII, and other sensitive information ...

Sr. IT Security Engineer

Draper, UT · On-site

$107K - $146K/yr

Partner with IT teams to ensure security controls are integrated into infrastructure and ... Support the vulnerability management program through assessment, prioritization, tracking, and ...

Sr. IT Security Engineer

Draper, UT · On-site

$107K - $146K/yr

Partner with IT teams to ensure security controls are integrated into infrastructure and ... Support the vulnerability management program through assessment, prioritization, tracking, and ...

Sr. IT Security Engineer

Draper, UT · On-site

$107K - $146K/yr

Partner with IT teams to ensure security controls are integrated into infrastructure and ... Support the vulnerability management program through assessment, prioritization, tracking, and ...

Sr. IT Security Engineer

Draper, UT · Hybrid

$100K - $130K/yr

Partner with IT teams to ensure security controls are integrated into infrastructure and ... Support the vulnerability management program through assessment, prioritization, tracking, and ...

Sr. IT Security Engineer

Draper, UT · On-site

$107K - $146K/yr

Partner with IT teams to ensure security controls are integrated into infrastructure and ... Support the vulnerability management program through assessment, prioritization, tracking, and ...

Sr. IT Security Engineer

Draper, UT · On-site

$107K - $146K/yr

Partner with IT teams to ensure security controls are integrated into infrastructure and ... Support the vulnerability management program through assessment, prioritization, tracking, and ...

Staff Cloud Security Specialist

Lehi, UT · On-site

$61.50 - $81.75/hr

... controls to compliance frameworks. Support evidence collection, control validation, and remediation activities during audits and assessments. Conduct Security Reviews Work with project teams to ...

Staff Cloud Security Specialist

Lehi, UT · On-site

$61.50 - $81.75/hr

... controls to compliance frameworks. Support evidence collection, control validation, and remediation activities during audits and assessments. Conduct Security Reviews Work with project teams to ...

next page

Showing results 1-20

Security Controls Assessor information

See Utah salary details

$8

$53

$71

How much do security controls assessor jobs pay per hour?

As of Sep 7, 2026, the average hourly pay for security controls assessor in Utah is $53.50, according to ZipRecruiter salary data. Most workers in this role earn between $45.96 and $61.92 per hour, depending on experience, location, and employer.

What is a security controls assessor?

Security Controls Assessors are professionals responsible for evaluating and validating the effectiveness of security controls within an organization's information systems. They conduct assessments to ensure compliance with regulatory standards, such as NIST, FISMA, or other security frameworks. Their work helps organizations identify vulnerabilities, manage risks, and maintain the confidentiality, integrity, and availability of critical data. Security Controls Assessors often provide recommendations for remediation and support efforts to achieve or maintain security certifications.

What does a security controls assessor do?

A security controls assessor (SCA) evaluates the security controls within network systems to identify vulnerabilities and recommend actions to correct problems, working either alone or as part of a team. As a security controls assessor, your duties begin with conducting an in-depth assessment of the management, operations, and technical security controls. You must analyze information and prepare reports describing the vulnerability level of the network with specific detail as to what compromises data systems. You then develop a plan to address vulnerabilities and continue to monitor the security of network systems.

What are the key skills and qualifications needed to thrive as a security controls assessor, and why are they important?

To thrive as a Security Controls Assessor, you need expertise in information security frameworks, risk assessment methodologies, and compliance requirements, often supported by a degree in cybersecurity or related fields and certifications like CISSP, CISA, or CAP. Familiarity with tools such as vulnerability scanners, security assessment platforms, and compliance management systems is typically required. Strong analytical thinking, attention to detail, and effective communication skills help you identify risks and clearly report findings to stakeholders. These skills ensure that organizations maintain robust security postures and meet regulatory requirements to protect critical assets.

What are some common challenges security controls assessors face when evaluating compliance across multiple systems?

Security Controls Assessors often encounter challenges with inconsistent documentation, varying system configurations, and differing interpretations of compliance standards across departments. Coordinating with multiple teams to collect evidence and clarify control implementations can be time-consuming, especially in large organizations. Staying current with evolving regulations and ensuring all systems meet the latest requirements also demands continuous learning and adaptability. Building strong communication channels with system owners and IT staff helps overcome these hurdles and ensures thorough, accurate assessments.

What is the difference between Security Controls Assessor vs Security Analyst?

AspectSecurity Controls AssessorSecurity Analyst
CertificationsISO 27001 Lead Auditor, CISSP, CISACISSP, Security+
Work EnvironmentAssessing security controls, compliance auditsMonitoring security systems, incident response
Employer & IndustryGovernment agencies, compliance firmsCorporate IT, cybersecurity teams

The Security Controls Assessor primarily evaluates and verifies security controls for compliance, often in government or regulated environments. In contrast, a Security Analyst focuses on monitoring, analyzing, and responding to security threats within organizations. While both roles require security certifications and involve cybersecurity, their core responsibilities and work settings differ significantly.

What are popular job titles related to Security Controls Assessor jobs in Utah?

For Security Controls Assessor jobs in Utah, the most frequently searched job titles are:

What job categories do people searching Security Controls Assessor jobs in Utah look for?

The top searched job categories for Security Controls Assessor jobs in Utah are:

What cities in Utah are hiring for Security Controls Assessor jobs?

Cities in Utah with the most Security Controls Assessor job openings:

What are popular job titles related to Security Controls Assessor jobs in UT?

For Security Controls Assessor jobs in UT, the most frequently searched job titles are:

Infographic showing various Security Controls Assessor job openings in Utah as of August 2026, with employment types broken down into 85% Full Time, 13% Part Time, and 2% Contract. Highlights an 92% Physical, 3% Hybrid, and 5% Remote job distribution, with an average salary of $111,280 per year, or $53.5 per hour.

Security Control Assessor Representative (SCAR)

Dark Wolf Solutions

Ogden, UT • On-site

$130K - $180K/yr

Full-time, Contractor

Posted 11 days ago


Job description

Dark Wolf is hiring in Ogden, Utah for a Security Controls Assessor Representative (SCAR). This position works with fellow SCARs, Security Controls Assessors (SCAs), Information System Security Managers (ISSM), Program Managers (PM), and Authorizing Official (AO) representatives to obtain and maintain Authority toOperate (ATO) approvals for various AFNWC weapon subsystems and supporting IT systems by adhering to the Risk Management Framework (RMF). This position is responsible for reviewing, assessing, and providing advice/recommendations to the SCA/AO throughout the RMF process for assigned programs. This is an on-site position on Hill Air Force Base.
Required Qualifications:
  • 10+ years of relevant work experience, including experience as an ISSO, ISSM, SCA, SCAR, or similar roles.
  • Mastery of the NIST Risk Management Framework (RMF), including all seven steps and in-depth knowledge of NIST SP 800-53 security controls and their application to complex government information systems.
  • Comprehensive technical understanding and practical experience with Windows/Linux OS hardening (including STIGs), network protocols (TCP/IP), firewall configurations, IDS/IPS, cloud security (FedRAMP, AWS/Azure GovCloud), virtualization, and database security.
  • Hands-on experience with vulnerability scanning (ACAS/Tenable.sc/Nessus), configuration assessment (SCAP/STIG tools), and log analysis/SIEM platforms (e.g., Splunk, Elastic Stack) to identify and evaluate security posture. Expert-level knowledge of DoD/Agency-specific security requirements (e.g., DoDI 8500.01, CNSSI 1253), IAVMs, and STIG implementation/verification.
  • Proven ability to develop and review System Security Plans (SSPs), write comprehensive Security Assessment Reports (SARs), and manage Plans of Action and Milestones (POA&Ms).
  • Strong capability in analyzing control effectiveness, identifying critical risks, and articulating residual risk to Authorizing Officials (AOs).
  • A Bachelors degree in a relevant field or 3+ years of relevant experience in lieu of degree.
  • US Citizenship and an active Top Secret security clearance with SCI eligibility.

This location is located on Hill AFB in Ogden, Utah. On-site presence is expected 5 days per week. We are hiring for multiple levels, with base salary estimates ranging from $130,000.00 - $180,000.00, commensurate on experience and technical skillset.
We are strictly looking for direct, full-time W2 employees. We do not engage with third-party staffing agencies, C2C, or 1099 independent contractors for this role.
We are proud to be an EEO/AA employer Minorities/Women/Veterans/Disabled and other protected categories.
In compliance with federal law, all persons hired will be required to verify identity, confirm US Citizenship, and complete the required employment eligibility verification upon hire.