1

Security Controls Assessor Jobs in Utah (NOW HIRING)

... assessment, authorization, and continuous monitoring) * Develop, maintain, and review RMF documentation (e.g., SSPs, SARs, POA&Ms, Security Plans) * Interpret and apply security controls from NIST SP ...

Showing results 41-60

Security Controls Assessor information

See Utah salary details

$8

$53

$71

How much do security controls assessor jobs pay per hour?

As of Aug 23, 2026, the average hourly pay for security controls assessor in Utah is $53.50, according to ZipRecruiter salary data. Most workers in this role earn between $45.96 and $61.92 per hour, depending on experience, location, and employer.

What is a security controls assessor?

Security Controls Assessors are professionals responsible for evaluating and validating the effectiveness of security controls within an organization's information systems. They conduct assessments to ensure compliance with regulatory standards, such as NIST, FISMA, or other security frameworks. Their work helps organizations identify vulnerabilities, manage risks, and maintain the confidentiality, integrity, and availability of critical data. Security Controls Assessors often provide recommendations for remediation and support efforts to achieve or maintain security certifications.

What does a security controls assessor do?

A security controls assessor (SCA) evaluates the security controls within network systems to identify vulnerabilities and recommend actions to correct problems, working either alone or as part of a team. As a security controls assessor, your duties begin with conducting an in-depth assessment of the management, operations, and technical security controls. You must analyze information and prepare reports describing the vulnerability level of the network with specific detail as to what compromises data systems. You then develop a plan to address vulnerabilities and continue to monitor the security of network systems.

What are the key skills and qualifications needed to thrive as a security controls assessor, and why are they important?

To thrive as a Security Controls Assessor, you need expertise in information security frameworks, risk assessment methodologies, and compliance requirements, often supported by a degree in cybersecurity or related fields and certifications like CISSP, CISA, or CAP. Familiarity with tools such as vulnerability scanners, security assessment platforms, and compliance management systems is typically required. Strong analytical thinking, attention to detail, and effective communication skills help you identify risks and clearly report findings to stakeholders. These skills ensure that organizations maintain robust security postures and meet regulatory requirements to protect critical assets.

What are some common challenges security controls assessors face when evaluating compliance across multiple systems?

Security Controls Assessors often encounter challenges with inconsistent documentation, varying system configurations, and differing interpretations of compliance standards across departments. Coordinating with multiple teams to collect evidence and clarify control implementations can be time-consuming, especially in large organizations. Staying current with evolving regulations and ensuring all systems meet the latest requirements also demands continuous learning and adaptability. Building strong communication channels with system owners and IT staff helps overcome these hurdles and ensures thorough, accurate assessments.

What is the difference between Security Controls Assessor vs Security Analyst?

AspectSecurity Controls AssessorSecurity Analyst
CertificationsISO 27001 Lead Auditor, CISSP, CISACISSP, Security+
Work EnvironmentAssessing security controls, compliance auditsMonitoring security systems, incident response
Employer & IndustryGovernment agencies, compliance firmsCorporate IT, cybersecurity teams

The Security Controls Assessor primarily evaluates and verifies security controls for compliance, often in government or regulated environments. In contrast, a Security Analyst focuses on monitoring, analyzing, and responding to security threats within organizations. While both roles require security certifications and involve cybersecurity, their core responsibilities and work settings differ significantly.

What are popular job titles related to Security Controls Assessor jobs in Utah?

For Security Controls Assessor jobs in Utah, the most frequently searched job titles are:

What job categories do people searching Security Controls Assessor jobs in Utah look for?

The top searched job categories for Security Controls Assessor jobs in Utah are:

What cities in Utah are hiring for Security Controls Assessor jobs?

Cities in Utah with the most Security Controls Assessor job openings:

What are popular job titles related to Security Controls Assessor jobs in UT?

For Security Controls Assessor jobs in UT, the most frequently searched job titles are:

Infographic showing various Security Controls Assessor job openings in Utah as of August 2026, with employment types broken down into 79% Full Time, 19% Part Time, and 2% Contract. Highlights an 92% Physical, 3% Hybrid, and 5% Remote job distribution, with an average salary of $111,280 per year, or $53.5 per hour.

Full-time

Re-posted 27 days ago


Job description

Odyssey Systems has an exciting opportunity for a Information System Security Officer (ISSO) to support the Aerospace Dominance Enabler Division (AFLCMC/C3BM)at Hill AFB in Ogden Utah. 

This role supports the protection, accreditation, and ongoing security posture of Air Force information systems. In this role, you will work closely with the Information System Security Manager (ISSM) to ensure systems meet all DoD and Air Force cybersecurity requirements, align with the Risk Management Framework (RMF), and maintain the confidentiality, integrity, and availability of critical networks and data.

You will conduct risk assessments, support accreditation activities, evaluate system security controls, and help enforce policies, configurations, and user access standards. Additional responsibilities include monitoring for vulnerabilities, assisting with incident response actions, maintaining compliance artifacts, and supporting secure system design efforts.

This position requires strong attention to detail, a commitment to cybersecurity excellence, and the ability to collaborate across technical and leadership teams.

*Contingent Upon Contract Award*


Responsibilities may include, but are not limited to:

  • Ensure all systems and applications meet DoD and Air Force cybersecurity requirements as directed by the Information System Security Manager (ISSM).
  • Protect the confidentiality, integrity, and availability of systems, networks, and data by developing, implementing, and maintaining cybersecurity programs, policies, procedures, and security tools.
  • Support all Risk Management Framework (RMF) authorization and accreditation activities, including configuration, artifact creation, documentation, and compliance reviews.
  • Assist the ISSM in performing risk and vulnerability assessments on planned and operational information systems, identifying security gaps and recommending mitigation actions.
  • Conduct security evaluations, audits, and reviews; support development of system contingency and disaster recovery plans; and promote user compliance with cybersecurity policies and training requirements.
  • Participate in system and network design efforts to ensure appropriate security controls and RMF activities are incorporated from the start.
  • Assist in the collection, analysis, and preservation of digital evidence related to cybersecurity incidents or policy violations.
  • Maintain the operational security posture of assigned IT systems, monitor situational awareness, and implement actions to improve or restore cybersecurity resilience.
  • Enforce Air Force cybersecurity policies, procedures, configuration guidelines (e.g., STIGs/SRGs), and change management processes.
  • Maintain and audit authorized user access documentation and ensure users meet clearance, needtoknow, and annual training requirements.
  • Report security incidents or vulnerabilities to the ISSM and support implementation of corrective or protective measures.
  • Initiate and track exceptions, deviations, or waivers to cybersecurity requirements as needed.

*Contingent Upon Contract Award*


Must be a U.S Citizen 

Clearnace: Must have and be able to maintain an Active Secret Clearance. 

Certifications: IAT Level II (Security+, GSEC, CCNA-Security, Certified Systems Security Professional

Preferred Qualifications:

Education: Bachelor’s or Master’s Degree in a related field and at least 3 years of experience discipline being performed, 3 of which must be in the DoD, OR,

    • 7 years of directly related experience, 5 of which must be in the DoD.

Certifications: CISSP, or equivalent certification

  • Must maintain required cybersecurity certifications in accordance with AFMAN 171303.
Technical Skills
  • Experience supporting Risk Management Framework (RMF) activities and cybersecurity compliance
  • Experience using eMASS for authorization packages, artifact management, and accreditation support
  • Vulnerability assessment and risk mitigation analysis
  • STIG/SRG implementation and configuration management
  • Security audits, assessments, and incident response support
  • Information system security and operational security posture management
  • Secure system and network design support in DoD environments

Interpersonal Skills:

  • Ability to develop innovative approaches to complex test problems
  • Strong attention to quality, adequacy, and completeness of test results and conclusions
  • Ability to deliver thorough, timely, and efficient task execution
  • Ability to provide clear analysis and recommendations to program test leadership

Location: Hill AFB, UT (onsite)

Travel: Travel may be required at the customer's discretion

#LI-JG1

*Contingent Upon Contract Award*


Odyssey is a world-class technical, engineering, and integration company serving the warfighting ecosystem with airborne integration, ISR, C2, and warfighter readiness capabilities. Odyssey meets the military’s operational needs by integrating layered defense systems from equipment, technology, and services to data, information, and business operations. We streamline defense acquisition and sustainment, engineering the technical battlefield with domain-specific proficiency to ensure lethality. Odyssey is dedicated to excellent contract execution, peak organizational performance, and fostering a workplace built on employee care.

Odyssey is proud to live out our core values of commitment, ambition, and respect in our work and communities through OdysseyCares, a philanthropic group focused on giving back through direct donations, an employer match program, and volunteering events.

Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities