1

Security Controls Assessor Jobs in Virginia (NOW HIRING)

Job#: 3046820 Security Controls Assessor About the Role The Security Controls Assessor evaluates information systems, processes, and controls to identify risks, vulnerabilities, and compliance gaps.

Security Controls Assessor

Bluemont, VA ยท On-site

$110K - $125K/yr

... security controls. The candidate will lead cybersecurity compliance assessments, identify control gaps and vulnerabilities, and recommend risk-mitigation strategies to support enterprise system ...

next page

Showing results 1-20

Security Controls Assessor information

See Virginia salary details

$8

$58

$77

How much do security controls assessor jobs pay per hour?

As of Aug 25, 2026, the average hourly pay for security controls assessor in Virginia is $58.26, according to ZipRecruiter salary data. Most workers in this role earn between $50.05 and $67.45 per hour, depending on experience, location, and employer.

What is a security controls assessor?

Security Controls Assessors are professionals responsible for evaluating and validating the effectiveness of security controls within an organization's information systems. They conduct assessments to ensure compliance with regulatory standards, such as NIST, FISMA, or other security frameworks. Their work helps organizations identify vulnerabilities, manage risks, and maintain the confidentiality, integrity, and availability of critical data. Security Controls Assessors often provide recommendations for remediation and support efforts to achieve or maintain security certifications.

What does a security controls assessor do?

A security controls assessor (SCA) evaluates the security controls within network systems to identify vulnerabilities and recommend actions to correct problems, working either alone or as part of a team. As a security controls assessor, your duties begin with conducting an in-depth assessment of the management, operations, and technical security controls. You must analyze information and prepare reports describing the vulnerability level of the network with specific detail as to what compromises data systems. You then develop a plan to address vulnerabilities and continue to monitor the security of network systems.

What are the key skills and qualifications needed to thrive as a security controls assessor, and why are they important?

To thrive as a Security Controls Assessor, you need expertise in information security frameworks, risk assessment methodologies, and compliance requirements, often supported by a degree in cybersecurity or related fields and certifications like CISSP, CISA, or CAP. Familiarity with tools such as vulnerability scanners, security assessment platforms, and compliance management systems is typically required. Strong analytical thinking, attention to detail, and effective communication skills help you identify risks and clearly report findings to stakeholders. These skills ensure that organizations maintain robust security postures and meet regulatory requirements to protect critical assets.

What are some common challenges security controls assessors face when evaluating compliance across multiple systems?

Security Controls Assessors often encounter challenges with inconsistent documentation, varying system configurations, and differing interpretations of compliance standards across departments. Coordinating with multiple teams to collect evidence and clarify control implementations can be time-consuming, especially in large organizations. Staying current with evolving regulations and ensuring all systems meet the latest requirements also demands continuous learning and adaptability. Building strong communication channels with system owners and IT staff helps overcome these hurdles and ensures thorough, accurate assessments.

What is the difference between Security Controls Assessor vs Security Analyst?

AspectSecurity Controls AssessorSecurity Analyst
CertificationsISO 27001 Lead Auditor, CISSP, CISACISSP, Security+
Work EnvironmentAssessing security controls, compliance auditsMonitoring security systems, incident response
Employer & IndustryGovernment agencies, compliance firmsCorporate IT, cybersecurity teams

The Security Controls Assessor primarily evaluates and verifies security controls for compliance, often in government or regulated environments. In contrast, a Security Analyst focuses on monitoring, analyzing, and responding to security threats within organizations. While both roles require security certifications and involve cybersecurity, their core responsibilities and work settings differ significantly.

What are the most commonly searched types of Security Controls Assessor jobs in Virginia?

The most popular types of Security Controls Assessor jobs in Virginia are:

What are popular job titles related to Security Controls Assessor jobs in Virginia?

For Security Controls Assessor jobs in Virginia, the most frequently searched job titles are:

What job categories do people searching Security Controls Assessor jobs in Virginia look for?

The top searched job categories for Security Controls Assessor jobs in Virginia are:

What cities in Virginia are hiring for Security Controls Assessor jobs?

Cities in Virginia with the most Security Controls Assessor job openings:

What are popular job titles related to Security Controls Assessor jobs in VA?

For Security Controls Assessor jobs in VA, the most frequently searched job titles are:

Infographic showing various Security Controls Assessor job openings in Virginia as of August 2026, with employment types broken down into 79% Full Time, 19% Part Time, and 2% Contract. Highlights an 92% Physical, 3% Hybrid, and 5% Remote job distribution, with an average salary of $121,188 per year, or $58.3 per hour.

Security Controls Assessor

Apex Systems

Richmond, VA โ€ข On-site

Other

Medical, Dental, Vision, Life, Retirement

Posted 7 days ago


Job description

Job#: 3046820
Job Description:
Security Controls Assessor
About the Role
The Security Controls Assessor evaluates information systems, processes, and controls to identify risks, vulnerabilities, and compliance gaps. This individual conducts security assessments, collaborates with cross-functional stakeholders, and provides practical recommendations to strengthen security and risk management practices.
The role also supports the evolution of security assessment programs through the use of automation, continuous monitoring, and data-driven analysis to improve efficiency and effectiveness.
What You Will Do
Security Assessments & Compliance
  • Conduct assessments of security controls to identify risks, vulnerabilities, and control deficiencies.
  • Review and validate policies, procedures, technical documentation, and control evidence.
  • Document findings, recommendations, and risk observations.
  • Utilize automated evidence collection, monitoring solutions, and reporting tools to support assessment activities.
  • Analyze large and complex datasets to identify trends, anomalies, and recurring control issues.
  • Apply consistent assessment methodologies and risk evaluation practices.
  • Evaluate controls against internal requirements, regulatory expectations, and industry security frameworks.
Advisory & Collaboration
  • Provide guidance to business and technology stakeholders on security best practices and risk mitigation strategies.
  • Partner with system owners, architects, engineers, and security teams to address identified risks.
  • Communicate assessment results and recommendations to both technical and non-technical audiences.
  • Participate in cross-functional initiatives focused on security, compliance, automation, and process improvements.
Risk Analysis & Reporting
  • Translate technical findings into clear and actionable insights.
  • Identify recurring risk themes and control weaknesses.
  • Support discussions regarding remediation priorities and risk management strategies.
  • Assist stakeholders in understanding the potential impact of security and compliance issues.
Process Improvement & Automation
  • Contribute to the enhancement of assessment processes through automation and analytics.
  • Identify opportunities to improve efficiency, consistency, and transparency in assessment activities.
  • Perform root cause analysis on recurring issues and recommend corrective actions.
  • Support the adoption of continuous monitoring and modern assessment techniques.
Minimum Qualifications
  • Bachelor's degree in Information Security, Computer Science, Information Technology, or a related field, or equivalent professional experience.
  • 3-5+ years of experience in information security, cybersecurity, risk management, audit, compliance, or a related discipline.
  • Experience conducting security assessments and working with security or compliance frameworks.
  • Familiarity with industry standards and frameworks such as NIST, ISO 27001, CIS Controls, or similar.
  • Strong written, verbal, and presentation communication skills.
  • Experience collaborating across technical and business teams.
Preferred Qualifications
  • Professional certifications such as CISSP, CISA, CISM, CRISC, Security+, or similar.
  • Experience within governance, risk, compliance, audit, or assurance functions.
  • Familiarity with security automation, monitoring, compliance, or analytics platforms.
  • Knowledge of cloud platforms and associated security considerations.
  • Experience with security control testing, compliance validation, and risk assessment methodologies.
  • Understanding of secure development practices and modern security operations concepts.
Key Competencies
  • Strong interpersonal, collaboration, and stakeholder management skills.
  • Excellent analytical and problem-solving abilities.
  • Ability to interpret and communicate complex technical and risk-related information.
  • Sound judgment and risk-based decision-making capabilities.
  • Strategic mindset with a focus on continuous improvement.
  • Ability to influence outcomes and build consensus across diverse teams.

Everforth Apex is a world-class IT services company that serves thousands of clients across the globe. When you join Everforth Apex, you become part of a team that values innovation, collaboration, and continuous learning. We offer quality career resources, training, certifications, development opportunities, and a comprehensive benefits package. Our commitment to excellence is reflected in many awards, including ClearlyRateds Best of Staffing in Talent Satisfaction in the United States and Great Place to Work in the United Kingdom and Mexico.
Everforth Apex uses a virtual recruiter as part of the application process. Click for more details. By applying for this job, you agree to receive calls, AI-generated calls, text messages, or emails from Everforth Apex and its affiliates, and contracted partners. Frequency varies for text messages. Message and data rates may apply. Carriers are not liable for delayed or undelivered messages. You can reply STOP to cancel and HELP for help. You can access our privacy policy at
Everforth Apex Benefits Overview: Everforth Apex offers a range of supplemental benefits, including medical, dental, vision, life, disability, and other insurance plans that offer an optional layer of financial protection. We offer an ESPP (employee stock purchase program) and a 401K program which allows you to contribute typically within 30 days of starting, with a company match after 12 months of tenure. Everforth Apex also offers a HSA (Health Savings Account on the HDHP plan), a SupportLinc Employee Assistance Program (EAP) with up to 8 free counseling sessions, a corporate discount savings program and other discounts. In terms of professional development, Everforth Apex hosts an on-demand training program, provides access to certification prep and a library of technical and leadership courses/books/seminars once you have 6+ months of tenure, and certification discounts and other perks to associations that include CompTIA and IIBA. Everforth Apex has a dedicated customer service team for our Consultants that can address questions around benefits and other resources, as well as a certified Career Coach. You can access a full list of our benefits, programs, support teams and resources within our 'Welcome Packet' as well, which an Everforth Apex team member can provide.
Everforth Apex Systems is an equal opportunity employer. We do not discriminate or allow discrimination on the basis of race, color, religion, creed, sex (including pregnancy, childbirth, breastfeeding, or related medical conditions), age, sexual orientation, gender identity, national origin, ancestry, citizenship, genetic information, registered domestic partner status, marital status, disability, status as a crime victim, protected veteran status, political affiliation, union membership, or any other characteristic protected by law. Everforth Apex will consider qualified applicants with criminal histories in a manner consistent with the requirements of applicable law.
If you require an accommodation under the Americans with Disabilities Act to participate in an interview with a virtual recruiter or to use our website for a search or application, please contact our Benefits Department at or . Please note that this contact information is strictly to be used for medical ADA accommodations and that no other inquiries will be answered.
UnitedHealthcare creates and publishes the Transparency in Coverage Machine-Readable Files on behalf of Everforth Apex Systems.