1

Security Controls Assessor Jobs in Virginia (NOW HIRING)

Security Control Assessor

Arlington, VA · On-site

$120K - $145K/yr

Evaluate the implementation and effectiveness of security controls and document assessment findings, risks, deficiencies, and recommended corrective actions. * Communicate government-approved ...

Working knowledge of NIST SP 80053 security and privacy controls * Understanding of riskbased assessment concepts * Ability to analyze assessment evidence and clearly document findings What Would Be ...

The successful candidate will perform independent assessments of security controls to ensure compliance with federal cybersecurity policies, standards, and frameworks, such as the Risk Management ...

Working knowledge of NIST SP 800-53 security and privacy controls * Understanding of risk-based assessment concepts * Ability to analyze assessment evidence and clearly document findings What Would ...

Job#: 3044387 Security Control Assessor Location: Alexandria, Virginia (Onsite) Role Overview We ... Perform access controls, interpret findings, write artifacts, and help push systems through the ...

Showing results 21-40

Security Controls Assessor information

See Virginia salary details

$8

$58

$77

How much do security controls assessor jobs pay per hour?

As of Aug 18, 2026, the average hourly pay for security controls assessor in Virginia is $58.26, according to ZipRecruiter salary data. Most workers in this role earn between $50.05 and $67.45 per hour, depending on experience, location, and employer.

What is a security controls assessor?

Security Controls Assessors are professionals responsible for evaluating and validating the effectiveness of security controls within an organization's information systems. They conduct assessments to ensure compliance with regulatory standards, such as NIST, FISMA, or other security frameworks. Their work helps organizations identify vulnerabilities, manage risks, and maintain the confidentiality, integrity, and availability of critical data. Security Controls Assessors often provide recommendations for remediation and support efforts to achieve or maintain security certifications.

What does a security controls assessor do?

A security controls assessor (SCA) evaluates the security controls within network systems to identify vulnerabilities and recommend actions to correct problems, working either alone or as part of a team. As a security controls assessor, your duties begin with conducting an in-depth assessment of the management, operations, and technical security controls. You must analyze information and prepare reports describing the vulnerability level of the network with specific detail as to what compromises data systems. You then develop a plan to address vulnerabilities and continue to monitor the security of network systems.

What are the key skills and qualifications needed to thrive as a security controls assessor, and why are they important?

To thrive as a Security Controls Assessor, you need expertise in information security frameworks, risk assessment methodologies, and compliance requirements, often supported by a degree in cybersecurity or related fields and certifications like CISSP, CISA, or CAP. Familiarity with tools such as vulnerability scanners, security assessment platforms, and compliance management systems is typically required. Strong analytical thinking, attention to detail, and effective communication skills help you identify risks and clearly report findings to stakeholders. These skills ensure that organizations maintain robust security postures and meet regulatory requirements to protect critical assets.

What are some common challenges security controls assessors face when evaluating compliance across multiple systems?

Security Controls Assessors often encounter challenges with inconsistent documentation, varying system configurations, and differing interpretations of compliance standards across departments. Coordinating with multiple teams to collect evidence and clarify control implementations can be time-consuming, especially in large organizations. Staying current with evolving regulations and ensuring all systems meet the latest requirements also demands continuous learning and adaptability. Building strong communication channels with system owners and IT staff helps overcome these hurdles and ensures thorough, accurate assessments.

What is the difference between Security Controls Assessor vs Security Analyst?

AspectSecurity Controls AssessorSecurity Analyst
CertificationsISO 27001 Lead Auditor, CISSP, CISACISSP, Security+
Work EnvironmentAssessing security controls, compliance auditsMonitoring security systems, incident response
Employer & IndustryGovernment agencies, compliance firmsCorporate IT, cybersecurity teams

The Security Controls Assessor primarily evaluates and verifies security controls for compliance, often in government or regulated environments. In contrast, a Security Analyst focuses on monitoring, analyzing, and responding to security threats within organizations. While both roles require security certifications and involve cybersecurity, their core responsibilities and work settings differ significantly.

What are the most commonly searched types of Security Controls Assessor jobs in Virginia?

The most popular types of Security Controls Assessor jobs in Virginia are:

What are popular job titles related to Security Controls Assessor jobs in Virginia?

For Security Controls Assessor jobs in Virginia, the most frequently searched job titles are:

What job categories do people searching Security Controls Assessor jobs in Virginia look for?

The top searched job categories for Security Controls Assessor jobs in Virginia are:

What cities in Virginia are hiring for Security Controls Assessor jobs?

Cities in Virginia with the most Security Controls Assessor job openings:

What are popular job titles related to Security Controls Assessor jobs in VA?

For Security Controls Assessor jobs in VA, the most frequently searched job titles are:

Infographic showing various Security Controls Assessor job openings in Virginia as of August 2026, with employment types broken down into 79% Full Time, 19% Part Time, and 2% Contract. Highlights an 92% Physical, 3% Hybrid, and 5% Remote job distribution, with an average salary of $121,188 per year, or $58.3 per hour.

Open Security Controls Assessment Language (SME) (TS/SCI)

kgs

Alexandria, VA

Full-time

Medical, Dental, Vision, Retirement, PTO

Posted 25 days ago


Job description

Koniag IT Systems, a Koniag Government Services company, is seeking an Open Security Controls Assessment Language SME with an active TS/SCI to support KITS and our government customer at the Mark Center, Alexandria, VA. This is a hybrid opportunity that requires 1-4 days of onsite work.

We offer competitive compensation and an extraordinary benefits package including health, dental, and vision insurance, 401K with company matching, flexible spending accounts, paid holidays, three weeks paid time off, and more.

We are seeking an experienced Open Security Controls Assessment Language (OSCAL) Subject Matter Expert (SME) to support the design, implementation, and optimization of automated security compliance and risk management solutions. The OSCAL SME will play a critical role in advancing our cybersecurity compliance initiatives by enabling machine-readable security documentation, enhancing interoperability, and streamlining authorization processes across multiple federal frameworks.

Essential Functions, Responsibilities & Duties may include, but are not limited to:

  • Serve as the technical expert for OSCAL adoption, implementation, and integration within federal compliance programs (e.g., FedRAMP, NIST RMF, DoD).
  • Develop, validate, and maintain OSCAL-based artifacts, including system security plans (SSPs), assessment plans, assessment results, and POA&M packages.
  • Provide guidance on mapping security controls to OSCAL models and ensuring alignment with NIST standards.
  • Support automation of ATO/authorization workflows by integrating OSCAL with governance, risk, and compliance (GRC) tools.
  • Collaborate with system owners, security assessors, and compliance teams to improve efficiency in security control assessment and reporting.
  • Deliver training, documentation, and best practices to internal teams and customers on OSCAL adoption.
  • Provide support and recommendations for the Department of Defense OSCAL standards development.
  • Stay current with OSCAL federal policy changes and industry adoption trends.

Qualifications

Required:

  • TS/SCI security Clearance required.
  • Bachelor’s degree in Cybersecurity, Information Systems, Computer Science, or related field (or equivalent work experience).
  • 15+ years of experience in cybersecurity compliance, security assessment, or risk management.
  • Hands-on expertise with OSCAL schema, XML/JSON/YAML, and associated validation tools.
  • Deep knowledge of NIST frameworks (NIST SP-800-53 Rev. 5, NIST SP-800-37 Rev. 2 RMF, NIST Cybersecurity Framework [CSF 2.0]) and federal compliance standards (e.g., FedRAMP, FISMA, DoD RMF [DoDI 8510.01]).
  • Experience with cybersecurity documentation automation and Governance, Risk, and Compliance (GRC) platforms.
  • Excellent communication and technical writing skills.
  • Ability to work on-site 1-4 days a week.

Preferred:

  • Experience of contributing to or collaborating with the NIST OSCAL community.
  • Familiarity with DevSecOps pipelines, CI/CD automation, and security-as-code practices.
  • Understanding of cloud service provider (CSP) compliance processes (AWS, Azure, GCP, etc.).
  • Active security certification (e.g., CISSP, CISM, CAP, CCSP).

Our Equal Employment Opportunity Policy

The company is an equal opportunity employer. The company shall not discriminate against any employee or applicant because of race, color, religion, creed, ethnicity, sex, sexual orientation, gender or gender identity (except where gender is a bona fide occupational qualification), national origin or ancestry, age, disability, citizenship, military/veteran status, marital status, genetic information or any other characteristic protected by applicable federal, state, or local law. We are committed to equal employment opportunity in all decisions related to employment, promotion, wages, benefits, and all other privileges, terms, and conditions of employment.

The company is dedicated to seeking all qualified applicants. If you require an accommodation to navigate or apply for a position on our website, please get in touch with Heaven Wood via e-mail at accommodations@koniag-gs.com or by calling 703-488-9377 to request accommodations.

Koniag Government Services (KGS) is an Alaska Native Owned corporation supporting the values and traditions of our native communities through an agile employee and corporate culture that delivers Enterprise Solutions, Professional Services and Operational Management to Federal Government Agencies. As a wholly owned subsidiary of Koniag, we apply our proven commercial solutions to a deep knowledge of Defense and Civilian missions to provide forward leaning technical, professional, and operational solutions. KGS enables successful mission outcomes for our customers through solution-oriented business partnerships and a commitment to exceptional service delivery. We ensure long-term success with a continuous improvement approach while balancing the collective interests of our customers, employees, and native communities. For more information, please visit www.koniag-gs.com.

Equal Opportunity Employer/Veterans/Disabled. Shareholder Preference in accordance with Public Law 88-352