Koniag IT Systems, a Koniag Government Services company , is seeking an Open Security Controls Assessment Language SME with an active TS/SCI to support KITS and our government customer at the Mark ...
Koniag IT Systems, a Koniag Government Services company , is seeking an Open Security Controls Assessment Language SME with an active TS/SCI to support KITS and our government customer at the Mark ...
Koniag IT Systems, a Koniag Government Services company , is seeking an Open Security Controls Assessment Language SME with an active TS/SCI to support KITS and our government customer at the Mark ...
Koniag IT Systems, a Koniag Government Services company , is seeking an Open Security Controls Assessment Language SME with an active TS/SCI to support KITS and our government customer at the Mark ...
Security Control Assessor
Petersburg, VA · On-site
$90K - $95K/yr
Assess implemented technical, operational, and management security controls through documentation ... review, interviews, observation, testing, and analysis of artifacts such as vulnerability scan ...
Quick apply
Security Control Assessor
Petersburg, VA · On-site
$90K - $95K/yr
Assess implemented technical, operational, and management security controls through documentation ... review, interviews, observation, testing, and analysis of artifacts such as vulnerability scan ...
Open Security Controls Assessment Language (SME) (TS/SCI)
Alexandria, VA · On-site
$190K - $210K/yr
Koniag IT Systems, a Koniag Government Services company , is seeking an Open Security Controls Assessment Language SME with an active TS/SCI to support KITS and our government customer at the Mark ...
Open Security Controls Assessment Language (SME) (TS/SCI)
Alexandria, VA · On-site
$190K - $210K/yr
Koniag IT Systems, a Koniag Government Services company , is seeking an Open Security Controls Assessment Language SME with an active TS/SCI to support KITS and our government customer at the Mark ...
Open Security Controls Assessment Language (SME) (TS/SCI) with Security Clearance
Alexandria, VA · On-site
Koniag IT Systems, a Koniag Government Services company, is seeking an Open Security Controls Assessment Language SME with an active TS/SCI to support KITS and our government customer at the Mark ...
Open Security Controls Assessment Language (SME) (TS/SCI) with Security Clearance
Alexandria, VA · On-site
Koniag IT Systems, a Koniag Government Services company, is seeking an Open Security Controls Assessment Language SME with an active TS/SCI to support KITS and our government customer at the Mark ...
Security Control Assessor
Arlington, VA · On-site
$120K - $145K/yr
Evaluate the implementation and effectiveness of security controls and document assessment findings, risks, deficiencies, and recommended corrective actions. * Communicate government-approved ...
Quick apply
Security Control Assessor
Arlington, VA · On-site
$120K - $145K/yr
Evaluate the implementation and effectiveness of security controls and document assessment findings, risks, deficiencies, and recommended corrective actions. * Communicate government-approved ...
Security Assessor
Mclean, VA · On-site
Working knowledge of NIST SP 80053 security and privacy controls * Understanding of riskbased assessment concepts * Ability to analyze assessment evidence and clearly document findings What Would Be ...
Security Assessor
Mclean, VA · On-site
Working knowledge of NIST SP 80053 security and privacy controls * Understanding of riskbased assessment concepts * Ability to analyze assessment evidence and clearly document findings What Would Be ...
Offensive Security Control Assessor Security Control Assessor Representative
Herndon, VA · On-site +1
Lead security assessment efforts, establishing reusable security playbooks and assessment ... Hands-on experience mapping security controls to the NIST AI Risk Management Framework (AI RMF ...
New
Quick apply
Offensive Security Control Assessor Security Control Assessor Representative
Herndon, VA · On-site +1
Lead security assessment efforts, establishing reusable security playbooks and assessment ... Hands-on experience mapping security controls to the NIST AI Risk Management Framework (AI RMF ...
New
Security Control Assessor
Arlington, VA · On-site
Evaluate the implementation and effectiveness of security controls and document assessment findings, risks, deficiencies, and recommended corrective actions. * Communicate government-approved ...
Security Control Assessor
Arlington, VA · On-site
Evaluate the implementation and effectiveness of security controls and document assessment findings, risks, deficiencies, and recommended corrective actions. * Communicate government-approved ...
A Security Control Assessor (SCA) performs comprehensive INFOSEC assessment of management ... Additionally, the SCA must verify that all allocated controls have an acceptable status (i.e ...
A Security Control Assessor (SCA) performs comprehensive INFOSEC assessment of management ... Additionally, the SCA must verify that all allocated controls have an acceptable status (i.e ...
Intermediate Security Assessor
Mclean, VA · On-site
Leading and conducting independent assessments of security controls as documented in the System Security Plan (SSP) * Leading and conducting risk assessments based on findings of security controls ...
Quick apply
Intermediate Security Assessor
Mclean, VA · On-site
Leading and conducting independent assessments of security controls as documented in the System Security Plan (SSP) * Leading and conducting risk assessments based on findings of security controls ...
Security Control Assessor
Springfield, VA · On-site
The successful candidate will perform independent assessments of security controls to ensure compliance with federal cybersecurity policies, standards, and frameworks, such as the Risk Management ...
Security Control Assessor
Springfield, VA · On-site
The successful candidate will perform independent assessments of security controls to ensure compliance with federal cybersecurity policies, standards, and frameworks, such as the Risk Management ...
Security Control Assessor
Springfield, VA · On-site
The successful candidate will perform independent assessments of security controls to ensure compliance with federal cybersecurity policies, standards, and frameworks, such as the Risk Management ...
Security Control Assessor
Springfield, VA · On-site
The successful candidate will perform independent assessments of security controls to ensure compliance with federal cybersecurity policies, standards, and frameworks, such as the Risk Management ...
The role involves assessing and evaluating the effectiveness of security controls, identifying ... Responsibilities : • Assess the effectiveness of security controls in information systems • ...
The role involves assessing and evaluating the effectiveness of security controls, identifying ... Responsibilities : • Assess the effectiveness of security controls in information systems • ...
Security Control Assessor/Representatives
Arlington, VA · On-site +1
$135K - $150K/yr
Lead security assessment efforts, establishing reusable security playbooks and assessment ... Hands-on experience mapping security controls to the NIST AI Risk Management Framework (AI RMF ...
Quick apply
Security Control Assessor/Representatives
Arlington, VA · On-site +1
$135K - $150K/yr
Lead security assessment efforts, establishing reusable security playbooks and assessment ... Hands-on experience mapping security controls to the NIST AI Risk Management Framework (AI RMF ...
A Security Control Assessor (SCA) performs comprehensive INFOSEC assessment of management ... Additionally, the SCA must verify that all allocated controls have an acceptable status (i.e ...
Quick apply
A Security Control Assessor (SCA) performs comprehensive INFOSEC assessment of management ... Additionally, the SCA must verify that all allocated controls have an acceptable status (i.e ...
Security Assessor
Mclean, VA · On-site
Working knowledge of NIST SP 800-53 security and privacy controls * Understanding of risk-based assessment concepts * Ability to analyze assessment evidence and clearly document findings What Would ...
Security Assessor
Mclean, VA · On-site
Working knowledge of NIST SP 800-53 security and privacy controls * Understanding of risk-based assessment concepts * Ability to analyze assessment evidence and clearly document findings What Would ...
Security Control Assessor
Springfield, VA · On-site
The successful candidate will perform independent assessments of security controls to ensure compliance with federal cybersecurity policies, standards, and frameworks, such as the Risk Management ...
Security Control Assessor
Springfield, VA · On-site
The successful candidate will perform independent assessments of security controls to ensure compliance with federal cybersecurity policies, standards, and frameworks, such as the Risk Management ...
Mid Level Security Assessor
Mclean, VA · On-site
Conducting independent assessments of security controls as documented in the System Security Plan (SSP) * Conducting risk assessments based on findings of security controls assessments * Developing ...
Quick apply
Mid Level Security Assessor
Mclean, VA · On-site
Conducting independent assessments of security controls as documented in the System Security Plan (SSP) * Conducting risk assessments based on findings of security controls assessments * Developing ...
Security Control Assessor
Alexandria, VA · On-site
Job#: 3044387 Security Control Assessor Location: Alexandria, Virginia (Onsite) Role Overview We ... Perform access controls, interpret findings, write artifacts, and help push systems through the ...
Security Control Assessor
Alexandria, VA · On-site
Job#: 3044387 Security Control Assessor Location: Alexandria, Virginia (Onsite) Role Overview We ... Perform access controls, interpret findings, write artifacts, and help push systems through the ...
Security Controls Assessor information
See Virginia salary details
$8.82 - $15.06
2% of jobs
$15.06 - $21.30
2% of jobs
$21.30 - $27.54
0% of jobs
$27.54 - $33.78
0% of jobs
$33.78 - $40.02
3% of jobs
$40.02 - $46.26
5% of jobs
$49.92 is the 25th percentile. Wages below this are outliers.
$46.26 - $52.50
21% of jobs
The median wage is $57.59 / hr.
$52.50 - $58.74
20% of jobs
$58.74 - $64.98
18% of jobs
$66.42 is the 75th percentile. Wages above this are outliers.
$64.98 - $71.22
15% of jobs
$71.22 - $77.46
14% of jobs
$8
$58
$77
How much do security controls assessor jobs pay per hour?
What is a security controls assessor?
What does a security controls assessor do?
A security controls assessor (SCA) evaluates the security controls within network systems to identify vulnerabilities and recommend actions to correct problems, working either alone or as part of a team. As a security controls assessor, your duties begin with conducting an in-depth assessment of the management, operations, and technical security controls. You must analyze information and prepare reports describing the vulnerability level of the network with specific detail as to what compromises data systems. You then develop a plan to address vulnerabilities and continue to monitor the security of network systems.
What are the key skills and qualifications needed to thrive as a security controls assessor, and why are they important?
What are some common challenges security controls assessors face when evaluating compliance across multiple systems?
What is the difference between Security Controls Assessor vs Security Analyst?
| Aspect | Security Controls Assessor | Security Analyst |
|---|---|---|
| Certifications | ISO 27001 Lead Auditor, CISSP, CISA | CISSP, Security+ |
| Work Environment | Assessing security controls, compliance audits | Monitoring security systems, incident response |
| Employer & Industry | Government agencies, compliance firms | Corporate IT, cybersecurity teams |
The Security Controls Assessor primarily evaluates and verifies security controls for compliance, often in government or regulated environments. In contrast, a Security Analyst focuses on monitoring, analyzing, and responding to security threats within organizations. While both roles require security certifications and involve cybersecurity, their core responsibilities and work settings differ significantly.
What are the most commonly searched types of Security Controls Assessor jobs in Virginia?
The most popular types of Security Controls Assessor jobs in Virginia are:
What are popular job titles related to Security Controls Assessor jobs in Virginia?
For Security Controls Assessor jobs in Virginia, the most frequently searched job titles are:
What job categories do people searching Security Controls Assessor jobs in Virginia look for?
The top searched job categories for Security Controls Assessor jobs in Virginia are:
What cities in Virginia are hiring for Security Controls Assessor jobs?
Cities in Virginia with the most Security Controls Assessor job openings:
What are popular job titles related to Security Controls Assessor jobs in VA?
For Security Controls Assessor jobs in VA, the most frequently searched job titles are:

Full-time
Medical, Dental, Vision, Retirement, PTO
Posted 25 days ago
Job description
Koniag IT Systems, a Koniag Government Services company, is seeking an Open Security Controls Assessment Language SME with an active TS/SCI to support KITS and our government customer at the Mark Center, Alexandria, VA. This is a hybrid opportunity that requires 1-4 days of onsite work.
We offer competitive compensation and an extraordinary benefits package including health, dental, and vision insurance, 401K with company matching, flexible spending accounts, paid holidays, three weeks paid time off, and more.
We are seeking an experienced Open Security Controls Assessment Language (OSCAL) Subject Matter Expert (SME) to support the design, implementation, and optimization of automated security compliance and risk management solutions. The OSCAL SME will play a critical role in advancing our cybersecurity compliance initiatives by enabling machine-readable security documentation, enhancing interoperability, and streamlining authorization processes across multiple federal frameworks.
Essential Functions, Responsibilities & Duties may include, but are not limited to:
- Serve as the technical expert for OSCAL adoption, implementation, and integration within federal compliance programs (e.g., FedRAMP, NIST RMF, DoD).
- Develop, validate, and maintain OSCAL-based artifacts, including system security plans (SSPs), assessment plans, assessment results, and POA&M packages.
- Provide guidance on mapping security controls to OSCAL models and ensuring alignment with NIST standards.
- Support automation of ATO/authorization workflows by integrating OSCAL with governance, risk, and compliance (GRC) tools.
- Collaborate with system owners, security assessors, and compliance teams to improve efficiency in security control assessment and reporting.
- Deliver training, documentation, and best practices to internal teams and customers on OSCAL adoption.
- Provide support and recommendations for the Department of Defense OSCAL standards development.
- Stay current with OSCAL federal policy changes and industry adoption trends.
Qualifications
Required:
- TS/SCI security Clearance required.
- Bachelor’s degree in Cybersecurity, Information Systems, Computer Science, or related field (or equivalent work experience).
- 15+ years of experience in cybersecurity compliance, security assessment, or risk management.
- Hands-on expertise with OSCAL schema, XML/JSON/YAML, and associated validation tools.
- Deep knowledge of NIST frameworks (NIST SP-800-53 Rev. 5, NIST SP-800-37 Rev. 2 RMF, NIST Cybersecurity Framework [CSF 2.0]) and federal compliance standards (e.g., FedRAMP, FISMA, DoD RMF [DoDI 8510.01]).
- Experience with cybersecurity documentation automation and Governance, Risk, and Compliance (GRC) platforms.
- Excellent communication and technical writing skills.
- Ability to work on-site 1-4 days a week.
Preferred:
- Experience of contributing to or collaborating with the NIST OSCAL community.
- Familiarity with DevSecOps pipelines, CI/CD automation, and security-as-code practices.
- Understanding of cloud service provider (CSP) compliance processes (AWS, Azure, GCP, etc.).
- Active security certification (e.g., CISSP, CISM, CAP, CCSP).
Our Equal Employment Opportunity Policy
The company is an equal opportunity employer. The company shall not discriminate against any employee or applicant because of race, color, religion, creed, ethnicity, sex, sexual orientation, gender or gender identity (except where gender is a bona fide occupational qualification), national origin or ancestry, age, disability, citizenship, military/veteran status, marital status, genetic information or any other characteristic protected by applicable federal, state, or local law. We are committed to equal employment opportunity in all decisions related to employment, promotion, wages, benefits, and all other privileges, terms, and conditions of employment.
The company is dedicated to seeking all qualified applicants. If you require an accommodation to navigate or apply for a position on our website, please get in touch with Heaven Wood via e-mail at accommodations@koniag-gs.com or by calling 703-488-9377 to request accommodations.
Koniag Government Services (KGS) is an Alaska Native Owned corporation supporting the values and traditions of our native communities through an agile employee and corporate culture that delivers Enterprise Solutions, Professional Services and Operational Management to Federal Government Agencies. As a wholly owned subsidiary of Koniag, we apply our proven commercial solutions to a deep knowledge of Defense and Civilian missions to provide forward leaning technical, professional, and operational solutions. KGS enables successful mission outcomes for our customers through solution-oriented business partnerships and a commitment to exceptional service delivery. We ensure long-term success with a continuous improvement approach while balancing the collective interests of our customers, employees, and native communities. For more information, please visit www.koniag-gs.com.
Equal Opportunity Employer/Veterans/Disabled. Shareholder Preference in accordance with Public Law 88-352