1

Security Controls Assessor Jobs in Chicago, IL (NOW HIRING)

The ideal candidate will have experience scoping and executing SAP security segregation of duties assessments, security role designs, as well as experience with business automated controls. Basic ...

POSITION SUMMARY: The Member Access Control supports the work of the Y, a leading nonprofit committed to strengthening community through youth development, healthy living, and social responsibility.

Understanding of security controls assessment and effectiveness * Knowledge of adoption and protection of Gen AI in Cyber Security * Understanding of compliance and regulatory requirements. Build a ...

Senior Security Engineer

Chicago, IL · On-site

$118K - $161K/yr

Cloud & SaaS Security Support security controls and governance within AWS, Microsoft Azure, and SaaS platforms. * Assess cloud services against security standards and best practices. * Participate in ...

next page

Showing results 1-20

Security Controls Assessor information

See Chicago, IL salary details

$9

$60

$80

How much do security controls assessor jobs pay per hour?

As of Sep 1, 2026, the average hourly pay for security controls assessor in Chicago, IL is $60.54, according to ZipRecruiter salary data. Most workers in this role earn between $52.02 and $70.10 per hour, depending on experience, location, and employer.

What is a security controls assessor?

Security Controls Assessors are professionals responsible for evaluating and validating the effectiveness of security controls within an organization's information systems. They conduct assessments to ensure compliance with regulatory standards, such as NIST, FISMA, or other security frameworks. Their work helps organizations identify vulnerabilities, manage risks, and maintain the confidentiality, integrity, and availability of critical data. Security Controls Assessors often provide recommendations for remediation and support efforts to achieve or maintain security certifications.

What does a security controls assessor do?

A security controls assessor (SCA) evaluates the security controls within network systems to identify vulnerabilities and recommend actions to correct problems, working either alone or as part of a team. As a security controls assessor, your duties begin with conducting an in-depth assessment of the management, operations, and technical security controls. You must analyze information and prepare reports describing the vulnerability level of the network with specific detail as to what compromises data systems. You then develop a plan to address vulnerabilities and continue to monitor the security of network systems.

What are the key skills and qualifications needed to thrive as a security controls assessor, and why are they important?

To thrive as a Security Controls Assessor, you need expertise in information security frameworks, risk assessment methodologies, and compliance requirements, often supported by a degree in cybersecurity or related fields and certifications like CISSP, CISA, or CAP. Familiarity with tools such as vulnerability scanners, security assessment platforms, and compliance management systems is typically required. Strong analytical thinking, attention to detail, and effective communication skills help you identify risks and clearly report findings to stakeholders. These skills ensure that organizations maintain robust security postures and meet regulatory requirements to protect critical assets.

What are some common challenges security controls assessors face when evaluating compliance across multiple systems?

Security Controls Assessors often encounter challenges with inconsistent documentation, varying system configurations, and differing interpretations of compliance standards across departments. Coordinating with multiple teams to collect evidence and clarify control implementations can be time-consuming, especially in large organizations. Staying current with evolving regulations and ensuring all systems meet the latest requirements also demands continuous learning and adaptability. Building strong communication channels with system owners and IT staff helps overcome these hurdles and ensures thorough, accurate assessments.

What is the difference between Security Controls Assessor vs Security Analyst?

AspectSecurity Controls AssessorSecurity Analyst
CertificationsISO 27001 Lead Auditor, CISSP, CISACISSP, Security+
Work EnvironmentAssessing security controls, compliance auditsMonitoring security systems, incident response
Employer & IndustryGovernment agencies, compliance firmsCorporate IT, cybersecurity teams

The Security Controls Assessor primarily evaluates and verifies security controls for compliance, often in government or regulated environments. In contrast, a Security Analyst focuses on monitoring, analyzing, and responding to security threats within organizations. While both roles require security certifications and involve cybersecurity, their core responsibilities and work settings differ significantly.

What are the most commonly searched types of Security Controls Assessor jobs in Chicago, IL?

The most popular types of Security Controls Assessor jobs in Chicago, IL are:

What are popular job titles related to Security Controls Assessor jobs in Chicago, IL?

For Security Controls Assessor jobs in Chicago, IL, the most frequently searched job titles are:

What job categories do people searching Security Controls Assessor jobs in Chicago, IL look for?

The top searched job categories for Security Controls Assessor jobs in Chicago, IL are:

Infographic showing various Security Controls Assessor job openings in Chicago, IL as of August 2026, with employment types broken down into 80% Full Time, and 20% Contract. Highlights an 70% In-person, 10% Hybrid, and 20% Remote job distribution, with an average salary of $125,921 per year, or $60.5 per hour.

SAP Security Controls Senior Associate

RSM

Chicago, IL • On-site

Full-time

Re-posted 9 days ago


Job description

We are the leading provider of professional services to the middle market globally, our purpose is to instill confidence in a world of change, empowering our clients and people to realize their full potential. Our exceptional people are the key to our unrivaled, culture and talent experience and our ability to be compelling to our clients. You'll find an environment that inspires and empowers you to thrive both personally and professionally. There's no one like you and that's why there's nowhere like RSM.

RSM's Business Application Risk practice is seeking an experienced SAP security & controls specialist with a strong background in SAP automated controls, and experience with SAP compliant security solutions, to join our fast-growing SAP risk transformation team.

The Business Application Risk Solutions practice in consulting, specializes in managing governance, and regulatory risk, for security, controls, data, across the full lifecycle of core business applications-from implementation through operations.

The practice performs implementation risk quarterback solutions, system integrity solutions, security and controls designs/assessments, complex data analytics, GRC automation/implementation, security role design, security managed services, segregation of duties assessments, as well as intelligent control implementations. The ideal candidate will have experience scoping and executing SAP security segregation of duties assessments, security role designs, as well as experience with business automated controls.

Basic Qualifications:

  • Degree required
  • 2-4 years' experience working with SAP as a business analyst, IT auditor, or implementation architect
  • Exposure to SAP functional automated controls and SAP security role architecture
  • Experience in performing IT audits or recipient of an audit (ITGCs, Security, Controls)
  • Experience on at least one SAP implementation
  • Clear and concise communication skills. Ability to understand what to communicate to difference audiences
  • Highly organized with the ability to monitor engagement time and expenses
  • Ability to provide client status updates, review deliverables, maintain updates with the engagement supervisor timely and communicate client opportunities
  • Ability to put forth additional effort to meet deadlines when necessary

Preferred Qualifications:

  • Demonstrated knowledge of using SAP experience
  • Experience with data analytics tools (such as ACL or MS Access) performing complex queries
  • Team member of at least one SAP implementation.
  • Experience with other business applications is a plus.
  • Demonstrated knowledge of auditing SAP automated business controls
  • 2 - 3 years of professional experience in public accounting or relevant compliance industry experience relating to Sarbanes Oxley (SOX) compliance or other COBIT/NIST/ISO frameworks
  • Desire to obtain certification, such as CISA, PMP, CPA, or other SAP related certifications.

Standards of Performance:

  • The successful candidate will have a high level of energy analytical, organized, and innovative problem solver, with critical thinking skills
  • Ability to communicate effectively with a broad audience ranging from technical to non-technical
  • Excellent organizational skills and the ability to prioritize multiple tasks, projects and assignments
  • Possess strong business ethics and willingness to adhere

At RSM, we offer a competitive benefits and compensation package for all our people.We offer flexibility in your schedule, empowering you to balance life's demands, while also maintaining your ability to serve clients.Learn more about our total rewards at https://rsmus.com/careers/working-at-rsm/benefits.

All applicants will receive consideration for employment as RSM does not tolerate discrimination and/or harassment based on race; color; creed; sincerely held religious beliefs, practices or observances; sex (including pregnancy or disabilities related to nursing); gender; sexual orientation; HIV Status; national origin; ancestry; familial or marital status; age; physical or mental disability; citizenship; political affiliation; medical condition (including family and medical leave); domestic violence victim status; past, current or prospective service in the US uniformed service; US Military/Veteran status; pre-disposing genetic characteristics or any other characteristic protected under applicable federal, state or local law.

Accommodation for applicants with disabilities is available upon request in connection with the recruitment process and/or employment/partnership.RSM is committed to providing equal opportunity and reasonable accommodation for people with disabilities. If you require a reasonable accommodation to complete an application, interview, or otherwise participate in the recruiting process, please call us at 800-274-3978 or send us an email at careers@rsmus.com.

RSM does not intend to hire entry level candidates who will require sponsorship now OR in the future (i.e. F-1 visa holders). If you are a recent U.S. college / university graduate possessing 1-2 years of progressive and relevant work experience in a same or similar role to the one for which you are applying, excluding internships, you may be eligible for hire as an experienced associate.

RSM will consider for employment qualified applicants with arrest or conviction records. For those living in California or applying to a position in California, please click here for additional information.

At RSM, an employee's pay at any point in their career is intended to reflect their experiences, performance, and skills for their current role. The salary range (or starting rate for interns and associates) for this role represents numerous factors considered in the hiring decisions including, but not limited to, education, skills, work experience, certifications, location, etc. As such, pay for the successful candidate(s) could fall anywhere within the stated range.

Compensation Range: $85,100 - $161,700

Individualsselected for this role will be eligible for a discretionary bonus based on firm and individual performance.