1

Security Controls Assessor Jobs in Decatur, GA (NOW HIRING)

Principal, Cloud Security Engineer

Atlanta, GA

$53.50 - $71.75/hr

Ensure cloud vendors adhere to RISE controls, data protection regulations, and global cloud governance standards. Coordinate assessments, security reviews, and audits of cloud vendors and managed ...

Threat Modeling & Controls * Perform AI threat modeling and risk assessments to identify, prioritize, and mitigate security risks related to AI/ML initiatives. DevSecOps for AI * Ensure alignment of ...

Cloud Security Engineer

Atlanta, GA · On-site

$53.50 - $71.75/hr

Assess cloud environments across AWS, GCP, and Azure to identify security risks, control gaps, and configuration issues. * Design, implement, and improve cloud security controls, including identity ...

Cloud Security Engineer

Atlanta, GA · Hybrid

$53.50 - $71.75/hr

Assess cloud environments across AWS, GCP, and Azure to identify security risks, control gaps, and configuration issues. * Design, implement, and improve cloud security controls, including identity ...

Senior Information Security Engineer

Alpharetta, GA · On-site

$104K - $141.10K/yr

Architect and implement cutting-edge security controls across networks, endpoints, cloud platforms ... Deliver clear, actionable risk assessments to leadership. * Track and close security risks with ...

Partner with Cloud Architecture teams to ensure consistent application of cloud security controls ... risk assessment techniques. * Knowledge of identity and access management , OAuth2/OIDC, JWT ...

Partner with Cloud Architecture teams to ensure consistent application of cloud security controls ... risk assessment techniques. * Knowledge of identity and access management , OAuth2/OIDC, JWT ...

Conduct risk assessments, design and validation of security controls, compliance monitoring, and thirdparty security evaluations. * Manage internal and external audits, including audit preparation ...

Conduct risk assessments, design and validation of security controls, compliance monitoring, and third-party security evaluations. * Manage internal and external audits, including audit preparation ...

Conduct risk assessments, design and validation of security controls, compliance monitoring, and thirdparty security evaluations. * Manage internal and external audits, including audit preparation ...

Director - Product Security

Atlanta, GA · On-site +1

$224.10K - $234.60K/yr

Oversee a rigorous threat modeling program and lead cybersecurity risk assessments for all new and existing products. * Champion DevSecOps principles and automate security controls and testing within ...

Sr IT Security Engineer

Atlanta, GA · On-site

$102.40K - $139K/yr

Responsibilities : • Performs information security risk assessments of internally developed ... controls to ensure continued security compliance with Interface standards, and authors and reviews ...

Coordinate and perform threat modeling and risk assessments of technology projects and systems * Recommend, prioritize, design, and monitor the implementation of security controls * Educate, advise ...

next page

Showing results 1-20

Security Controls Assessor information

See Decatur, GA salary details

$8

$57

$76

How much do security controls assessor jobs pay per hour?

As of Jun 1, 2026, the average hourly pay for security controls assessor in Decatur, GA is $57.38, according to ZipRecruiter salary data. Most workers in this role earn between $49.28 and $66.44 per hour, depending on experience, location, and employer.

What Does a Security Controls Assessor Do?

A security controls assessor (SCA) evaluates the security controls within network systems to identify vulnerabilities and recommend actions to correct problems, working either alone or as part of a team. As a security controls assessor, your duties begin with conducting an in-depth assessment of the management, operations, and technical security controls. You must analyze information and prepare reports describing the vulnerability level of the network with specific detail as to what compromises data systems. You then develop a plan to address vulnerabilities and continue to monitor the security of network systems.

What are the key skills and qualifications needed to thrive as a Security Controls Assessor, and why are they important?

To thrive as a Security Controls Assessor, you need expertise in information security frameworks, risk assessment methodologies, and compliance requirements, often supported by a degree in cybersecurity or related fields and certifications like CISSP, CISA, or CAP. Familiarity with tools such as vulnerability scanners, security assessment platforms, and compliance management systems is typically required. Strong analytical thinking, attention to detail, and effective communication skills help you identify risks and clearly report findings to stakeholders. These skills ensure that organizations maintain robust security postures and meet regulatory requirements to protect critical assets.

What are some common challenges Security Controls Assessors face when evaluating compliance across multiple systems?

Security Controls Assessors often encounter challenges with inconsistent documentation, varying system configurations, and differing interpretations of compliance standards across departments. Coordinating with multiple teams to collect evidence and clarify control implementations can be time-consuming, especially in large organizations. Staying current with evolving regulations and ensuring all systems meet the latest requirements also demands continuous learning and adaptability. Building strong communication channels with system owners and IT staff helps overcome these hurdles and ensures thorough, accurate assessments.

What are Security Controls Assessors?

Security Controls Assessors are professionals responsible for evaluating and validating the effectiveness of security controls within an organization's information systems. They conduct assessments to ensure compliance with regulatory standards, such as NIST, FISMA, or other security frameworks. Their work helps organizations identify vulnerabilities, manage risks, and maintain the confidentiality, integrity, and availability of critical data. Security Controls Assessors often provide recommendations for remediation and support efforts to achieve or maintain security certifications.

What is the difference between Security Controls Assessor vs Security Analyst?

AspectSecurity Controls AssessorSecurity Analyst
CertificationsISO 27001 Lead Auditor, CISSP, CISACISSP, Security+
Work EnvironmentAssessing security controls, compliance auditsMonitoring security systems, incident response
Employer & IndustryGovernment agencies, compliance firmsCorporate IT, cybersecurity teams

The Security Controls Assessor primarily evaluates and verifies security controls for compliance, often in government or regulated environments. In contrast, a Security Analyst focuses on monitoring, analyzing, and responding to security threats within organizations. While both roles require security certifications and involve cybersecurity, their core responsibilities and work settings differ significantly.

What job categories do people searching Security Controls Assessor jobs in Decatur, GA look for? The top searched job categories for Security Controls Assessor jobs in Decatur, GA are:
What cities near Decatur, GA are hiring for Security Controls Assessor jobs? Cities near Decatur, GA with the most Security Controls Assessor job openings:

$53.50 - $71.75/hr

Other

Posted 11 days ago


Job description

About Us
Mercedes-Benz is USA is responsible for the sales, marketing and service of all Mercedes-Benz and Maybach products in the United States. In our people, you will find tremendous commitment to our corporate values. Our products and employees reflect this dedication. We are looking for diverse top-notch individuals to join the Mercedes-Benz Team and uphold these hallmarks.

Job Overview

We are seeking a highly skilled and proactive individual to design, implement, and maintain secure cloud infrastructure across multi cloud environments (Azure, AWS, GCP). This role ensures alignment with enterprise security policies and regulatory requirements while safeguarding cloud assets, maintaining compliance, and supporting secure digital transformation initiatives.

The Principal, Cloud Security Engineer contributes to the development of the system design and application architecture and ensures that the security requirements, RISE (Regulations for Information Security) will be fulfilled by the project and thus information security risks are mitigated.

This role will lead the team through establishing highly effective policies based on the RISE Cybersecurity Framework, establishing sustainable processes for assessing and tracking cybersecurity risk, performing security control testing, and delivering performance metrics and reporting for each program under its management scope.

Experience or familiarity with the use of AI driven security technologies, including generative AI, AI/ML, and intelligent or autonomous agents, to support cloud security operations, threat detection, vulnerability management, risk management, and compliance activities, in accordance with enterprise AI governance and security standards, is preferred.

Candidate will possess a strong understanding of the RISE Cybersecurity Framework, understanding of performing risk assessment, as well as performing technical control assessment.
 

Responsibilities

Cloud Security Operations & Governance
    Lead cloud security governance for all cloud-hosted applications and services, ensuring alignment with RISE security requirements and Mercedes-Benz cloud security standards.
    Conduct cloud application and architecture security reviews to ensure compliance with security policies, data protection requirements, and regulatory standards.
    Develop, Manage and enhance cloud security dashboards (e.g., workload protection, posture management, policy compliance, vulnerability trends).
    Oversee Cloud Security Posture Management (CSPM), ensuring continuous compliance monitoring, remediation tracking, and risk reporting.
    Ensure proper configuration, provisioning, and ongoing assessment of cloud environments across AWS, Azure, and other MB-approved cloud platforms.
    Support secure cloud migration initiatives by embedding security controls, encryption, identity practices, and workload protection early in the lifecycle.
    Coordinate cloud-related security incidents, investigations, and SOC escalations.
    Perform cloud vulnerability management activities including code scanning, FOSS, GitHub, and Qualys scans for cloud workloads.
    Support implementation of zero-trust principles in cloud networks, applications, and identity structures.
SDLC - Security Implementation on SDLC Gates
Secure Development Lifecycle Integration
    Embed cybersecurity requirements at all SDLC gates, ensuring security acceptance criteria are fulfilled before progressing to next stages.
    Collaborate with development and architecture teams to define security technical requirements and validate their implementation.
    Support security in DevOps/DevSecOps processes, including CI/CD pipeline checks, automated scanning, and secure coding practices.
    Perform technical control assessments throughout the SDLC, including code reviews, architecture reviews, and threat modeling.
    Ensure vulnerabilities identified through SAST, DAST, dependency checks, and container scans are properly triaged and remediated.
    Work with application teams to implement countermeasures and design secure solutions that meet business and compliance needs.
    Provide guidance and approval for security controls during design, testing, deployment, and production cutover.
    Ensure application teams follow regulatory, internal policy, and RISE-based software security controls.
Governance of Cybersecurity (Policies, Procedures, Compliance)
Information Security Governance
    Govern compliance with RISE (Regulations for Information Security), IT policies, standards, and procedures across the business unit.
    Develop and maintain documentation such as cybersecurity policies, standards, frameworks, guidelines, and awareness materials.
    Develop and Govern AI cybersecurity and risk frameworks, ensuring secure, compliant, and responsible use of AI aligned with enterprise security and regulatory requirements.
    Manage Information Security Risk Management (ISRM) processes, including risk identification, assessment, mitigation tracking, and reporting.
    Support business-specific risk management in cybersecurity and report regularly to ISO Coordinator and senior IT leadership.
    Ensure execution of security spot checks, audits, and cybersecurity assessments across applications and infrastructure.
    Support internal and external audits, ensuring evidence readiness, control testing, and remediation oversight.
    Lead Cybersecurity KPI definition, tracking, reporting, and continuous improvement efforts.
    Govern Identity & Access Management (IAM) controls, User Access Management (UAM), and information classification adherence.
    Oversee the security governance of Shadow IT applications, ensuring visibility, risk mitigation, and compliance measures.
    Support global and regional cybersecurity awareness campaigns and deliver local awareness initiatives.
    Ensure continuous improvement of ISRM and support the Business Continuity Program (BCP).
Cloud Vendor Management
Vendor & Third Party Cyber Risk Oversight
    Manage cloud service provider (CSP) security evaluations, ensuring compliance with MB security frameworks and contractual obligations.
    Oversee third party cybersecurity risk management processes for cloud vendors, including due diligence, risk scoring, and mitigation tracking.
    Ensure cloud vendors adhere to RISE controls, data protection regulations, and global cloud governance standards.
    Coordinate assessments, security reviews, and audits of cloud vendors and managed service providers.
    Track SLAs, security obligations, vulnerabilities, incident response readiness, and compliance deliverables from cloud vendors.
    Collaborate closely with GCS, Central ISOC, and MBAG teams on global cloud security governance, tool harmonization, and reporting.
    Review vendor architecture and service changes to ensure they do not introduce new risks or non-compliance.
    Provide regular reporting on vendor risks, cloud security posture, and compliance dashboards to leadership.

This position reports to Mercedes-Benz NAFTA Information Security Officer, closely working with the Director Cybersecurity & Cross functions, Global Chief Information Security Officer (CISO).
 

Qualifications

Education:
Bachelor's/master's degree (accredited school) or equivalent with emphasis in: 
Cyber Security / Computer / Information Science
Information Technology
 

Knowledge, Skills & Abilities: 

  • Minimum of 10 years of relevant work experience in IT 

  • Experience in many of the following areas:

    • Knowledge in IT security, with a focus on cloud environments

    • Hands-on experience with security tools and cloud-native services across Azure, AWS, and GCP

    • Knowledge of IT guidelines and corporate IT policies, IT standards, knowledge of IT organization (e.g., for escalation paths for non-standard requests)

    • Overview of current threats, risks, information security techniques, and controls to mitigate them.

    • Experience in application software planning, development, and integration into proposed business solutions

    • Experience implementing comprehensive application testing methodology.

    • Experience identifying, evaluating and managing risk in a complex and changing environment.

    • Experience in developing and implementing countermeasures to identify application security risks.

    • Working knowledge of NIST, Open Web Application Security Project (OWASP) and Open-Source Security Testing Methodology Manual (OSSTMM)

    • Experience interacting with development teams to articulate security requirements and processes while collaborating on architecture and engineering design options, implementation, testing and user acceptance.

    • Highly proficient in the configuration and deployment of applications in complex environments

    • Experience in working with software developers throughout the software development life cycle (SDLC)

    • Experience supporting security in DevOps processes.

    • Hands-on development experience and working knowledge of web application languages and framework.

    • Experience discerning an organization's security control for application software based on vulnerabilities and business needs.

    • Strong proficiency with common management frameworks, regulatory requirements, and industry-leading practices

Certifications:
    Professional certifications such as CISSP (Certified Information Systems Security Professional) or CCSP (Certified Cloud Security Professional).
    Cloud platform certifications (AWS, Microsoft Azure, and/or Google Cloud)
    The ideal candidate must pursue Current & Future Mercedes-Benz-mandated certifications
Additional Information 
    No Sponsorship/Visa Transfer Available 
    Must be able to work flexible hours/work schedule. 
    Travel Domestic and International
    Work Holidays, Weekends when required. 
 

EEO Statement

Mercedes-Benz USA is committed to fostering an inclusive environment that appreciates and leverages the diversity of our team. We provide equal employment opportunity (EEO) to all qualified applicants and employees without regard to race, color, ethnicity, gender, age, national origin, religion, marital status, veteran status, physical or other disability, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local law.