Collaborate with the Privacy Officer, Legal, and Compliance teams to align security controls with ... assessments * Monitor the evolving regulatory and legislative landscape and proactively advise ...
Collaborate with the Privacy Officer, Legal, and Compliance teams to align security controls with ... assessments * Monitor the evolving regulatory and legislative landscape and proactively advise ...
VP Info Security
Atlanta, GA · On-site
Collaborate with the Privacy Officer, Legal, and Compliance teams to align security controls with ... assessments * Monitor the evolving regulatory and legislative landscape and proactively advise ...
VP Info Security
Atlanta, GA · On-site
Collaborate with the Privacy Officer, Legal, and Compliance teams to align security controls with ... assessments * Monitor the evolving regulatory and legislative landscape and proactively advise ...
Sr IT Security Engineer
Atlanta, GA · On-site
$110.10K - $151K/yr
Performs information security risk assessments of internally developed solutions and cloud-based ... Evaluates vendor security controls to ensure continued security compliance with Interface standards ...
Sr IT Security Engineer
Atlanta, GA · On-site
$110.10K - $151K/yr
Performs information security risk assessments of internally developed solutions and cloud-based ... Evaluates vendor security controls to ensure continued security compliance with Interface standards ...
Sr IT Security Engineer
Atlanta, GA · On-site
$110.10K - $151K/yr
Performs information security risk assessments of internally developed solutions and cloud-based ... Evaluates vendor security controls to ensure continued security compliance with Interface standards ...
Sr IT Security Engineer
Atlanta, GA · On-site
$110.10K - $151K/yr
Performs information security risk assessments of internally developed solutions and cloud-based ... Evaluates vendor security controls to ensure continued security compliance with Interface standards ...
Sr IT Security Engineer
$110.10K - $151K/yr
Performs information security risk assessments of internally developed solutions and cloud-based ... Evaluates vendor security controls to ensure continued security compliance with Interface standards ...
Sr IT Security Engineer
$110.10K - $151K/yr
Performs information security risk assessments of internally developed solutions and cloud-based ... Evaluates vendor security controls to ensure continued security compliance with Interface standards ...
Security Engineer
Atlanta, GA · On-site
Experience with patching and vulnerability assessment tools. * Knowledge of industry frameworks like NIST Cybersecurity Framework and Center for * Internet Security (CIS) Critical Security Controls.
Security Engineer
Atlanta, GA · On-site
Experience with patching and vulnerability assessment tools. * Knowledge of industry frameworks like NIST Cybersecurity Framework and Center for * Internet Security (CIS) Critical Security Controls.
Sr IT Security Engineer
$110.10K - $151K/yr
Performs information security risk assessments of internally developed solutions and cloud-based ... Evaluates vendor security controls to ensure continued security compliance with Interface standards ...
Sr IT Security Engineer
$110.10K - $151K/yr
Performs information security risk assessments of internally developed solutions and cloud-based ... Evaluates vendor security controls to ensure continued security compliance with Interface standards ...
Sr IT Security Engineer
$110.10K - $151K/yr
Performs information security risk assessments of internally developed solutions and cloud-based ... Evaluates vendor security controls to ensure continued security compliance with Interface standards ...
Sr IT Security Engineer
$110.10K - $151K/yr
Performs information security risk assessments of internally developed solutions and cloud-based ... Evaluates vendor security controls to ensure continued security compliance with Interface standards ...
Performs vulnerability assessments against new devices before production implementation. • ... controls for business systems. 5.Assists the Information Security Officer with technology ...
Performs vulnerability assessments against new devices before production implementation. • ... controls for business systems. 5.Assists the Information Security Officer with technology ...
Security Architect
Atlanta, GA · On-site
$62.50 - $80.75/hr
Understanding of security frameworks such as MITRE ATT&CK, NIST CSF, and CIS Controls. * Strong problem-solving skills with the ability to assess and mitigate security risks effectively. * Excellent ...
Security Architect
Atlanta, GA · On-site
$62.50 - $80.75/hr
Understanding of security frameworks such as MITRE ATT&CK, NIST CSF, and CIS Controls. * Strong problem-solving skills with the ability to assess and mitigate security risks effectively. * Excellent ...
Security Architect
Atlanta, GA · On-site
$62.50 - $80.75/hr
Understanding of security frameworks such as MITRE ATT&CK, NIST CSF, and CIS Controls. * Strong problem-solving skills with the ability to assess and mitigate security risks effectively. * Excellent ...
Security Architect
Atlanta, GA · On-site
$62.50 - $80.75/hr
Understanding of security frameworks such as MITRE ATT&CK, NIST CSF, and CIS Controls. * Strong problem-solving skills with the ability to assess and mitigate security risks effectively. * Excellent ...
Lead Cybersecurity - Application Security Architect - AI Models, Frameworks & Implementation
Alpharetta, GA · On-site
Hands-on experience withAI security controls and implementation * Ability tocode, automate ... Assess risks such asprompt injection, model evasion, data poisoning, jailbreaks, model inversion ...
Lead Cybersecurity - Application Security Architect - AI Models, Frameworks & Implementation
Alpharetta, GA · On-site
Hands-on experience withAI security controls and implementation * Ability tocode, automate ... Assess risks such asprompt injection, model evasion, data poisoning, jailbreaks, model inversion ...
Hands-on experience withAI security controls and implementation * Ability tocode, automate ... Assess risks such asprompt injection, model evasion, data poisoning, jailbreaks, model inversion ...
Hands-on experience withAI security controls and implementation * Ability tocode, automate ... Assess risks such asprompt injection, model evasion, data poisoning, jailbreaks, model inversion ...
Perform ongoing vulnerability assessments with Tenable, track remediation efforts, and validate ... of security controls. * Support external and internal audits (IRS, CMS, SSA, NIST, FISMA) by ...
Perform ongoing vulnerability assessments with Tenable, track remediation efforts, and validate ... of security controls. * Support external and internal audits (IRS, CMS, SSA, NIST, FISMA) by ...
Senior Network Security Engineer
$56.25 - $73.50/hr
Deploy andmaintainnetwork security controls including next-generation firewalls, IDS/IPS, WAF, and ... Experience with risk assessments, vulnerability testing, and incident response * Deep understanding ...
Senior Network Security Engineer
$56.25 - $73.50/hr
Deploy andmaintainnetwork security controls including next-generation firewalls, IDS/IPS, WAF, and ... Experience with risk assessments, vulnerability testing, and incident response * Deep understanding ...
VP Info Security
$149.90K - $187.60K/yr
Collaborate with the Privacy Officer, Legal, and Compliance teams to align security controls with ... assessments * Monitor the evolving regulatory and legislative landscape and proactively advise ...
VP Info Security
$149.90K - $187.60K/yr
Collaborate with the Privacy Officer, Legal, and Compliance teams to align security controls with ... assessments * Monitor the evolving regulatory and legislative landscape and proactively advise ...
Ability to assess technical risk and translate findings into actionable engineering controls and governance language. * Working knowledge of AI/ML security risks relevant to an enterprise consumer ...
Ability to assess technical risk and translate findings into actionable engineering controls and governance language. * Working knowledge of AI/ML security risks relevant to an enterprise consumer ...
Implement security controls for Model Context Protocol (MCP) and similar agent integration patterns ... Perform threat modeling and risk assessments for AI architectures, including RAG pipelines, vector ...
Implement security controls for Model Context Protocol (MCP) and similar agent integration patterns ... Perform threat modeling and risk assessments for AI architectures, including RAG pipelines, vector ...
Implement security controls for Model Context Protocol (MCP) and similar agent integration patterns ... Perform threat modeling and risk assessments for AI architectures, including RAG pipelines, vector ...
Implement security controls for Model Context Protocol (MCP) and similar agent integration patterns ... Perform threat modeling and risk assessments for AI architectures, including RAG pipelines, vector ...
Implement security controls for Model Context Protocol (MCP) and similar agent integration patterns ... Perform threat modeling and risk assessments for AI architectures, including RAG pipelines, vector ...
Implement security controls for Model Context Protocol (MCP) and similar agent integration patterns ... Perform threat modeling and risk assessments for AI architectures, including RAG pipelines, vector ...
Security Controls Assessor information
See Decatur, GA salary details
$8.68 - $14.83
2% of jobs
$14.83 - $20.97
2% of jobs
$20.97 - $27.12
0% of jobs
$27.12 - $33.26
0% of jobs
$33.26 - $39.41
3% of jobs
$39.41 - $45.55
5% of jobs
$49.16 is the 25th percentile. Wages below this are outliers.
$45.55 - $51.70
21% of jobs
The median wage is $56.71 / hr.
$51.70 - $57.84
20% of jobs
$57.84 - $63.99
18% of jobs
$65.41 is the 75th percentile. Wages above this are outliers.
$63.99 - $70.13
15% of jobs
$70.13 - $76.28
14% of jobs
$8
$57
$76
How much do security controls assessor jobs pay per hour?
What Does a Security Controls Assessor Do?
A security controls assessor (SCA) evaluates the security controls within network systems to identify vulnerabilities and recommend actions to correct problems, working either alone or as part of a team. As a security controls assessor, your duties begin with conducting an in-depth assessment of the management, operations, and technical security controls. You must analyze information and prepare reports describing the vulnerability level of the network with specific detail as to what compromises data systems. You then develop a plan to address vulnerabilities and continue to monitor the security of network systems.
What are the key skills and qualifications needed to thrive as a Security Controls Assessor, and why are they important?
What are some common challenges Security Controls Assessors face when evaluating compliance across multiple systems?
What are Security Controls Assessors?
What is the difference between Security Controls Assessor vs Security Analyst?
| Aspect | Security Controls Assessor | Security Analyst |
|---|---|---|
| Certifications | ISO 27001 Lead Auditor, CISSP, CISA | CISSP, Security+ |
| Work Environment | Assessing security controls, compliance audits | Monitoring security systems, incident response |
| Employer & Industry | Government agencies, compliance firms | Corporate IT, cybersecurity teams |
The Security Controls Assessor primarily evaluates and verifies security controls for compliance, often in government or regulated environments. In contrast, a Security Analyst focuses on monitoring, analyzing, and responding to security threats within organizations. While both roles require security certifications and involve cybersecurity, their core responsibilities and work settings differ significantly.
Full-time
Posted 14 days ago
Piedmont Healthcare rating
7.0
Based on 449 frontline employees who took The Breakroom Quiz
400th of 864 rated healthcare providers
Job description
The VP of Information Security is the senior executive accountable for the protection of Piedmont Healthcare system's information assets, technology infrastructure, and patient data across a complex, integrated delivery network. Reporting directly to the Chief Information Officer (CIO), this position provides strategic vision, enterprise-wide governance, and hands-on leadership for all aspects of information security, cyber risk, and regulatory compliance.
Will be responsible for building and sustaining a mature security program capable of defending against sophisticated threats targeting healthcare - one of the most targeted sectors in the world - while enabling the organization to leverage digital innovation, cloud platforms, and advanced analytics in support of its clinical and operational mission.
This role serves as a primary advisor to the CIO and the Information Security Steering Committee on all matters of cybersecurity strategy, risk posture, and regulatory compliance, and is the organization's primary liaison to government agencies, law enforcement, and external security partners in the event of a significant cyber incident.
ResponsibilitiesSecurity Strategy & Program Leadership
- Develop, implement, and continuously mature a comprehensive enterprise information security strategy aligned to business objectives, clinical operations, and the organization's risk appetite
- Build and govern a security program spanning people, processes, and technology - including security architecture, engineering, operations, threat intelligence, and incident response
- Establish and maintain a security governance framework, including policies, standards, procedures, and control frameworks (NIST CSF, HITRUST, ISO 27001, or equivalent)
- Serve as the organization's authoritative voice on cybersecurity strategy, communicating risk posture and program maturity to the CIO, executive leadership, and Board Audit/Risk Committee
- Define and manage a multi-year security roadmap, balancing proactive investment with operational sustainability
Risk Management & Threat Intelligence
- Own the enterprise cyber risk management program - identifying, assessing, prioritizing, and remediating risks across clinical, operational, and administrative systems
- Lead threat intelligence, vulnerability management, and red team/penetration testing programs to proactively identify and address exposure
- Maintain situational awareness of the evolving healthcare threat landscape, including ransomware, nationstate actors, medical device vulnerabilities, and supply chain risk
- Develop and maintain a comprehensive third-party and vendor risk management program, including security assessments for business associates and technology partners
- Ensure cyber risk is effectively quantified, reported, and integrated into enterprise risk management and strategic planning processes
Regulatory Compliance & Privacy
- Ensure the organization maintains compliance with all applicable information security and privacy regulations including HIPAA, HITECH, 21st Century Cures Act, state privacy laws, and CMS requirements
- Collaborate with the Privacy Officer, Legal, and Compliance teams to align security controls with privacy obligations and to manage regulatory inquiries and breach notification requirements
- Lead preparation for and response to OCR audits, state regulatory reviews, and other external assessments
- Monitor the evolving regulatory and legislative landscape and proactively advise leadership on implications for the security program
Clinical & Operational Technology Security
- Develop and lead a dedicated program for securing clinical technology, including medical devices, IoT/IoMT, connected diagnostics, and OT/ICS environments
- Partner with clinical engineering, nursing informatics, and physician leaders to implement security controls that protect patient safety without disrupting care delivery
- Drive secure design and deployment principles for EHR integrations, telehealth platforms, and digital health solutions
- Ensure security is embedded into system development lifecycle (SDLC) and technology procurement processes across the enterprise
Leadership & Culture
- Build, mentor, and retain a high-performing security team of 30-80+ professionals across security architecture, engineering, operations, GRC, and awareness
- Cultivate a strong security culture across the organization through executive engagement, workforce training, and a security-by-design mindset
- Foster a collaborative, transparent relationship with the CTO, infrastructure, and application teams to integrate security into technology operations
- Establish strong relationships with peer CISOs, government agencies (HHS, CISA, FBI), and healthcare information sharing organizations (H-ISAC)
Education
- Bachelor's Degree in Computer Science, Information Security, Information Systems, or a related field required
Work Experience
- 10 years of progressive information security experience, with at least 7 years in a senior security leadership role (CISO, Deputy CISO, VP of Security, or equivalent)
- Demonstrated experience building and leading enterprise security programs at large, complex organizations - healthcare experience strongly preferred
- Proven track record managing significant cybersecurity incidents, including ransomware response, data breach notification, and regulatory investigations
- Experience presenting to and advising boards of directors, audit/risk committees, and C-suite executives on cyber risk and security strategy
- Familiarity with clinical environments, medical device security, and the unique operational constraints of healthcare delivery
Licenses and Certifications
- Professional certifications strongly preferred: CISSP, CISM, CISO, CRISC, GSLC, or equivalent; HCISPP or HITRUST certification
Disclaimer: The above information is intended to describe the general nature and level of work being performed by people assigned to this job. It is not intended to be an exhaustive list of responsibilities, duties and skills required of personnel so classified.
Business Unit : Company NamePiedmont Healthcare CorporateEmployment Type: FULL_TIMEWhat Piedmont Healthcare employees say
Pay
Benefits
Hours and flexibility
Workplace
Get the full story on Breakroom
About Piedmont
Sourced by ZipRecruiter
Industry
Health care and social assistance
Company size
10,000+ Employees
Headquarters location
Atlanta, GA, US
Year founded
1905