Implement preventive, default-on security controls across cloud and enterprise environments ... Support third-party and vendor risk assessments, with a focus on vendors who process data through ...
Implement preventive, default-on security controls across cloud and enterprise environments ... Support third-party and vendor risk assessments, with a focus on vendors who process data through ...
Sr IT Security Engineer
Atlanta, GA · On-site
$110K - $151K/yr
Performs information security risk assessments of internally developed solutions and cloud-based ... Evaluates vendor security controls to ensure continued security compliance with Interface standards ...
Sr IT Security Engineer
Atlanta, GA · On-site
$110K - $151K/yr
Performs information security risk assessments of internally developed solutions and cloud-based ... Evaluates vendor security controls to ensure continued security compliance with Interface standards ...
Security Engineer
Atlanta, GA · On-site
Experience with patching and vulnerability assessment tools. * Knowledge of industry frameworks like NIST Cybersecurity Framework and Center for * Internet Security (CIS) Critical Security Controls.
Security Engineer
Atlanta, GA · On-site
Experience with patching and vulnerability assessment tools. * Knowledge of industry frameworks like NIST Cybersecurity Framework and Center for * Internet Security (CIS) Critical Security Controls.
Sr IT Security Engineer
Atlanta, GA · On-site
$110K - $151K/yr
Performs information security risk assessments of internally developed solutions and cloud-based ... Evaluates vendor security controls to ensure continued security compliance with Interface standards ...
Sr IT Security Engineer
Atlanta, GA · On-site
$110K - $151K/yr
Performs information security risk assessments of internally developed solutions and cloud-based ... Evaluates vendor security controls to ensure continued security compliance with Interface standards ...
Sr IT Security Engineer
Atlanta, GA · On-site
$110K - $151K/yr
Performs information security risk assessments of internally developed solutions and cloud-based ... Evaluates vendor security controls to ensure continued security compliance with Interface standards ...
Sr IT Security Engineer
Atlanta, GA · On-site
$110K - $151K/yr
Performs information security risk assessments of internally developed solutions and cloud-based ... Evaluates vendor security controls to ensure continued security compliance with Interface standards ...
Sr IT Security Engineer
$110K - $151K/yr
Performs information security risk assessments of internally developed solutions and cloud-based ... Evaluates vendor security controls to ensure continued security compliance with Interface standards ...
Sr IT Security Engineer
$110K - $151K/yr
Performs information security risk assessments of internally developed solutions and cloud-based ... Evaluates vendor security controls to ensure continued security compliance with Interface standards ...
Sr IT Security Engineer
$110K - $151K/yr
Performs information security risk assessments of internally developed solutions and cloud-based ... Evaluates vendor security controls to ensure continued security compliance with Interface standards ...
Sr IT Security Engineer
$110K - $151K/yr
Performs information security risk assessments of internally developed solutions and cloud-based ... Evaluates vendor security controls to ensure continued security compliance with Interface standards ...
Senior Vendor Risk Analyst
Atlanta, GA · Hybrid
$100K - $130K/yr
In coordination with the customers vendor relationship owners, manage assessments of vendors' security controls to identify shortfalls. * Communicate remediation options to the vendors * Collaborate ...
Senior Vendor Risk Analyst
Atlanta, GA · Hybrid
$100K - $130K/yr
In coordination with the customers vendor relationship owners, manage assessments of vendors' security controls to identify shortfalls. * Communicate remediation options to the vendors * Collaborate ...
Senior Vendor Risk Analyst
Atlanta, GA · On-site
$100K - $130K/yr
In coordination with the customers vendor relationship owners, manage assessments of vendors' security controls to identify shortfalls. * Communicate remediation options to the vendors * Collaborate ...
Senior Vendor Risk Analyst
Atlanta, GA · On-site
$100K - $130K/yr
In coordination with the customers vendor relationship owners, manage assessments of vendors' security controls to identify shortfalls. * Communicate remediation options to the vendors * Collaborate ...
Performs vulnerability assessments against new devices before production implementation. • ... controls for business systems. 5.Assists the Information Security Officer with technology ...
Performs vulnerability assessments against new devices before production implementation. • ... controls for business systems. 5.Assists the Information Security Officer with technology ...
... assessments, remediation tracking, and security hardening. - Manage endpoint protection systems, email security, MFA, Conditional Access, and identity security controls. - Configure and maintain SIEM ...
... assessments, remediation tracking, and security hardening. - Manage endpoint protection systems, email security, MFA, Conditional Access, and identity security controls. - Configure and maintain SIEM ...
REMOTE Cybersecurity Engineer ( W2 direct hire, US citizen or GC only, no C2C )
Atlanta, GA · On-site +1
... assessments, remediation tracking, and security hardening. - Manage endpoint protection systems, email security, MFA, Conditional Access, and identity security controls. - Configure and maintain SIEM ...
REMOTE Cybersecurity Engineer ( W2 direct hire, US citizen or GC only, no C2C )
Atlanta, GA · On-site +1
... assessments, remediation tracking, and security hardening. - Manage endpoint protection systems, email security, MFA, Conditional Access, and identity security controls. - Configure and maintain SIEM ...
Security Architect
$62.50 - $80.75/hr
Understanding of security frameworks such as MITRE ATT&CK, NIST CSF, and CIS Controls. * Strong problem-solving skills with the ability to assess and mitigate security risks effectively. * Excellent ...
Security Architect
$62.50 - $80.75/hr
Understanding of security frameworks such as MITRE ATT&CK, NIST CSF, and CIS Controls. * Strong problem-solving skills with the ability to assess and mitigate security risks effectively. * Excellent ...
Security Architect
Atlanta, GA · On-site
$62.50 - $80.75/hr
Understanding of security frameworks such as MITRE ATT&CK, NIST CSF, and CIS Controls. * Strong problem-solving skills with the ability to assess and mitigate security risks effectively. * Excellent ...
Security Architect
Atlanta, GA · On-site
$62.50 - $80.75/hr
Understanding of security frameworks such as MITRE ATT&CK, NIST CSF, and CIS Controls. * Strong problem-solving skills with the ability to assess and mitigate security risks effectively. * Excellent ...
Perform ongoing vulnerability assessments with Tenable, track remediation efforts, and validate ... of security controls. * Support external and internal audits (IRS, CMS, SSA, NIST, FISMA) by ...
Perform ongoing vulnerability assessments with Tenable, track remediation efforts, and validate ... of security controls. * Support external and internal audits (IRS, CMS, SSA, NIST, FISMA) by ...
Ability to assess technical risk and translate findings into actionable engineering controls and governance language. * Working knowledge of AI/ML security risks relevant to an enterprise consumer ...
Ability to assess technical risk and translate findings into actionable engineering controls and governance language. * Working knowledge of AI/ML security risks relevant to an enterprise consumer ...
Cloud Security Engineer
$53.50 - $71.75/hr
Partner with engineering and DevOps teams to integrate security controls into CI/CD pipelines and ... Support security assessments of AI/ML workloads and cloud-native data platforms; contribute to ...
Cloud Security Engineer
$53.50 - $71.75/hr
Partner with engineering and DevOps teams to integrate security controls into CI/CD pipelines and ... Support security assessments of AI/ML workloads and cloud-native data platforms; contribute to ...
Cloud Security Engineer
Atlanta, GA · On-site
$53.50 - $71.75/hr
Partner with engineering and DevOps teams to integrate security controls into CI/CD pipelines and ... Support security assessments of AI/ML workloads and cloud-native data platforms; contribute to ...
Cloud Security Engineer
Atlanta, GA · On-site
$53.50 - $71.75/hr
Partner with engineering and DevOps teams to integrate security controls into CI/CD pipelines and ... Support security assessments of AI/ML workloads and cloud-native data platforms; contribute to ...
Implement security controls for Model Context Protocol (MCP) and similar agent integration patterns ... Perform threat modeling and risk assessments for AI architectures, including RAG pipelines, vector ...
Implement security controls for Model Context Protocol (MCP) and similar agent integration patterns ... Perform threat modeling and risk assessments for AI architectures, including RAG pipelines, vector ...
LanceSoft, Inc. is seeking a Vulnerability Assessment Analyst to join their Cybersecurity ... security controls and hardening practices, including image scanning, least privilege, non-root ...
LanceSoft, Inc. is seeking a Vulnerability Assessment Analyst to join their Cybersecurity ... security controls and hardening practices, including image scanning, least privilege, non-root ...
Security Controls Assessor information
See Decatur, GA salary details
$8.68 - $14.83
2% of jobs
$14.83 - $20.97
2% of jobs
$20.97 - $27.12
0% of jobs
$27.12 - $33.26
0% of jobs
$33.26 - $39.41
3% of jobs
$39.41 - $45.55
5% of jobs
$49.16 is the 25th percentile. Wages below this are outliers.
$45.55 - $51.70
21% of jobs
The median wage is $56.71 / hr.
$51.70 - $57.84
20% of jobs
$57.84 - $63.99
18% of jobs
$65.41 is the 75th percentile. Wages above this are outliers.
$63.99 - $70.13
15% of jobs
$70.13 - $76.28
14% of jobs
$8
$57
$76
How much do security controls assessor jobs pay per hour?
What are Security Controls Assessors?
What are the key skills and qualifications needed to thrive as a Security Controls Assessor, and why are they important?
What are some common challenges Security Controls Assessors face when evaluating compliance across multiple systems?
What Does a Security Controls Assessor Do?
A security controls assessor (SCA) evaluates the security controls within network systems to identify vulnerabilities and recommend actions to correct problems, working either alone or as part of a team. As a security controls assessor, your duties begin with conducting an in-depth assessment of the management, operations, and technical security controls. You must analyze information and prepare reports describing the vulnerability level of the network with specific detail as to what compromises data systems. You then develop a plan to address vulnerabilities and continue to monitor the security of network systems.
What is the difference between Security Controls Assessor vs Security Analyst?
| Aspect | Security Controls Assessor | Security Analyst |
|---|---|---|
| Certifications | ISO 27001 Lead Auditor, CISSP, CISA | CISSP, Security+ |
| Work Environment | Assessing security controls, compliance audits | Monitoring security systems, incident response |
| Employer & Industry | Government agencies, compliance firms | Corporate IT, cybersecurity teams |
The Security Controls Assessor primarily evaluates and verifies security controls for compliance, often in government or regulated environments. In contrast, a Security Analyst focuses on monitoring, analyzing, and responding to security threats within organizations. While both roles require security certifications and involve cybersecurity, their core responsibilities and work settings differ significantly.

Full-time
Medical, Dental, Vision, Life, Retirement, PTO
Posted 3 days ago
Job description
Rithum™ is the world’s most trusted commerce network, accelerating how brands, suppliers, and retailers work together to deliver seamless e-commerce experiences. We provide an unmatched platform for brands and retailers, enabling them to accelerate growth, optimize operations across channels, scale product offerings and enhance margins.
Today, more than 40,000 companies trust Rithum to grow their business across hundreds of channels, representing over $50 billion in annual GMV. Using our commerce, marketing, and delivery solutions, our customers create optimized consumer shopping journeys from beginning to end.
Overview
As an AI-first organization, Rithum expects employees across all roles to leverage AI and technology to improve efficiency, streamline workflows, and create scalable ways of working.
Rithum is embedding AI into every corner of how it operates — and security is no exception.
As a Staff AI-First Information Security Engineer, you own the intersection of AI adoption and information security: designing guardrails for AI-powered products, building automated security tooling, designing security controls and monitoring for an AI-First workforce, helping every team at Rithum move fast without creating risk they cannot see. This is not a typical security role. You spend as much time building and automating as you do reviewing, turning a repeating control into infrastructure-as-code, a manual review into a workflow, and a vague AI risk into a concrete, enforced guardrails. You work autonomously, balancing research with fast-paced delivery, and collaborating closely with Platform Engineering, IT, Security Champions, and external auditors.
Responsibilities
- Act as the bridge between architectural intent and operational reality; mediate conflicts between security requirements and feasible implementation, propose compensating controls where gaps exist and help register, track and remediate residual risks.
- Implement preventive, default-on security controls across cloud and enterprise environments, codified as policy- and infrastructure-as-code so security is enforced by design, including controls that govern how AI tools and models may be used.
- Implement and enforce identity and access controls to an agreed standard, including access boundaries for AI systems and non-human/agent identities by partnering with Platform Engineering and IT to align tooling and policy to the architecture.
- Assist in maintaining the InfoSec risk register; track emerging threats and translate them into actionable guidance for engineering teams.
- Support third-party and vendor risk assessments, with a focus on vendors who process data through AI pipelines.
- Automate repetitive security workflows (evidence collection, access reviews, alert enrichment) and build or operate AI-assisted security agents — with human-in-the-loop approval gates, least-privilege credentials, and explicit attention to each agent\'s own blast radius.
- Integrate security tooling (SIEM, CSPM, DAST/SAST, vulnerability scanners) with LLM layers to surface actionable insight and automated responses.
- Define and enforce security requirements for AI-powered features: model access controls, prompt-injection mitigations, output validation, and data-handling boundaries.
- Conduct threat modelling on agentic and LLM-based systems, accounting for novel attack surfaces such as tool misuse, indirect prompt injection, and supply chain risk.
Qualifications
Minimum Qualifications
- 5+ years of security engineering experience with demonstrated AI/ML security depth (prompt injection, model supply chain, adversarial inputs, RAG).
- Experience using AI tools (ChatGPT, Copilot, Claude, etc.) and LLM frameworks and APIs (OpenAI, Anthropic, LangChain, or similar) to accelerate and elevate your work.
- Hands-on identity and access expertise across modern enterprise and cloud identity stacks, including access models for AI systems and non-human identities.
- Infrastructure and policy-as-code (e.g. Terraform, OPA/Rego) and proficiency in a scripting language for automation (Python preferred).
- Cloud security expertise: AWS Solutions Architect / Security Specialty or equivalent demonstrated expertise, including multi-account governance, preventive guardrails, and policy-as-code.
- Application security (OWASP Top 10 and the OWASP LLM/GenAI Top 10, secure SDLC) and threat-modelling methodologies (STRIDE, PASTA, or equivalent). Practical experience building or operating AI agents, and integrating security tooling (SIEM, CSPM, SAST/DAST/SCA) so it surfaces action rather than raw alerts.
- Working knowledge of SOC 2 and/or ISO 27001 control frameworks.
Preferred Qualifications
- Experience building or operating AI agents in a production environment.
- Awareness of privacy regulation (GDPR/CCPA) as it touches AI including privacy-by-design and DPIAs.
- Red teaming or adversarial ML research backgrounds.
- Experience implementing privileged-access, key-management, posture-management, or data-protection programs.
- Experience with EDR, CASB, DLP, Security automation and SAST, DAST, IAST and SCA tools.
- Cloud Architecture or Security certifications (CCSK, TAISE, AWS).
Travel Required
Up to 10%
Other Duties
Please note this job description is not designed to cover or contain a comprehensive listing of activities, duties or responsibilities required of the employee for this job. Duties, responsibilities, and activities may change at any time with or without notice.
What it’s like to work at Rithum
When you join Rithum, you can expect to work with smart risk-takers, courageous collaborators, and curious minds.
As part of the Rithum team, you are valued, supported, and included. Guided by a transparent culture and accessible, approachable leadership, we offer career opportunities aligned to your ambitions and talents. To ensure work and life balance works for you, we also offer an array of resources to support you and your families, including comprehensive benefits and wellness plans.
At Rithum you will:
- Partner with the leading brands and retailers.
- Connect with passionate professionals who will help support your goals.
- Participate in an inclusive, welcoming work atmosphere.
- Achieve work-life balance through remote-first working conditions, generous time off, and wellness days.
- Receive industry-competitive compensation and total rewards benefits.
We believe in transparency and fairness in our compensation practices.
For this position, the expected base pay range is: $170,000-$220,000 per year.
This range represents the base pay for the role across all U.S. locations and is determined based on market data, internal equity, and experience. Final compensation may vary depending on geographic location, skills, and relevant experience.In addition to base pay, we offer a discretionary bonus for non-sales roles, a comprehensive benefits package, and, where applicable, sales incentives.
For this position, the expected discretionary bonus is 12% of the annual base salary.
Benefits
- Medical, dental and vision benefits: Affordable health care plans and company HSA contributions, starting on Day 1
- A 6% 401(k) match
- Competitive time off package with 20 days of Paid Time Off, 9 Company-Paid holidays, 2 paid floating holidays, 7 paid sick days, 2 Wellness days, and 1 Paid Volunteer Day; at 3 years of service PTO increases to 22 days, and at 5 years it increases to 25 days
- 12 weeks primary caregiver leave & 4 weeks secondary caregiver leave
- Accident, critical illness, and hospital indemnity insurance
- Pet insurance
- Legal assistance and identity theft insurance plans
- Life insurance 2x salary
- Access to the Calm app and the Employee Assistance Program
- $65/month Remote work stipend for internet
- Culture and team-building activities
- Tuition assistance
- Career development opportunities
- Charitable contribution match up to $250 per year
Rithum is an equal opportunity employer. We are committed to providing an environment of mutual respect where equal employment opportunities are available to all applicants and teammates without regard to race, religion, color, sex, gender identity, sexual orientation, age, non-disqualifying physical or mental disability, national origin, veteran status or any other protected characteristic. All employment is decided on the basis of qualifications, merit, and business need.
We\'re committed to providing reasonable accommodations in accordance with the law for qualified applicants. If you require assistance during the interview process due to a medical condition or need support accessing our website or completing the application process, please reach out to us by completing the Accommodations Request Form. Your comfort and accessibility are important to us, and we\'re here to ensure a seamless experience as you explore opportunities with our team.