1

Security Controls Assessor Jobs in Hanover, MD (NOW HIRING)

Security Controls Assessor

Washington, DC ยท On-site

$150K - $168K/yr

ECS is seeking a Security Controls Assessor to work in our Washington, DC (hybrid) office. Please Note: This position is contingent upon contract award. ECS seeks a Security Controls Assessor to ...

Security Controls Assessor

Washington, DC ยท On-site

$160K - $180K/yr

SPA has an immediate need for a Security Controls Assessor (SCA). #FC #Dice Responsibilities The Security Controls Assessor (SCA) is responsible for conducting a comprehensive assessment of the ...

U.S. Citizenship Senior Security Controls Assessor (SCA): The primary role of personnel in this position will be assessing the overall security compliance of the client's information systems. This ...

AWS Assessor

Washington, DC ยท On-site

$130K - $147K/yr

This Assessor is responsible for leading the Risk Management Engineering (RME) team in planning and ... Complete and execute a cloud Security Controls Test (SCT) plan. * Provide the final cloud analysis ...

next page

Showing results 1-20

Security Controls Assessor information

See Hanover, MD salary details

$8

$58

$77

How much do security controls assessor jobs pay per hour?

As of Aug 19, 2026, the average hourly pay for security controls assessor in Hanover, MD is $58.47, according to ZipRecruiter salary data. Most workers in this role earn between $50.24 and $67.69 per hour, depending on experience, location, and employer.

What is a security controls assessor?

Security Controls Assessors are professionals responsible for evaluating and validating the effectiveness of security controls within an organization's information systems. They conduct assessments to ensure compliance with regulatory standards, such as NIST, FISMA, or other security frameworks. Their work helps organizations identify vulnerabilities, manage risks, and maintain the confidentiality, integrity, and availability of critical data. Security Controls Assessors often provide recommendations for remediation and support efforts to achieve or maintain security certifications.

What does a security controls assessor do?

A security controls assessor (SCA) evaluates the security controls within network systems to identify vulnerabilities and recommend actions to correct problems, working either alone or as part of a team. As a security controls assessor, your duties begin with conducting an in-depth assessment of the management, operations, and technical security controls. You must analyze information and prepare reports describing the vulnerability level of the network with specific detail as to what compromises data systems. You then develop a plan to address vulnerabilities and continue to monitor the security of network systems.

What are the key skills and qualifications needed to thrive as a security controls assessor, and why are they important?

To thrive as a Security Controls Assessor, you need expertise in information security frameworks, risk assessment methodologies, and compliance requirements, often supported by a degree in cybersecurity or related fields and certifications like CISSP, CISA, or CAP. Familiarity with tools such as vulnerability scanners, security assessment platforms, and compliance management systems is typically required. Strong analytical thinking, attention to detail, and effective communication skills help you identify risks and clearly report findings to stakeholders. These skills ensure that organizations maintain robust security postures and meet regulatory requirements to protect critical assets.

What are some common challenges security controls assessors face when evaluating compliance across multiple systems?

Security Controls Assessors often encounter challenges with inconsistent documentation, varying system configurations, and differing interpretations of compliance standards across departments. Coordinating with multiple teams to collect evidence and clarify control implementations can be time-consuming, especially in large organizations. Staying current with evolving regulations and ensuring all systems meet the latest requirements also demands continuous learning and adaptability. Building strong communication channels with system owners and IT staff helps overcome these hurdles and ensures thorough, accurate assessments.

What is the difference between Security Controls Assessor vs Security Analyst?

AspectSecurity Controls AssessorSecurity Analyst
CertificationsISO 27001 Lead Auditor, CISSP, CISACISSP, Security+
Work EnvironmentAssessing security controls, compliance auditsMonitoring security systems, incident response
Employer & IndustryGovernment agencies, compliance firmsCorporate IT, cybersecurity teams

The Security Controls Assessor primarily evaluates and verifies security controls for compliance, often in government or regulated environments. In contrast, a Security Analyst focuses on monitoring, analyzing, and responding to security threats within organizations. While both roles require security certifications and involve cybersecurity, their core responsibilities and work settings differ significantly.

What are popular job titles related to Security Controls Assessor jobs in Hanover, MD?

For Security Controls Assessor jobs in Hanover, MD, the most frequently searched job titles are:

What cities near Hanover, MD are hiring for Security Controls Assessor jobs?

Cities near Hanover, MD with the most Security Controls Assessor job openings:

Infographic showing various Security Controls Assessor job openings in Hanover, MD as of August 2026, with employment types broken down into 85% Full Time, 12% Part Time, and 3% Contract. Highlights an 93% Physical, 2% Hybrid, and 5% Remote job distribution, with an average salary of $121,625 per year, or $58.5 per hour.

$150K - $168K/yr

Other

Posted 8 days ago


Job description

Job Description
ECS is seeking a Security Controls Assessor to work in our Washington, DC (hybrid) office. Please Note: This position is contingent upon contract award.
ECS seeks a Security Controls Assessor to support a full range of cybersecurity services on a long-term, full-time contract with a U.S. Government civilian agency. This position requires mostly CONUS and occasional OCONUS assessments and is available immediately for a qualified candidate with an active security clearance.
Key Responsibilities
  • Review and update information security policies, standards, and procedures in accordance with federal and departmental regulations
  • Perform independent security and privacy control assessments on behalf of the client CSO in support of Security Assessment & Authorization (SA&A)
  • Assess existing and new FISMA systems and subsystems, and communicate findings and potential impacts of identified control weaknesses
  • Review and analyze A&A packages-including System Security Plans (SSP), Risk Assessments, Information System Contingency Plans (ISCP), Backup SOPs, Incident Response Plans (IRP), Configuration Management Plans (CMP), hardware/software inventories, network diagrams, data flows, system change requests, vulnerability scan reports, test reports, and POA&Ms-for completeness, accuracy, and effective control implementation
  • Develop and maintain test cases for control-level security testing across system components (applications, servers, databases, operating systems, network devices, end-user devices, etc.)
  • Develop and execute security and privacy assessment plans in accordance with NIST SP 800-53A, supporting RMF Steps 4-6
  • Document findings and recommendations that are clear, system-specific, and actionable
  • Analyze security tool outputs to distinguish residual risk from false positives prior to finalizing findings
  • CONUS and OCONUS travel to conduct system assessments
  • Other duties as assigned
Salary Range: $150,000-$168,000
General Description of Benefits
Required Skills
  • Active Secret clearance required with eligibility to get Top Secret clearance
  • Bachelor's degree in Computer Science, MIS/IT, Engineering, Information Security/Assurance, or a related field
  • Minimum five (5) years of information security experience
  • Minimum three (3) years of experience supporting security assessment teams, including planning assessments and serving as a senior team member
  • Two (2) years of experience using GRC tools
  • Demonstrated experience conducting full-scope technical security control testing across component types, including development of security and privacy assessment plans
  • Working knowledge of RMF Steps 1-6
  • Strong understanding of NIST SP 800-53 controls, the NIST Cybersecurity Framework, and applicable information security/privacy laws and regulations
  • Ability to analyze information system configurations and technical specifications against NIST SP 800-53 and related overlays
  • Experience developing risk-based documentation
  • Excellent written and verbal communication skills, with the ability to present control requirements and deficiencies clearly to both technical and non-technical audiences

Desired Skills
  • Assessment and Authorization (A&A) activities, including risk assessments, Security Plans, Security Controls Assessments (SCA), and related documentation
  • Current industry practices for evaluating, implementing, and disseminating IT security assessment, monitoring, detection, and remediation tools
  • Assessing systems hosted in AWS and/or Azure cloud environments
  • Conducting assessments in accordance with OMB, NIST, and FedRAMP policies, procedures, and standards
  • One of the following:
    • CISSP (Certified Information Systems Security Professional)
    • CEH (Certified Ethical Hacker)
    • CRISC (Certified in Risk and Information Systems Control)
    • CISA (Certified Information Systems Auditor)
    • AAIA (Advanced in AI Audits)
ECS Federal LLC is an equal opportunity employer and does not discriminate or allow discrimination on the basis any characteristic protected by law. All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, or local jurisdiction law.
Everforth ECS is the federal segment of Everforth , a $4B global organization with over 10,000 employees. Our nearly 3,500 professionals deliver advanced technology solutions in data and AI, cybersecurity, and enterprise transformation, serving defense, intelligence, and federal civilian agencies.
Our work powers mission-critical outcomes, strengthens technology partnerships, and creates meaningful opportunities for our people. We are defined by a commitment to excellence in delivery, a culture of innovation, and an environment where talent can thrive and grow.
We value:
  • Attracting and developing top talent and high-performing teams
  • Fostering a culture that is engaging, accountable, and mission-driven

Meet the challenge. Make a difference with Everforth ECS!