1

Security Controls Assessor Jobs in Reston, VA (NOW HIRING)

Working knowledge of NIST SP 80053 security and privacy controls * Understanding of riskbased assessment concepts * Ability to analyze assessment evidence and clearly document findings What Would Be ...

Showing results 21-40

Security Controls Assessor information

See Reston, VA salary details

$9

$61

$81

How much do security controls assessor jobs pay per hour?

As of Aug 22, 2026, the average hourly pay for security controls assessor in Reston, VA is $61.14, according to ZipRecruiter salary data. Most workers in this role earn between $52.50 and $70.77 per hour, depending on experience, location, and employer.

What is a security controls assessor?

Security Controls Assessors are professionals responsible for evaluating and validating the effectiveness of security controls within an organization's information systems. They conduct assessments to ensure compliance with regulatory standards, such as NIST, FISMA, or other security frameworks. Their work helps organizations identify vulnerabilities, manage risks, and maintain the confidentiality, integrity, and availability of critical data. Security Controls Assessors often provide recommendations for remediation and support efforts to achieve or maintain security certifications.

What does a security controls assessor do?

A security controls assessor (SCA) evaluates the security controls within network systems to identify vulnerabilities and recommend actions to correct problems, working either alone or as part of a team. As a security controls assessor, your duties begin with conducting an in-depth assessment of the management, operations, and technical security controls. You must analyze information and prepare reports describing the vulnerability level of the network with specific detail as to what compromises data systems. You then develop a plan to address vulnerabilities and continue to monitor the security of network systems.

What are the key skills and qualifications needed to thrive as a security controls assessor, and why are they important?

To thrive as a Security Controls Assessor, you need expertise in information security frameworks, risk assessment methodologies, and compliance requirements, often supported by a degree in cybersecurity or related fields and certifications like CISSP, CISA, or CAP. Familiarity with tools such as vulnerability scanners, security assessment platforms, and compliance management systems is typically required. Strong analytical thinking, attention to detail, and effective communication skills help you identify risks and clearly report findings to stakeholders. These skills ensure that organizations maintain robust security postures and meet regulatory requirements to protect critical assets.

What are some common challenges security controls assessors face when evaluating compliance across multiple systems?

Security Controls Assessors often encounter challenges with inconsistent documentation, varying system configurations, and differing interpretations of compliance standards across departments. Coordinating with multiple teams to collect evidence and clarify control implementations can be time-consuming, especially in large organizations. Staying current with evolving regulations and ensuring all systems meet the latest requirements also demands continuous learning and adaptability. Building strong communication channels with system owners and IT staff helps overcome these hurdles and ensures thorough, accurate assessments.

What is the difference between Security Controls Assessor vs Security Analyst?

AspectSecurity Controls AssessorSecurity Analyst
CertificationsISO 27001 Lead Auditor, CISSP, CISACISSP, Security+
Work EnvironmentAssessing security controls, compliance auditsMonitoring security systems, incident response
Employer & IndustryGovernment agencies, compliance firmsCorporate IT, cybersecurity teams

The Security Controls Assessor primarily evaluates and verifies security controls for compliance, often in government or regulated environments. In contrast, a Security Analyst focuses on monitoring, analyzing, and responding to security threats within organizations. While both roles require security certifications and involve cybersecurity, their core responsibilities and work settings differ significantly.

What are popular job titles related to Security Controls Assessor jobs in Reston, VA?

For Security Controls Assessor jobs in Reston, VA, the most frequently searched job titles are:

What job categories do people searching Security Controls Assessor jobs in Reston, VA look for?

The top searched job categories for Security Controls Assessor jobs in Reston, VA are:

What cities near Reston, VA are hiring for Security Controls Assessor jobs?

Cities near Reston, VA with the most Security Controls Assessor job openings:

Infographic showing various Security Controls Assessor job openings in Reston, VA as of August 2026, with employment types broken down into 86% Full Time, 11% Part Time, and 3% Contract. Highlights an 93% Physical, 2% Hybrid, and 5% Remote job distribution, with an average salary of $127,169 per year, or $61.1 per hour.

Security Controls Assessor - Senior with Security Clearance

SMS Data Products Group, Inc

Springfield, VA • On-site

Other

Posted 14 days ago


Job description

SMS is seeking a Senior Security Controls Assessor and Validator to join our team supporting the United States Coast Guard in Alexandria, VA. The successful senior level candidate will be responsible for evaluating, testing, and validating the effectiveness of security controls, with a strong emphasis on applying the Risk Management Framework (RMF) and have experience in leading a team of Assessors. Since 1976, SMS has specialized in modernizing legacy IT and sustaining complex enterprise environments for federal agencies. With the goal of building long-term partnerships with our customers, we invest in our employees by providing the training, tools, and support they need to keep critical missions operational, improve performance, and reduce risk. SMS is headquartered in McLean, Virginia, with offices and on-site operations at customer locations throughout the United States. For additional information on SMS, visit www.sms.com . Submit your resume today! Job Responsibilities * Serve as senior member and representative of assigned team for meetings and efficiently lead internal resources to meet established milestones and targeted completion dates. * Provide guidance, coaching and training to employees of assigned team. * Assist in Security Assessment & Authorization Coordination * Plan and conduct security authorization reviews of federal systems * Manage and review Accreditation Packages * Support USCG system accreditation and Ongoing Assessment and Ongoing Authorization processes and activities for assigned systems. * Provide SME knowledge of Risk Management Framework (RMF) policy and application, NIST Security Controls, and Control Implementation methodologies for the A&A process. * Review and provide guidance on System Security Plan, Security Assessment Report (SAR), and Plans of Action and Milestones and other security documentation * Support POA&M remediation activities and the review of POA&M closure documentation. * Responsible for assessing and developing authorization packages for technical solutions that may require collaboration with internal expertise and deep analysis of the technical solution. * Collaborate and communicates with parties within, and outside, of own job function. May have responsibility for communicating with parties external to the organization (e.g., customers, vendors) * Understands and supports Privacy Compliance Activities to include the review of Privacy Impact Analysis (PIA), Privacy Threshold Analysis (PTA), and Statement of Record Notices (SORN). * Facilitates and monitors information assurance (IA) processes for new projects, including the development of security authorization packages and the tracking of progress for all Security Control implementations and Plans of Action and Milestones (POA&M). * Support and/or development of all Security Authorization artifacts and documentation and assembling of Authorization packages. * Responsible for administration and adherence of the Risk Management Plan. * Coordinate closely with the Quality Assurance Specialists in identifying and mitigating risk to meet established quality standards. Required Qualifications * Minimum of an active DoD Secret clearance required * University Degree (BA/BS) or equivalent experience and minimum 5 years related work experience * CSSP-AU: CEH, CySA+, CISA, PenTest+, GSNA, or CFR . Within 60 days of hire. * DOD 8750 IAT III certifications: CASP+ CE, CCNP Security, CISA, CISSP (or associate), GCED, GCIH, or CCSP * Relevant DOD, DHS or .gov Cyber Security Information Assurance focused experience with specific current hands-on experience researching, writing, and submitting complete A&A documentation packages for new system authorizations. * Well-developed understanding of Federal Civilian or DHS Security Assessment and Authorization (SA&A) processes. * Experience with continuous monitoring/ongoing authorization * Intimate understanding of NIST RMF implementation guidance. * In-depth understanding of the relevance of NIST Security Controls and Control Implementation methodologies to the SA&A process. * Experience assessing security controls based on cybersecurity principles and tenets. (e.g., NIST SP 800-53, Cybersecurity Framework, etc.). * Demonstrated understanding of critical documentation required in Security Authorization (SA) Packages. * Ability to understand and support Privacy Compliance Activities to include the development of Privacy Impact Analysis (PIA), Privacy Threshold Analysis (PTA), and Statement of Record Notices (SORN). * Experience managing client relationships, including determining client needs/requirements, managing client expectations, and demonstrating commitment to delivering quality results. * Experience analyzing strategic guidance for issues requiring clarification and/or additional guidance. * Understanding of the basic concepts and issues related to cyber and its organizational impact. * Experience as senior or lead member of a team, including experience coaching and providing guidance to less experienced or new team resources, reviewing work products, tracking deadlines, and coverage, reporting, facilitating onboarding / offboarding procedures, etc. * Experience with administrative planning activities, to include preparation of functional and specific support plans and preparing and managing correspondence. * Understanding of Cloud Services delivery models and how each delivery model influences the Assessment and Authorization process. Desired Qualifications * Well-developed understanding of Systems Development Lifecycle (SDLC) and ideally the DHS Systems Engineering Lifecycle (SELC) process as it relates to Security Assessment and Authorization (SA&A) * Hands on experience with eMASS or similar application SMS is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.