1

Security Controls Assessor Jobs in Reston, VA (NOW HIRING)

Security Control Assessor

Arlington, VA · On-site

$140K - $160K/yr

This includes ensuring to guide the RMF process so that security controls are integrated seamlessly ... Ensure security assessments are completed for each IS. * Initiate a POA&M with identified ...

Security Control Assessor

Arlington, VA · On-site

$140K - $160K/yr

This includes ensuring to guide the RMF process so that security controls are integrated seamlessly ... Ensure security assessments are completed for each IS. * Initiate a POA&M with identified ...

Showing results 21-40

Security Controls Assessor information

See Reston, VA salary details

$9

$61

$81

How much do security controls assessor jobs pay per hour?

As of Sep 14, 2026, the average hourly pay for security controls assessor in Reston, VA is $61.25, according to ZipRecruiter salary data. Most workers in this role earn between $52.60 and $70.91 per hour, depending on experience, location, and employer.

What is a security controls assessor?

Security Controls Assessors are professionals responsible for evaluating and validating the effectiveness of security controls within an organization's information systems. They conduct assessments to ensure compliance with regulatory standards, such as NIST, FISMA, or other security frameworks. Their work helps organizations identify vulnerabilities, manage risks, and maintain the confidentiality, integrity, and availability of critical data. Security Controls Assessors often provide recommendations for remediation and support efforts to achieve or maintain security certifications.

What does a security controls assessor do?

A security controls assessor (SCA) evaluates the security controls within network systems to identify vulnerabilities and recommend actions to correct problems, working either alone or as part of a team. As a security controls assessor, your duties begin with conducting an in-depth assessment of the management, operations, and technical security controls. You must analyze information and prepare reports describing the vulnerability level of the network with specific detail as to what compromises data systems. You then develop a plan to address vulnerabilities and continue to monitor the security of network systems.

What are the key skills and qualifications needed to thrive as a security controls assessor, and why are they important?

To thrive as a Security Controls Assessor, you need expertise in information security frameworks, risk assessment methodologies, and compliance requirements, often supported by a degree in cybersecurity or related fields and certifications like CISSP, CISA, or CAP. Familiarity with tools such as vulnerability scanners, security assessment platforms, and compliance management systems is typically required. Strong analytical thinking, attention to detail, and effective communication skills help you identify risks and clearly report findings to stakeholders. These skills ensure that organizations maintain robust security postures and meet regulatory requirements to protect critical assets.

What are some common challenges security controls assessors face when evaluating compliance across multiple systems?

Security Controls Assessors often encounter challenges with inconsistent documentation, varying system configurations, and differing interpretations of compliance standards across departments. Coordinating with multiple teams to collect evidence and clarify control implementations can be time-consuming, especially in large organizations. Staying current with evolving regulations and ensuring all systems meet the latest requirements also demands continuous learning and adaptability. Building strong communication channels with system owners and IT staff helps overcome these hurdles and ensures thorough, accurate assessments.

What is the difference between Security Controls Assessor vs Security Analyst?

AspectSecurity Controls AssessorSecurity Analyst
CertificationsISO 27001 Lead Auditor, CISSP, CISACISSP, Security+
Work EnvironmentAssessing security controls, compliance auditsMonitoring security systems, incident response
Employer & IndustryGovernment agencies, compliance firmsCorporate IT, cybersecurity teams

The Security Controls Assessor primarily evaluates and verifies security controls for compliance, often in government or regulated environments. In contrast, a Security Analyst focuses on monitoring, analyzing, and responding to security threats within organizations. While both roles require security certifications and involve cybersecurity, their core responsibilities and work settings differ significantly.

What are popular job titles related to Security Controls Assessor jobs in Reston, VA?

For Security Controls Assessor jobs in Reston, VA, the most frequently searched job titles are:

What job categories do people searching Security Controls Assessor jobs in Reston, VA look for?

The top searched job categories for Security Controls Assessor jobs in Reston, VA are:

What cities near Reston, VA are hiring for Security Controls Assessor jobs?

Cities near Reston, VA with the most Security Controls Assessor job openings:

Infographic showing various Security Controls Assessor job openings in Reston, VA as of September 2026, with employment types broken down into 2% As Needed, 86% Full Time, 5% Part Time, and 7% Contract. Highlights an 86% In-person, 4% Hybrid, and 10% Remote job distribution, with an average salary of $127,403 per year, or $61.3 per hour.

Cybersecurity Controls Assessor with Security Clearance

Washington, DC • On-site

Contractor

Medical, Dental, Vision, Life, Retirement

Posted 12 days ago


Key responsibilities

  • Conduct independent assessments of security controls across FEMA information systems to evaluate their effectiveness and compliance with federal cybersecurity standards.

  • Perform security assessment procedures such as interviews, documentation reviews, examinations, and technical testing to identify security gaps and vulnerabilities.

  • Generate assessment artifacts, including Security Assessment Reports and develop recommendations to support authorization and continuous monitoring activities.


Job description

Job #: 3047689 Apex Systems is currently hiring a security controls assessor with a large federal client. In this role, you will be responsible for conducting independent assessments of security controls across FEMA information systems to ensure compliance with federal cybersecurity requirements and standards. You will partner with system owners, ISSOs, stakeholders, and cybersecurity teams to evaluate control implementation, identify security gaps, assess residual risk, and support authorization efforts for mission-critical systems. The ideal candidate will have experience performing security control assessments, developing assessment artifacts, and supporting Risk Management Framework (RMF) activities in a federal environment. Key Responsibilities
• Evaluate the effectiveness of IT security controls and assess compliance with NIST SP 800-53 and DHS RMF requirements
• Conduct security assessment procedures including:
o Interviews
o Documentation reviews
o Examinations
o Technical testing
• Analyze and assess:
o System Security Plans (SSPs)
o Policies and procedures
o Security documentation
o Evidence artifacts
• Identify security gaps, vulnerabilities, and residual risk
• Generate findings and recommendations for Security Assessment Reports
• Perform independent assessments across assigned systems and authorization boundaries
• Evaluate management, operational, and technical security controls
• Review and maintain security architecture documentation within the system of record
• Provide written and verbal analysis of security architecture documentation, risk assessments, and vulnerability assessments
• Support Authorization to Operate (ATO) activities
• Assist with continuous monitoring and ongoing authorization efforts
• Support vulnerability management, incident response, and remediation activities
• Develop assessment artifacts and document assessment findings
• Ensure compliance with applicable government cybersecurity policies and standards
• Support information assurance activities to maintain confidentiality, integrity, and availability of information systems
Required Qualifications
• FEMA EOD Suitability or Current DHS/FEMA EOD preferred
• Bachelor's degree and 6+ years of experience in:
o Risk Management Framework (RMF)
o Security control assessments
o Cybersecurity compliance
o Information security audits
o Security engineering
• Strong understanding of:
o NIST SP 800-53
o NIST SP 800-37 (RMF)
o DHS 4300 Series
• Experience with security control assessment methodologies and tools
• Knowledge of:
o Tenable
o Qualys
o dbProtect
o CSAM
o STIG Viewer
o RMF tools
• Experience creating assessment artifacts including:
o Security Assessment Plans (SAPs)
o Risk Traceability Matrices (RTMs)
o Security Assessment Reports (SARs)
• Experience developing POA&Ms
• Strong analytical and risk assessment skills
• Experience identifying security gaps and evaluating residual risk
• Experience with vulnerability prioritization and trend analysis Location: local to DC area
Onsite expectation: fully remote Clearance Level: DHS EOD/Up to a TS/SCI
Salary/Pay range: 95-100K PLEASE NOTE: Candidates must be able to obtain and/or maintain a public trust security clearance as a condition and continuation of employment* If you are interested, please apply here or email an updated copy of your resume to Apex Systems Military & Veteran Programs
At Apex Systems, we are proud to support those who serve. Our commitment to the military community is reflected in our robust veteran hiring initiatives, military-friendly workplace policies, and nationally recognized programs. We value the leadership, discipline, and mission-first mindset that military professionals bring to our team. Join us in continuing your mission. Why Apex is a Top Choice for Veterans and Military Talent:
• Military-Friendly Employer: Recognized as a Military Friendly® Employer for multiple consecutive years.
• Transition Programs: DoD Skill Bridge program with multiple pathway options.
• Veteran Hiring Commitment: We actively partner with multiple veteran and military organizations that specialize in IT upskilling and certification training, helping service members and veterans transition into high-demand tech careers
• Apex Military Network: Internal employee resource group supporting veterans, Guard/Reserve members, and their families. Apex Benefits Overview
Apex offers a range of supplemental benefits, including medical, dental, vision, life, disability, and other insurance plans that offer an optional layer of financial protection. We offer an ESPP (employee stock purchase program) and a 401K program which allows you to contribute typically within 30 days of starting, with a company match after 12 months of tenure. Apex also offers a HSA (Health Savings Account on the HDHP plan), a SupportLinc Employee Assistance Program (EAP) with up to 8 free counseling sessions, a corporate discount savings program and other discounts. In terms of professional development, Apex hosts an on-demand training program, provides access to certification prep and a library of technical and leadership courses/books/seminars once you have 6+ months of tenure, and certification discounts and other perks to associations that include CompTIA and IIBA. Apex has a dedicated customer service team for our Consultants that can address questions around benefits and other resources, as well as a certified Career Coach. You can access a full list of our benefits, programs, support teams and resources within our ‘Welcome Packet’ as well, which an Apex team member can provide. Everforth Apex is a world-class IT services company that serves thousands of clients across the globe. When you join Everforth Apex, you become part of a team that values innovation, collaboration, and continuous learning. We offer quality career resources, training, certifications, development opportunities, and a comprehensive benefits package. Our commitment to excellence is reflected in many awards, including ClearlyRateds Best of Staffing® in Talent Satisfaction in the United States and Great Place to Work® in the United Kingdom and Mexico. Everforth Apex uses a virtual recruiter as part of the application process. Click here for more details. By applying for this job, you agree to receive calls, AI-generated calls, text messages, or emails from Everforth Apex and its affiliates, and contracted partners. Frequency varies for text messages. Message and data rates may apply. Carriers are not liable for delayed or undelivered messages. You can reply STOP to cancel and HELP for help. You can access our privacy policy at https://www.apexsystems.com/privacy-policy
Everforth Apex Benefits Overview: Everforth Apex offers a range of supplemental benefits, including medical, dental, vision, life, disability, and other insurance plans that offer an optional layer of financial protection. We offer an ESPP (employee stock purchase program) and a 401K program which allows you to contribute typically within 30 days of starting, with a company match after 12 months of tenure. Everforth Apex also offers a HSA (Health Savings Account on the HDHP plan), a SupportLinc Employee Assistance Program (EAP) with up to 8 free counseling sessions, a corporate discount savings program and other discounts. In terms of professional development, Everforth Apex hosts an on-demand training program, provides access to certification prep and a library of technical and leadership courses/books/seminars once you have 6+ months of tenure, and certification discounts and other perks to associations that include CompTIA and IIBA. Everforth Apex has a dedicated customer service team for our Consultants that can address questions around benefits and other resources, as well as a certified Career Coach. You can access a full list of our benefits, programs, support teams and resources within our ‘Welcome Packet’ as well, which an Everforth Apex team member can provide.
Everforth Apex Systems is an equal opportunity employer. We do not discriminate or allow discrimination on the basis of race, color, religion, creed, sex (including pregnancy, childbirth, breastfeeding, or related medical conditions), age, sexual orientation, gender identity, national origin, ancestry, citizenship, genetic information, registered domestic partner status, marital status, disability, status as a crime victim, protected veteran status, political affiliation, union membership, or any other characteristic protected by law. Everforth Apex will consider qualified applicants with criminal histories in a manner consistent with the requirements of applicable law. If you require an accommodation under the Americans with Disabilities Act to participate in an interview with a virtual recruiter or to use our website for a search or application, please contact our Benefits Department at or 804-523-8228. Please note that this contact information is strictly to be used for medical ADA accommodations and that no other inquiries will be answered.
UnitedHealthcare creates and publishes the Transparency in Coverage Machine-Readable Files on behalf of Everforth Apex Systems.