1

Security Controls Assessor Jobs in Reston, VA (NOW HIRING)

The successful candidate will perform independent assessments of security controls to ensure compliance with federal cybersecurity policies, standards, and frameworks, such as the Risk Management ...

Working knowledge of NIST SP 800-53 security and privacy controls * Understanding of risk-based assessment concepts * Ability to analyze assessment evidence and clearly document findings What Would ...

Lead  Control Implementation Review and Test (CIRT)  procedures and system-level security assessments to evaluate the adequacy of technical, operational, and management security controls

The successful candidate will perform independent assessments of security controls to ensure compliance with federal cybersecurity policies, standards, and frameworks, such as the Risk Management ...

Assess the effectiveness of security controls in information systems * Conduct security control ... testing and evaluations * Identify security gaps and vulnerabilities in systems * Collaborate with ...

Yes The Security Control Assessor (SCA) II is responsible for conducting a comprehensive assessment of the management, operational, and technical security controls employed within or inherited by an ...

Assess the effectiveness of security controls in information systems * Conduct security control ... testing and evaluations * Identify security gaps and vulnerabilities in systems * Collaborate with ...

Showing results 41-60

Security Controls Assessor information

See Reston, VA salary details

$9

$61

$81

How much do security controls assessor jobs pay per hour?

As of Aug 22, 2026, the average hourly pay for security controls assessor in Reston, VA is $61.14, according to ZipRecruiter salary data. Most workers in this role earn between $52.50 and $70.77 per hour, depending on experience, location, and employer.

What is a security controls assessor?

Security Controls Assessors are professionals responsible for evaluating and validating the effectiveness of security controls within an organization's information systems. They conduct assessments to ensure compliance with regulatory standards, such as NIST, FISMA, or other security frameworks. Their work helps organizations identify vulnerabilities, manage risks, and maintain the confidentiality, integrity, and availability of critical data. Security Controls Assessors often provide recommendations for remediation and support efforts to achieve or maintain security certifications.

What does a security controls assessor do?

A security controls assessor (SCA) evaluates the security controls within network systems to identify vulnerabilities and recommend actions to correct problems, working either alone or as part of a team. As a security controls assessor, your duties begin with conducting an in-depth assessment of the management, operations, and technical security controls. You must analyze information and prepare reports describing the vulnerability level of the network with specific detail as to what compromises data systems. You then develop a plan to address vulnerabilities and continue to monitor the security of network systems.

What are the key skills and qualifications needed to thrive as a security controls assessor, and why are they important?

To thrive as a Security Controls Assessor, you need expertise in information security frameworks, risk assessment methodologies, and compliance requirements, often supported by a degree in cybersecurity or related fields and certifications like CISSP, CISA, or CAP. Familiarity with tools such as vulnerability scanners, security assessment platforms, and compliance management systems is typically required. Strong analytical thinking, attention to detail, and effective communication skills help you identify risks and clearly report findings to stakeholders. These skills ensure that organizations maintain robust security postures and meet regulatory requirements to protect critical assets.

What are some common challenges security controls assessors face when evaluating compliance across multiple systems?

Security Controls Assessors often encounter challenges with inconsistent documentation, varying system configurations, and differing interpretations of compliance standards across departments. Coordinating with multiple teams to collect evidence and clarify control implementations can be time-consuming, especially in large organizations. Staying current with evolving regulations and ensuring all systems meet the latest requirements also demands continuous learning and adaptability. Building strong communication channels with system owners and IT staff helps overcome these hurdles and ensures thorough, accurate assessments.

What is the difference between Security Controls Assessor vs Security Analyst?

AspectSecurity Controls AssessorSecurity Analyst
CertificationsISO 27001 Lead Auditor, CISSP, CISACISSP, Security+
Work EnvironmentAssessing security controls, compliance auditsMonitoring security systems, incident response
Employer & IndustryGovernment agencies, compliance firmsCorporate IT, cybersecurity teams

The Security Controls Assessor primarily evaluates and verifies security controls for compliance, often in government or regulated environments. In contrast, a Security Analyst focuses on monitoring, analyzing, and responding to security threats within organizations. While both roles require security certifications and involve cybersecurity, their core responsibilities and work settings differ significantly.

What are popular job titles related to Security Controls Assessor jobs in Reston, VA?

For Security Controls Assessor jobs in Reston, VA, the most frequently searched job titles are:

What job categories do people searching Security Controls Assessor jobs in Reston, VA look for?

The top searched job categories for Security Controls Assessor jobs in Reston, VA are:

What cities near Reston, VA are hiring for Security Controls Assessor jobs?

Cities near Reston, VA with the most Security Controls Assessor job openings:

Infographic showing various Security Controls Assessor job openings in Reston, VA as of August 2026, with employment types broken down into 86% Full Time, 11% Part Time, and 3% Contract. Highlights an 93% Physical, 2% Hybrid, and 5% Remote job distribution, with an average salary of $127,169 per year, or $61.1 per hour.

Security Control Assessor

Novul Solutions

Arlington, VA • On-site

Full-time

Medical, Dental, Vision, Retirement, PTO

Re-posted 2 days ago


Job description


Position Overview
We are seeking an experienced Security Control Assessor to support cybersecurity assessment and authorization activities for Department of Defense information systems. This role is responsible for conducting in-depth security control assessments, validating control implementation, reviewing system security documentation, and supporting the development and maintenance of complete and accurate Authorization to Operate packages.
The ideal candidate will bring extensive experience with the Risk Management Framework, NIST security standards, DoD cybersecurity policies, and the Joint Special Access Program Implementation Guide. The individual must be capable of communicating assessment findings, remediation requirements, and government-approved mitigation strategies to system owners and technical stakeholders.
Key Responsibilities:
  • Conduct comprehensive security control assessments of DoD information systems in accordance with NIST SP 800-53, DoD RMF policies, CNSSI 1253, and the JSIG.
  • Evaluate the implementation and effectiveness of security controls and document assessment findings, risks, deficiencies, and recommended corrective actions.
  • Communicate government-approved mitigation and remediation requirements to system owners, cybersecurity personnel, and technical stakeholders in support of the RMF process.
  • Apply the cybersecurity principles of confidentiality, integrity, and availability when evaluating system categorization and impact levels, including High, Moderate, and Low classifications.
  • Validate security controls identified as inherited from hosting environments, connected systems, enterprise services, or other authorized systems.
  • Assess program compliance with security controls associated with registered Ports, Protocols, and Services, including the proper generation, retention, protection, and handling of system log files.
  • Review system security documentation and supporting evidence for accuracy, completeness, consistency, and alignment with applicable cybersecurity requirements.
  • Lead the review, preparation, and quality assurance of Authorization to Operate packages and related RMF documentation.
  • Identify control gaps, weaknesses, and areas of noncompliance and provide clear, actionable recommendations for remediation.
  • Coordinate with system owners, information system security personnel, engineers, program leadership, and government stakeholders throughout the assessment and authorization lifecycle.
  • Support the development, review, and validation of Plans of Action and Milestones and other risk-management documentation.
  • Provide leadership and technical guidance to assessment teams and support the resolution of complex cybersecurity compliance issues.

Requirements
Required Qualifications:
  • Bachelor's degree in cybersecurity, information technology, computer science, information systems, engineering, or a related field.
  • Eight or more years of professional experience in cybersecurity.
  • Five or more years of experience supporting Certification and Accreditation or Assessment and Authorization activities.
  • Expert-level knowledge of the DoD Risk Management Framework.
  • Strong working knowledge of NIST SP 800-37, NIST SP 800-53, CNSSI 1253, and the JSIG.
  • Experience conducting security control assessments and evaluating technical, operational, and management controls.
  • Experience reviewing and preparing ATO packages and supporting documentation.
  • Experience validating inherited controls and assessing Ports, Protocols, and Services requirements.
  • Demonstrated leadership experience, including previous experience serving in a lead or senior assessment role.
  • Strong written and verbal communication skills, with the ability to clearly explain technical findings, risks, and remediation requirements to system owners and government stakeholders.

Preferred Qualifications
  • Experience supporting DoD Special Access Programs or other highly classified environments.
  • Experience working directly with system owners, ISSOs, ISSMs, security engineers, and Authorizing Official representatives.
  • Familiarity with security assessment reports, risk assessment reports, system security plans, POA&Ms, and continuous-monitoring documentation.
  • Experience leading assessment teams or overseeing multiple system authorization efforts.
  • Strong analytical, documentation-review, and quality-assurance skills.

Benefits
Core Benefits:
  • Paid Time OffPTO):TEN (10) Paid days off & FIVE (5) Floating days off.
  • Holidays: 11 Paid Holidays. Flex time can be utilized instead of holiday time usage.
  • Payroll: Paid Bi-Monthly.
  • 401(k): Partnered with the SECOND LARGEST Retirement plan provider in the U.S. Guaranteed 3% match. Eligibility - 21 years of age or older, after 3 months of employment
  • Individual or company-wide performance and recognition awards (Quarterly)

Health Benefits:
  • UNITED HEALTHCARE PPO, extensive national coverage.
  • INCLUDES: Medical/Dental/Vision/HSA.
  • Eligible on the first of the month, immediately after the start date.
  • Submit the enrollment form within 30 days of your start date otherwise, you will have to wait until October for the new year enrollment.

Quality of Life Benefits:
  • Training & Career Development Reimbursement of Tuition and training needed to support career development.
  • $150 monthly reimbursement contribution paid monthly towards parking expenses.
  • Receipts must be submitted by the close of business on the 25th of each month.
  • Reimbursements will be paid on the first payroll AFTER reimbursements are submitted each month.

Special Benefits:
  • Performance bonus - Project-based
  • Yearly bonus - Company based