1

Security Controls Assessor Jobs in Reston, VA (NOW HIRING)

Lead  Control Implementation Review and Test (CIRT)  procedures and system-level security assessments to evaluate the adequacy of technical, operational, and management security controls

Assess the effectiveness of security controls in information systems * Conduct security control ... testing and evaluations * Identify security gaps and vulnerabilities in systems * Collaborate with ...

The successful candidate will perform independent assessments of security controls to ensure compliance with federal cybersecurity policies, standards, and frameworks, such as the Risk Management ...

Assess the effectiveness of security controls in information systems * Conduct security control ... testing and evaluations * Identify security gaps and vulnerabilities in systems * Collaborate with ...

Assess the effectiveness of security controls in information systems * Conduct security control ... testing and evaluations * Identify security gaps and vulnerabilities in systems * Collaborate with ...

Showing results 41-60

Security Controls Assessor information

See Reston, VA salary details

$9

$61

$81

How much do security controls assessor jobs pay per hour?

As of Jul 30, 2026, the average hourly pay for security controls assessor in Reston, VA is $61.14, according to ZipRecruiter salary data. Most workers in this role earn between $52.50 and $70.77 per hour, depending on experience, location, and employer.

What are Security Controls Assessors?

Security Controls Assessors are professionals responsible for evaluating and validating the effectiveness of security controls within an organization's information systems. They conduct assessments to ensure compliance with regulatory standards, such as NIST, FISMA, or other security frameworks. Their work helps organizations identify vulnerabilities, manage risks, and maintain the confidentiality, integrity, and availability of critical data. Security Controls Assessors often provide recommendations for remediation and support efforts to achieve or maintain security certifications.

What are the key skills and qualifications needed to thrive as a Security Controls Assessor, and why are they important?

To thrive as a Security Controls Assessor, you need expertise in information security frameworks, risk assessment methodologies, and compliance requirements, often supported by a degree in cybersecurity or related fields and certifications like CISSP, CISA, or CAP. Familiarity with tools such as vulnerability scanners, security assessment platforms, and compliance management systems is typically required. Strong analytical thinking, attention to detail, and effective communication skills help you identify risks and clearly report findings to stakeholders. These skills ensure that organizations maintain robust security postures and meet regulatory requirements to protect critical assets.

What are some common challenges Security Controls Assessors face when evaluating compliance across multiple systems?

Security Controls Assessors often encounter challenges with inconsistent documentation, varying system configurations, and differing interpretations of compliance standards across departments. Coordinating with multiple teams to collect evidence and clarify control implementations can be time-consuming, especially in large organizations. Staying current with evolving regulations and ensuring all systems meet the latest requirements also demands continuous learning and adaptability. Building strong communication channels with system owners and IT staff helps overcome these hurdles and ensures thorough, accurate assessments.

What Does a Security Controls Assessor Do?

A security controls assessor (SCA) evaluates the security controls within network systems to identify vulnerabilities and recommend actions to correct problems, working either alone or as part of a team. As a security controls assessor, your duties begin with conducting an in-depth assessment of the management, operations, and technical security controls. You must analyze information and prepare reports describing the vulnerability level of the network with specific detail as to what compromises data systems. You then develop a plan to address vulnerabilities and continue to monitor the security of network systems.

What is the difference between Security Controls Assessor vs Security Analyst?

AspectSecurity Controls AssessorSecurity Analyst
CertificationsISO 27001 Lead Auditor, CISSP, CISACISSP, Security+
Work EnvironmentAssessing security controls, compliance auditsMonitoring security systems, incident response
Employer & IndustryGovernment agencies, compliance firmsCorporate IT, cybersecurity teams

The Security Controls Assessor primarily evaluates and verifies security controls for compliance, often in government or regulated environments. In contrast, a Security Analyst focuses on monitoring, analyzing, and responding to security threats within organizations. While both roles require security certifications and involve cybersecurity, their core responsibilities and work settings differ significantly.

What are popular job titles related to Security Controls Assessor jobs in Reston, VA? For Security Controls Assessor jobs in Reston, VA, the most frequently searched job titles are:
What job categories do people searching Security Controls Assessor jobs in Reston, VA look for? The top searched job categories for Security Controls Assessor jobs in Reston, VA are:
What cities near Reston, VA are hiring for Security Controls Assessor jobs? Cities near Reston, VA with the most Security Controls Assessor job openings:
Infographic showing various Security Controls Assessor job openings in Reston, VA as of July 2026, with employment types broken down into 1% As Needed, 53% Full Time, 7% Part Time, 1% Temporary, 2% Contract, and 36% Nights. Highlights an 87% Physical, 3% Hybrid, and 10% Remote job distribution, with an average salary of $127,403 per year, or $61.3 per hour.

SME Security Control Assessor

IMAGINEEER LLC

Arlington, VA • On-site

$45 - $50/hr

Full-time

Re-posted 22 days ago


Job description

Benefits:
  • Competitive salary

About this Role: 
We are looking for a SME Security Control Assessor that supports security control assessment activities for HHS-ACF information systems by applying NIST security controls and frameworks to evaluate control implementation and effectiveness. This role is responsible for gathering, organizing, and documenting assessment evidence; conducting security testing and evaluations; and assisting with vulnerability scanning and analysis. The assessor leads security control interviews, supports continuous monitoring activities, and contributes to the development of assessment reports, briefings, and formal deliverables. Additionally, the role maintains assessment documentation and tracking artifacts, reviews security documentation, and assists in the development of Plans of Action and Milestones (POA&Ms). The SME Security Control Assessor I actively participates in team meetings and technical discussions to support compliance, risk management, and overall system security posture. 
Key Responsibilities: 
  • Support security control assessment activities 
  • Gather and organize assessment evidence 
  • Document security control implementation 
  • Conduct security testing and evaluations 
  • Assist with vulnerability scans and analysis 
  • Create of assessment reports and briefings 
  • Maintain assessment documentation and tracking sheets 
  • Lead security control interviews 
  • Prepare assessment deliverables 
  • Applying NIST security controls and frameworks 
  • Support continuous monitoring activities 
  • Assist with security documentation review 
  • Contribute to Plans of Action and Milestones (POA&Ms) development 
  • Participate in team meetings and technical discussions 
 
Qualifications and Skills: 
  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related field 
  • 2+ years of experience in security control assessments 
  • Basic understanding of cybersecurity principles and concepts 
  • Knowledge of NIST frameworks and security controls 
  • Familiarity with common security tools and technologies 
  • Strong attention to detail 
  • Excellent organizational skills 
  • Basic technical writing abilities 
  • Proficiency in Microsoft Office suite 
  • Strong analytical and problem-solving skills 
  • Ability to follow detailed instructions and procedures 
  • Good communication skills 
  • Eagerness to learn and develop professional skills 
  • Basic understanding of networking concepts 
  • Ability to work effectively in a team environment 
  • Commitment to maintaining confidentiality and security protocols 
  • Familiarity with Risk Management Framework (RMF) 
 
Desired Skills and Competencies: 
  • Security+ certification or in progress 
  • Basic understanding of FISMA requirements 
  • Experience with vulnerability scanning tools 
  • Knowledge of basic scripting or programming 
  • Familiarity with cloud computing concepts 
  • Understanding of basic system administration 
  • Experience with documentation management systems 
  • Knowledge of compliance frameworks 
  • Basic understanding of security assessment methodologies 
  • Familiarity with cybersecurity best practices 
  • Experience with technical documentation 
  • Interest in federal government cybersecurity 
  • Basic understanding of privacy principles 
 
Additional Information: 
Employment for this position is contingent upon the candidate being a United States citizen and having the ability to successfully obtain and maintain a Public Trust clearance, in accordance with applicable federal regulations. All hiring decisions will be made in compliance with applicable federal, state, and local laws and regulations 
Equal Opportunity Employer: 
We are an Equal Opportunity Employer and do not discriminate in employment decisions on the basis of race, color, religion, sex (including pregnancy, sexual orientation, or gender identity), national origin, age, disability, genetic information, veteran status, or any other status protected by applicable federal, state, or local laws. All employment decisions are based on business needs, job requirements, and individual qualifications. 

Flexible work from home options available.