1

Security Controls Assessor Jobs in Springfield, VA

Working knowledge of NIST SP 800-53 security and privacy controls * Understanding of risk-based assessment concepts * Ability to analyze assessment evidence and clearly document findings What Would ...

Security Control Assessor

Arlington, VA · On-site

$140K - $160K/yr

This includes ensuring to guide the RMF process so that security controls are integrated seamlessly ... Ensure security assessments are completed for each IS. * Initiate a POA&M with identified ...

Job#: 3044387 Security Control Assessor Location: Alexandria, Virginia (Onsite) Role Overview We ... Perform access controls, interpret findings, write artifacts, and help push systems through the ...

Showing results 41-60

Security Controls Assessor information

See Springfield, VA salary details

$9

$61

$81

How much do security controls assessor jobs pay per hour?

As of Sep 3, 2026, the average hourly pay for security controls assessor in Springfield, VA is $61.38, according to ZipRecruiter salary data. Most workers in this role earn between $52.74 and $71.06 per hour, depending on experience, location, and employer.

What is a security controls assessor?

Security Controls Assessors are professionals responsible for evaluating and validating the effectiveness of security controls within an organization's information systems. They conduct assessments to ensure compliance with regulatory standards, such as NIST, FISMA, or other security frameworks. Their work helps organizations identify vulnerabilities, manage risks, and maintain the confidentiality, integrity, and availability of critical data. Security Controls Assessors often provide recommendations for remediation and support efforts to achieve or maintain security certifications.

What does a security controls assessor do?

A security controls assessor (SCA) evaluates the security controls within network systems to identify vulnerabilities and recommend actions to correct problems, working either alone or as part of a team. As a security controls assessor, your duties begin with conducting an in-depth assessment of the management, operations, and technical security controls. You must analyze information and prepare reports describing the vulnerability level of the network with specific detail as to what compromises data systems. You then develop a plan to address vulnerabilities and continue to monitor the security of network systems.

What are the key skills and qualifications needed to thrive as a security controls assessor, and why are they important?

To thrive as a Security Controls Assessor, you need expertise in information security frameworks, risk assessment methodologies, and compliance requirements, often supported by a degree in cybersecurity or related fields and certifications like CISSP, CISA, or CAP. Familiarity with tools such as vulnerability scanners, security assessment platforms, and compliance management systems is typically required. Strong analytical thinking, attention to detail, and effective communication skills help you identify risks and clearly report findings to stakeholders. These skills ensure that organizations maintain robust security postures and meet regulatory requirements to protect critical assets.

What are some common challenges security controls assessors face when evaluating compliance across multiple systems?

Security Controls Assessors often encounter challenges with inconsistent documentation, varying system configurations, and differing interpretations of compliance standards across departments. Coordinating with multiple teams to collect evidence and clarify control implementations can be time-consuming, especially in large organizations. Staying current with evolving regulations and ensuring all systems meet the latest requirements also demands continuous learning and adaptability. Building strong communication channels with system owners and IT staff helps overcome these hurdles and ensures thorough, accurate assessments.

What is the difference between Security Controls Assessor vs Security Analyst?

AspectSecurity Controls AssessorSecurity Analyst
CertificationsISO 27001 Lead Auditor, CISSP, CISACISSP, Security+
Work EnvironmentAssessing security controls, compliance auditsMonitoring security systems, incident response
Employer & IndustryGovernment agencies, compliance firmsCorporate IT, cybersecurity teams

The Security Controls Assessor primarily evaluates and verifies security controls for compliance, often in government or regulated environments. In contrast, a Security Analyst focuses on monitoring, analyzing, and responding to security threats within organizations. While both roles require security certifications and involve cybersecurity, their core responsibilities and work settings differ significantly.

What are popular job titles related to Security Controls Assessor jobs in Springfield, VA?

For Security Controls Assessor jobs in Springfield, VA, the most frequently searched job titles are:

What job categories do people searching Security Controls Assessor jobs in Springfield, VA look for?

The top searched job categories for Security Controls Assessor jobs in Springfield, VA are:

What cities near Springfield, VA are hiring for Security Controls Assessor jobs?

Cities near Springfield, VA with the most Security Controls Assessor job openings:

Infographic showing various Security Controls Assessor job openings in Springfield, VA as of August 2026, with employment types broken down into 82% Full Time, 15% Part Time, and 3% Contract. Highlights an 92% Physical, 3% Hybrid, and 5% Remote job distribution, with an average salary of $128,387 per year, or $61.7 per hour.

Security Control Assessor/Representatives

Dark Wolf Solutions

Washington, DC • Hybrid

$135K - $150K/yr

Full-time

Re-posted 4 days ago


Job description

Dark Wolf Solutions is seeking Security Control Assessor/Representatives (SCA/Rs) to lead security control assessments across high-priority projects. Working at the intersection of cybersecurity engineering, cloud architecture, and DevSecOps prototyping, you will evaluate security controls for cutting-edge AI/LLM technologies across multiple classification levels. This position is ideal for a pragmatic cloud assessor or SCAR who excels in fast-paced DevSecOps environments, understands AWS cloud security, and is eager to shape the cybersecurity posture of next-generation DoD AI capabilities.This position will be based out of Arlington, VA with hybrid opportunities. Additional responsibilities include:

Key Responsibilities

  • Execute formal SCA/R duties.
  • Lead security assessment efforts, establishing reusable security playbooks and assessment frameworks for rapid AI deployment into enterprise workflows.
  • Evaluate technical control effectiveness across AWS cloud infrastructure, DevSecOps pipelines, microservices, containerized workloads, and GenAI/LLM application stacks.
  • Partner directly with cybersecurity engineering and DevSecOps prototyping teams to integrate security controls early in the development lifecycle.
  • Review, author, and maintain assessment packages-including System Security Plans (SSPs), Security Assessment Plans (SAPs), Security Assessment Reports (SARs), and POA&Ms-tailored to rapid prototyping and AI systems.
  • Assess technical security risks specific to AI/LLM implementations, such as API exposure, vector database access controls, model integration surface area, and software supply chain dependencies.
  • Support continuous monitoring (ConMon), technical risk evaluations, and cloud architecture reviews across multi-tenant, multi-classification environments.
  • Coordinate with Authorizing Officials (AOs), program managers, and engineering leads to deliver decision-ready risk briefings and ATO recommendations.
  • Provide technical input and oversight for cybersecurity engineering and penetration testing activities across prototype projects.

Required Qualifications

  • Active Top Secret security clearance
  • Current DoD 8570/8140 IAM Level II or Level III certification (e.g., Security+, CySA+, CISM, CISSP, CCISO, CAP/CISC)
  • 3-5+ years of experience conducting security control assessments, compliance testing, or A&A/RMF activities for DoD or federal information systems
  • Solid operational understanding of core AWS cloud services (EC2, S3, IAM, VPCs, Security Groups, Security Hub) and how security controls function within cloud-native and CI/CD pipeline environments.
  • Strong working knowledge of NIST SP 800-53 (Rev. 4/5), NIST SP 800-37 (RMF), DoD Cloud Computing SRG, and FedRAMP baselines.
  • Demonstrated experience writing and evaluating core RMF artifacts (SSPs, SAPs, SARs, POA&Ms)
  • Exceptional written and verbal communication skills, with the ability to articulate technical risk clearly to executive stakeholders, Authorizing Officials, and engineering teams.
  • Hands-on experience navigating government GRC repositories, such as eMASS or XACTA.

Desired Qualifications

  • Hands-on experience mapping security controls to the NIST AI Risk Management Framework (AI RMF), the OWASP Top 10 for LLM Applications, or the DoD Responsible AI (RAI) Guidelines.
  • Familiarity evaluating secure design patterns for autonomous AI Agents (e.g., tool-calling permissions, sandboxing agent execution environments, prompt boundaries, and ReAct/LangGraph architectures).
  • Experience assessing cloud-managed AI ecosystems and foundation model platforms (e.g., AWS Bedrock, AWS SageMaker, Hugging Face Enterprise, or self-hosted open-source models).
  • Understanding of data protection, access controls, and boundary security for RAG pipelines and vector databases (e.g., OpenSearch Vector Engine, Pinecone, Milvus, or PostgreSQL pgvector).
  • Familiarity evaluating risks unique to LLMs-including prompt injection, data poisoning, model inversion, insecure output handling, and open-source supply chain vulnerabilities in AI libraries (PyTorch, LangChain, LlamaIndex).
  • Exposure to LLM guardrail platforms, evaluation frameworks, or AI security tools (e.g., Promptfoo, Garak, Giskard, NeMo Guardrails) used to test model robustness and output safety.
  • Experience with cATO methodologies, Infrastructure as Code (IaC) templates (Terraform, CloudFormation), and container security (AWS EKS/ECS, Docker).
  • Active AWS Certifications (e.g., AWS Certified Security - Specialty or AWS Certified Solutions Architect).
  • Background or familiarity with offensive security, penetration testing

The salary range for this position is estimated to be between $135,000.00 - $150,000.00, commensurate on experience and technical skillset.

We are proud to be an EEO/AA employer Minorities/Women/Veterans/Disabled and other protected categories.

In compliance with federal law, all persons hired will be required to verify identity, confirm US Citizenship, and complete the required employment eligibility verification upon hire.

We are strictly looking for direct, full-time W2 employees. We do not engage with third-party staffing agencies, C2C, or 1099 independent contractors for this role.