1

Security Controls Assessor Jobs in Springfield, VA

The successful candidate will perform independent assessments of security controls to ensure compliance with federal cybersecurity policies, standards, and frameworks, such as the Risk Management ...

The successful candidate will perform independent assessments of security controls to ensure compliance with federal cybersecurity policies, standards, and frameworks, such as the Risk Management ...

... controls and frameworks to evaluate control implementation and effectiveness. This role is responsible for gathering, organizing, and documenting assessment evidence; conducting security testing and ...

Assess the effectiveness of security controls in information systems * Conduct security control ... testing and evaluations * Identify security gaps and vulnerabilities in systems * Collaborate with ...

Showing results 41-60

Security Controls Assessor information

See Springfield, VA salary details

$9

$61

$81

How much do security controls assessor jobs pay per hour?

As of Aug 8, 2026, the average hourly pay for security controls assessor in Springfield, VA is $61.47, according to ZipRecruiter salary data. Most workers in this role earn between $52.79 and $71.15 per hour, depending on experience, location, and employer.

What is a security controls assessor?

Security Controls Assessors are professionals responsible for evaluating and validating the effectiveness of security controls within an organization's information systems. They conduct assessments to ensure compliance with regulatory standards, such as NIST, FISMA, or other security frameworks. Their work helps organizations identify vulnerabilities, manage risks, and maintain the confidentiality, integrity, and availability of critical data. Security Controls Assessors often provide recommendations for remediation and support efforts to achieve or maintain security certifications.

What are the key skills and qualifications needed to thrive as a security controls assessor, and why are they important?

To thrive as a Security Controls Assessor, you need expertise in information security frameworks, risk assessment methodologies, and compliance requirements, often supported by a degree in cybersecurity or related fields and certifications like CISSP, CISA, or CAP. Familiarity with tools such as vulnerability scanners, security assessment platforms, and compliance management systems is typically required. Strong analytical thinking, attention to detail, and effective communication skills help you identify risks and clearly report findings to stakeholders. These skills ensure that organizations maintain robust security postures and meet regulatory requirements to protect critical assets.

What are some common challenges security controls assessors face when evaluating compliance across multiple systems?

Security Controls Assessors often encounter challenges with inconsistent documentation, varying system configurations, and differing interpretations of compliance standards across departments. Coordinating with multiple teams to collect evidence and clarify control implementations can be time-consuming, especially in large organizations. Staying current with evolving regulations and ensuring all systems meet the latest requirements also demands continuous learning and adaptability. Building strong communication channels with system owners and IT staff helps overcome these hurdles and ensures thorough, accurate assessments.

What does a security controls assessor do?

A security controls assessor (SCA) evaluates the security controls within network systems to identify vulnerabilities and recommend actions to correct problems, working either alone or as part of a team. As a security controls assessor, your duties begin with conducting an in-depth assessment of the management, operations, and technical security controls. You must analyze information and prepare reports describing the vulnerability level of the network with specific detail as to what compromises data systems. You then develop a plan to address vulnerabilities and continue to monitor the security of network systems.

What is the difference between Security Controls Assessor vs Security Analyst?

AspectSecurity Controls AssessorSecurity Analyst
CertificationsISO 27001 Lead Auditor, CISSP, CISACISSP, Security+
Work EnvironmentAssessing security controls, compliance auditsMonitoring security systems, incident response
Employer & IndustryGovernment agencies, compliance firmsCorporate IT, cybersecurity teams

The Security Controls Assessor primarily evaluates and verifies security controls for compliance, often in government or regulated environments. In contrast, a Security Analyst focuses on monitoring, analyzing, and responding to security threats within organizations. While both roles require security certifications and involve cybersecurity, their core responsibilities and work settings differ significantly.

What are popular job titles related to Security Controls Assessor jobs in Springfield, VA? For Security Controls Assessor jobs in Springfield, VA, the most frequently searched job titles are:
What job categories do people searching Security Controls Assessor jobs in Springfield, VA look for? The top searched job categories for Security Controls Assessor jobs in Springfield, VA are:
What cities near Springfield, VA are hiring for Security Controls Assessor jobs? Cities near Springfield, VA with the most Security Controls Assessor job openings:
Infographic showing various Security Controls Assessor job openings in Springfield, VA as of August 2026, with employment types broken down into 85% Full Time, 5% Part Time, 5% Temporary, and 5% Contract. Highlights an 86% In-person, and 14% Remote job distribution, with an average salary of $127,859 per year, or $61.5 per hour.

Security Control Assessor, Junior

Booz Allen Hamilton

Mclean, VA • On-site

$53K - $108K/yr

Other

Medical, Life, Retirement, PTO

Posted 5 days ago


Booz Allen Hamilton rating

8.9

Company rating: 8.9 out of 10

Based on 49 frontline employees who took The Breakroom Quiz

9th of 72 rated business consultants


Job description

Security Control Assessor, Junior

Conduct independent security control testing and assessments of the management, operational, and technical security controls to determine the overall effectiveness of security controls, based on the NIST Risk Management Framework (RMF). Technically assess both major application and general support system security configurations and implementation using manual and automated test methods. Provide an assessment of the severity of weaknesses or deficiencies discovered in the information system and its environment of operation and recommend corrective actions to address identified vulnerabilities. Develop and review SCA artifacts such as Security Assessment Plan (SAP), Security Assessment Reports (SAR) and System Security Plan (SSP).

Location: McLean, VA Secret Polygraph Unspecified Career Level not specified $53,000 - $108,000

Job Requirements

You Have:

  • Experience conducting security control assessments on federal applications and general support systems (GSSs) to ensure compliance with the NIST SP 800-53 Rev. 4, NIST 800-37 Rev.1, and agency-specific requirements
  • Experience working with Plans of Action and Milestones (POA&Ms), including providing detailed vulnerability summaries and impacts and drafting risk mitigation strategies for identified risk
  • Experience with RMF steps 4-6: Assess, Authorize, and Monitor for federal applications and GSSs
  • Experience conducting vulnerability assessments and analysis of vulnerability scan results with a vulnerability scanning tool
  • Experience assessing Web Application securely via security controls assessment and vulnerability and compliance scanning analysis, and assessing the security of cloud environments and cloud-hosted applications based on FedRAMP controls
  • Knowledge of cybersecurity principles used to manage risks related to the use, processing, storage, and transmission of information or data, and information technology (IT) security principles and methods, such as firewalls, demilitarized zones, and encryption
  • Knowledge of network security architecture concepts, including topology, protocols, components, and principles, such as application of defense-in-depth
  • Ability to obtain a Secret clearance
  • Bachelor's degree in CS, IT, or Engineering
  • CISSP, CISA, CAP/CGRC, or GSNA Certification

Nice If You Have:

  • Knowledge of security principles for Industrial Control Systems (ICS)
  • Knowledge of security principles for IT infrastructure systems, such as PKI, network appliances, and intrusion detection and prevention systems
  • Possession of excellent written and verbal communication skills, including documentation

Clearance: Applicants selected will be subject to a security investigation and may need to meet eligibility requirements for access to classified information.

Compensation At Booz Allen, we celebrate your contributions, provide you with opportunities and choices, and support your total well-being. Our offerings include health, life, disability, financial, and retirement benefits, as well as paid leave, professional development, tuition assistance, work-life programs, and dependent care. Our recognition awards program acknowledges employees for exceptional performance and superior demonstration of our values. Full-time and part-time employees working at least 20 hours a week on a regular basis are eligible to participate in Booz Allen's benefit programs. Individuals that do not meet the threshold are only eligible for select offerings, not inclusive of health benefits. We encourage you to learn more about our total benefits by visiting the Resource page on our Careers site and reviewing Our Employee Benefits page.

Salary at Booz Allen is determined by various factors, including but not limited to location, the individual's particular combination of education, knowledge, skills, competencies, and experience, as well as contract-specific affordability and organizational requirements. The projected compensation range for this position is $53,000.00 to $108,000.00 (annualized USD). The estimate displayed represents the typical salary range for this position and is just one component of Booz Allen's total compensation package for employees.

Identity Statement As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during interviews and assessments. We reserve the right to take your picture to verify your identity and prevent fraud.

Candidate AI Usage Policy AI is a part of our daily work at Booz Allen, and we are committed to the responsible and ethical use of AI tools. However, we want to ensure a fair candidate process based on your own skills and knowledge. As part of this commitment, the use of artificial intelligence (AI) or other tools to assist with responses during interviews (whether in-person or virtual) is prohibited unless permission is explicitly provided.

Work Model Our people-first culture prioritizes the benefits of collaboration, whether it occurs in person or virtually. To support engagement and effective communication, employees working virtually are generally expected to have their cameras on during meetings.

Commitment to Non-Discrimination All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, local, or international law.


What Booz Allen Hamilton employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


Booz Allen Hamilton logo

About Booz Allen Hamilton

Sourced by ZipRecruiter

Booz Allen Hamilton is a leading provider of management and technology consulting services to the US government in defense, intelligence, and civil markets. Headquartered in McLean, Virginia, the firm also serves major corporations, institutions, and not-for-profit organizations. Founded in 1914 by Edwin G. Booz, the company has a long-standing tradition of helping clients achieve success by delivering a wide range of consulting services that include strategic planning, human capital and learning, communication, systems development, and others. The company's mission is to empower people to change the world, and it has a reputation for maintaining the highest standards of integrity and-excellence.

Industry

It services

Company size

10,000+ Employees

Headquarters location

McLean, VA, US

Year founded

1914