1

Security Controls Assessor Jobs (NOW HIRING)

... assessment of the management, operational, and technical security controls employed within or inherited by an IS to determine the overall effectiveness of the controls (i.e., the extent to which the ...

Avint is seeking a highly motivated Senior Security Controls Assessor (SCA) in support of a critical federal contract. The Senior SCA is a subject matter expert responsible for executing ...

Avint is seeking a highly motivated Journeyman Security Controls Assessor (SCA) in support of a critical federal contract. The Journeyman SCA is a mid-level professional responsible for executing ...

Showing results 21-40

Security Controls Assessor information

See salary details

$8

$58

$78

How much do security controls assessor jobs pay per hour?

As of Aug 7, 2026, the average hourly pay for security controls assessor in the United States is $58.77, according to ZipRecruiter salary data. Most workers in this role earn between $50.48 and $68.03 per hour, depending on experience, location, and employer.

What is a security controls assessor?

Security Controls Assessors are professionals responsible for evaluating and validating the effectiveness of security controls within an organization's information systems. They conduct assessments to ensure compliance with regulatory standards, such as NIST, FISMA, or other security frameworks. Their work helps organizations identify vulnerabilities, manage risks, and maintain the confidentiality, integrity, and availability of critical data. Security Controls Assessors often provide recommendations for remediation and support efforts to achieve or maintain security certifications.

What are the key skills and qualifications needed to thrive as a security controls assessor, and why are they important?

To thrive as a Security Controls Assessor, you need expertise in information security frameworks, risk assessment methodologies, and compliance requirements, often supported by a degree in cybersecurity or related fields and certifications like CISSP, CISA, or CAP. Familiarity with tools such as vulnerability scanners, security assessment platforms, and compliance management systems is typically required. Strong analytical thinking, attention to detail, and effective communication skills help you identify risks and clearly report findings to stakeholders. These skills ensure that organizations maintain robust security postures and meet regulatory requirements to protect critical assets.

What are some common challenges security controls assessors face when evaluating compliance across multiple systems?

Security Controls Assessors often encounter challenges with inconsistent documentation, varying system configurations, and differing interpretations of compliance standards across departments. Coordinating with multiple teams to collect evidence and clarify control implementations can be time-consuming, especially in large organizations. Staying current with evolving regulations and ensuring all systems meet the latest requirements also demands continuous learning and adaptability. Building strong communication channels with system owners and IT staff helps overcome these hurdles and ensures thorough, accurate assessments.

What does a security controls assessor do?

A security controls assessor (SCA) evaluates the security controls within network systems to identify vulnerabilities and recommend actions to correct problems, working either alone or as part of a team. As a security controls assessor, your duties begin with conducting an in-depth assessment of the management, operations, and technical security controls. You must analyze information and prepare reports describing the vulnerability level of the network with specific detail as to what compromises data systems. You then develop a plan to address vulnerabilities and continue to monitor the security of network systems.

What is the difference between Security Controls Assessor vs Security Analyst?

AspectSecurity Controls AssessorSecurity Analyst
CertificationsISO 27001 Lead Auditor, CISSP, CISACISSP, Security+
Work EnvironmentAssessing security controls, compliance auditsMonitoring security systems, incident response
Employer & IndustryGovernment agencies, compliance firmsCorporate IT, cybersecurity teams

The Security Controls Assessor primarily evaluates and verifies security controls for compliance, often in government or regulated environments. In contrast, a Security Analyst focuses on monitoring, analyzing, and responding to security threats within organizations. While both roles require security certifications and involve cybersecurity, their core responsibilities and work settings differ significantly.

What cities are hiring for Security Controls Assessor jobs? Cities with the most Security Controls Assessor job openings:
What are the most commonly searched types of Security Controls Assessor jobs? The most popular types of Security Controls Assessor jobs are:
Who are the top companies hiring for Security Controls Assessor jobs? The top employers for Security Controls Assessor jobs are:
What states have the most Security Controls Assessor jobs? States with the most job openings for Security Controls Assessor jobs include:
What job categories do people searching Security Controls Assessor jobs look for? The top searched job categories for Security Controls Assessor jobs are:
What are popular job titles related to Security Controls Assessor jobs? For Security Controls Assessor jobs, the most frequently searched job titles are:
Infographic showing various Security Controls Assessor job openings in the United States as of August 2026, with employment types broken down into 85% Full Time, 5% Part Time, 5% Temporary, and 5% Contract. Highlights an 86% In-person, and 14% Remote job distribution, with an average salary of $122,236 per year, or $58.8 per hour.

Senior Security Controls Assessor - Contingent

Aretum

Mclean, VA • Remote

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted 23 days ago


Job description

Public Trust Eligibility Required
This is a contingent position, meaning employment is dependent upon the successful award of the associated contract to Aretum and completion of any required background investigation or security clearance verification. 

About Aretum

Aretum is a mission-driven organization committed to delivering innovative, technology-enabled solutions to our customers across defense, civilian, and homeland security sectors. Our teams work at the intersection of strategy, technology, and transformation, helping agencies solve their most critical challenges. We believe in investing in our people and creating a culture where collaboration, inclusion, and professional growth are at the forefront.

Job Summary 

Aretum is seeking a Senior Security Controls Assessor. As a Senior Security Controls Assessor, you will be responsible for conducting comprehensive security assessments of information systems to ensure compliance with applicable security controls and regulations.

Due to the nature of our work as a federal consulting organization, employees may be expected to handle Controlled Unclassified Information (CUI) and must adhere to applicable safeguarding and compliance requirements.  

Responsibilities

  • Independently perform all aspects of the security controls assessment in alignment with NIST 800-53 Revision 5
  • Ensure comprehensive understanding and application of ATO documentation requirements
  • Coordinate all aspects of testing with relevant stakeholders and team lead
  • Develop a security assessment plan with input from stakeholders
  • Conduct and lead assessment interviews and tests and manage evidence
  • Provide insightful recommendations to improve security posture

Requirements

  • Minimum of 3 years leading security controls assessments
  • Experience performing assessments while supporting the federal government
  • Proficient understanding of NIST RMF
  • Expertise in NIST 800-53 Rev 5
  • Understanding of the ATO process
  • Strong communication and task management skills

Preferred Qualifications 

  • BA/BS degree, Information Security or Related
  • Certifications: CISSP, CISM, CISA, or equivalent
  • CSAM/JCAM Experience

Travel Requirements

This is a remote position; however, occasional travel may be required based on project needs, client meetings, team collaboration events, or training sessions. Travel is expected to be less than 10% and will be communicated in advance whenever possible. 

EEO Statement

Aretum is committed to fostering a workplace rooted in excellence, integrity, and equal opportunity for all. We adhere to merit-based hiring practices, ensuring that all employment decisions are made based on qualifications, skills, and ability to perform the job, without preference or consideration of factors unrelated to job performance. 

As an Equal Opportunity Employer, Aretum complies with all applicable federal, state, and local employment laws. 

We are proud to support our nation's veterans and military families, providing career opportunities that honor their service and experience. 

If you require reasonable accommodation during the hiring process due to a disability, please contact hr@aretum.com for assistance. 

Equal Opportunity Employer/Veterans/Disabled

U.S. Work Authorization

Due to federal contract requirements, only U.S. citizens are eligible for this position. This position supports a federal government contract and requires the ability to obtain and maintain a Public Trust or Suitability Determination, depending on the agency's background investigation requirements.  

Benefits

  • Health Care Plan (Medical, Dental & Vision)   
  • Retirement Plan (401k)  
  • Life Insurance (Basic, Voluntary & AD&D)   
  • Paid Time Off  
  • Family Leave (Maternity, Paternity)   
  • Short Term & Long-Term Disability   
  • Training & Development