1

Security Controls Assessor Jobs (NOW HIRING)

Showing results 41-60

Security Controls Assessor information

See salary details

$8

$58

$78

How much do security controls assessor jobs pay per hour?

As of Sep 12, 2026, the average hourly pay for security controls assessor in the United States is $58.77, according to ZipRecruiter salary data. Most workers in this role earn between $50.48 and $68.03 per hour, depending on experience, location, and employer.

What is a security controls assessor?

Security Controls Assessors are professionals responsible for evaluating and validating the effectiveness of security controls within an organization's information systems. They conduct assessments to ensure compliance with regulatory standards, such as NIST, FISMA, or other security frameworks. Their work helps organizations identify vulnerabilities, manage risks, and maintain the confidentiality, integrity, and availability of critical data. Security Controls Assessors often provide recommendations for remediation and support efforts to achieve or maintain security certifications.

What does a security controls assessor do?

A security controls assessor (SCA) evaluates the security controls within network systems to identify vulnerabilities and recommend actions to correct problems, working either alone or as part of a team. As a security controls assessor, your duties begin with conducting an in-depth assessment of the management, operations, and technical security controls. You must analyze information and prepare reports describing the vulnerability level of the network with specific detail as to what compromises data systems. You then develop a plan to address vulnerabilities and continue to monitor the security of network systems.

What are the key skills and qualifications needed to thrive as a security controls assessor, and why are they important?

To thrive as a Security Controls Assessor, you need expertise in information security frameworks, risk assessment methodologies, and compliance requirements, often supported by a degree in cybersecurity or related fields and certifications like CISSP, CISA, or CAP. Familiarity with tools such as vulnerability scanners, security assessment platforms, and compliance management systems is typically required. Strong analytical thinking, attention to detail, and effective communication skills help you identify risks and clearly report findings to stakeholders. These skills ensure that organizations maintain robust security postures and meet regulatory requirements to protect critical assets.

What are some common challenges security controls assessors face when evaluating compliance across multiple systems?

Security Controls Assessors often encounter challenges with inconsistent documentation, varying system configurations, and differing interpretations of compliance standards across departments. Coordinating with multiple teams to collect evidence and clarify control implementations can be time-consuming, especially in large organizations. Staying current with evolving regulations and ensuring all systems meet the latest requirements also demands continuous learning and adaptability. Building strong communication channels with system owners and IT staff helps overcome these hurdles and ensures thorough, accurate assessments.

What is the difference between Security Controls Assessor vs Security Analyst?

AspectSecurity Controls AssessorSecurity Analyst
CertificationsISO 27001 Lead Auditor, CISSP, CISACISSP, Security+
Work EnvironmentAssessing security controls, compliance auditsMonitoring security systems, incident response
Employer & IndustryGovernment agencies, compliance firmsCorporate IT, cybersecurity teams

The Security Controls Assessor primarily evaluates and verifies security controls for compliance, often in government or regulated environments. In contrast, a Security Analyst focuses on monitoring, analyzing, and responding to security threats within organizations. While both roles require security certifications and involve cybersecurity, their core responsibilities and work settings differ significantly.

What cities are hiring for Security Controls Assessor jobs?

Cities with the most Security Controls Assessor job openings:

What are the most commonly searched types of Security Controls Assessor jobs?

The most popular types of Security Controls Assessor jobs are:

Who are the top companies hiring for Security Controls Assessor jobs?

The top employers for Security Controls Assessor jobs are:

What states have the most Security Controls Assessor jobs?

States with the most job openings for Security Controls Assessor jobs include:

What are popular job titles related to Security Controls Assessor jobs?

For Security Controls Assessor jobs, the most frequently searched job titles are:

Infographic showing various Security Controls Assessor job openings in the United States as of September 2026, with employment types broken down into 2% As Needed, 87% Full Time, 3% Part Time, and 8% Contract. Highlights an 89% In-person, 3% Hybrid, and 8% Remote job distribution, with an average salary of $122,236 per year, or $58.8 per hour.

Cyber Security Controls Assessor

San Francisco, CA • Hybrid

$104K - $145K/yr

Full-time

Posted 16 days ago


Job description

Pivot Point Solutions

Pivot Point Solutions is a California-based technology consulting firm that specializes in delivering IT solutions and support for the construction and utility industries. We partner with organizations across the state to provide reliable technology services that improve operational efficiency, enhance project delivery, and support critical business systems.

Our team understands the unique technology challenges facing construction and utility organizations, from field operations and infrastructure projects to enterprise applications and cybersecurity. By combining industry expertise with responsive service, we help clients modernize their technology environments, streamline workflows, and maintain secure, reliable IT systems that support long-term growth.


Job Overview
Title: Cyber Security Controls Assessor 
Sector: Information Technology / Cybersecurity
Seniority: Mid to Senior Level
Location: California (Hybrid)
Job Type: Contract
Contract Length: 6+ Months
Compensation: $104K - $145K

About the Role
PPS is seeking a Cyber Security Controls Assessor to support the protection of critical energy infrastructure through the assessment and validation of cybersecurity controls across enterprise and operational technology (OT) environments. This role evaluates compliance with cybersecurity policies, regulatory requirements, and industry standards to ensure the confidentiality, integrity, and availability of systems supporting electric and gas utility operations. The ideal candidate brings strong experience in security assessments, risk management, compliance, and control validation, with a focus on protecting critical infrastructure and supporting regulatory obligations.

Key Responsibilities

  • Conduct cybersecurity control assessments for enterprise IT, cloud, and OT/industrial control system environments
  • Evaluate security controls against NIST CSF, NIST 800-53, NERC CIP, CIS Controls, and security policies
  • Identify security risks, control deficiencies, and compliance gaps, and recommend corrective actions
  • Prepare assessment reports detailing findings, risk ratings, remediation recommendations, and control effectiveness
  • Partner with cybersecurity, engineering, IT, OT, compliance, and business stakeholders on risk identification and management
  • Validate implementation and effectiveness of security controls for new projects, system upgrades, and technology deployments
  • Support internal audits, regulatory reviews, and compliance initiatives related to critical infrastructure protection
  • Track remediation activities and validate closure of cybersecurity findings
  • Maintain assessment methodologies, standards, and procedures supporting cybersecurity programs
  • Mentor junior assessors and contribute to continuous improvement initiatives within the Cybersecurity Risk & Compliance team

Qualifications

Required:

  • Bachelor's degree in Cybersecurity, Information Security, Computer Science, Engineering, IT, or related field; or equivalent experience
  • 5+ years of experience in cybersecurity, risk management, compliance, audit, or security controls assessment
  • Experience performing security assessments and evaluating cybersecurity controls
  • Knowledge of cybersecurity frameworks such as NIST CSF, NIST 800-53, CIS Controls, and risk management methodologies
  • Experience with regulatory compliance programs and audit support
  • Strong analytical, communication, and technical documentation skills
  • Ability to communicate security risks and recommendations to technical and non-technical stakeholders

Preferred:

  • Experience within electric utilities, critical infrastructure, energy, or other regulated industries
  • Knowledge of NERC CIP standards and compliance requirements
  • Experience assessing OT, SCADA, ICS, or energy management systems
  • Familiarity with cloud security environments (Azure, AWS)
  • Experience with GRC platforms
  • Professional certifications: CISSP, CISA, CRISC, GICSP, Security+, or equivalent

Work Environment

  • Standard office/field environment supporting critical infrastructure operations