Lead Security Control Assessor

Booz Allen Hamilton

Confirmed live yesterday High trust

Quick summary

Work type
On-site
Location
Aberdeen Proving Ground, MDAlexandria, VA
Salary
$99,000–$225,000 / yr
Posted
1 day ago
Freshness
Confirmed live yesterday

Market check

Salary context

Competitive pay

How this pay compares to similar roles

Similar $169k
This role $162k
$84k most similar roles pay here $240k

This role pays less than 54% of similar roles. Most pay $145,000–$193,275 — the shaded band above. At the midpoint, this role pays about $162k versus about $169k for comparable roles.

Based on 240 similar postings.

Employer

About Booz Allen Hamilton

Booz Allen Hamilton is a management and technology consulting firm that provides analytics, digital, engineering, and cybersecurity solutions primarily to U.S. government agencies and commercial clients. Industry: Management & Technology Consulting

Booz Allen Hamilton currently has 789 open roles on FindRole.

Listed pay typically runs $86,800–$198,000 across 766 roles with salary data.

Most-posted roles

View all roles at Booz Allen Hamilton

At a glance

TL;DR · Lead Security Control Assessor

The Security Control Assessor, Lead directs the assessment workstream and provides independent cybersecurity leadership for CDAO systems and environments. This role is responsible for developing and governing the assessment approach, quality standards, and risk adjudication while overseeing the lifecycle of security assessment plans and reports. The lead will manage eMASS administration, analyze STIG, SCAP, ACAS findings, and POA&Ms to ensure authorization readiness. Key responsibilities include evaluating complex enterprise, cloud, hybrid, and AI-enabled architectures while mentoring a team of assessors. Required expertise includes NIST SP 800-53, NIST SP 800-37, and DoD RMF frameworks. The candidate must possess experience with Windows, Linux, AWS Cloud, and containerization systems. This role solves critical cybersecurity risks by ensuring technical evidence sufficiency and providing risk recommendations to senior stakeholders for authorization decisions within a federal defense context.

What you'll do

  • Lead independent security control assessments in accordance with DoD RMF and NIST guidance.
  • Manage the assessment lifecycle including strategy, quality standards, evidence requirements, and test procedures.
  • Review and approve Security Assessment Plans (SAPs) and Security Assessment Reports (SARs) for technical accuracy.
  • Analyze STIG, SCAP, ACAS findings, and technical evidence to determine control effectiveness and risk.
  • Develop RMF Body of Evidence documentation and manage data within eMASS or other approved databases.
  • Brief senior stakeholders and Authorizing Officials on assessment status, systemic risks, and remediation priorities.
  • Oversee assessment execution for ATOs, reauthorizations, and continuous monitoring activities.
  • Mentor assessors and calibrate judgment to ensure objectivity across the assessment lifecycle.

What we're looking for

  • TS/SCI clearance is required.
  • Bachelor's degree in a technical field such as Engineering or Cyber.
  • 8+ years of experience with cybersecurity including DoD or federal RMF, security assessment, security engineering, or authorization.
  • Experience with eMASS, STIG, SCAP, ACAS findings, POA&Ms, and technical evidence analysis.
  • Experience leading security control assessments and producing or approving SSPs, SAPs, SARs, and authorization packages.
  • Experience with administration of Windows, Linux, AWS Cloud, and containerization systems.
  • Knowledge of NIST SP 800-53, NIST SP 800-37, DoD RMF, STIGs, and vulnerability management.
  • Ability to evaluate complex architectures and communicate risks at the AO and executive levels.

More like this

Similar roles

Security Controls Assessor

Booz Allen Hamilton

San Diego, CA 39 days ago $99,000$225,000
Risk Management Framework Cybersecurity Information Security Cross Domain Solutions Virtualization Artificial Intelligence Machine Learning Operational Technology Information Technology Security Controls Assessment TS/SCI Clearance
10+ yrs exp

Security Control Assessor II

General Dynamics

Ogden, UT 64 days ago $129,965$175,835
Risk Management Framework (RMF) JSIG Information Assurance Cybersecurity SDLC Continuous Monitoring Security Assessment Report (SAR) Plan of Action and Milestones (POA&M) Information Security Management System Development Life Cycle (SDLC)
7+ yrs exp

Security Control Assessor I

General Dynamics

Colorado Springs, CO 23 days ago $129,813$158,815
Risk Management Framework (RMF) JSIG SDLC Information Security Cybersecurity Continuous Monitoring Security Assessment Report (SAR) Plan of Action and Milestones (POA&M) CISSP CASP+ CCNP Security CISA
5+ yrs exp

Security Control Assessor II

General Dynamics

Bedford, MA +12 12 days ago $142,792$181,010
Risk Management Framework (RMF) JSIG Information Assurance Cybersecurity SDLC Continuous Monitoring Security Assessment Report (SAR) Plan of Action and Milestones (POA&M) Information Security Management System Development Life Cycle
7+ yrs exp

Security Control Assessor I

General Dynamics

Washington, DC +2 16 days ago $96,569$130,651
Risk Management Framework (RMF) JSIG SDLC Information Security Risk Management Continuous Monitoring Cybersecurity Security Assessment Report (SAR) Plan of Action and Milestones (POA&M) CISSP CISA CASP+ CCNP Security SAP SCI
9+ yrs exp

Security Control Assessor II

General Dynamics

Arlington, VA 37 days ago $142,792$181,010
Risk Management Framework (RMF) JSIG Information Security SDLC Continuous Monitoring Cybersecurity Security Assessment Report (SAR) Plan of Action and Milestones (POA&M) CISSP CISA CASP+ CCNP Security SAP SCI
7+ yrs exp