Lead Security Control Assessor

Booz Allen Hamilton

Confirmed live today High trust

Quick summary

Work type
On-site
Location
Alexandria, VAAberdeen Proving Ground, MD
Salary
$99,000–$225,000 / yr
Posted
1 day ago
Freshness
Confirmed live today

Market check

Salary context

Competitive pay

How this pay compares to similar roles

Similar $168k
This role $162k
$84k most similar roles pay here $240k

This role pays less than 52% of similar roles. Most pay $144,828–$190,950 — the shaded band above. At the midpoint, this role pays about $162k versus about $168k for comparable roles.

Based on 240 similar postings.

Employer

About Booz Allen Hamilton

Booz Allen Hamilton is a management and technology consulting firm that provides analytics, digital, engineering, and cybersecurity solutions primarily to U.S. government agencies and commercial clients. Industry: Management & Technology Consulting

Booz Allen Hamilton currently has 777 open roles on FindRole.

Listed pay typically runs $86,800–$198,000 across 751 roles with salary data.

Most-posted roles

View all roles at Booz Allen Hamilton

At a glance

TL;DR · Lead Security Control Assessor

The Security Control Assessor, Lead directs the SCA workstream and provides independent cybersecurity assessment leadership for CDAO systems and environments. This role is responsible for developing and governing the assessment approach, quality standards, and risk adjudication while overseeing the lifecycle of security assessments to ensure authorization readiness. The lead will manage eMASS administration, analyze STIG, SCAP, and ACAS findings, and develop RMF Body of Evidence documentation. Key responsibilities include reviewing Security Assessment Plans and Reports, mentoring assessors, and briefing senior stakeholders on residual risks. Required expertise includes NIST SP 800-53, NIST SP 800-37, and DoD RMF protocols. The role requires proficiency in Windows, Linux, AWS Cloud, and containerized systems to evaluate complex enterprise architectures including hybrid and AI-enabled environments while ensuring compliance with federal cybersecurity policies and technical evidence standards.

What you'll do

  • Lead independent security control assessments in accordance with DoD RMF and NIST guidance.
  • Manage the assessment lifecycle including strategy, quality standards, evidence requirements, and test procedures.
  • Review and approve Security Assessment Plans (SAPs) and Security Assessment Reports (SARs) for technical accuracy.
  • Analyze STIG, SCAP, ACAS findings, and other technical evidence within the eMASS system.
  • Develop RMF Body of Evidence documentation to ensure compliance with authorization requirements.
  • Brief senior stakeholders and Authorizing Officials on risk recommendations, assessment status, and remediation priorities.
  • Oversee assessment execution for ATOs, reauthorizations, and continuous monitoring activities.
  • Mentor assessors and calibrate judgment to ensure objectivity across the assessment lifecycle.

What we're looking for

  • Bachelor's degree in an Engineering or Cyber field.
  • 8+ years of experience with cybersecurity, including DoD or federal RMF, security assessment, security engineering, or authorization.
  • Experience with eMASS, STIG, SCAP, ACAS findings, POA&Ms, and technical evidence analysis.
  • Experience leading security control assessments and producing or approving SSPs, SAPs, SARs, and authorization packages.
  • Experience with administration of Windows, Linux, AWS Cloud, and containerization systems.
  • Knowledge of NIST SP 800-53, NIST SP 800-37, DoD RMF, STIGs, and vulnerability management.
  • Ability to evaluate complex architectures including cloud, hybrid, and AI-enabled environments (preferred); ability to adjudicate findings and lead continuous monitoring reviews (preferred).
  • TS/SCI clearance.

More like this

Similar roles

Lead Security Control Assessor

Booz Allen Hamilton

Aberdeen Proving Ground, MD +1 8 days ago $99,000–$225,000
RMF NIST SP 800-53 NIST SP 800-37 eMASS STIG SCAP ACAS POA&M AWS Linux Windows Containerization Vulnerability Management Continuous Monitoring Technical Writing Security Assessment Risk Assessment
8+ yrs exp

Security Controls Assessor

Booz Allen Hamilton

San Diego, CA 45 days ago $99,000–$225,000
Risk Management Framework Cybersecurity Information Security Cross Domain Solutions Virtualization Artificial Intelligence Machine Learning Operational Technology Information Technology Security Controls Assessment TS/SCI Clearance
10+ yrs exp

Security Control Assessor II

General Dynamics

Ogden, UT 71 days ago $129,965–$175,835
Risk Management Framework (RMF) JSIG Information Assurance Cybersecurity SDLC Continuous Monitoring Security Assessment Report (SAR) Plan of Action and Milestones (POA&M) Information Security Management System Development Life Cycle (SDLC)
7+ yrs exp

Security Control Assessor I

General Dynamics

Colorado Springs, CO 29 days ago $129,813–$158,815
Risk Management Framework (RMF) JSIG SDLC Information Security Cybersecurity Continuous Monitoring Security Assessment Report (SAR) Plan of Action and Milestones (POA&M) CISSP CASP+ CCNP Security CISA
5+ yrs exp

Security Control Assessor II

General Dynamics

Bedford, MA +12 18 days ago $142,792–$181,010
Risk Management Framework (RMF) JSIG Information Assurance Cybersecurity SDLC Continuous Monitoring Security Assessment Report (SAR) Plan of Action and Milestones (POA&M) Information Security Management System Development Life Cycle
7+ yrs exp

Security Control Assessor I

General Dynamics

Washington, DC +2 22 days ago $96,569–$130,651
Risk Management Framework (RMF) JSIG SDLC Information Security Risk Management Continuous Monitoring Cybersecurity Security Assessment Report (SAR) Plan of Action and Milestones (POA&M) CISSP CISA CASP+ CCNP Security SAP SCI
9+ yrs exp