Security Control Assessor

Leidos

Confirmed live yesterday High trust

Quick summary

Work type
On-site
Location
Alexandria, VAFort Meade, MDChambersburg, PA
Salary
$69,550–$125,725 / yr
Employment
Full-time
Posted
11 days ago
Freshness
Confirmed live yesterday

Market check

Salary context

Below market

How this pay compares to similar roles

Similar $176k
This role $98k
$52k $233k
below market most similar roles pay here above market

This role pays less than 97% of similar roles. Most pay $137,700–$215,238 — the blue band above. At the midpoint, this role pays about $98k versus about $176k for comparable roles.

Based on 240 similar postings.

Employer

About Leidos

Leidos is an industry and technology leader serving government and commercial customers with smarter, more efficient digital and mission innovations.

Leidos currently has 399 open roles on FindRole.

Listed pay typically runs $92,300–$166,850 across 331 roles with salary data.

Most-posted roles

View all roles at Leidos

At a glance

TL;DR · Security Control Assessor

The Security Control Assessor joins the assessment team to conduct cybersecurity assessments, audits, and inspections for DoD organizations and partners handling DoD information or connecting to the DoDIN. The role involves evaluating systems and Defensive Cyberspace Operations using cyber threat emulation and performance-based testing. Daily responsibilities include performing vulnerability assessments, capturing results using STIG Viewer, documenting findings in eMASS, and providing risk analysis for authorization recommendations. The position requires validating cybersecurity controls, TTPs, STIGs, and RMF controls while ensuring compliance with DoD policies. Key technical skills include experience with Nessus, ACAS, SCAP, and HBSS, alongside knowledge of NIST SP 800-37, NIST SP 800-53, and CNSSI 1253. The work covers diverse domains including Network, Mobility, Windows, UNIX, Cloud Environments, Databases, and Applications.

What you'll do

  • Conduct cybersecurity assessments, audits, and inspections for DoD organizations and partners.
  • Evaluate systems and Defensive Cyberspace Operations using cyber threat emulation and performance-based testing.
  • Perform vulnerability assessments and document findings in eMASS using STIG Viewer or other designated tools.
  • Analyze security gaps and provide specific mitigation recommendations to stakeholders.
  • Validate cybersecurity controls, TTPs, STIGs, and RMF compliance against DoD policies.
  • Provide risk analysis and assessment results to support authorization recommendations.
  • Participate in daily assessment reviews and share findings with the SCA-R.
  • Mentor and guide personnel by providing technical expertise and professional development support.

What we're looking for

  • Active DoD Top Secret clearance with SCI eligibility required.
  • Current DoD 8570 IAM II or IAT II certification required.
  • Bachelor's degree in an IT-related field (preferred).
  • Five years of cybersecurity or network security experience.
  • Three years of experience in a Certification and Accreditation/A&A role.
  • Demonstrated experience with STIGs, SRGs, POA&Ms, and tools like eMASS, Nessus, ACAS, SCAP, or HBSS.
  • Strong understanding of RMF process, NIST SP 800-37, NIST SP 800-53, and CNSSI 1253.
  • Ability and willingness to travel for assessments up to 80% of the time.

More like this

Similar roles

Security Control Assessor, Lead

Booz Allen Hamilton

Alexandria, VA +1 18 days ago
DoD RMF NIST SP 800-53 eMASS STIG SCAP ACAS POA&M AWS Windows Linux Containerization Vulnerability Management Security Control Assessment Continuous Monitoring SharePoint Security Engineering Risk Assessment
8+ yrs exp

Security Control Assessor, Lead

Booz Allen Hamilton

Alexandria, VA +1 25 days ago
DoD RMF NIST SP 800-53 eMASS STIG SCAP ACAS POA&M AWS Linux Windows Containerization Vulnerability Management Security Control Assessment Continuous Monitoring SharePoint Technical Writing Security Engineering
8+ yrs exp

Security Controls Assessor

Booz Allen Hamilton

San Diego, CA 62 days ago $99,000–$225,000
Risk Management Framework Cybersecurity Information Security Cross Domain Solutions Artificial Intelligence Machine Learning Virtualization Operational Technology Information Technology Security Controls Assessment TS/SCI Clearance CISSP CASP
10+ yrs exp

Security Control Assessor II

General Dynamics

Arlington, VA 61 days ago $142,792–$181,010
Risk Management Framework (RMF) JSIG Information Security SDLC Continuous Monitoring Cybersecurity Information System Security Security Assessment Report (SAR) Plan of Action and Milestones (POA&M) SAP SCI CISSP CASP+ CE CCNP Security CISA
7+ yrs exp

Security Control Assessor

General Dynamics

Bethesda, MD 36 days ago $139,400–$188,600
Cybersecurity AWS Azure Cloud NIST SP 800-53 Risk Management Framework MITRE ATT&CK TCP/IP DNS PKI identity, and access management Information Assurance ICD 503 CNSSI 1253 IV&V Cyber Defense Network Protocols
6+ yrs exp

Security Control Assessor

General Dynamics

Bethesda, MD 30 days ago $148,750–$201,250
AWS Cloud Azure RMF NIST SP 800-53 MITRE ATT&CK TCP/IP DNS PKI IAM Penetration Testing ICD 503 CNSSI 1253 IV&V SOP
6+ yrs exp