Security Controls Assessor

Booz Allen Hamilton

Confirmed live yesterday High trust

Quick summary

Work type
On-site
Location
San Diego, CA
Salary
$99,000–$225,000 / yr
Posted
32 days ago
Freshness
Confirmed live yesterday
Closes
Dec 14, 2026

Market check

Salary context

Competitive pay

How this pay compares to similar roles

Similar $168k
This role $162k
$84k most similar roles pay here $240k

This role pays more than 51% of similar roles. Most pay $137,500–$198,150 — the shaded band above. At the midpoint, this role pays about $162k versus about $168k for comparable roles.

Based on 239 similar postings.

Employer

About Booz Allen Hamilton

Booz Allen Hamilton is a management and technology consulting firm that provides analytics, digital, engineering, and cybersecurity solutions primarily to U.S. government agencies and commercial clients. Industry: Management & Technology Consulting

Booz Allen Hamilton currently has 802 open roles on FindRole.

Listed pay typically runs $86,800–$198,000 across 783 roles with salary data.

Most-posted roles

View all roles at Booz Allen Hamilton

At a glance

TL;DR · Security Controls Assessor

The Security Controls Assessor joins the team to design, implement, and manage policies and procedures ensuring database and software security. This role involves solving complex problems through innovative solutions while mentoring staff on technical competencies. The successful candidate will assess relevant controls within operational systems, including both information technology and operational technology environments. Key responsibilities include reviewing broad-scope technical implementations for disparate systems involving cross domain solutions, layered defensive techniques, cloud or hybrid solutions, virtualization, Artificial Intelligence, Machine Learning, and robotic processing. Required expertise includes NIST Special Publication 800-53, Risk Management Framework processes, and DoW components. The role requires a TS/SCI clearance and proficiency in communicating technical information regarding security controls. Candidates should possess experience with Joint Special Access Program Implementation Guides and potentially hold CISSP or CASP certifications to support the security of critical infrastructure.

What you'll do

  • Design, implement, and manage policies and procedures to ensure database and software security.
  • Apply advanced principles and theories to solve complex cybersecurity problems with innovative solutions.
  • Assess relevant security controls within operational technology and information technology systems.
  • Review broad technical implementations for diverse systems including cloud, hybrid, virtualization, and AI/ML technologies.
  • Communicate factual information regarding system security and the impact of implemented controls to stakeholders.
  • Mentor or supervise employees in both company procedures and technical cybersecurity competencies.

What we're looking for

  • 14+ years of experience in cybersecurity or information security fields.
  • Knowledge of NIST SP 800-53, associated security controls, and DoD Risk Management Framework processes.
  • Knowledge of the DoW components and their respective authorities and responsibilities.
  • Ability to assess relevant controls within operational technology and information technology systems.
  • Ability to review broad scope technical implementations including cross domain solutions, cloud/hybrid environments, and AI/ML.
  • Experience with DoW systems, JSAPIG knowledge, Master's degree, or expert certifications like CISSP/CASP (preferred).
  • TS/SCI clearance.

More like this

Similar roles

Security Control Assessor II

General Dynamics

Arlington, VA 31 days ago $142,792$181,010
Risk Management Framework (RMF) JSIG Information Security SDLC Continuous Monitoring Cybersecurity Security Assessment Report (SAR) Plan of Action and Milestones (POA&M) CISSP CISA CASP+ CCNP Security SAP SCI
7+ yrs exp

Security Control Assessor I

General Dynamics

Washington, DC +2 10 days ago $96,569$130,651
Risk Management Framework (RMF) JSIG SDLC Information Security Risk Management Continuous Monitoring Cybersecurity Security Assessment Report (SAR) Plan of Action and Milestones (POA&M) CISSP CISA CASP+ CCNP Security SAP SCI
9+ yrs exp

Security Control Assessor II

General Dynamics

Ogden, UT 58 days ago $129,965$175,835
Risk Management Framework (RMF) JSIG Information Assurance Cybersecurity SDLC Continuous Monitoring Security Assessment Report (SAR) Plan of Action and Milestones (POA&M) Information Security Management System Development Life Cycle (SDLC)
7+ yrs exp

Security Control Assessor II

General Dynamics

Bedford, MA +12 6 days ago $142,792$181,010
Risk Management Framework (RMF) JSIG Information Assurance Cybersecurity SDLC Continuous Monitoring Security Assessment Report (SAR) Plan of Action and Milestones (POA&M) Information Security Management System Development Life Cycle
7+ yrs exp

Security Control Assessor I

General Dynamics

Colorado Springs, CO 17 days ago $129,813$158,815
Risk Management Framework (RMF) JSIG SDLC Information Security Cybersecurity Continuous Monitoring Security Assessment Report (SAR) Plan of Action and Milestones (POA&M) CISSP CASP+ CCNP Security CISA
5+ yrs exp

Security Control Assessor

General Dynamics

Bethesda, MD 6 days ago $139,400$188,600
AWS Azure Cloud NIST SP 800-53 Risk Management Framework MITRE ATT&CK PKI TCP/IP DNS Cyber Defense Information Assurance ICD 503 CNSSI 1253
6+ yrs exp