Security Controls Assessor (SCA) - Senior

Apply Now ↗
🌍 Remote📍 TELECOMMUTE📍 United States

About this role

Avint is seeking a highly motivated Senior Security Controls Assessor (SCA) in support of a critical federal contract. The Senior SCA is a subject matter expert responsible for executing comprehensive, independent assessments of the organization’s most complex information systems, applications, and cloud infrastructures. Operating as a senior-level individual contributor, this role focuses on verifying the implementation, correctness, and effectiveness of technical, operational, and management security controls. The Senior SCA handles the most complex, critical, or sensitive system assessments, serving as a technical mentor to junior assessors and a primary technical advisor to system owners during the Risk Management Framework (RMF) lifecycle.

Security Assessment and Validation
• Lead comprehensive security control assessments of complex information systems using interview, examination, and testing methods.
• Verify compliance with established frameworks such as NIST SP 800-37, NIST SP 800-53, NIST SP 800-171, FISMA, and/or FedRAMP, depending on organizational requirements.
• Analyze system architectures, network diagrams, configuration settings, and policies to identify vulnerabilities and compliance gaps.
• Review vulnerability scanning results (e.g., Nessus, Qualys) and penetration testing reports to validate the implementation of technical controls.

Technical Mentorship and Quality Assurance
• Act as a senior technical escalation point and mentor for mid- and junior-level Security Controls Assessors on the team.
• Perform peer reviews of assessment documentation, test results, and reports generated by other team members to ensure technical accuracy and consistency.
• Support the SCA Team Lead in defining, refining, and standardizing assessment methodologies, testing procedures, and reporting templates.

Reporting and Risk Management
• Author, review, and finalize high-quality Security Assessment Reports (SAR) detailing assessment findings, risks, and recommended remediations.
• Present assessment findings and risk postures to Authorizing Officials (AO), system owners, and other stakeholders in clear, actionable terms.
• Assist system owners in the development of realistic Plans of Action and Milestones (POA&M) to remediate identified deficiencies.
• Collaborate with the Risk Management team to ensure assessment data accurately informs the organization’s continuous monitoring strategy.

Continuous Improvement and Strategy
• Stay current on emerging cyber threats, vulnerabilities, regulatory changes, and assessment techniques
• Identify opportunities to automate assessment processes and integrate modern tooling into the assessment lifecycle.
• Participate in the development and refinement of enterprise information security policies, standards, and guidelines.

Qualifications

Technical Areas of Expertise:
• Advanced knowledge of security control frameworks (specifically NIST SP 800-53, NIST SP 800-37, and NIST SP 800-171).
• Familiarity with cloud security concepts (AWS, Azure, Google Cloud) and cloud compliance frameworks (FedRAMP).
• Knowledge of operating system security, network protocols, access control mechanisms, and vulnerability management tools.

Education:
• Bachelor’s degree (BS/BA) OR equivalent professional experience.
• Security+; higher certifications such as CISSP, CAP, or CASP desired.

Experience:
• Minimum of 8-10 years of dedicated experience in cybersecurity, information assurance, or IT auditing.
• At least six (6) years of dedicated experience performing hands-on security controls assessments of the most complex (C4) systems.

Clearance Requirements:
• Must be a U.S. citizen (no dual citizenship).
• Ability to pass a background investigation.
• Able to obtain and maintain DHS Suitability/Entry on Duty (EOD).

Soft Skills:
• Strong analytical, critical thinking, and problem-solving skills with a high level of technical professional skepticism.
• Excellent technical writing skills, with the ability to clearly document complex technical findings and defend assessment results to stakeholders.
• Exceptional interpersonal and diplomatic skills, allowing for productive collaboration with system administrators, developers, and management.

Joining Avint is a win-win proposition! You will feel the personal touch of a small business and receive BIG business benefits, from competitive salaries, full health insurance, generous time off, and observation of federal holidays. Additionally, we encourage every Avint employee to further their professional development. To assist you in achieving your goals, we offer reimbursement for courses, exams, and tuition. Interested in a class, conference, program, or degree? Avint will invest in YOU and your professional development! Salary Range $125,000-$141,00

Frequently Asked Questions

Is the salary disclosed for the Security Controls Assessor (SCA) - Senior position at Avint?
The salary for this Security Controls Assessor (SCA) - Senior role at Avint is not publicly listed. Click "Apply Now" to learn more about the compensation package on their official careers page.
Is the Security Controls Assessor (SCA) - Senior job at Avint remote?
Yes, this Security Controls Assessor (SCA) - Senior position at Avint is remote, with team members based in TELECOMMUTE, United States. You can work from home or anywhere in the supported regions.
How do I apply for the Security Controls Assessor (SCA) - Senior position at Avint?
Click the "Apply Now" button on this page. You will be redirected to Avint's official application portal hosted on workable where you can submit your application directly.
When was the Security Controls Assessor (SCA) - Senior job at Avint posted?
This Security Controls Assessor (SCA) - Senior position at Avint was posted on Jul 9, 2026. Apply as soon as possible — early applications are often reviewed first.
Security Controls Assessor (SCA) - Senior
Avint
Apply for this role ↗

You'll be redirected to Avint's official application page on workable.