Steampunk logo

Security Control Assessor

Steampunk

McLean, VA · HybridJob$105–160K/yrPosted 2 days agoSeen in employer's feed today

Most applications go out cold — see where you stand first. No sign-up to start.

Watch jobs like this.

At a glance

Compensation
$105–160K/yr
Location
McLean, VAHybrid
Work Authorization
Not specified

Olive lists jobs from US employers, including remote roles you can work from the United States.

Requirements

Credentials this posting asks for.

CISSP, CASP, CISA, Or CISM

Job overview

Steampunk seeks a Security Control Assessor to support a government customer by assessing cybersecurity controls and maintaining system risk at an acceptable level. The role leads assessments, evaluates technical evidence, documents findings, coordinates remediation, and presents risk analysis. Candidates may qualify through one of three degree-and-experience paths and must hold one of the listed certifications or obtain one within six months of hire.

Skills & qualifications

RequiredNice to have

Skills

NIST SP 800-53FIPS 199/200NIST SP 800-30/37/39/53/60DHS Directive 4300ASecurity Control Artifact ReviewSystem Authorization PackagesAWSAzureNessusTenable.SCSplunkSCAP ScannersVulnerability AnalysisCompliance Gap AnalysisFIPS-Validated EncryptionSIEM LoggingIAM/MFAActive DirectoryOktaAzure ADFirewall ConfigurationACL ConfigurationSecurity Group ConfigurationDISA STIGRisk AnalysisAWS/Azure GovCloudMavenJenkinsAnsibleTomcatIISF5OracleMSSQLPostgreSQLAI/ML SecurityJIRAServiceNow

Qualifications

Bachelor's + 5, No Degree + 9, or Master's + 3 YearsCISSP, CASP, CISA, or CISMSecurity Control Assessor Experience

Full job description

Overview

Steampunk is seeking a Security Control Assessor to support a government customer, ensuring risk within the system is maintained at an acceptable level. This role requires initiative, organization, strong communication across all levels of the organization, and sound judgment with sensitive and confidential information in a fast-paced environment.

Contributions

As a member of one of our assessment teams, you will play an important role in performing a wide array of cybersecurity duties including:

  • Lead security assessments in accordance with NIST SP 800-53, NIST RMF (SP 800-37), FedRAMP, and agency-specific guidance.

  • Evaluate technical, operational, and management controls across cloud, on-premises, and hybrid environments, including hands-on review of technical control evidence (e.g., encryption configurations, SIEM logging, identity/access management, network boundary controls, STIG compliance).

  • Develop Assessment Plans and Security Assessment Reports (SARs), and document findings and risk in compliance with FISMA, FedRAMP, and organizational standards.

  • Coordinate with ISSOs, System Owners, and Authorization Officials to review evidence and remediate control deficiencies.

  • Analyze vulnerability scans, configuration baselines, and penetration test results to determine control effectiveness and recommend remediation.

  • Present findings and risk analysis to management and Authorization Officials.

  • Support continuous monitoring and control validation for ongoing authorization.

Qualifications

  • Bachelor's Degree and 5 years of relevant experience; OR

  • No degree with a total of 9years of relevant experience; OR

  • Master's degree and 3 years of relevant experience

  • One of the following certifications (may be obtained within six (6) months of hire):

  • Certified Information System Security Professional (CISSP)

  • CompTIA Advanced Security Practitioner (CASP)

  • Certified Information Systems Auditor (CISA)

  • Certified Information Security Manager (CISM)

  • Strong knowledge of NIST SP 800-53, FIPS 199/200, and NIST SP 800-30/37/39/53/60; familiarity with DHS Directive 4300A.

  • Hands-on experience reviewing security control artifacts and providing independent evaluations for system authorization packages, including in cloud environments (AWS, Azure).

  • Proficiency with assessment/scanning tools (e.g., Nessus, Tenable.SC, Splunk, SCAP scanners) and analytical skill to interpret vulnerabilities and compliance gaps.

  • Demonstrated ability to review technical controls directly, as a core part of the role — for example: verifying FIPS-validated encryption, auditing SIEM logging architecture, reviewing IAM/MFA enforcement (AD, Okta, Azure AD), analyzing firewall/ACL/Security Group configurations, and evaluating DISA STIG results.

Preferred:

  • Experience as a Security Control Assessor and performing risk analysis/assessment.

  • Working knowledge of AWS/Azure GovCloud and enterprise application stacks (e.g., Maven, Jenkins, Ansible, Tomcat, IIS, F5, Oracle, MSSQL, PostgreSQL).

  • Familiarity with AI/ML concepts and their security implications.

  • Working knowledge of JIRA, ServiceNow, or equivalent.

About steampunk

Steampunk relies on several factors to determine salary, including but not limited to geographic location, contractual requirements, education, knowledge, skills, competencies, and experience. The projected compensation range for this position is $105,000 to $160,000. The estimate displayed represents a typical annual salary range for this position. Annual salary is just one aspect of Steampunk’s total compensation package for employees. Learn more about additional Steampunk benefits here.

Identity Statement

As part of the application process, you are expected to be on camera during interviews and assessments. We reserve the right to take your picture to verify your identity and prevent fraud.

Steampunk is a Change Agent in the Federal contracting industry, bringing new thinking to clients in the Homeland, Federal Civilian, Health and DoD sectors. Through our Human-Centered delivery methodology , we are fundamentally changing the expectations our Federal clients have for true shared accountability in solving their toughest mission challenges. If you want to learn more about our story, visit http://www.steampunk.com .

We are an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veteran status, or any other characteristic protected by law. Steampunk participates in the E-Verify program.

Refer a Friend (https://careers-steampunk.icims.com/jobs/8327/security-control-assessor/job?mode=apply&apply=yes&in\_iframe=1&hashed=-336029103)

Need help finding the right job?

We can recommend jobs specifically for you!Software Powered by ICIMS (https://careers-steampunk.icims.com/connect?back=intro&findajob=1&in\_iframe=1&hashed=-435593565)

Job Location US-VA-McLean

Posted Date (10/8/2026 11:39 AM)

Job ID 8327

Clearance Requirement Public Trust

Similar jobs, posted recently

Open roles like this one, listed in the last 30 days.

You've read the whole posting — now see how you match it.