Part-Time

Security Controls Assessor

Updated on 9/3/2026

TestPros

TestPros

Compensation Overview

$50 - $95/hr

Remote in USA

Remote

Bachelor's

Category
Cybersecurity (1)
Required Skills
Incident Response
Vulnerability Analysis
Risk Management
Penetration Testing
Requirements
  • At least 5 years of directly related experience in information technology security compliance, including recent experience with National Institute of Standards and Technology Special Publication 800-53 Revision 5, Security and Privacy Controls for Federal Information Systems and Organizations.
  • Experience with cloud computing security.
  • Experience with security governance and policy.
  • Experience with security risk analysis.
  • Experience auditing and monitoring systems.
  • Experience with scanning and vulnerability management systems.
  • Experience with Advanced Malware Protection.
  • Experience with threat intelligence.
  • Experience with incident management, including analysis, detection, and handling of security events.
  • Experience with penetration testing and associated tools such as Nmap and Metasploit.
  • A preferred bachelor's degree in Computer Science or a related technical discipline, or an equivalent combination of education, professional training, or work experience.
  • Military or practical job experience may substitute for formal education when accompanied by significant industry certifications.
Responsibilities
  • Develop System Security Plans based on National Institute of Standards and Technology Special Publication 800-53 Revision 5.
  • Create or update applicable National Institute of Standards and Technology Special Publication 800-53 Revision 5 documents, specifically Security Assessment Reports.
  • Create or update associated Plans of Actions and Milestones.
  • Provide detailed security-related reports containing data, analyses, and conclusions after tests, scans, and assessments, including mitigations and appropriate escalation of identified risks and vulnerabilities when indicated.
  • Verify and document implementation of security controls necessary to achieve compliance.
  • Keep management informed of impending areas of concern verbally and in writing.
  • Review and develop System Security Plans, Plans of Actions and Milestones, and other necessary artifacts.
  • Facilitate the Plans of Actions and Milestones program to ensure customer systems provide accurate and complete information for Plans of Actions and Milestones activities, including valid remediation of findings.
  • Develop policy documents and standard operating procedures or concepts of operations as required, including policies for configuration management, information system sanitization, media security, password management, business continuity, continuity of operations, incident response, disaster recovery, and security assessments.
  • Develop new information security and risk policies and mature existing policies.
  • Initiate and lead ongoing information security maturity assessment processes and training using industry-accepted frameworks and implement them into the overall cybersecurity posture.
  • Produce and review key performance indicators for implemented security measures and distribute the key performance indicators.
  • Maintain knowledge of the threat landscape by monitoring threat intelligence and related sources.

Company Size

N/A

Company Stage

N/A

Total Funding

N/A

Headquarters

N/A

Founded

N/A