Security Controls Assessor

TestPros

United States

Remote

USD 69,000 - 131,000

Part time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

TestPros, an IT assessment partner, seeks Security Controls Assessors for part-time consulting. Work involves supporting NIST 800-53 Rev5 ATOs for federal and commercial clients.

Opportunities begin in late 2026 or 2027, with a focus on developing SSPs, SARs, and POA&Ms, plus policy work and risk reporting.

Qualifications

  • 5+ years of IT security compliance experience, including NIST 800-53 Rev 5.
  • Experience with cloud security, governance, and risk analysis.
  • Strong auditing and vulnerability management skills.
  • Proficiency with penetration testing tools (e.g., Nmap, Metasploit).
  • Bachelor's Degree in Computer Science or related field preferred.

Responsibilities

  • Develop NIST 800-53 Rev5 based SSPs.
  • Create/update SARs and POA&Ms.
  • Produce security reports with mitigations and risk escalation.
  • Verify implementation of security controls for compliance.
  • Draft and maintain security policies and SOPs.

Skills

NIST 800-53 Rev5
Cloud security
Governance & policy
Risk analysis
Auditing & monitoring
Vulnerability management
Malware protection
Threat intelligence
Incident management
Penetration testing

Education

Bachelor's Degree in Computer Science

Tools

Nmap
Metasploit

Job description

TestPros delivers innovative independent IT assessment solutions to critical challenges facing the nation and the world. We support the U.S. Federal Government and Commercial clients within the continental USA.TestPros is dedicated to making lives better, safer and more secure. TestPros is looking forSecurity Controls Assessorswith experience performing on risk management programs for U.S. Federal and commercial clients by utilizing NIST, RMF, and FISMA compliance frameworks. Start: Future projects late 2026 or 2027 (not an immediate job opening) Type: Part-time consulting Overview Specifically, we are looking for professionals with experience in conducting NIST 800-53 Rev 5 based Authority To Operate (ATO) support.

  • Develop NIST 800-53 Rev5 based System Security Plan (SSP).
  • Create/Update the applicable documents identified by NIST 800-53 Rev 5, specifically the Security Assessment Report (SAR).
  • Create/Update the associated Plan of Actions and Milestones (POA&M).
  • Provide detailed security-related reports including data, analyses, and conclusions upon completion of tests, scans, and assessments, including mitigations and, if indicated, appropriate escalation of identified risks and vulnerabilities.
  • Verify and document the implementation of security controls necessary to achieve compliance.
  • Keep management apprised of impending areas of concern, verbally and in writing.
  • Review and develop System Security Plans (SSPs), Plans of Actions and Milestones (POA&Ms), and as well as other necessary artifacts.
  • Facilitate the Plan of Actions and Milestones (POA&M) program to ensure customer systems have accurately and fully provided information for POA&M activities to include valid remediation of findings.
  • Develop various policy documents (SOPs/CONOPs) as required. This may include policies regarding Configuration Management, IS Sanitization, Media Security, Password Policy, Business Continuity, Continuity of Operations, Incident Response, Disaster Recover, and Security Assessments.
  • Develop new, and mature existing information security and risk policies.
  • Initiate, and lead on-going information security maturity assessment processes and training, using industry accepted frameworks and implement into the overall cyber security posture.
  • Produce and review key performance indicators for implemented security measures and distribute KPIs.
  • Maintain knowledge of threat landscape by monitoring threat intelligence, and other related sources.
Qualifications and Skills:
  • 5+ years of directly related experience in IT security compliance, including recent experience with NIST 800-53 Rev 5 'Security and Privacy Controls for Federal Information Systems and Organizations'
  • Cloud computing security
  • Security governance and policy
  • Security risk analysis
  • Auditing and monitoring systems
  • Scanning and vulnerability management systems
  • Advanced Malware Protection
  • Threat Intelligence
  • Incident Management - analysis, detection, and handling of security events
  • Penetration testing and associated tools (e.g., nmap, Metasploit, etc.)
  • Bachelor's Degree in Computer Science or a related technical discipline, or the equivalent combination of education, professional training, or work experience (preferred)
  • Military and/or practical job experience may be considered in-lieu of formal education, with significant industry certifications
Rate:

$50-95/hr (1099 or Corp.To Corp.). This rangerepresentsagood-faithestimate and is not a guarantee; final compensation isdeterminedby factors such as experience, qualifications, and government contract labor rate requirements and may fall outside the stated range. Equal Opportunity Employer TestPros is an equal-opportunity employer and does not discriminate in employment based on race, color, religion, sex (including pregnancy and gender identity), national origin, political affiliation, sexual orientation, marital status, disability, genetic information, age, membership in an employee organization, retaliation, parental status, military service, or any other non-merit factor. Offer Considerations TestPros considers several factors when extending an offer, including but not limited to, Federal Government contract labor categories and contract wage rates, relevant prior work experience, specific skills and competencies, geographic location, education, and certifications. Federal Compliance As a federal contractor, TestPros is subject to all federal and state mandates and/or other customer requirements.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Controls Assessor / OSCAL
Security Controls Assessor / OSCAL

TestPros • United States

Remote
USD 69,000 - 117,000
Medical/dental/vision insurance
Life insurance
Paid time off
+2
SOC 2 Assessor
SOC 2 Assessor

TestPros • United States

Remote
USD 69,000 - 124,000
Lead CCA Certified Professionals
Lead CCA Certified Professionals

TestPros • United States

Remote
USD 83,000 - 145,000
Penetration Tester
Penetration Tester

TestPros • United States

Remote
USD 143,270,000 - 242,458,000
Information System Security Officer (ISSO)
Information System Security Officer (ISSO)

TestPros • Washington

On-site
USD 70,000 - 145,000
FedRAMP Subject Matter Expert
FedRAMP Subject Matter Expert

TestPros • United States

Remote
USD 69,000 - 131,000
SME
SME

TestPros • United States

Remote
USD 83,000 - 145,000
Cybersecurity Program Manager
Cybersecurity Program Manager

Testpros • Washington

On-site
USD 160,000 - 230,000
Medical/dental/vision insurance
401(k) retirement plan with company match
Paid time off
+1
Information System Security Officer (ISSO)
Information System Security Officer (ISSO)

Testpros • Washington

On-site
USD 70,000 - 145,000
Senior Security Controls Assessor
Senior Security Controls Assessor

ecsfederal • Virginia (MN)

Hybrid
USD 160,000 - 190,000
Remote work