> Markdown version of [/jobs/ext/1216406-security-control-assessor-it-security-specialist-3](https://www.wearedevelopers.com/jobs/ext/1216406-security-control-assessor-it-security-specialist-3). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Control Assessor - IT Security Specialist 3 - **Company:** Tyton LLC - **Location:** United States (Remote available) - **Experience:** Experienced - **Salary:** $120,000.0 - $150,000.0 - **Contract:** Permanent contract - **Skills:** Cyber Security, Information Systems, Linux, Supervisory Control and Data Acquisition (SCADA), Google Cloud, Cloud Platform System, SC Clearance, Information Technology - **Published:** July 9, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=6145d023d5492fe9 ## About the Role * Bachelor's degree * 12 years of relevant experience * 2 years of hands-on experience in Security Control Assessments * Proven ability to handle a high volume of assessments, with a focus on program-scale operations * In-depth knowledge of NIST 800-53/800-30 standards * Effective communication skills to convey complex security concepts to various stakeholders * Excellent organizational skills and the ability to manage a rotating schedule of assessments * Ability to obtain Secret clearance * Within 50 miles radius for a NASA facility (https://science.nasa.gov/about-us/nasa-centers) * Availability for occasional travel 20% Nice to Have Qualifications: * Security control assessments or ISSO, ISSM, ISSE experience. * Demonstrated proficiency in cloud platforms, with a preference for Google Cloud Platform (GCP) * Strong expertise in Linux systems and the ability to apply security measures across a diverse range of IT systems * Supervisory control and data acquisition (SCADA) experience. * Experience in assessing non-traditional IT systems, particularly in a program-scale context * Within 50 mile radius of NASA JPL, Ames, Armstrong, Marshall, JSC , Glenn or KSC (https://science.nasa.gov/about-us/nasa-centers), * relevant IT: 10 years (Required) * NIST 800-53/800-30 standards: 5 years (Required) * IT Security Control Assessments: 2 years (Required) ## Description Join our team supporting NASA cyber security in the area of Risk Management and Enterprise Assessment Services. Our team provides Risk Management services supporting Independent Assessments in accordance with Federal mandates, NIST guidance, and NASA policies and procedures. This includes support to an effective and comprehensive enterprise independent assessment service for NASA information systems, including Operational Technologies and cloud systems. Security Control Assessor (SCA) Position Description: * Conduct independent comprehensive assessments of the management, operational, and technical security controls and control enhancements employed within or inherited for traditional information technology (IT), operational technology (OT), and mission systems to determine the overall effectiveness of the controls (as defined in NIST SP 800-37) * Create a pre-assessment verification checklist and submit to ISO * Provide verification that System Security Plans (SSPs) to be assessed and audited are ready for an assessment via use of an Agency approved tool * Create security assessment plan prior to scheduling assessment * Submit security assessment plan to Information System Owner (ISO) for approval * Schedule assessments * Conduct technical and non-technical security assessment * Create Security Assessment Report (SAR) using agreed upon format * Schedule and perform system assessment out-brief with ISO * Attend Authorization To Operate (ATO) brief with Authorizing Official (to be scheduled by ISO) * Upload all security assessment documentation in the Agency approved tool * Work collaboratively with cross-functional teams to gather necessary information for assessments * Ensure timely and accurate reporting of assessment results, vulnerabilities, and compliance status * Collaborate with stakeholders to develop and implement corrective action plans based on assessment findings * Provide expertise in scaling security measures to meet the unique requirements of diverse IT systems * Maintain awareness of emerging threats and industry best practices to continually enhance assessment methodologies * Operate effectively in a fast-paced environment, demonstrating the ability to be proactive and adaptive * Act as a client-facing representative of the organization, engaging with clients professionally and effectively * Perform security assessment duties including ## Related Videos - [The Cloud is Calling: Answer with In-Demand Skills](https://www.wearedevelopers.com/videos/945-the-cloud-is-calling-answer-with-in-demand-skills) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Cloud Run- the rise of serverless and containerization](https://www.wearedevelopers.com/videos/106-cloud-run-the-rise-of-serverless-and-containerization) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [Maturity assessment for technicians or how I learned to love OWASP SAMM](https://www.wearedevelopers.com/videos/351-maturity-assessment-for-technicians-or-how-i-learned-to-love-owasp-samm) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)