> Markdown version of [/jobs/ext/2527494-control-assessment-analyst](https://www.wearedevelopers.com/jobs/ext/2527494-control-assessment-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Control Assessment Analyst - **Company:** Horizontal Talent - **Location:** Washington, DC, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Xacta, Software System Penetration Testing, Cloud Computing Security, Cyber Security, Information Systems, Security Content Automation Protocol, Information Technology, Nessus - **Published:** August 19, 2026 - **Apply:** https://www.dice.com/job-detail/71d0bb4b-dc4b-4278-b949-299698f926e6 ## About the Role * Bachelor's degree in Computer Science, Information Security, or a related field * 3 to 5 years of experience in information security or cybersecurity compliance * Experience supporting federal government systems and FISMA compliance requirements * Hands-on experience with RMF and ATO processes * Strong knowledge of NIST security frameworks, including 800-53, 800-37, and 800-171 * Ability to develop clear security documentation and manage compliance records * Strong analytical skills with the ability to assess risk and track remediation efforts * Effective communication and collaboration skills across technical and non-technical teams Preferred Skills * Experience with security assessment tools such as Nessus, ACAS, and SCAP * Familiarity with cloud security and FedRAMP concepts * Experience with compliance management platforms such as Xacta or similar tools * Knowledge of how security controls are implemented across different platforms and environments * Experience supporting security tool implementation or configuration Horizontal is committed to fostering an inclusive workplace where diverse perspectives are valued and respected. We believe equity and belonging help create stronger teams, better ideas, and more meaningful outcomes for everyone. ## Description Join a high-impact Governance, Risk, and Compliance team supporting security authorization and compliance efforts for federal information systems. This role is ideal for an experienced security professional who enjoys managing RMF/ATO activities, strengthening documentation, and collaborating across technical and business teams to support a strong security posture. Responsibilities * Support the full security authorization lifecycle for information systems under NIST RMF guidance * Prepare, update, and maintain security authorization packages, including system security plans, security assessment reports, and plans of action and milestones * Perform continuous monitoring activities to help maintain authorization status and compliance readiness * Assess security controls, review vulnerabilities, and document weaknesses and remediation efforts * Develop and maintain POA&Ms, risk findings, and supporting security documentation * Assist with annual security reviews, authorization updates, and audit-related requests * Coordinate vulnerability scans, penetration testing activities, and review of scan results * Support incident response efforts and assist with security event investigations as needed * Partner with system owners, security teams, vendors, and technical stakeholders to align on security requirements * Maintain security documentation, metrics, and reports in approved repositories ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Maturity assessment for technicians or how I learned to love OWASP SAMM](https://www.wearedevelopers.com/videos/351-maturity-assessment-for-technicians-or-how-i-learned-to-love-owasp-samm) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Less Is More: How Lagom and Agile Can Create Harmonious Workflows](https://www.wearedevelopers.com/videos/1993-less-is-more-how-lagom-and-agile-can-create-harmonious-workflows) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)