Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Cybersecurity Compliance Auditor / Security Control Assessor (SCA)

$100k

The Johns Hopkins University Applied Physics Laboratory

Description

Do you enjoy assessing complex systems and ensuring they meet the highest cybersecurity standards in support of national security, space exploration, and advanced technologies?

If so, we are looking for someone like you to join our team at APL.

Recognized as one of Computerworld's Top Places to Work in IT for seven consecutive years, APL is expanding its cybersecurity compliance and assessment capabilities.

We are seeking a Cybersecurity Compliance Auditor / Security Control Reviewer (SCR) to perform independent security control assessments across classified information systems to determine the overall effectiveness of the controls.

Our team is mission-driven-focused on securing systems that enable critical national security objectives. We operate in a collaborative, technically rigorous environment where your expertise directly impacts mission success.

As a Cybersecurity Compliance Auditor / Security Control Reviewer (SCR), you will:

  • Planning, conducting, and performing independent security control assessments of classified systems in accordance with Risk Management Framework (RMF), Joint Special Access Program (SAP) Implementation Guide (JSIG), and applicable DoD/IC standards.
  • Evaluate the implementation and effectiveness of security controls across a wide range of technologies and environments.
  • Conduct risk-based assessments to determine system compliance and identify vulnerabilities, control gaps, and areas for process improvement.
  • Analyze system documentation, test results, and artifacts to validate control implementation and authorization readiness.
  • Develop clear, concise, and defensible assessment reports, including findings, risk determinations, corrective actions, and recommendations to address identified vulnerabilities.
  • Collaborate with Program Managers/System Owners, ISSMs, ISSOs, system engineers/administrators, and program teams to resolve findings and improve security posture.
  • Support internal security reviews and external inspections (e.g., DCSA, DoD, IC), ensuring systems are prepared for independent evaluation and compliance inspections.
  • Interpret and apply cybersecurity policies and frameworks, including RMF, NISPOM, DAAG/DAAPM, and JSIG.
  • Evaluate the effectiveness and implementation of Continuous Monitoring Plans
  • Contribute to the continuous improvement of assessment methodologies, tools, and processes.

Qualifications

You meet our minimum qualifications for the job if you:

  • Hold a Bachelor's degree in Information Systems, Computer Science, Cybersecurity, or a related field (or equivalent experience).
  • Have at least 5 years of cybersecurity experience, including involvement in RMF, Certification & Accreditation (C&A), or Assessment & Authorization (A&A) processes.
  • Have experience performing or supporting Security Control Assessments or independent validation of security controls.
  • Have experience in three or more of the following areas:
    • Network, endpoint, and application security
    • Identity and access management
    • Vulnerability and configuration management
    • Encryption and data protection technologies
    • Incident response and monitoring
  • Hold a relevant certification such as CISA, GSNA, CASP+ CE, CISSP, CISM or DoD 8570/8140 IAT/IAM Level II/III equivalent.
  • Have experience applying cybersecurity standards such as:
    • NISPOM
    • DAAG/DAAPM
    • JSIG
    • NIST SP 800-53 / RMF
  • Demonstrate strong technical understanding of operating systems, networking, virtualization, AI/ML, and cloud environments.
  • Possess strong written and verbal communication skills, with the ability to clearly document and communicate risk.
  • Hold an active Secret clearance with the ability to obtain a Top-Secret clearance. If selected, you will be subject to a government security clearance investigation and must meet the requirements for access to classified information. Eligibility requirements include U.S. citizenship.

You'll go above and beyond our minimum requirements if you:

  • Have direct experience functioning as a Security Control Assessor (SCA) in DoD or IC environments.
  • Have served in roles such as ISSO, ISSM, ISSE, Security Engineer, or Cyber Risk Analyst.
  • Possess deep expertise in RMF, NIST SP 800-37, NIST SP 800-53, and CNSSI 1253.
  • Have supported DCSA, DoD, or IC inspections and understand external assessment expectations.
  • Experience with GRC/RMF Tools such as eMASS, ServiceNow (SNOW), XACTA
  • Have 8+ years of cybersecurity experience in classified environments.
  • Are familiar with JHU/APL systems, processes, and mission areas.
  • Hold an active TS/SCI (or TS/SCI with polygraph).

About Us

Why Work at APL?

The Johns Hopkins University Applied Physics Laboratory (APL) brings world-class expertise to our nation's most critical defense, security, space and science challenges. While we are dedicated to solving complex challenges and pioneering new technologies, what makes us truly outstanding is our culture. We offer a vibrant, welcoming atmosphere where you can bring your authentic self to work, continue to grow, and build strong connections with inspiring teammates.

At APL, we celebrate our differences of perspectives and encourage creativity and bold, new ideas. Our employees enjoy generous benefits, including a robust education assistance program, unparalleled retirement contributions, and a healthy work/life balance. APL's campus is located in the Baltimore-Washington metro area. Learn more about our career opportunities at

All qualified applicants will receive consideration for employment without regard to race, creed, color, religion, sex, gender identity or expression, sexual orientation, national origin, age, physical or mental disability, genetic information, veteran status, occupation, marital or familial status, political opinion, personal appearance, or any other characteristic protected by applicable law.APL is committed to providing reasonable accommodation to individuals of all abilities, including those with disabilities. If you require a reasonable accommodation to participate in any part of the hiring process, please View email address on click.appcast.io.

The referenced pay range is based on JHU APL's good faith belief at the time of posting. Actual compensation may vary based on factors such as geographic location, work experience, market conditions, education/training and skill level with consideration for internal parity. For salaried employees scheduled to work less than 40 hours per week, annual salary will be prorated based on the number of hours worked. APL may offer bonuses or other forms of compensation per internal policy and/or contractual designation. Additional compensation may be provided in the form of a sign-on bonus, relocation benefits, locality allowance or discretionary payments for exceptional performance. APL provides eligible staff with a comprehensive benefits package including retirement plans, paid time off, medical, dental, vision, life insurance, short-term disability, long-term disability, flexible spending accounts, education assistance, and training and development. Applications are accepted on a rolling basis.

Minimum Rate

$100,000 Annually


Maximum Rate

$245,000 Annually
Required
Preferred
Job Industries
  • Other
Vacancy posted 15 hours ago
Similar jobs that could be interesting for youBased on the Cybersecurity Compliance Auditor / Security Control Assessor (SCA) in Laurel, MD vacancy
  • $70k - $74k

     ...Newberry Group seeks a Jr. Security Control Assessor to support its Government...  ...: Conduct cybersecurity assessments, audits, and inspections...  ...plans, and scope with the SCA Team Lead. Perform vulnerability...  ...STIGs, RMF controls, and compliance with DoD policies and... 
    Suggested
    Contract work
    Temporary work
    For contractors
    Interim role
    Remote work
    Flexible hours

    The Newberry Group

    Annapolis Junction, MD
    7 days ago
  • $225k - $235k

     ...Security Control Assessor Location: Fort Meade, MD Salary: $225K-235K Clearance Required: Active...  ...complex systems to ensure compliance with federal security requirements....  ...Qualifications: ~12+ years in cybersecurity or systems engineering ~ Recent experience... 
    Suggested
    Full time

    Sun Recruiting

    Columbia, MD
    1 day ago
  • $112k - $179k

     ...Information Systems Security Officer (Technical ISSO / RMF Assessor) Job Locations...  ...and validating security controls within DoD RMF environments...  ...or closely related DoD cybersecurity role. ~ Demonstrated experience...  ...Security Control Assessor (SCA) or assessor support.... 
    Suggested
    Contract work
    Shift work

    Peraton

    Riverdale, MD
    2 days ago
  •  ...Asset Auditor - Quality Specialist 1 Annapolis Junction,...  ...protect assets by ensuring compliance with internal control procedures, and regulations...  ...range of services in cybersecurity, software, data transport...  ...that enhance our nation's security. In an ultra-competitive... 
    Suggested
    Work at office
    Immediate start
    Flexible hours

    Synergy ECP

    Annapolis Junction, MD
    3 days ago
  • $63.54k - $95.31k

     ...Audit Job Description: The Senior Auditor is responsible to perform and document...  ...audits/projects. They independently assess control design and operating effectiveness...  ...auditors. The Senior Auditor - U.S. Compliance Audit is responsible for executing and... 
    Suggested
    Work at office
    Local area
    Work from home
    Flexible hours

    TD Bank

    Laurel, MD
    4 days ago
  •  ...Internal Auditor Conducts internal audits to determine compliance with federal regulations, policies/procedures, and sound business practices. Risks and controls will be evaluated to determine strengths and/or weaknesses in business processes and will be reported to... 
    Flexible hours

    MRINetwork

    Annapolis Junction, MD
    2 days ago
  •  ...Revenue Auditor I The Revenue Auditor I plays a vital role in maintaining the financial integrity and regulatory compliance of Live! Casino & Hotel by accurately reviewing, recording, and...  ...by the Maryland Lottery & Gaming Control Agency. Physical Requirements:... 
    Full time
    Temporary work
    Part time
    Work at office
    Shift work
    Weekend work

    Live! Casino & Hotel

    Hanover, MD
    12 hours ago
  •  ...Description Auditor, Financial Controls - Federal Financials Silver Spring, Maryland @Orchard LLC is actively seeking to engage an experienced Auditor, Financial Controls for a new project, anticipated to last up to 5 years in support of NOAA's financial... 
    For contractors
    Work at office

    Orchard , CO

    Silver Spring, MD
    3 days ago
  •  ...Job Title: Internal Auditor/Healthcare Analyst Talantage is currently seeking...  ...healthcare auditing team and clients to evaluate compliance with applicable regulations and industry...  .../reviewer Ability to obtain a security clearance, to include drug screen and... 
    Full time
    Contract work

    Talantage

    Columbia, MD
    3 days ago
  • $128.45k - $167.5k

     ...networking, sensing, and security. IonQ's newest...  ...modeling, logistics, cybersecurity, and defense. In 2025...  ...gap between technical control requirements and enterprise...  ..., IT, and legal/compliance pillars, ensuring governance...  ...with external auditors to ensure a seamless... 
    Permanent employment
    Contract work
    Work at office

    IonQ Inc.

    College Park, MD
    14 hours ago
  •  ...for a CMMC Certified Assessor (CCA) at CyberRx, Inc...  ...interviews, validating compliance with NIST 800-171 and...  ...technical rigor of cybersecurity assessments and prefer...  ...national security and committed to partnering...  ...related to handling Controlled Unclassified Information... 
    Full time
    For contractors
    Remote work

    CyberRx LLC

    Silver Spring, MD
    5 days ago
  •  ...Certified CMMC Assessor The Certified CMMC Assessor (...  ...assessment leadership, control evaluation, and final compliance determinations, while ensuring...  ...of experience in: ~ Cybersecurity ~ IT audit or...  ...compliance ~ Information security program management... 

    DigiFlight

    Columbia, MD
    4 days ago
  •  ...Senior Auditor The Senior Auditor is responsible for completing compliance testing of the Company’s SOX/Internal Controls Program as assigned and championing internal control and corporate governance concepts throughout the business. This includes planning, executing... 

    MRINetwork

    Annapolis Junction, MD
    2 days ago
  • $70k

     ...a Claims Review Specialist (Workers Compensation) at the corporate office in Hanover, MD. Reporting to the Workers Compensation Compliance Supervisor and Workers Compensation Compliance Manager, the Claims Review Specialist will assist in the monitoring and administering... 
    Temporary work
    Work experience placement
    Work at office
    Immediate start

    Aerotek

    Hanover, MD
    3 days ago
  • $34.16 - $58.08 per hour

     ...evaluating the actual cash value of losses, drafting authority memoranda, and negotiating settlements. Essential Functions - • Secures statements (recorded and written) from claimants, employees, witnesses, etc. • Establishes reserves on claim files • Reviews and evaluates... 
    Hourly pay
    Full time
    Contract work
    Temporary work
    Part time
    Casual work
    Work at office

    WSSC Water

    Laurel, MD
    1 day ago
  •  ...Position Summary The Lot Attendant / Lot Auditor helps ensure a smooth, safe, and...  ...the lot, and keeping the area clean and secure. The ideal candidate is friendly, detail...  ...organized records of parked cars. Security & Compliance Check the lot regularly, report... 
    Hourly pay
    Minimum wage
    Full time
    Part time
    Local area
    Shift work
    Night shift

    Parking Management Services

    Hanover, MD
    2 days ago
  •  ...Job Description Job Description Now accepting applications for an Energy Auditor to perform Home Performance with Energy Star audits, with the end goal of moving customers through the client cycle from the initial audit to job completion. Your role will be to educate... 
    Casual work
    Work at office
    Work from home

    Elysian Energy

    Laurel, MD
    4 days ago
  • $64.97k - $99k

     ...property claims with exposures up to $500,000 Evaluate coverage and policy terms to determine the validity of claims and ensure compliance with local regulations Negotiate and settle claims within the authorized limits, considering policy provisions, industry standards... 
    Work experience placement
    Work at office
    Local area
    Remote work
    Work from home
    Flexible hours

    State Farm

    Laurel, MD
    4 days ago
  • We are hiring a Senior Claims Representative (workers' compensation) for one of our clients in Mount Laurel, NJ . Job Description: Under the supervision of a Claims Supervisor, a Senior Claims Representative investigates, evaluates and manages assigned...
    Permanent employment
    Work experience placement
    Work at office
    Remote work
    Flexible hours
    Afternoon shift

    Biogensys

    Laurel, MD
    5 days ago
  • $70k - $103.5k

    The SIU Investigator is responsible for the accurate detection and in-depth investigation of potentially fraudulent insurance activity, ranging from complex medical and staged accident claims and auto property matters to simpler application fraud issues. Investigative ...
    Work from home

    Plymouth Rock Assurance

    Laurel, MD
    4 days ago
  • IS IT TIME FOR A CAREER CHANGE? INDEPENDENT INSURANCE CLAIMS ADJUSTERS NEEDED NOW! Are you ready to embark on a dynamic and in-demand career as an Independent Insurance Claims Adjuster? This is your chance to join a thriving industry with endless opportunities ...

    MileHigh Adjusters Houston

    Laurel, MD
    2 days ago
  • $74.6k - $112k

     ...and support Government Business Systems Audits as well as SOX compliance. Results will be achieved through partnering with management to...  ..., financial, Government Business System, and Financial Control audits with guidance from internal management Provide audit... 
    Work at office
    Night shift

    Oceaneering

    Hanover, MD
    8 hours ago
  • Introduction At Gallagher Bassett, we're there when it matters most because helping people through challenging moments is more than just our job, it’s our purpose. Every day, we help clients navigate complexity, support recovery, and deliver outcomes that make a real difference...
    Full time
    Live out
    Work at office
    Local area
    Remote work
    Flexible hours

    Gallagher Bassett

    Laurel, MD
    8 hours ago
  • $20.4 - $32.6 per hour

     ...should be! Position Overview As a Vehicle Condition Assessor (VCA), you will play a critical role in delivering exceptional...  ...auction preparation and operations. Complete vehicle secures and confirmations, verifying appraisal details and resolving discrepancies... 
    Hourly pay
    Full time
    Night shift
    Weekend work

    CarMax

    Ellicott City, MD
    2 days ago
  • $92.22k - $149.31k

     ...development of Audit Planning Memorandum (APM), Process Risk and Control Matrix (pRCM), Findings Grid and Audit Report Completes L1...  ...process with the stakeholders, senior management and external auditors for specific and/or overall Audit area Contributes to audit... 
    Work at office
    Work from home
    Flexible hours

    TD Bank

    Laurel, MD
    3 days ago
  •  ...Energy Assessor We are seeking an Energy Assessor to join our growing team in New Jersey. In this role, you'll perform insulation...  ...light and moderately heavy construction equipment Safety & Compliance: Follow all safety guidelines and company protocols... 
    Hourly pay
    Weekend work
    Afternoon shift

    Seel

    Laurel, MD
    2 days ago
  • $21.57 - $23.04 per hour

    Progressive is dedicated to helping employees move forward and live fully in their careers. Your journey has already begun. Apply today and take the first step to Destination: Progress. As a claims administrative support specialist , you'll play a vital role supporting...
    Temporary work
    H1b
    Work at office
    Monday to Friday
    Flexible hours

    Progressive Casualty Insurance Company

    Laurel, MD
    1 day ago
  • $64.7k - $107.9k

     ...relationships and cash flow projections on each borrower, guarantor, and contingent liability. * Review loan documentation to assess compliance with loan covenants and loan agreements, as well as to confirm compliance with bank regulation and the bank's commercial lending... 
    Full time
    Temporary work
    Work experience placement
    Local area
    Work visa
    Flexible hours

    Fulton Financial

    Laurel, MD
    3 days ago
  • Job Posting California applicants: Please review the Costco Applicant Privacy Notice. The jobs listed are examples of the typical kinds of positions that Costco may hire for when openings exist. The listing does not mean that any positions are currently open or available...
    Temporary work

    Costco Wholesale Corporation

    Hanover, MD
    2 days ago
  • A leading provider of insurance adjusting services is seeking Independent Claims Adjusters to join their team. The role offers an opportunity to make a meaningful impact on clients' lives while enjoying autonomy and competitive pay. Candidates will benefit from tailored...
    Flexible hours

    MileHigh Adjusters Houston

    Elkridge, MD
    4 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Cybersecurity Compliance Auditor / Security Control Assessor (SCA). Be the first to apply!