Cybersecurity Consultant
Job Description
Guidehouse supports cybersecurity professionals with a comprehensive total rewards package, competitive compensation, and flexible benefits designed to help you thrive in a diverse and supportive workplace. This onsite role in McLean, VA offers an annual salary range of USD 85,000 - 141,000 and the opportunity to deliver practical cyber risk management across client systems.
Responsibilities
- Lead cyber risk management efforts across a portfolio of client applications.
- Own the end-to-end POA&M lifecycle, including creation, tracking, validation, and closure of identified security weaknesses.
- Prioritize remediation activities using risk severity, compliance requirements, and operational impact.
- Conduct regular POA&M status reviews and coordinate with system owners and O&M teams to monitor milestone progress.
- Perform BIAs to identify critical systems, functions, dependencies, and recovery time/objectives.
- Collaborate with stakeholders to validate system criticality and align with continuity and contingency planning requirements.
- Build and maintain strong working relationships across business, engineering, and security teams to validate fixes, resolve blockers, and support timely remediation.
- Prepare reports and briefings for leadership and federal oversight stakeholders.
- Provide cyber subject matter expertise during information security audits and assessments.
- Maintain and update BIA documentation as system architecture and mission priorities evolve.
Requirements
- Minimum two (2) years of overall work experience.
- Experience in cybersecurity or IT risk management; candidates with cybersecurity risk management focus are preferred.
- Hands-on experience with GRC platforms.
- Deep understanding of NIST SP 800-53, FISMA requirements, and 800-37.
- Strong communication and analytical thinking, with the ability to manage multiple concurrent priorities and deadlines.
- Must be able to OBTAIN and MAINTAIN a Federal or DoD “PUBLIC TRUST”. Approved adjudication of the PUBLIC TRUST is required prior to onboarding with Guidehouse.
- Candidates with an ACTIVE PUBLIC TRUST or SUITABILITY and an active HHS/NIH clearance are preferred.
Technologies
- GRC platforms, NIST SP 800-53, FISMA, 800-37
- Power BI, MITRE ATT&CK, EPSS, CVSS v3
Benefits
- Medical, Rx, Dental & Vision Insurance
- Personal and Family Sick Time & Company Paid Holidays
- Position may be eligible for a discretionary variable incentive bonus
- Parental Leave and Adoption Assistance
- 401(k) Retirement Plan
- Basic Life & Supplemental Life
- Health Savings Account, Dental/Vision & Dependent Care Flexible Spending Accounts
- Short-Term & Long-Term Disability
- Student Loan PayDown
- Tuition Reimbursement, Personal Development & Learning Opportunities
- Skills Development & Certifications
- Employee Referral Program
- Corporate Sponsored Events & Community Outreach
- Emergency Back-Up Childcare Program
- Mobility Stipend
Additional Information
- Job Family: Cyber Consulting
- Travel Required: Up to 25%
- Clearance Required: Ability to Obtain Public Trust
- Minimum Experience: 2 years
What Would Be Nice To Have
- Experience developing automated data pipelines or integrating APIs into Power BI dashboards.
- Knowledge of MITRE ATT&CK framework and vulnerability prioritization methodologies (e.g., EPSS, CVSS v3).
- Prior experience supporting a federal agency or working in a Public Health environment.
- Active CompTIA Security+ CE preferred; CISSP, CEH, or cloud-related certifications are a plus.