Stand out for this role — generate a tailored resume and cover letter in about a minute.
Guidehouse seeks a cybersecurity professional to lead vulnerability management for a portfolio of client applications, coordinating remediation efforts with business, engineering, and security teams. You will support POA&M activities and ensure timely remediation in line with federal requirements.
You will develop automated vulnerability reports, dashboards, KPIs, and metrics to monitor progress and asset risk, while preparing briefings for leadership and oversight authorities.
Cyber Consulting Travel Required : Up to 25% Clearance Required : Ability to Obtain Public Trust
Lead vulnerability management efforts across a portfolio of client applications, including analyzing findings, identifying affected versions, providing remediation guidance, assigning issues to teams, and tracking vulnerabilities through closure. Build and maintain strong working relationships with business, engineering, and security teams to validate fixes, resolve blockers, and support timely remediation. Support POA&M activities, patching timelines, remediation deadlines, and related federal cybersecurity and compliance requirements. Develop and maintain automated vulnerability reports, dashboards, KPIs, and metrics to track remediation progress, compliance gaps, and asset risk. Prepare reports and briefings for leadership and federal oversight stakeholders. Monitor suspicious activity and security alerts in Splunk and coordinate follow-up actions with relevant teams. Support secure development efforts through security documentation, secure coding guidance, annual training support, and evaluation of security tools and processes. Provide cyber subject matter expertise during information security audits and assessments.
Must be able to OBTAIN and MAINTAIN a Federal or DoD "PUBLIC TRUST"; candidates must obtain approved adjudication of their PUBLIC TRUST prior to onboarding with Guidehouse. Candidates with an ACTIVE PUBLIC TRUST or SUITABILITY and maintain an active HHS/NIH clearance are preferred. Minimum of THREE (3) years of cybersecurity or IT risk management experience, candidates with experience focused on vulnerability management and/or secure configuration are preferred. Minimum of a Bachelors Degree is required. Tools: Hands-on experience with Invicti, Splunk, and Atlassian tools (Jira & Confluence) Knowledge: Deep understanding of NIST SP 800-53, FISMA requirements, and OWASP Top 10. Certifications: Active CompTIA Security+ CE preferred; CISSP, CEH, or cloud-related certifications are a plus. Soft Skills: Strong communication and analytical thinking; ability to manage multiple concurrent priorities and deadlines.
Experience developing automated data pipelines or integrating APIs into Power BI dashboards. Knowledge of MITRE ATT&CK framework and vulnerability prioritization methodologies (e.g., EPSS, CVSS v3). Prior experience supporting a federal agency or working in a