Cybersecurity Consultant

Guidehouse

McLean (VA)

On-site

USD 85,000 - 141,000

Full time

2 hours ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Guidehouse in McLean, VA is seeking a cyber risk lead to manage a portfolio of client applications, guiding end-to-end POA&M lifecycle and prioritizing remediation based on risk and compliance.

You will conduct BIAs, coordinate with system owners and O&M teams, produce leadership briefs, and provide SME support during audits, while maintaining up-to-date BIA documentation.

Qualifications

  • Minimum of two years of overall work experience in cybersecurity or IT risk management.
  • Hands-on experience with GRC platforms and knowledge of NIST SP 800-53, FISMA, and 800-37.
  • Ability to obtain and maintain a Federal or DoD Public Trust clearance.

Responsibilities

  • Lead cyber risk management efforts across a portfolio of client applications.
  • Manage end-to-end POA&M lifecycle, including creation, tracking, validation, and closure of identified security weaknesses.
  • Prioritize remediation activities based on risk severity, compliance requirements, and operational impact.
  • Conduct BIAs to identify critical systems, functions, dependencies, and recovery time/objectives.
  • Collaborate with stakeholders to validate system criticality and align with continuity and contingency planning requirements.
  • Prepare reports and briefings for leadership and federal oversight stakeholders.

Skills

Cyber risk management
Communication
Analytical thinking
Prioritization

Tools

GRC platforms

Job description

  • Lead cyber risk management efforts across a portfolio of client applications.
  • Manage end-to-end POA&M lifecycle, including creation, tracking, validation, and closure of identified security weaknesses
  • Prioritize remediation activities based on risk severity, compliance requirements, and operational impact
Job Family

Cyber Consulting

Travel Required

Up to 25%

Clearance Required

Ability to Obtain Public Trust

What You Will Do
  • Lead cyber risk management efforts across a portfolio of client applications.
  • Manage end-to-end POA&M lifecycle, including creation, tracking, validation, and closure of identified security weaknesses
  • Prioritize remediation activities based on risk severity, compliance requirements, and operational impact

Conduct regular POA&M status reviews and coordinate with system owners and O&M teams to track milestone progress

Perform BIAs to identify critical systems, functions, dependencies, and recovery time/objectives

Collaborate with stakeholders to validate system criticality and align with continuity and contingency planning requirements

  • Build and maintain strong working relationships with business, engineering, and security teams to validate fixes, resolve blockers, and support timely remediation.
  • Prepare reports and briefings for leadership and federal oversight stakeholders.
  • Provide cyber subject matter expertise during information security audits and assessments.
  • Maintain and update BIA documentation in alignment with evolving system architecture and mission priorities
What You Will Need
  • Minimum of Two (2) years of overall work experience.
  • Experience in cybersecurity or IT risk management experience, candidates with experience focused on cybersecurity risk management are preferred.
  • Tools: Hands-on experience with GRC platforms.
  • Knowledge: Deep understanding of NIST SP 800-53, FISMA requirements, and 800-37.
  • Soft Skills: Strong communication and analytical thinking; ability to manage multiple concurrent priorities and deadlines.
  • Must be able to OBTAIN and MAINTAIN a Federal or DoD "PUBLIC TRUST"; candidates must obtain approved adjudication of their PUBLIC TRUST prior to onboarding with Guidehouse. Candidates with an ACTIVE PUBLIC TRUST or SUITABILITY and maintain an active HHS/NIH clearance are preferred.
What Would Be Nice To Have
  • Experience developing automated data pipelines or integrating APIs into Power BI dashboards.
  • Knowledge of MITRE ATT&CK framework and vulnerability prioritization methodologies (e.g., EPSS, CVSS v3).
  • Prior experience supporting a federal agency or working in a Public Health environment.
  • Certifications: Active CompTIA Security+ CE preferred; CISSP, CEH, or cloud-related certifications are a plus.

The annual salary range for this position is $85,000.00-$141,000.00. Compensation decisions depend on a wide range of factors, including but not limited to skill sets, experience and training, security clearances, licensure and certifications, and other business and organizational needs.

What We Offer

Guidehouse offers a comprehensive, total rewards package that includes competitive compensation and a flexible benefits package that reflects our commitment to creating a diverse and supportive workplace.

Benefits Include
  • Medical, Rx, Dental & Vision Insurance
  • Personal and Family Sick Time & Company Paid Holidays
  • Position may be eligible for a discretionary variable incentive bonus
  • Parental Leave and Adoption Assistance
  • 401(k) Retirement Plan
  • Basic Life & Supplemental Life
  • Health Savings Account, Dental/Vision & Dependent Care Flexible Spending Accounts
  • Short-Term & Long-Term Disability
  • Student Loan PayDown
  • Tuition Reimbursement, Personal Development & Learning Opportunities
  • Skills Development & Certifications
  • Employee Referral Program
  • Corporate Sponsored Events & Community Outreach
  • Emergency Back-Up Childcare Program
  • Mobility Stipend
About Guidehouse

Guidehouse is an Equal Opportunity Employer–Protected Veterans, Individuals with Disabilities or any other basis protected by law, ordinance, or regulation.

Guidehouse will consider for employment qualified applicants with criminal histories in a manner consistent with the requirements of applicable law or ordinance including the Fair Chance Ordinance of Los Angeles and San Francisco.

If you have visited our website for information about employment opportunities, or to apply for a position, and you require an accommodation, please contact Guidehouse Recruiting at 1-571-633-1711 or via email at RecruitingAccommodation@guidehouse.com. All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodation.

All communication regarding recruitment for a Guidehouse position will be sent from Guidehouse email domains including @guidehouse.com or guidehouse@myworkday.com. Correspondence received by an applicant from any other domain should be considered unauthorized and will not be honored by Guidehouse. Note that Guidehouse will never charge a fee or require a money transfer at any stage of the recruitment process and does not collect fees from educational institutions for participation in a recruitment event. Never provide your banking information to a third party purporting to need that information to proceed in the hiring process.

If any person or organization demands money related to a job opportunity with Guidehouse, please report the matter to Guidehouse's Ethics Hotline. If you want to check the validity of correspondence you have received, please contact recruiting@guidehouse.com. Guidehouse is not responsible for losses incurred (monetary or otherwise) from an applicant’s dealing with unauthorized third parties.

Guidehouse does not accept unsolicited resumes through or from search firms or staffing agencies. All unsolicited resumes will be considered the property of Guidehouse and Guidehouse will not be obligated to pay a placement fee.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity GRC Program Manager
Cybersecurity GRC Program Manager

Guidehouse • Washington

On-site
USD 130,000 - 216,000
Medical, Rx, Dental & Vision Insurance
401(k) Retirement Plan
Paid Holidays & Sick Time
+1
Cybersecurity GRC Program Manager
Cybersecurity GRC Program Manager

Guidehouse • Arlington (VA)

On-site
USD 130,000 - 216,000
Medical Insurance
401(k) Retirement Plan
Parental Leave
+1
Cybersecurity Consultant
Cybersecurity Consultant

3M HEALTHCARE • Bloomington (IL)

On-site
USD 85,000 - 141,000
Medical, Rx, Dental & Vision Insurance
401(k) Retirement Plan
Tuition Reimbursement & Learning
+1
Senior Internal Control & Business Transformation Consultant
Senior Internal Control & Business Transformation Consultant

Guidehouse • McLean (VA)

On-site
USD 110,000 - 150,000
Medical, Rx, Dental & Vision Insurance
401(k) Retirement Plan
Tuition Reimbursement
+1
Senior Cyber Consultant - ISSO/ISSM
Senior Cyber Consultant - ISSO/ISSM

Dovel Technologies, Inc • Washington

On-site
USD 113,000 - 188,000
Medical Insurance
Dental & Vision
401(k) Plan
+3
Cybersecurity GRC Program Manager
Cybersecurity GRC Program Manager

Dovel Technologies, Inc • Arlington (VA), Northern (KY)

Hybrid
USD 130,000 - 216,000
Medical, Rx, Dental & Vision
401(k) Retirement Plan
Parental Leave and Adoption Assistance
+1
Senior Data Engineer
Senior Data Engineer

Guidehouse • Washington

Hybrid
USD 113,000 - 188,000
Health insurance
401(k) Retirement Plan
Tuition Reimbursement
Senior Data Engineer
Senior Data Engineer

Guidehouse • Arlington (VA)

Hybrid
USD 113,000 - 188,000
Operations Facilitation Specialist
Operations Facilitation Specialist

Guidehouse • McLean (VA)

On-site
USD 110,000 - 160,000
Medical, Rx, Dental & Vision Insurance
Parental Leave and Adoption Assistance
401(k) Retirement Plan
+2
IT Advisory Manager
IT Advisory Manager

Guidehouse • Chantilly (VA)

On-site
USD 140,000 - 200,000
Medical, Rx, Dental & Vision Insurance
Paid holidays and parental leave
401(k) Retirement Plan
+3