IT Security Auditor - Senior Consultant

IT Job Board - Tech Jobs Portal in USA

Chantilly (VA)

On-site

USD 120,000 - 180,000

Full time

3 hours ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Medical insurance
Dental & Vision
Parental Leave
401(k) Plan
Life Insurance
Student Loan PayDown
Tuition Reimbursement
Mobility Stipend

Job summary

Guidehouse is seeking a Senior IT Security Auditor to lead stakeholder engagement and technical delivery for IT controls assessments and program evaluations for federal agencies. The role suits someone with information security and assurance or IT audit background to analyze IT control weaknesses, identify root causes, and develop remediation plans.

You will mentor junior staff, plan and execute IT assessments, and communicate results to senior leadership while working up to 10% travel and

Qualifications

  • Active and maintained TS/SCI federal or DoD clearance with CI polygraph.
  • Bachelor's Degree in a Technical or Business field.
  • 3+ years' experience providing IT consulting, including federal government clients and knowledge of FISMA, NIST SP 800, FISCAM.

Responsibilities

  • Perform IT controls assessments using industry-standard guidance and best practices.
  • Conduct interviews with client stakeholders including ISSOs and system administrators.
  • Review and analyze documents for IT controls testing (SSPs, SOPs, audit logs, scans).
  • Evaluate control implementation against federal requirements and guidance.
  • Document IT controls testing results clearly for review.
  • Summarize assessment results to client leadership and stakeholders.
  • Identify root causes of IT control weaknesses and develop remediation plans.
  • Provide SME guidance on IT security and assurance to client personnel.
  • Respond to ad-hoc IT security requests from clients.
  • Plan and execute day-to-day IT assessment activities for the team.
  • Mentor junior team members in IT controls testing duties.

Skills

IT controls testing
Stakeholder engagement
IT audit
Remediation planning
Vulnerability assessment

Education

Bachelor's degree in a technical or business field

Job description

What You Will Do

The Senior IT Security Auditor will lead stakeholder engagement and technical delivery for efforts supporting federal agencies with IT controls assessments and program evaluations. This is an ideal role for someone with an information security and assurance or IT audit background who is looking to utilize their skills to work with the federal government to analyze IT control weaknesses, identify root causes, and develop remediation plans.

Job Family

Technology Consulting

Travel Required

Up to 10%

Clearance Required

Active Top Secret SCI with Polygraph

What You Will Do

The Senior IT Security Auditor will lead stakeholder engagement and technical delivery for efforts supporting federal agencies with IT controls assessments and program evaluations. This is an ideal role for someone with an information security and assurance or IT audit background who is looking to utilize their skills to work with the federal government to analyze IT control weaknesses, identify root causes, and develop remediation plans.

Responsibilities Include Some Or All Of The Following

Performing assessments of IT controls using industry-standard guidance and leading best practices

Conducting interviews and discussions with a variety of client stakeholders, including IT system personnel such as Information System Security Officers (ISSOs) and system administrators

  • Reviewing and analyzing documents and artifacts to assist in IT controls testing such as system security plans, SOPs, audit logs, configuration scans, and vulnerability scans
  • Evaluating the implementation and effectiveness of IT controls using provided artifacts against federal requirements, industry guidance, and leading best practices
  • Documenting the results of IT controls testing in a consistent and high-quality manner that would allow others to review and understand the results
  • Summarizing and communicating IT controls assessment results to a variety of client stakeholders, including senior leadership
  • Understanding and analyzing known IT control weaknesses, identifying root causes, and developing detailed remediation plans
  • Providing subject matter expertise to client personnel on a wide range of matters relating to IT security and assurance
  • Responding to ad-hoc IT security-related requests from client personnel
  • Planning and executing day-to-day activities of IT assessments and evaluations individually and for the team
  • Mentoring junior team members in day-to-day IT controls testing responsibilities
What You Will Need
  • An ACTIVE and MAINTAINED TS/SCI Federal or DoD security clearance with a COUNTERINTELLIGENCE (CI) polygraph
  • Bachelor's Degree in a Technical or Business field
  • THREE (3) + years' experience providing IT consulting. Experience should include but not be limited to:
    • Experience in consulting with the federal government to include senior government clients
    • Understanding and knowledge of federal information security and assurance laws, requirements, and guidance (i.e. FISMA, NIST SP 800, FISCAM)
What Would Be Nice To Have
  • Relevant certification such as the Certified Information Systems Auditor (CISA) or Certified Information Security Manager (CISM)
  • Demonstrated knowledge and experience in IT risk and controls through IT audits, IT controls assessments, or IT security reviews
  • Demonstrated ability and working knowledge of: FISMA, NIST SP 800 series, FISCAM, other relevant federal information assurance laws, regulations, and guidance
  • Experience performing: FISMA, OMB Circular A-123, or similar internal control assessments
  • Experience implementing or auditing access and account management principles, including authorization, provisioning, recertification, and separation of duties
  • Experience implementing or auditing contingency planning principles, including backups, testing of backups, and alternate processing sites
  • Experience implementing or auditing configuration management principles, including configuration baseline concepts, baseline deviations, baseline maintenance, change control, and monitoring, and industry-accepted configuration settings such as DISA STIGs
  • Experience performing audit logging and monitoring, including generation of audit logs, use of audit log aggregation and analysis tools, and audit log monitoring and review
What We Offer

Guidehouse offers a comprehensive, total rewards package that includes competitive compensation and a flexible benefits package that reflects our commitment to creating a diverse and supportive workplace.

Benefits Include
  • Medical, Rx, Dental & Vision Insurance
  • Personal and Family Sick Time & Company Paid Holidays
  • Position may be eligible for a discretionary variable incentive bonus
  • Parental Leave and Adoption Assistance
  • 401(k) Retirement Plan
  • Basic Life & Supplemental Life
  • Health Savings Account, Dental/Vision & Dependent Care Flexible Spending Accounts
  • Short-Term & Long-Term Disability
  • Student Loan PayDown
  • Tuition Reimbursement, Personal Development & Learning Opportunities
  • Skills Development & Certifications
  • Employee Referral Program
  • Corporate Sponsored Events & Community Outreach
  • Emergency Back-Up Childcare Program
  • Mobility Stipend
About Guidehouse

Guidehouse is an Equal Opportunity Employer-Protected Veterans, Individuals with Disabilities or any other basis protected by law, ordinance, or regulation.

Guidehouse will consider for employment qualified applicants with criminal histories in a manner consistent with the requirements of applicable law or ordinance including the Fair Chance Ordinance of Los Angeles and San Francisco.

If you have visited our website for information about employment opportunities, or to apply for a position, and you require an accommodation, please contact Guidehouse Recruiting at 1- or via email at . All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodation.

All communication regarding recruitment for a Guidehouse position will be sent from Guidehouse email domains or . Correspondence received by an applicant from any other domain should be considered unauthorized and will not be honored by Guidehouse. Note that Guidehouse will never charge a fee or require a money transfer at any stage of the recruitment process and does not collect fees from educational institutions for participation in a recruitment event. Never provide your banking information to a third party purporting to need that information to proceed in the hiring process.

If any person or organization demands money related to a job opportunity with Guidehouse, please report the matter to Guidehouse's Ethics Hotline. If you want to check the validity of correspondence you have received, please contact . Guidehouse is not responsible for losses incurred (monetary or otherwise) from an applicant's dealings with unauthorized third parties.

Guidehouse does not accept unsolicited resumes through or from search firms or staffing agencies. All unsolicited resumes will be considered the property of Guidehouse and Guidehouse will not be obligated to pay a placement fee.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IT Security Auditor - Consultant
IT Security Auditor - Consultant

Dovel Technologies, Inc • McLean (VA)

Hybrid
USD 100,000 - 150,000
Medical Insurance
Dental & Vision Insurance
401(k) Retirement Plan
+6
IT Advisory Manager
IT Advisory Manager

Guidehouse • McLean (VA)

Hybrid
USD 150,000 - 210,000
Medical & dental insurance
Retirement plan
Mobility stipend
+1
IT Security Auditor – Senior Consultant
IT Security Auditor – Senior Consultant

Dovel Technologies, Inc • Chantilly (VA)

Hybrid
USD 120,000 - 180,000
Medical Insurance
401(k) Retirement Plan
Paid Holidays
+1
IT Advisory Manager
IT Advisory Manager

Dovel Technologies, Inc • McLean (VA)

On-site
USD 110,000 - 150,000
Medical, Rx, Dental & Vision Insurance
401(k) Retirement Plan
Short-Term & Long-Term Disability
Senior Internal Controls, Audit Remediation, Readiness, and Risk Management Consultant
Senior Internal Controls, Audit Remediation, Readiness, and Risk Management Consultant

Guidehouse • Springfield (VA)

On-site
USD 90,000 - 130,000
Medical, Rx, Dental & Vision Insurance
401(k) Retirement Plan
Tuition Reimbursement
Cybersecurity Consultant
Cybersecurity Consultant

Guidehouse • Bethesda (MD)

On-site
USD 85,000 - 141,000
Medical, Dental, Vision Insurance
401(k) Retirement Plan
Paid Holidays
Senior Internal Controls, Audit Remediation, Readiness, and Risk Management Consultant
Senior Internal Controls, Audit Remediation, Readiness, and Risk Management Consultant

Guidehouse • McLean (VA)

On-site
USD 120,000 - 160,000
Medical, Rx, Dental & Vision Insurance
401(k) Retirement Plan
Tuition Reimbursement
+2
Operations Facilitation Specialist
Operations Facilitation Specialist

Guidehouse • Arlington (VA)

On-site
USD 95,000 - 140,000
Senior Cyber Consultant - ISSO/ISSM
Senior Cyber Consultant - ISSO/ISSM

Dovel Technologies, Inc • Washington

On-site
USD 113,000 - 188,000
Medical Insurance
Dental & Vision
401(k) Plan
+3
Consultant II - Public Health - CMS A-123 Information Technology
Consultant II - Public Health - CMS A-123 Information Technology

3M HEALTHCARE • Bloomington (IL)

On-site
USD 74,000 - 124,000
Medical, Rx, Dental & Vision Insurance
Paid Holidays
Discretionary bonus
+5