Security Control Assessor

Guidehouse

McLean (VA)

On-site

USD 130,000 - 170,000

Full time

34 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical Insurance
401(k) Retirement Plan
Parental Leave and Adoption Assistance
Tuition Reimbursement
Mobility Stipend

Job summary

Guidehouse is seeking a cybersecurity professional to lead RMF and A&A documentation for on-premise and cloud services, including SSPs, SARs, POA&Ms, and risk acceptance materials.

You will collaborate with System Owners, ISSOs, IAMs, and 3PAOs to ensure RMF compliance, automate evidence workflows, and support continuous authorization across multi-tenant environments.

Qualifications

  • Active federal or DoD Public Trust clearance.
  • Bachelor’s degree with seven years of cybersecurity experience, or Master’s with five years.
  • Experience as an SCA (current or past).
  • Security+, CAP, or equivalent cert; knowledge of NIST SP 800-37/53, FISMA, FedRAMP.
  • Strong verbal and written communication, report writing.
  • Ability to commute to client office as needed.

Responsibilities

  • Lead or support RMF and A&A documentation (SSPs, SARs, POA&Ms, risk acceptance).
  • Support authorization of on-premise and cloud services using FedRAMP packages and 3PAO readiness.
  • Interpret and operationalize FISMA, NIST RMF, FedRAMP, OSCAL standards to guide enhancements.
  • Ensure consistency across multi-tenant GRC environments and maintain documentation.
  • Embed RMF discipline across Agile teams and support backlog refinement.
  • Coordinate A&A activities with System Owners, ISSOs, IAMs, and third-party assessors; automate evidence workflows.
  • Provide RMF guidance through sprints, planning, testing, and release readiness.
  • Support continuous authorization (cATO) with automated control validation and OSCAL artifacts.

Skills

RMF
FedRAMP
NIST RMF
GRC Tools
OSCAL

Education

Bachelor’s Degree in Cybersecurity/IS
7+ years experience OR Master’s +5

Tools

ServiceNow
GRC platforms
Audit tools

Job description

  • Lead and/or support the development of RMF and A&A documentation including SSPs, control implementation matrices, SARs, POA&Ms, and risk acceptance materials.
  • Support authorization of on premise and cloud services leveraging FedRAMP packages, considering agency specific control requirements, and support 3PAO readiness assessments and SAR development for cloud platforms.
  • Interpret and operationalize FISMA, NIST RMF, FedRAMP, and OSCAL standards to guide application enhancements, evidence automation, and RMF workflow modernization across a GRC platform.
  • Ensuring consistency and compliance across multi-tenant GRC environments, helping Components and customer agencies implement security controls, maintain accurate documentation, and sustain reliable continuous monitoring.
  • Collaborating across Agile teams to embed RMF discipline, support backlog refinement, and validate that modernization activities remain compliant with Federal requirements.
  • Coordinate A&A activities and requirements with System Owners, ISSOs, IAMs, and third-party assessors, reducing manual burden for ISSOs and system owners by shaping automated workflows, improving evidence pathways, and strengthening data integrity used for scoring, dashboards, and compliance reporting.
  • Providing compliance and RMF subject matter guidance throughout sprint cycles, planning, testing activities, and release readiness processes, ensuring enhancements align with RMF control requirements and governance expectations.
  • Supporting continuous authorization (cATO) goals through integration of automated control validation, vulnerability data ingestion, security tooling alignment, and machine-readable artifacts (OSCAL).
Job Family

Cyber Consulting

Travel Required

Up to 10%

Clearance Required

Active Public Trust

What You Will Do
  • Lead and/or support the development of RMF and A&A documentation including SSPs, control implementation matrices, SARs, POA&Ms, and risk acceptance materials.
  • Support authorization of on premise and cloud services leveraging FedRAMP packages, considering agency specific control requirements, and support 3PAO readiness assessments and SAR development for cloud platforms.
  • Interpret and operationalize FISMA, NIST RMF, FedRAMP, and OSCAL standards to guide application enhancements, evidence automation, and RMF workflow modernization across a GRC platform.
  • Ensuring consistency and compliance across multi-tenant GRC environments, helping Components and customer agencies implement security controls, maintain accurate documentation, and sustain reliable continuous monitoring.
  • Collaborating across Agile teams to embed RMF discipline, support backlog refinement, and validate that modernization activities remain compliant with Federal requirements.
  • Coordinate A&A activities and requirements with System Owners, ISSOs, IAMs, and third-party assessors, reducing manual burden for ISSOs and system owners by shaping automated workflows, improving evidence pathways, and strengthening data integrity used for scoring, dashboards, and compliance reporting.
  • Providing compliance and RMF subject matter guidance throughout sprint cycles, planning, testing activities, and release readiness processes, ensuring enhancements align with RMF control requirements and governance expectations.
  • Supporting continuous authorization (cATO) goals through integration of automated control validation, vulnerability data ingestion, security tooling alignment, and machine-readable artifacts (OSCAL).
What You Will Need
  • An ACTIVE and CURRENT Federal or DoD Public Trust
  • Bachelor’s Degree AND Seven (7) years of relevant cybersecurity experience, OR a Master’s Degree AND Five (5) years of relevant experience.
  • Experience as an SCA (current or past)
  • Security+, CAP, or equivalent certification, and strong working knowledge of NIST SP 800 37, 800 53, FISMA, and FedRAMP.
  • Excellent verbal and written communication skills, specifically in report writing.
  • Ability to commute to client office as need per week
What Would Be Nice To Have
  • Experience supporting third party assessments or SAR development.
  • Familiarity with ServiceNow, GRC platforms, or audit tracking tools.
  • Experience consulting at large federal agencies such as the Department of State, Department of Justice or Department of Homeland Security related to GRC implementations
  • Demonstrated experience in the areas of external client-facing management and/or consulting for large firms
What We Offer

Guidehouse offers a comprehensive, total rewards package that includes competitive compensation and a flexible benefits package that reflects our commitment to creating a diverse and supportive workplace.

Benefits Include
  • Medical, Rx, Dental & Vision Insurance
  • Personal and Family Sick Time & Company Paid Holidays
  • Position may be eligible for a discretionary variable incentive bonus
  • Parental Leave and Adoption Assistance
  • 401(k) Retirement Plan
  • Basic Life & Supplemental Life
  • Health Savings Account, Dental/Vision & Dependent Care Flexible Spending Accounts
  • Short-Term & Long-Term Disability
  • Student Loan PayDown
  • Tuition Reimbursement, Personal Development & Learning Opportunities
  • Skills Development & Certifications
  • Employee Referral Program
  • Corporate Sponsored Events & Community Outreach
  • Emergency Back-Up Childcare Program
  • Mobility Stipend
About Guidehouse

Guidehouse is an Equal Opportunity Employer-Protected Veterans, Individuals with Disabilities or any other basis protected by law, ordinance, or regulation.

Guidehouse will consider for employment qualified applicants with criminal histories in a manner consistent with the requirements of applicable law or ordinance including the Fair Chance Ordinance of Los Angeles and San Francisco.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Control Assessor
Security Control Assessor

Dovel Technologies, Inc • McLean (VA)

Hybrid
USD 120,000 - 180,000
Medical, Rx, Dental & Vision Insurance
401(k) Retirement Plan
Paid Holidays
RMF and POAM Analyst
RMF and POAM Analyst

Dovel Technologies, Inc • McLean (VA)

Hybrid
USD 110,000 - 150,000
Medical Insurance
401(k) Plan
Paid Holidays
+2
RMF and POAM Analyst
RMF and POAM Analyst

Guidehouse • McLean (VA)

Hybrid
USD 110,000 - 140,000
Medical, Rx, Dental & Vision Insurance
401(k) Retirement Plan
Tuition Reimbursement
Consultant II - Public Health - CMS A-123 Information Technology
Consultant II - Public Health - CMS A-123 Information Technology

3M HEALTHCARE • Bloomington (IL)

On-site
USD 74,000 - 124,000
Medical, Rx, Dental & Vision Insurance
Paid Holidays
Discretionary bonus
+5
Cybersecurity GRC Program Manager
Cybersecurity GRC Program Manager

Dovel Technologies, Inc • Arlington (VA), Northern (KY)

Hybrid
USD 130,000 - 216,000
Medical, Rx, Dental & Vision
401(k) Retirement Plan
Parental Leave and Adoption Assistance
+1
Cybersecurity Consultant
Cybersecurity Consultant

3M HEALTHCARE • Bloomington (IL)

On-site
USD 85,000 - 141,000
Medical, Rx, Dental & Vision Insurance
401(k) Retirement Plan
Tuition Reimbursement & Learning
+1
IT Security Auditor - Consultant
IT Security Auditor - Consultant

Dovel Technologies, Inc • McLean (VA)

Hybrid
USD 100,000 - 150,000
Medical Insurance
Dental & Vision Insurance
401(k) Retirement Plan
+6
Senior Internal Controls, Audit Remediation, Readiness, and Risk Management Consultant
Senior Internal Controls, Audit Remediation, Readiness, and Risk Management Consultant

Dovel Technologies, Inc • Springfield (VA), Northern (KY)

Hybrid
USD 90,000 - 130,000
Medical, Rx, Dental & Vision Insurance
Paid Holidays
Associate Director-Federal Civilian Agencies
Associate Director-Federal Civilian Agencies

Guidehouse • McLean (VA)

On-site
USD 150,000 - 210,000
Medical Insurance
401(k) Plan
Parental Leave
+3
Senior Internal Controls, Audit Remediation, Readiness, and Risk Management Consultant
Senior Internal Controls, Audit Remediation, Readiness, and Risk Management Consultant

Guidehouse • McLean (VA)

On-site
USD 90,000 - 140,000
Medical Insurance
401(k) Retirement Plan
Paid Holidays
+1