Senior Cyber Risk and Vulnerability Assessor

Posted 18 Days Ago
Be an Early Applicant
McLean, VA, USA
In-Office
Senior level
Consulting
The Role
The Senior Cyber Risk and Vulnerability Assessor leads security control assessments for high-impact systems, ensuring compliance with federal cybersecurity standards and providing authoritative risk determinations.
Summary Generated by Built In

Job Family:

Cyber Consulting


Travel Required:

Up to 10%


Clearance Required:

Active Public Trust

What You Will Do:

Guidehouse’s Cybersecurity practice helps federal and regulated clients assess, manage, and reduce cybersecurity risk across high‑impact systems and mission‑critical environments. Our teams combine deep technical assessment expertise with strong knowledge of federal risk management and authorization processes to support informed risk decisions and system authorization outcomes.

As a Senior Cyber Risk and Vulnerability Assessor , you will lead comprehensive security control assessments for complex, high‑impact, and enterprise systems across on‑premises, cloud, and hybrid environments. You will oversee assessment strategy and execution, validate remediation effectiveness, and provide authoritative risk determinations in support of Authorizing Officials (AOs) and senior agency leadership.

This role is ideal for a senior assessment professional with strong technical depth, proven leadership experience, and the ability to translate assessment results into clear, defensible risk recommendations aligned to federal cybersecurity requirements.

This role positions you as a senior assessment authority within Guidehouse’s Cybersecurity practice, accountable for delivering high‑quality security assessments that enable informed authorization decisions and strengthen enterprise risk posture.

Key Responsibilities

  • Lead and oversee security control assessments for moderate‑ and high‑impact information systems, including complex enterprise and mission‑critical environments.
  • Direct assessment planning and control testing strategies, ensuring appropriate coverage, rigor, and consistency with system architectures and risk profiles.
  • Conduct and supervise cloud, on‑premises, and hybrid system assessments, including IaaS, PaaS, and SaaS environments.
  • Validate the effectiveness of remediation actions, including retesting controls and verifying closure of findings.
  • Analyze assessment results and develop risk determinations, observations, and recommendations suitable for senior decision‑makers and AOs.
  • Ensure assessments are executed in alignment with applicable federal frameworks and mandates, including: FISMA, NIST SP 800‑37, NIST SP 800‑53, OMB guidance and memoranda, Agency‑specific cybersecurity policies and procedures.
  • Oversee development and quality of assessment deliverables, including security assessment plans (SAPs), security assessment reports (SARs), POA&Ms, and authorization support documentation.
  • Provide guidance on risk acceptance, remediation prioritization, and continuous monitoring strategies.
  • Serve as a trusted advisor to system owners, ISSOs, and security engineers on assessment findings and control implementation improvements.
  • Coordinate assessment activities across multiple systems or programs, ensuring schedule adherence and stakeholder alignment.
  • Mentor and develop assessors and consultants; provide technical review and quality assurance for assessment work products.
  • Support practice growth through proposal development, technical contributions, and assessment methodology development.

What You Will Need:

  • Must be able to OBTAIN and MAINTAIN a Federal or DoD "PUBLIC TRUST"; candidates must obtain approved adjudication of their PUBLIC TRUST prior to onboarding with Guidehouse. Candidates with an ACTIVE PUBLIC TRUST or SUITABILITY and maintain an active HHS/NIH clearance are preferred.
  • Bachelor’s degree in Cybersecurity, Information Systems, Computer Science, or a related field (additional relevant experience may substitute for formal education).
  • Minimum of NINE (9) or more years of progressively responsible experience performing or leading security control assessments, audits, or cybersecurity risk assessments.
  • Required certifications:
    • Certified in Governance, Risk and Compliance (CGRC) (active)
    • Certified Information Systems Security Professional (CISSP) (active)
  • Demonstrated experience conducting assessments under the NIST RMF.
  • Experience assessing high‑impact or high‑value asset (HVA) systems.
  • Strong understanding of security control implementation and assessment across enterprise, cloud, and hybrid architectures.
  • Proven ability to communicate risk clearly and effectively to technical and executive stakeholders, including Authorizing Officials.
  • Excellent written and verbal communication skills, including formal assessment reporting and executive briefings.

What Would Be Nice to Have:

  • Experience with continuous monitoring programs and control inheritance models.
  • Familiarity with major cloud service providers and their shared responsibility models.
  • Additional certifications such as CISM, CISA, CCSP, HVA Assessment Lead/Technical Lead/Operator, or cloud security credentials.
  • Prior consulting experience with responsibility for delivery quality, stakeholder management, and team leadership.

What We Offer:

Guidehouse offers a comprehensive, total rewards package that includes competitive compensation and a flexible benefits package that reflects our commitment to creating a diverse and supportive workplace.

Benefits include:

  • Medical, Rx, Dental & Vision Insurance

  • Personal and Family Sick Time & Company Paid Holidays

  • Position may be eligible for a discretionary variable incentive bonus

  • Parental Leave and Adoption Assistance

  • 401(k) Retirement Plan

  • Basic Life & Supplemental Life

  • Health Savings Account, Dental/Vision & Dependent Care Flexible Spending Accounts

  • Short-Term & Long-Term Disability

  • Student Loan PayDown

  • Tuition Reimbursement, Personal Development & Learning Opportunities

  • Skills Development & Certifications

  • Employee Referral Program

  • Corporate Sponsored Events & Community Outreach

  • Emergency Back-Up Childcare Program

  • Mobility Stipend

About Guidehouse

Guidehouse is an Equal Opportunity Employer–Protected Veterans, Individuals with Disabilities or any other basis protected by law, ordinance, or regulation.

Guidehouse will consider for employment qualified applicants with criminal histories in a manner consistent with the requirements of applicable law or ordinance including the Fair Chance Ordinance of Los Angeles and San Francisco.

If you have visited our website for information about employment opportunities, or to apply for a position, and you require an accommodation, please contact Guidehouse Recruiting at 1-571-633-1711 or via email at [email protected]. All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodation.

All communication regarding recruitment for a Guidehouse position will be sent from Guidehouse email domains including @guidehouse.com or [email protected].  Correspondence received by an applicant from any other domain should be considered unauthorized and will not be honored by Guidehouse.  Note that Guidehouse will never charge a fee or require a money transfer at any stage of the recruitment process and does not collect fees from educational institutions for participation in a recruitment event. Never provide your banking information to a third party purporting to need that information to proceed in the hiring process.

If any person or organization demands money related to a job opportunity with Guidehouse, please report the matter to Guidehouse’s Ethics Hotline. If you want to check the validity of correspondence you have received, please contact [email protected]. Guidehouse is not responsible for losses incurred (monetary or otherwise) from an applicant’s dealings with unauthorized third parties.

Guidehouse does not accept unsolicited resumes through or from search firms or staffing agencies. All unsolicited resumes will be considered the property of Guidehouse and Guidehouse will not be obligated to pay a placement fee.

Skills Required

  • Bachelor's degree in Cybersecurity, Information Systems, Computer Science, or a related field
  • Minimum of nine years of experience in security control assessments, audits, or cybersecurity risk assessments
  • Certified in Governance, Risk and Compliance (CGRC)
  • Certified Information Systems Security Professional (CISSP)
  • Demonstrated experience conducting assessments under the NIST RMF
  • Experience assessing high-impact or high-value asset systems

Guidehouse Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Guidehouse and has not been reviewed or approved by Guidehouse.

  • Healthcare Strength Feedback suggests the benefits package includes broad medical, dental, vision, prescription, life, and disability coverage, which is often seen as a strong foundational offering. Access to HSA/FSA options further supports day-to-day healthcare and dependent-care needs.
  • Parental & Family Support Feedback suggests parental leave and adoption assistance are available, alongside an emergency back-up childcare program. These offerings indicate meaningful support for employees managing family responsibilities.
  • Wellbeing & Lifestyle Benefits Feedback suggests flexible work options and counseling/EAP-style support are part of the broader rewards mix. Additional lifestyle-oriented perks like community events and referral programs are also described as available in some contexts.

Guidehouse Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Washington, DC
12,000 Employees
Year Founded: 2018

What We Do

Guidehouse is a leading global provider of consulting services to the public sector and commercial markets, with broad capabilities in management, technology, and risk consulting. By combining our public and private sector expertise, we help clients address their most complex challenges and navigate significant regulatory pressures focusing on transformational change, business resiliency, and technology-driven innovation. Across a range of advisory, consulting, outsourcing, and digital services, we create scalable, innovative solutions that help our clients outwit complexity and position them for future growth and success. The company has more than 12,000 professionals in over 50 locations globally. Guidehouse is a Veritas Capital portfolio company, led by seasoned professionals with proven and diverse expertise in traditional and emerging technologies, markets, and agenda-setting issues driving national and global economies.

Similar Jobs

TransUnion Logo TransUnion

Lead Software Engineer

Big Data • Fintech • Information Technology • Business Intelligence • Financial Services • Cybersecurity • Big Data Analytics
Hybrid
Reston, VA, USA
13000 Employees
90K-150K Annually

Vantor Logo Vantor

Senior Technical Engagements & Knowledge Management Lead

Aerospace • Artificial Intelligence • Computer Vision • Software • Analytics • Defense • Big Data Analytics
In-Office
Reston, VA, USA
2500 Employees
118K-173K Annually

Pfizer Logo Pfizer

Vaccines Specialist, Health and Science Professional - Arlington, VA

Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Biotech • Pharmaceutical
Remote or Hybrid
Virginia, USA
121990 Employees
76K-200K Annually

Pfizer Logo Pfizer

Neuroscience Specialist, Health and Science Professional - Virginia Beach, VA

Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Biotech • Pharmaceutical
Remote or Hybrid
Virginia, USA
121990 Employees
76K-200K Annually

Similar Companies Hiring

Quantum Rise Thumbnail
Software • Professional Services • Natural Language Processing • Machine Learning • Consulting • Automation • Artificial Intelligence
Chicago, Illinois
20 Employees
Northslope Thumbnail
Artificial Intelligence • Information Technology • Software • Analytics • Consulting • Generative AI
London, GB
100 Employees
Amplify Platform Thumbnail
Fintech • Financial Services • Consulting • Cloud • Business Intelligence • Big Data Analytics
Scottsdale, AZ
62 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account