Senior Cyber Risk and Vulnerability Assessor
Job
US101 Guidehouse Inc.
Tysons, VA (In Person)
Full-Time
Review key factors to help you decide if the role fits your goals.
Pay Growth
?
out of 5
Not enough data
Not enough info to score pay or growth
Job Security
?
out of 5
Not enough data
Calculating job security score...
Total Score
77
out of 100
Average of individual scores
Skill Insights
Compare your current skills to what this opportunity needs—we'll show you what you already have and what could strengthen your application.
Job Description
Job Family:
Cyber Consulting Travel Required:
Up to 10%Clearance Required:
Active Public Trust What You Will Do:
Guidehouse's Cybersecurity practice helps federal and regulated clients assess, manage, and reduce cybersecurity risk across high‑impact systems and mission‑critical environments. Our teams combine deep technical assessment expertise with strong knowledge of federal risk management and authorization processes to support informed risk decisions and system authorization outcomes. As a Senior Cyber Risk and Vulnerability Assessor , you will lead comprehensive security control assessments for complex, high‑impact, and enterprise systems across on‑premises, cloud, and hybrid environments. You will oversee assessment strategy and execution, validate remediation effectiveness, and provide authoritative risk determinations in support of Authorizing Officials (AOs) and senior agency leadership. This role is ideal for a senior assessment professional with strong technical depth, proven leadership experience, and the ability to translate assessment results into clear, defensible risk recommendations aligned to federal cybersecurity requirements. This role positions you as a senior assessment authority within Guidehouse's Cybersecurity practice, accountable for delivering high‑quality security assessments that enable informed authorization decisions and strengthen enterprise risk posture. Key Responsibilities Lead and oversee security control assessments for moderate‑ and high‑impact information systems, including complex enterprise and mission‑critical environments. Direct assessment planning and control testing strategies, ensuring appropriate coverage, rigor, and consistency with system architectures and risk profiles. Conduct and supervise cloud, on‑premises, and hybrid system assessments, including IaaS, PaaS, and SaaS environments. Validate the effectiveness of remediation actions, including retesting controls and verifying closure of findings. Analyze assessment results and develop risk determinations, observations, and recommendations suitable for senior decision‑makers and AOs. Ensure assessments are executed in alignment with applicable federal frameworks and mandates, including:FISMA, NIST SP 800
‑37, NIST SP 800‑53, OMB guidance and memoranda, Agency‑specific cybersecurity policies and procedures. Oversee development and quality of assessment deliverables, including security assessment plans (SAPs), security assessment reports (SARs), POA&Ms, and authorization support documentation. Provide guidance on risk acceptance, remediation prioritization, and continuous monitoring strategies. Serve as a trusted advisor to system owners, ISSOs, and security engineers on assessment findings and control implementation improvements. Coordinate assessment activities across multiple systems or programs, ensuring schedule adherence and stakeholder alignment. Mentor and develop assessors and consultants; provide technical review and quality assurance for assessment work products. Support practice growth through proposal development, technical contributions, and assessment methodology development.What You Will Need:
Must be able to OBTAIN andMAINTAIN
a Federal or DoD "PUBLIC TRUST
"; candidates must obtain approved adjudication of theirPUBLIC TRUST
prior to onboarding with Guidehouse. Candidates with anACTIVE PUBLIC
TRUST or SUITABILITY and maintain an active HHS/NIH clearance are preferred. Bachelor's degree in Cybersecurity, Information Systems, Computer Science, or a related field (additional relevant experience may substitute for formal education). Minimum of NINE (9) or more years of progressively responsible experience performing or leading security control assessments, audits, or cybersecurity risk assessments.Required certifications:
Certified in Governance, Risk and Compliance (CGRC) (active) Certified Information Systems Security Professional (CISSP) (active) Demonstrated experience conducting assessments under theNIST RMF.
Experience assessing high‑impact or high‑value asset (HVA) systems. Strong understanding of security control implementation and assessment across enterprise, cloud, and hybrid architectures. Proven ability to communicate risk clearly and effectively to technical and executive stakeholders, including Authorizing Officials. Excellent written and verbal communication skills, including formal assessment reporting and executive briefings. What Would Be Nice toHave:
Experience with continuous monitoring programs and control inheritance models. Familiarity with major cloud service providers and their shared responsibility models. Additional certifications such asCISM, CISA, CCSP, HVA
Assessment Lead/Technical Lead/Operator, or cloud security credentials. Prior consulting experience with responsibility for delivery quality, stakeholder management, and team leadership.What We Offer:
Guidehouse offers a comprehensive, total rewards package that includes competitive compensation and a flexible benefits package that reflects our commitment to creating a diverse and supportive workplace.Benefits include:
Medical, Rx, Dental & Vision Insurance Personal and Family Sick Time & Company Paid Holidays Position may be eligible for a discretionary variable incentive bonus Parental Leave and Adoption Assistance 401(k) Retirement Plan Basic Life & Supplemental Life Health Savings Account, Dental/Vision & Dependent Care Flexible Spending Accounts Short-Term & Long-Term Disability Student Loan PayDown Tuition Reimbursement, Personal Development & Learning Opportunities Skills Development & Certifications Employee Referral Program Corporate Sponsored Events & Community Outreach Emergency Back-Up Childcare Program Mobility Stipend About Guidehouse Guidehouse is an Equal Opportunity Employer-Protected Veterans, Individuals with Disabilities or any other basis protected by law, ordinance, or regulation. Guidehouse will consider for employment qualified applicants with criminal histories in a manner consistent with the requirements of applicable law or ordinance including the Fair Chance Ordinance of Los Angeles and San Francisco. If you have visited our website for information about employment opportunities, or to apply for a position, and you require an accommodation, please contact Guidehouse Recruiting at 1-571-633-1711 or via email at RecruitingAccommodation@guidehouse.com. All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodation. All communication regarding recruitment for a Guidehouse position will be sent from Guidehouse email domains including @guidehouse.com or guidehouse@myworkday.com. Correspondence received by an applicant from any other domain should be considered unauthorized and will not be honored by Guidehouse. Note that Guidehouse will never charge a fee or require a money transfer at any stage of the recruitment process and does not collect fees from educational institutions for participation in a recruitment event. Never provide your banking information to a third party purporting to need that information to proceed in the hiring process. If any person or organization demands money related to a job opportunity with Guidehouse, please report the matter to Guidehouse's Ethics Hotline. If you want to check the validity of correspondence you have received, please contact recruiting@guidehouse.com. Guidehouse is not responsible for losses incurred (monetary or otherwise) from an applicant's dealings with unauthorized third parties. Guidehouse does not accept unsolicited resumes through or from search firms or staffing agencies. All unsolicited resumes will be considered the property of Guidehouse and Guidehouse will not be obligated to pay a placement fee. Guidehouse is a global AI-led professional services firm delivering advisory, technology, and managed services to the commercial and government sectors. With an integrated business technology approach, Guidehouse drives efficiency and resilience in the healthcare, financial services, energy, infrastructure, and national security markets. Built to help clients across industries outwit complexity, the firm brings together approximately 18,000 professionals to achieve lasting impact and shape a meaningful future. guidehouse.comSimilar jobs in Tysons, VA
Similar jobs in Virginia
Truist
Richmond, VA
Posted1 day ago
Updated3 hours ago
University of Virginia
Charlottesville, VA
Posted1 day ago
Updated3 hours ago
Serco
Reston, VA
Posted1 day ago
Updated3 hours ago