Guidehouse
ITSecurityControlAssessor
Neural analysis suggests this role is
optimal for Mid candidates.
“IT Security Control Assessor at Guidehouse. Skills: NIST SP 800-53, RMF lifecycle, Security control assessments. Conduct FISMA security control assessments. Support system authorization efforts”
Industry & Context.
Identify control gaps; Identify control weaknesses; Identify POA&M items
Up to 25% travel, Ability to Obtain Secret clearance
What They're Looking For.
Must Have
Bachelor's degree in computer science, 3 years of experience in cybersecurity, Ability to Obtain Secret clearance, Demonstrated experience performing FISMA or RMF-based security control assessments, working knowledge of FISMA, working knowledge of NIST SP 800-53, working knowledge of NIST SP 800-53A, working knowledge of NIST SP 800-37, Experience assessing cloud-based systems, Ability to clearly document technical and non-technical findings, Understanding of federal cybersecurity compliance requirements, Understanding of governance processes
Nice to Have
Master's Degree, Active "SECRET" or higher-level clearance, Knowledge of cloud security (FedRAMP), Experience with security tools (ACAS/Nessus, Splunk, etc.), Project management experience
What You'll Do.
Conduct FISMA security control assessments
Support system authorization efforts
Perform control testing
Perform evidence reviews
Document assessment results
Document risk determinations
Identify control gaps
Identify control weaknesses
Coordinate with system owners
Coordinate with ISSOs
Coordinate with engineers
Coordinate with program stakeholders
Support continuous monitoring activities
Perform ongoing control assessments
Perform ad hoc reviews
Ensure assessments align with agency policies
How You'll Work.
Team & Collaboration
Coordinate with system owners; Coordinate with ISSOs; Coordinate with engineers; Coordinate with program stakeholders
Communication Scope
Document findings; Document risk determinations
Full Job Description
**_Job Family_ :** Cyber Consulting ** _Travel Required_ :** Up to 25% **_Clearance Required_ :** Ability to Obtain Secret ** _What You Will Do_ :** * Conduct FISMA security control assessments in accordance with NIST SP 800-53 and NIST SP 800-53A * Support system authorization efforts across the RMF lifecycle * Perform control testing, interviews, and evidence reviews for management, operational, and technical controls * Document assessment results, findings, and risk determinations in SARs and related ATO artifacts * Identify control gaps, weaknesses, and POA&M items with clear, actionable remediation guidance * Coordinate with system owners, ISSOs, engineers, and program stakeholders during assessments * Support continuous monitoring activities, including ongoing control assessments and ad hoc reviews * Ensure assessments align with agency-specific cybersecurity compliance and information security policies ** _What You Will Need_ :** * Bachelor’s degree in computer science, Information Technology, Cybersecurity, or related field * Minimum of THREE (3) years of experience in cybersecurity * Must be able to OBTAIN and MAINTAIN a Federal or DoD "SECRET" security clearance; candidates must obtain approved adjudication of clearance prior to onboarding with Guidehouse. Candidates with an ACTIVE "SECRET" or higher-level clearance are preferred. * Demonstrated experience performing FISMA or RMF-based security control assessments * Strong working knowledge of FISMA, NIST SP 800-53, NIST SP 800-53A, NIST SP 800-37 * Experience assessing cloud-based systems, including inherited controls * Ability to clearly document technical and non-technical findings for audit-ready reporting * Understanding of federal cybersecurity compliance requirements and governance processes * Relevant certifications preferred (e.g., CISSP, CISA, CAP, GSLC) **_What Would Be Nice To Have_ :** * Master’s Degree in in computer science, Information Technology, Cybersecurity, or related field * Certified
Applying for this IT Security Control Assessor role?
Most applicants get filtered before a human reads their resume. See if yours makes the cut.
How to Apply on Workday
- Workday has a multi-step form — save your progress after every section.
- "Apply With LinkedIn" can fail or lose data; manual entry is more reliable.
- Watch for the "Submit for Review" final step — hitting "Save" alone does not submit.
- Job requisition numbers are useful when following up with HR by email.
ANONYMOUS · UNFILTERED
What do employees actually say about Guidehouse?
Real rants from real employees. Read before you apply.