Guidehouse

IT Cyber Security

RiskManagementFramework(A&A)TechnicalConsultant

McLean, Virginia, United States FULL TIME
Market Sentiment
HIGH DEMAND

Neural analysis suggests this role is
optimal for Mid candidates.

The Brief

“Risk Management Framework (A&A) Technical Consultant at Guidehouse. Skills: Risk Management Framework, Authorization and Accreditation, NIST RMF, FedRAMP. Execute cybersecurity authorization and compliance activities. Develop RMF artifacts”

What You'll Achieve.

Ensure documentation remains current and audit ready

Industry & Context.

IT Cyber Security
Eligibility Requirements

Up to 10% Travel, Ability to Obtain Public Trust, Federal or DoD "PUBLIC TRUST" adjudication prior to onboarding, Maintain an active HHS/NIH clearance

What They're Looking For.

Must Have

Federal or DoD "PUBLIC TRUST", Demonstrated experience supporting federal RMF and A&A activities, Minimum of THREE (3) years of hands on experience with NIST RMF and federal A&A processes, working knowledge of NIST SP 800 37, 800 53, FISMA, and FedRAMP, Experience supporting audits, evidence collection, and POA&M management, Ability to translate technical security requirements into clear, compliant documentation, organizational, communication, and stakeholder coordination skills

Nice to Have

ACTIVE PUBLIC TRUST or SUITABILITY and maintain an active HHS/NIH clearance, Security+, CAP, or equivalent certification, Cloud Security Experience, Experience supporting third party assessments or SAR development, Familiarity with ServiceNow, GRC platforms, or audit tracking tools, Experience supporting cloud or financial system authorizations

What You'll Do.

Execute cybersecurity authorization and compliance activities

Develop RMF artifacts

Perform risk assessments

Develop RMF and A&A documentation

Support authorization of cloud services

Support 3PAO readiness assessments

Prepare audit documentation

Support remediation efforts

Maintain compliance repositories

How You'll Work.

Team & Collaboration

Stakeholder coordination skills

Communication Scope

Communication skills

Full Job Description

**_Job Family_ :** IT Cyber Security ** _Travel Required_ :** Up to 10% **_Clearance Required_ :** Ability to Obtain Public Trust _**What You Will Do:**_ The RMF / A&A Technical Consultant is a subject matter practitioner responsible for executing cybersecurity authorization and compliance activities across cloud and enterprise systems. This role develops the RMF artifacts, supports audits, and performs risk assessments. **Key Responsibilities** * Develop RMF and A&A documentation including SSPs, control implementation matrices, SARs, POA&Ms, and risk acceptance materials. * Support authorization of cloud services leveraging FedRAMP packages and agency specific control requirements. * Support 3PAO readiness assessments and SAR development for cloud platforms. * Prepare audit documentation, respond to PBC requests, and support FISMA and financial system audits. * Track audit findings, develop POA&Ms, and support remediation efforts through closure. * Maintain compliance repositories and ensure documentation remains current and audit ready. _**What You Will Need:**_ * Must be able to OBTAIN and MAINTAIN a Federal or DoD "PUBLIC TRUST"; candidates must obtain approved adjudication of their PUBLIC TRUST prior to onboarding with Guidehouse. Candidates with an ACTIVE PUBLIC TRUST or SUITABILITY and maintain an active HHS/NIH clearance are preferred. * Demonstrated experience supporting federal RMF and A&A activities. * Minimum of THREE (3) years of hands on experience with NIST RMF and federal A&A processes * Strong working knowledge of NIST SP 800 37, 800 53, FISMA, and FedRAMP. * Experience supporting audits, evidence collection, and POA&M management. * Ability to translate technical security requirements into clear, compliant documentation. * Strong organizational, communication, and stakeholder coordination skills. _**What Would Be Nice To Have:**_ * Security+, CAP, or equivalent certification. * Cloud Security Experience * Experience supporting third party assessment

Free ATS check

Applying for this Risk Management Framework (A&A) Technical Consultant role?

Most applicants get filtered before a human reads their resume. See if yours makes the cut.

How to Apply on Workday

  • Workday has a multi-step form — save your progress after every section.
  • "Apply With LinkedIn" can fail or lose data; manual entry is more reliable.
  • Watch for the "Submit for Review" final step — hitting "Save" alone does not submit.
  • Job requisition numbers are useful when following up with HR by email.

ANONYMOUS · UNFILTERED

What do employees actually say about Guidehouse?

Real rants from real employees. Read before you apply.

Read Company Rants →