Guidehouse

Cyber Consulting

SeniorITSecurityControlAssessor

McLean, Virginia, United States FULL TIME
Market Sentiment
HIGH DEMAND

Neural analysis suggests this role is
optimal for Senior candidates.

The Brief

“Senior IT Security Control Assessor at Guidehouse. Skills: FISMA security control assessments, NIST SP 800-53, NIST SP 800-53A, RMF lifecycle, security control assessments. Lead teams conducting FISMA security control assessments in accordance with NIST SP 800-53 and NIST SP 800-53A. Support system authorization efforts across the RMF lifecycle”

What You'll Achieve.

Support system authorization efforts across the RMF lifecycle; Document assessment results, findings, and risk determinations in SARs and related ATO artifacts; Identify control gaps, weaknesses, and POA&M items with clear, actionable remediation guidance; Ensure assessments align with agency-specific cybersecurity compliance and information security policies

Industry & Context.

Cyber Consulting
Problems you'll solve

Identify control gaps, weaknesses, and POA&M items with clear, actionable remediation guidance

Eligibility Requirements

Travel Required: Up to 25%, Ability to Obtain Secret Clearance, Must be able to OBTAIN and MAINTAIN a Federal or DoD "SECRET" security clearance, Candidates with an ACTIVE "SECRET" or higher-level clearance are preferred

What They're Looking For.

Must Have

Bachelor’s degree in computer science, Information Technology, Cybersecurity, or related field, Minimum of FIVE (5) years of experience in cybersecurity, Ability to Obtain Secret clearance, Demonstrated experience performing FISMA or RMF-based security control assessments, working knowledge of FISMA, NIST SP 800-53, NIST SP 800-53A, NIST SP 800-37, Experience assessing cloud-based systems, including inherited controls, Ability to clearly document technical and non-technical findings for audit-ready reporting, Understanding of federal cybersecurity compliance requirements and governance processes

Nice to Have

Master’s Degree in in computer science, Information Technology, Cybersecurity, or related field, Certified Information Systems Security Professional (CISSP), Knowledge of cloud security (FedRAMP), Experience with security tools (ACAS/Nessus, Splunk, etc.), Project management experience, ACTIVE "SECRET" or higher-level clearance

What You'll Do.

Lead teams conducting FISMA security control assessments in accordance with NIST SP 800-53 and NIST SP 800-53A

Support system authorization efforts across the RMF lifecycle

Perform control testing

and evidence reviews for management

and technical controls

Document assessment results

and risk determinations in SARs and related ATO artifacts

Identify control gaps

and POA&M items with clear

actionable remediation guidance

Support continuous monitoring activities

including ongoing control assessments and ad hoc reviews

Ensure assessments align with agency-specific cybersecurity compliance and information security policies

Oversee team deliverable reviews

offering real-time feedback and coaching to improve quality and performance

How You'll Work.

Team & Collaboration

Coordinate with system owners, ISSOs, engineers, and program stakeholders during assessments; Oversee team deliverable reviews, offering real-time feedback and coaching to improve quality and performance

Communication Scope

Ability to clearly document technical and non-technical findings for audit-ready reporting

Process & Methodology

Project management experience

Full Job Description

**_Job Family_ :** Cyber Consulting ** _Travel Required_ :** Up to 25% **_Clearance Required_ :** Ability to Obtain Secret ** _What You Will Do_ :** * Lead teams conducting FISMA security control assessments in accordance with NIST SP 800-53 and NIST SP 800-53A * Support system authorization efforts across the RMF lifecycle * Perform control testing, interviews, and evidence reviews for management, operational, and technical controls * Document assessment results, findings, and risk determinations in SARs and related ATO artifacts * Identify control gaps, weaknesses, and POA&M items with clear, actionable remediation guidance * Coordinate with system owners, ISSOs, engineers, and program stakeholders during assessments * Support continuous monitoring activities, including ongoing control assessments and ad hoc reviews * Ensure assessments align with agency-specific cybersecurity compliance and information security policies * Oversee team deliverable reviews, offering real-time feedback and coaching to improve quality and performance. ** _What You Will Need_ :** * Bachelor’s degree in computer science, Information Technology, Cybersecurity, or related field * Minimum of FIVE (5) years of experience in cybersecurity * Must be able to OBTAIN and MAINTAIN a Federal or DoD "SECRET" security clearance; candidates must obtain approved adjudication of clearance prior to onboarding with Guidehouse. Candidates with an ACTIVE "SECRET" or higher-level clearance are preferred. * Demonstrated experience performing FISMA or RMF-based security control assessments * Strong working knowledge of FISMA, NIST SP 800-53, NIST SP 800-53A, NIST SP 800-37 * Experience assessing cloud-based systems, including inherited controls * Ability to clearly document technical and non-technical findings for audit-ready reporting * Understanding of federal cybersecurity compliance requirements and governance processes * Relevant certifications preferred (e.g., CISSP, CISA, CAP, GSLC) * Team leadership

Free ATS check

Applying for this Senior IT Security Control Assessor role?

Most applicants get filtered before a human reads their resume. See if yours makes the cut.

How to Apply on Workday

  • Workday has a multi-step form — save your progress after every section.
  • "Apply With LinkedIn" can fail or lose data; manual entry is more reliable.
  • Watch for the "Submit for Review" final step — hitting "Save" alone does not submit.
  • Job requisition numbers are useful when following up with HR by email.

ANONYMOUS · UNFILTERED

What do employees actually say about Guidehouse?

Real rants from real employees. Read before you apply.

Read Company Rants →