Guidehouse
Cyber Consulting
SeniorRiskManagementFramework(A&A)Consultant
Neural analysis suggests this role is
optimal for Senior candidates.
“Senior Risk Management Framework (A&A) Consultant at Guidehouse. Skills: Risk Management Framework, Authorization and Accreditation, Cybersecurity compliance. Lead development of RMF and A&A documentation. Support authorization of cloud services”
What You'll Achieve.
Ensure documentation remains current and audit ready; Support remediation efforts through closure
Industry & Context.
Ability to Obtain Public Trust, Travel Required: Up to 10%
What They're Looking For.
Must Have
Federal or DoD "PUBLIC TRUST", Demonstrated experience supporting federal RMF and A&A activities, Minimum of THREE (3) years of hands on experience with NIST RMF and federal A&A processes, working knowledge of NIST SP 800 37, 800 53, FISMA, and FedRAMP, Experience supporting audits, evidence collection, and POA&M management, Ability to translate technical security requirements into clear, compliant documentation, organizational, communication, and stakeholder coordination skills
Nice to Have
ACTIVE PUBLIC TRUST or SUITABILITY and maintain an active HHS/NIH clearance, Security+, CAP, or equivalent certification, Experience supporting third party assessments or SAR development, Familiarity with ServiceNow, GRC platforms, or audit tracking tools, Experience supporting cloud or financial system authorizations
What You'll Do.
Lead development of RMF and A&A documentation
Support authorization of cloud services
Coordinate A&A activities
Support 3PAO readiness assessments
Prepare audit documentation
Develop recurring A&A and audit progress reports
Maintain compliance repositories
How You'll Work.
Team & Collaboration
Coordinate A&A activities with System Owners, ISSOs, IAMs, and third party assessors; Mentoring junior team members
Communication Scope
communication skills; stakeholder coordination skills
Full Job Description
**_Job Family_ :** Cyber Consulting ** _Travel Required_ :** Up to 10% **_Clearance Required_ :** Ability to Obtain Public Trust _**What You Will Do:**_ The Senior RMF / A&A Consultant is a subject matter practitioner responsible for executing cybersecurity authorization and compliance activities across cloud and enterprise systems. This role leads development of RMF artifacts, coordinates authorization activities, supports audits, and provides risk and compliance advisory services to government stakeholders. Senior Consultants operate independently on complex assignments while contributing to overall program execution and mentoring junior team members. **Key Responsibilities** * Lead development of RMF and A&A documentation including SSPs, control implementation matrices, SARs, POA&Ms, and risk acceptance materials. * Support authorization of cloud services leveraging FedRAMP packages and agency specific control requirements. * Coordinate A&A activities with System Owners, ISSOs, IAMs, and third party assessors. * Support 3PAO readiness assessments and SAR development for cloud platforms. * Prepare audit documentation, respond to PBC requests, and support FISMA and financial system audits. * Track audit findings, develop POA&Ms, and support remediation efforts through closure. * Develop recurring A&A and audit progress reports for government leadership. * Maintain compliance repositories and ensure documentation remains current and audit ready. **_What You Will Need:_** * Must be able to OBTAIN and MAINTAIN a Federal or DoD "PUBLIC TRUST"; candidates must obtain approved adjudication of their PUBLIC TRUST prior to onboarding with Guidehouse. Candidates with an ACTIVE PUBLIC TRUST or SUITABILITY and maintain an active HHS/NIH clearance are preferred. * Demonstrated experience supporting federal RMF and A&A activities. * Minimum of THREE (3) years of hands on experience with NIST RMF and federal A&A processes * Strong working knowledge of NIST SP 800 37, 800 53, FISM
Applying for this Senior Risk Management Framework (A&A) Consultant role?
Most applicants get filtered before a human reads their resume. See if yours makes the cut.
How to Apply on Workday
- Workday has a multi-step form — save your progress after every section.
- "Apply With LinkedIn" can fail or lose data; manual entry is more reliable.
- Watch for the "Submit for Review" final step — hitting "Save" alone does not submit.
- Job requisition numbers are useful when following up with HR by email.
ANONYMOUS · UNFILTERED
What do employees actually say about Guidehouse?
Real rants from real employees. Read before you apply.