Job Family:
IT Cyber Security
Travel Required:
Up to 10%
Clearance Required:
Ability to Obtain Public Trust
What You Will Do:
- Support the implementation and ongoing execution of theNIST RMF requirementsacross assigned authorization boundaries.
- Assist in systemcategorizationin accordance withFIPS 199and NIST SP 800-60 guidance.
- Help identify, document, and maintain applicableNIST SP 800-53 r5 security and privacy control implementations, control tailoring and inheritance.
- Develop, review, and/or maintain RMF or security related documentation, including:
- FIPS 199
- System Security Plans (SSPs)
- Plans of Action and Milestones (POA&Ms)
- Privacy and risk assessments
- Continuous monitoring documentation
- System specific security control or organizational level standard operating procedures
- Memorandums of Agreement/Understanding or Interconnection Security Agreements
- Supportsecurity control assessments, remediation efforts, and authorization activities.
- Identify security weaknesses, vulnerabilities, and compliance gaps; document findings and work with stakeholders to develop corrective actions.
- Manage and maintainPOA&Msresulting from continuous monitoring or assessment results to ensure weaknesses are tracked through to remediation and closure.
- Support the preparation of boundaries forAuthorization to Operate (ATO), reauthorization, and ongoing authorization activities.
- Monitor systems for compliance withFISMAand organizational cybersecurity policies, standards, and procedures.
- Ensure security requirements are integrated into system design, development, implementation, and operational changes.
- Supportcontinuous monitoringactivities, including control status reviews, vulnerability management, configuration management, and periodic assessments.
- Coordinate vulnerability scanning, review scan results, and track remediation of identified findings.
- Assist in incident response coordination, reporting, investigation, and follow-up corrective actions.
- Promote security best practices and help ensure systems maintain an acceptable level of risk.
- Manage boundary records in the applicable governance, risk, and compliance tool.
What You Will Need:
- Bachelors degree in computer science, information technology, or cybersecurity.
- Current Security+ certificate.
- Minimum (3) three years of experience in cybersecurity.
- Experience utilizing enterprise cybersecurity risk management and governance tools.
- Experience with cloud security.
- Must be able to obtain and maintain a Federal or DoD Public Trust. Candidates must receive approved adjudication of their Public Trust prior to onboarding with Guidehouse. Candidates with an active Public Trust or existing suitability are preferred.
- Working knowledge or familiarity with:
- FISMA (2014): Federal mandated framework for information security
- NIST SP 800-37 Rev. 2: Risk Management Framework for Information Systems and Organizations
- NIST SP 800-53 Rev. 5: Security and Privacy Controls for Information Systems
- NIST SP 800-53A: Assessing Security and Privacy Controls
What Would Be Nice To Have:
Working knowledge or experience with NIST IR 8467 Genomic Data Cybersecurity and Privacy Frameworks Community Profile
The annual salary range for this position is $74,000.00-$124,000.00. Compensation decisions depend on a wide range of factors, including but not limited to skill sets, experience and training, security clearances, licensure and certifications, and other business and organizational needs.
What We Offer:
Guidehouse offers a comprehensive, total rewards package that includes competitive compensation and a flexible benefits package that reflects our commitment to creating a diverse and supportive workplace.
Benefits include:
Medical, Rx, Dental & Vision Insurance
Personal and Family Sick Time & Company Paid Holidays
Parental Leave
401(k) Retirement Plan
Group Term Life and Travel Assistance
Voluntary Life and AD&D Insurance
Health Savings Account, Health Care & Dependent Care Flexible Spending Accounts
Transit and Parking Commuter Benefits
Short-Term & Long-Term Disability
Tuition Reimbursement, Personal Development, Certifications & Learning Opportunities
Employee Referral Program
Corporate Sponsored Events & Community Outreach
Care.com annual membership
Employee Assistance Program
Supplemental Benefits via Corestream (Critical Care, Hospital Indemnity, Accident Insurance, Legal Assistance and ID theft protection, etc.)
Position may be eligible for a discretionary variable incentive bonus