Guidehouse

IT Security Control Assessor

Guidehouse$90K — $120K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor’s degree in computer science, Information Technology, Cybersecurity, or related field
  • Minimum of 3 years of experience in cybersecurity
  • Ability to obtain and maintain a Federal or DoD 'SECRET' security clearance
  • Experience with FISMA or RMF-based security control assessments
  • Strong knowledge of FISMA, NIST SP 800-53, NIST SP 800-53A, NIST SP 800-37
  • Experience assessing cloud-based systems, including inherited controls
  • Ability to document findings for audit-ready reporting
  • Understanding of federal cybersecurity compliance requirements.

Responsibilities

  • Conduct FISMA security control assessments following NIST guidelines
  • Support system authorization efforts across the RMF lifecycle
  • Perform control testing, interviews, and evidence reviews
  • Document assessment results and findings in SARs and ATO artifacts
  • Identify control gaps and provide remediation guidance
  • Coordinate with system owners and stakeholders during assessments
  • Support continuous monitoring activities and ongoing control assessments

Benefits

  • Medical, Rx, Dental & Vision Insurance
  • Personal and Family Sick Time & Company Paid Holidays
  • Discretionary variable incentive bonus eligibility
  • Parental Leave and Adoption Assistance
  • 401(k) Retirement Plan
  • Basic and Supplemental Life Insurance
  • Health Savings Account and Flexible Spending Accounts
  • Short-Term & Long-Term Disability
  • Student Loan PayDown
  • Tuition Reimbursement, Personal Development & Learning Opportunities
  • Certifications and skills development support
  • Employee Referral Program
  • Corporate Sponsored Events & Community Outreach
  • Emergency Back-Up Childcare Program
  • Mobility Stipend
Full Job Description

Job Family:

Cyber Consulting


Travel Required:

Up to 25%


Clearance Required:

Ability to Obtain Secret

What You Will Do:

  • Conduct FISMA security control assessments in accordance with NIST SP 800-53 and NIST SP 800-53A
  • Support system authorization efforts across the RMF lifecycle
  • Perform control testing, interviews, and evidence reviews for management, operational, and technical controls
  • Document assessment results, findings, and risk determinations in SARs and related ATO artifacts
  • Identify control gaps, weaknesses, and POA&M items with clear, actionable remediation guidance
  • Coordinate with system owners, ISSOs, engineers, and program stakeholders during assessments
  • Support continuous monitoring activities, including ongoing control assessments and ad hoc reviews
  • Ensure assessments align with agency-specific cybersecurity compliance and information security policies


What You Will Need:

  • Bachelor’s degree in computer science, Information Technology, Cybersecurity, or related field
  • Minimum of THREE (3) years of experience in cybersecurity
  • Must be able to OBTAIN and MAINTAIN a Federal or DoD "SECRET" securityclearance; candidates must obtain approved adjudication ofclearanceprior to onboarding with Guidehouse. Candidates with an ACTIVE "SECRET" or higher-levelclearanceare preferred.
  • Demonstrated experience performing FISMA or RMF-based security control assessments
  • Strong working knowledge of FISMA, NIST SP 800-53, NIST SP 800-53A, NIST SP 800-37
  • Experience assessing cloud-based systems, including inherited controls
  • Ability to clearly document technical and non-technical findings for audit-ready reporting
  • Understanding of federal cybersecurity compliance requirements and governance processes
  • Relevant certifications preferred (e.g., CISSP, CISA, CAP, GSLC)


What Would Be Nice To Have:

  • Master’s Degree in in computer science, Information Technology, Cybersecurity, or related field
  • Certified Information Systems Security Professional (CISSP)
  • Knowledge of cloud security (FedRAMP)
  • Experience with security tools (ACAS/Nessus, Splunk, etc.)
  • Project management experience

#LI-DNI


What We Offer:

Guidehouse offers a comprehensive, total rewards package that includes competitive compensation and a flexible benefits package that reflects our commitment to creating a diverse and supportive workplace.

Benefits include:

  • Medical, Rx, Dental & Vision Insurance

  • Personal and Family Sick Time & Company Paid Holidays

  • Position may be eligible for a discretionary variable incentive bonus

  • Parental Leave and Adoption Assistance

  • 401(k) Retirement Plan

  • Basic Life & Supplemental Life

  • Health Savings Account, Dental/Vision & Dependent Care Flexible Spending Accounts

  • Short-Term & Long-Term Disability

  • Student Loan PayDown

  • Tuition Reimbursement, Personal Development & Learning Opportunities

  • Skills Development & Certifications

  • Employee Referral Program

  • Corporate Sponsored Events & Community Outreach

  • Emergency Back-Up Childcare Program

  • Mobility Stipend

About Guidehouse

Guidehouse is a management consulting firm headquartered in Washington, D.C. The firm provides consulting services to clients in the public and commercial sectors, with a focus on energy, financial services, healthcare, national security, and aerospace and defense. Guidehouse was founded in 2018 as a spin-off from PwC. The firm has over 7,000 employees and operates in more than 50 locations worldwide.
Learn more about Guidehouse
Size
8,000 employees
Industry
Founded
2018

Similar Jobs

More Jobs at Guidehouse

More Information Technology Jobs

Find similar IT Security Control Assessor jobs: