Job Family:Technology Consulting
Travel Required:Up to 10%
Clearance Required:None
What You Will Do:The Security Assessor supports security and privacy control assessments for public-sector systems by evaluating control effectiveness, validating evidence, and contributing to formal assessment documentation under the direction of a Senior Security Assessor.
This role is primarily focused on assessment execution and documentation; however, it also provides exposure to more technical aspects of system architecture and control implementation. Candidates should demonstrate curiosity and interest in expanding their skillset toward security engineering, automation, and emerging AI-enabled approaches to compliance and assessment activities.
This role focuses on assessment execution and documentation, not system engineering or operational security responsibilities.
Key job responsibilities include the following:
- Perform security and privacy control assessments in accordance with established assessment plans
- Review security documentation and technical evidence
- Validate control implementation through:
- Evidence inspection
- Architecture and system documentation review
- Interviews with system owners and technical staff
- Contribute to assessment artifacts, including:
- SSP updates
- SARs
- ISRAs
- POA&Ms
- Document assessment results and clearly articulate control gaps and risks
- Maintain assessment independence and objectivity
- Identify opportunities to improve assessment efficiency through standardization, tooling, or automation of evidence collection and validation
- Support the use of data-driven or AI-assisted techniques to enhance analysis, traceability, and reporting over time
What You Will Need:- Minimum of THREE (3) years of overall work experience ideally in supporting security control assessments, audits, or authorization activities
- Bachelors Degree from an accredited university
- US Citizenship is contractually required
- Hands-on experience contributing to formal security assessment documentation (SSPs, SARs, POA&Ms, or equivalents)
- Working knowledge of NIST SP 800-53 security and privacy controls
- Understanding of risk-based assessment concepts
- Ability to analyze assessment evidence and clearly document findings
What Would Be Nice To Have:- Experience supporting government or other regulated environments
- Exposure to CMS, healthcare, or public-sector security compliance frameworks
- Familiarity with A&A, RMF, or Security Control Assessment processes
- Relevant certifications (CISA, CISSP, CISM, Security+, or similar)
- Prior background in or exposure to security engineering, cloud security, or system implementation
- Familiarity with modern architectures (cloud platforms, IAM, logging/monitoring, APIs) and how controls are implemented in those environments
- Exposure to automation tools, scripting, or GRC platforms supporting assessment or compliance activities
- Interest in applying AI/automation to improve audit readiness, evidence analysis, or continuous monitoring processes
What We Offer:Guidehouse offers a comprehensive, total rewards package that includes competitive compensation and a flexible benefits package that reflects our commitment to creating a diverse and supportive workplace.
Benefits include:
- Medical, Rx, Dental & Vision Insurance
- Personal and Family Sick Time & Company Paid Holidays
- Position may be eligible for a discretionary variable incentive bonus
- Parental Leave and Adoption Assistance
- 401(k) Retirement Plan
- Basic Life & Supplemental Life
- Health Savings Account, Dental/Vision & Dependent Care Flexible Spending Accounts
- Short-Term & Long-Term Disability
- Student Loan PayDown
- Tuition Reimbursement, Personal Development & Learning Opportunities
- Skills Development & Certifications
- Employee Referral Program
- Corporate Sponsored Events & Community Outreach
- Emergency Back-Up Childcare Program
- Mobility Stipend