Jobs › Virginia › VA › Cybersecurity Consultant
Cybersecurity Consultant
Guidehouse is hiring for the role of Cybersecurity Consultant, VA, McLean (On-site). This is a Cybersecurity role in the governance, risk, and compliance field, with a posted range of $85,000-$141,000. Review the full details below and apply directly with Guidehouse.
Job Family :
Cyber Consulting
Travel Required :
Up to 25%
Clearance Required :
Ability to Obtain Public Trust
What You Will Do :
Lead vulnerability management efforts across a portfolio of client applications, including analyzing findings, identifying affected versions, providing remediation guidance, assigning issues to teams, and tracking vulnerabilities through closure.
Build and maintain strong working relationships with business, engineering, and security teams to validate fixes, resolve blockers, and support timely remediation.
Support POA&M activities, patching timelines, remediation deadlines, and related federal cybersecurity and compliance requirements.
Develop and maintain automated vulnerability reports, dashboards, KPIs, and metrics to track remediation progress, compliance gaps, and asset risk.
Prepare reports and briefings for leadership and federal oversight stakeholders.
Monitor suspicious activity and security alerts in Splunk and coordinate follow-up actions with relevant teams.
Support secure development efforts through security documentation, secure coding guidance, annual training support, and evaluation of security tools and processes.
Provide cyber subject matter expertise during information security audits and assessments.
What You Will Need :
Must be able to OBTAIN and MAINTAIN a Federal or DoD "PUBLIC TRUST"; candidates must obtain approved adjudication of their PUBLIC TRUST prior to onboarding with Guidehouse. Candidates with an ACTIVE PUBLIC TRUST or SUITABILITY and maintain an active HHS/NIH clearance are preferred.
Minimum of THREE (3) years of cybersecurity or IT risk management experience, candidates with experience focused on vulnerability management and/or secure configuration are preferred.
Minimum of a Bachelors Degree is required.
Tools: Hands-on experience with Invicti, Splunk, and Atlassian tools (Jira & Confluence)
Knowledge: Deep understanding of NIST SP 800-53, FISMA requirements, and OWASP Top 10.
Certifications: Active CompTIA Security+ CE preferred; CISSP, CEH, or cloud-related certifications are a plus.
Soft Skills: Strong communication and analytical thinking; ability to manage multiple concurrent priorities and deadlines.
What Would Be Nice To Have :
Experience developing automated data pipelines or integrating APIs into Power BI dashboards.
Knowledge of MITRE ATT&CK framework and vulnerability prioritization methodologies (e.g., EPSS, CVSS v3).
Prior experience supporting a federal agency or working in a Public Health environment.
#LI-DNI
The annual salary range for this position is $85,000.00-$141,000.00. Compensation decisions depend on a wide range of factors, including but not limited to skill sets, experience and training, security clearances, licensure and certifications, and other business and organizational needs.
What We Offer :
Guidehouse offers a comprehensive, total rewards package that includes competitive compensation and a flexible benefits package that reflects our commitment to creating a diverse and supportive workplace.
Benefits include:
Medical, Rx, Dental & Vision Insurance
Personal and Family Sick Time & Company Paid Holidays
Position may be eligible for a discretionary variable incentive bonus
Parental Leave and Adoption Assistance
401(k) Retirement Plan
Basic Life & Supplemental Life
Health Savings Account, Dental/Vision & Dependent Care Flexible Spending Accounts
Short-Term & Long-Term Disability
Student Loan PayDown
Tuition Reimbursement, Personal Development & Learning Opportunities
Skills Development & Certifications
Employee Referral Program
Corporate Sponsored Events & Community Outreach
Emergency Back-Up Childcare Program
Mobility Stipend
About Guidehouse
Guidehouse is an Equal Opportunity Employer–Protected Veterans, Individuals with Disabilities or any other basis protected by law, ordinance, or regulation.
Guidehouse will consider for employment qualified applicants with criminal histories in a manner consistent with the requirements of applicable law or ordinance including the Fair Chance Ordinance of Los Angeles and San Francisco.
If you have visited our website for information about employment opportunities, or to apply for a position, and you require an accommodation, please contact Guidehouse Recruiting at 1-571-633-1711 or via email at RecruitingAccommodation@guidehouse.com . All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodation.
All communication regarding recruitment for a Guidehouse position will be sent from Guidehouse email domains including @guidehouse.com or guidehouse@myworkday.com . Correspondence received by an applicant from any other domain should be considered unauthorized and will not be honored by Guidehouse. Note that Guidehouse will never charge a fee or require a money transfer at any sta
Location and market context
This role is based in VA on-site. Local candidates benefit from being close to Guidehouse's teams and regional hiring market. Confirm the exact in-office expectation and any relocation support with the employer.
About cybersecurity governance roles
Cybersecurity governance connects security control frameworks to business and regulatory risk, covering policy, risk assessment, and control assurance rather than hands-on operations. Roles like this one are typically evaluated against frameworks such as NIST CSF, ISO/IEC 27001, SOC 2, and security risk and control-assurance practices.
How to position yourself for this cybersecurity governance role
Strong candidates emphasize security control frameworks, risk assessment, policy and standards, and translating technical security posture into governance and board-level reporting. In your resume and outreach, tie your experience to how Guidehouse would apply NIST CSF, ISO/IEC 27001, SOC 2, and security risk and control-assurance practices, and lead with concrete outcomes rather than duties.
Similar GRC roles
- Head of Security & AI Governance · Flip · Los Angeles
- Information System Security Manager (ISSM) · Johns Hopkins University Applied Physics Laboratory · Laurel, MD
- Senior Cybersecurity Engineer Specialist · Concurrent Technologies Corporation · Johnstown, PA
- Cyber Security Engineer III - Incident Response & Risk · Commerce Bank · Kansas City, MO
- Information Security Risk Specialist · Booz Allen Hamilton · Arlington, VA
- Head of Government Cyber Integration · OpenAI · Remote
- Staff Security Engineer - Identity Risk & Governance · Nubank · Seattle, WA
- Systems Security Engineer · Modern Technology Solutions Inc · Wright-Patterson AFB, OH
Want to be next in a role like this?
Roles like Cybersecurity Consultant in VA, McLean open regularly. Be first to know, privately. No current employer ever sees you looking.
Employer, or see something wrong with this posting? Report this posting and we will review it promptly.