Jobs · Information Technology · Virginia

Cybersecurity Risk - Managing Consultant

Guidehouse · McLean, VA · 2 wk ago
On-siteInformation Technology$130k–$216k/yrFull-time

Travel Required: Up to 10%. Clearance Required: Active Secret.

About the Role

The Managing Consultant will oversee three workstreams led by Senior Consultants in Cybersecurity, Risk & Compliance. This management role involves coordinating and leading across multiple cybersecurity risk teams within the agency, providing leadership and subject matter expertise in cybersecurity risk assessments, high-value asset (HVA) systems’ oversight, and risk governance. The Managing Consultant will work closely with team leaders, IT stakeholders, and federal partners to ensure alignment with federal cybersecurity mandates, including CISA and OMB Directives related to HVA oversight, and NIST guidance related to risk management and risk assessment.

Responsibilities

  • Oversee, manage, and lead the development and execution of cybersecurity risk management, risk governance, risk assessments, and HVA oversight and assessments. This includes maintaining and improving the enterprise-level risk register, coordinating and planning enterprise and organizational unit risk assessments, overseeing specified technology risk assessments, and managing HVA oversight program functions.
  • Support cross-training in these areas and provide strategic direction and guidance to team leads for the workstreams.
  • Review and advise on deliverables, performing QA/QC for all workstreams.
  • Advise on and incorporate federal cybersecurity frameworks into evaluations/assessments, such as NIST IR 8286, SP 800-171, SP 800-60, SP 1800-39A, FIPS 140-3, and FIPS 199.
  • Develop, maintain, and provide input on agency-wide cybersecurity policies, procedures, and documentation related to risk management and HVA programs, including SOPs, playbooks, guidance, and slick sheets.
  • Prepare and update risk management and HVA-related plans, standard operating procedures, and project schedules to ensure efficient program operations.
  • Provide expert guidance to system owners, analysts, and leadership on cybersecurity best practices related to HVA requirements and risk management functions.
  • Lead discussions with agency stakeholders to ensure Federal requirements are fulfilled, fostering collegial working relationships and providing technical assistance in standardized formats.
  • Present complex risk assessment and HVA assessment findings and recommendations to technical and executive audiences, including preparing briefing materials for weekly reports and specific stakeholders.
  • Advise on the severity of assessment results and recommend courses of action to government stakeholders.
  • Collaborate with internal teams and external stakeholders, including federal agencies such as CISA and the Department of State, while remaining flexible to ensure compliance and adapt guidance to resource constraints and strategic direction.

Requirements

  • Active and current Secret federal security clearance.
  • Bachelor’s Degree from an accredited university.
  • Seven (7) years of relevant cybersecurity experience, OR a Master’s Degree and five (5) years of relevant experience.
  • US Citizenship.
  • Excellent verbal and written communication skills, specifically in report writing.
  • Certified in one of the following or another relevant certification: Certified Information Systems Security Professional (CISSP), Certified in Risk and Information Systems Controls (CRISC), Certified Authorization Professional (CAP) / Certified in Governance, Risk and Compliance (CGRC), Certified Information Systems Auditor (CISA).

Preferred Qualifications

  • Experience consulting at large federal agencies such as the Department of State, Department of Justice, or Department of Homeland Security on cybersecurity audits and/or IT controls.
  • Demonstrated experience in external client-facing management and/or consulting for large firms.

Pay

The annual salary range for this position is $130,000.00 - $216,000.00. Compensation decisions depend on skill sets, experience, training, security clearances, licensure, certifications, and other business and organizational needs.

Benefits

  • Medical, Rx, Dental & Vision Insurance
  • Personal and Family Sick Time & Company Paid Holidays
  • Position may be eligible for a discretionary variable incentive bonus
  • Parental Leave and Adoption Assistance
  • 401(k) Retirement Plan
  • Basic Life & Supplemental Life Insurance
  • Health Savings Account, Dental/Vision & Dependent Care Flexible Spending Accounts
  • Short-Term & Long-Term Disability
  • Student Loan PayDown
  • Tuition Reimbursement, Personal Development & Learning Opportunities
  • Skills Development & Certifications
  • Employee Referral Program
  • Corporate Sponsored Events & Community Outreach
  • Emergency Back-Up Childcare Program
  • Mobility Stipend

Similar jobs

Cybersecurity Consultant

KAI Partners, Inc.Roseville, CA· 1 mo ago
Information Technology$118k–$133k/yrapply on jobs.jobvite.com

Cybersecurity Consultant

Accord Technologies IncIrving, TX· 2 mo ago
Information Technologyapply on candidateportal.ceipal.com

Cybersecurity Consultant

GuidehouseMcLean, VA· 1 mo ago
Information Technology$85k–$141k/yrapply on guidehouse.wd1.myworkdayjobs.com

Cybersecurity Consultant

GuidehouseBethesda, MD· 1 mo ago
Information Technology$85k–$141k/yrapply on guidehouse.wd1.myworkdayjobs.com