Senior Cyber Risk and Vulnerability Assessor

GuidehouseTysons, VA
Hybrid

About The Position

Guidehouse’s Cybersecurity practice helps federal and regulated clients assess, manage, and reduce cybersecurity risk across high‑impact systems and mission‑critical environments. Our teams combine deep technical assessment expertise with strong knowledge of federal risk management and authorization processes to support informed risk decisions and system authorization outcomes. As a Senior Cyber Risk and Vulnerability Assessor, you will lead comprehensive security control assessments for complex, high‑impact, and enterprise systems across on‑premises, cloud, and hybrid environments. You will oversee assessment strategy and execution, validate remediation effectiveness, and provide authoritative risk determinations in support of Authorizing Officials (AOs) and senior agency leadership. This role is ideal for a senior assessment professional with strong technical depth, proven leadership experience, and the ability to translate assessment results into clear, defensible risk recommendations aligned to federal cybersecurity requirements. This role positions you as a senior assessment authority within Guidehouse’s Cybersecurity practice, accountable for delivering high‑quality security assessments that enable informed authorization decisions and strengthen enterprise risk posture.

Requirements

  • Must be able to OBTAIN and MAINTAIN a Federal or DoD "PUBLIC TRUST"; candidates must obtain approved adjudication of their PUBLIC TRUST prior to onboarding with Guidehouse.
  • Bachelor’s degree in Cybersecurity, Information Systems, Computer Science, or a related field (additional relevant experience may substitute for formal education).
  • Minimum of NINE (9) or more years of progressively responsible experience performing or leading security control assessments, audits, or cybersecurity risk assessments.
  • Certified in Governance, Risk and Compliance (CGRC) (active)
  • Certified Information Systems Security Professional (CISSP) (active)
  • Demonstrated experience conducting assessments under the NIST RMF.
  • Experience assessing high‑impact or high‑value asset (HVA) systems.
  • Strong understanding of security control implementation and assessment across enterprise, cloud, and hybrid architectures.
  • Proven ability to communicate risk clearly and effectively to technical and executive stakeholders, including Authorizing Officials.
  • Excellent written and verbal communication skills, including formal assessment reporting and executive briefings.

Nice To Haves

  • Candidates with an ACTIVE PUBLIC TRUST or SUITABILITY and maintain an active HHS/NIH clearance are preferred.
  • Experience with continuous monitoring programs and control inheritance models.
  • Familiarity with major cloud service providers and their shared responsibility models.
  • Additional certifications such as CISM, CISA, CCSP, HVA Assessment Lead/Technical Lead/Operator, or cloud security credentials.
  • Prior consulting experience with responsibility for delivery quality, stakeholder management, and team leadership.

Responsibilities

  • Lead and oversee security control assessments for moderate‑ and high‑impact information systems, including complex enterprise and mission‑critical environments.
  • Direct assessment planning and control testing strategies, ensuring appropriate coverage, rigor, and consistency with system architectures and risk profiles.
  • Conduct and supervise cloud, on‑premises, and hybrid system assessments, including IaaS, PaaS, and SaaS environments.
  • Validate the effectiveness of remediation actions, including retesting controls and verifying closure of findings.
  • Analyze assessment results and develop risk determinations, observations, and recommendations suitable for senior decision‑makers and AOs.
  • Ensure assessments are executed in alignment with applicable federal frameworks and mandates, including: FISMA, NIST SP 800‑37, NIST SP 800‑53, OMB guidance and memoranda, Agency‑specific cybersecurity policies and procedures.
  • Oversee development and quality of assessment deliverables, including security assessment plans (SAPs), security assessment reports (SARs), POA&Ms, and authorization support documentation.
  • Provide guidance on risk acceptance, remediation prioritization, and continuous monitoring strategies.
  • Serve as a trusted advisor to system owners, ISSOs, and security engineers on assessment findings and control implementation improvements.
  • Coordinate assessment activities across multiple systems or programs, ensuring schedule adherence and stakeholder alignment.
  • Mentor and develop assessors and consultants; provide technical review and quality assurance for assessment work products.
  • Support practice growth through proposal development, technical contributions, and assessment methodology development.

Benefits

  • Medical, Rx, Dental & Vision Insurance
  • Personal and Family Sick Time & Company Paid Holidays
  • Position may be eligible for a discretionary variable incentive bonus
  • Parental Leave and Adoption Assistance
  • 401(k) Retirement Plan
  • Basic Life & Supplemental Life
  • Health Savings Account, Dental/Vision & Dependent Care Flexible Spending Accounts
  • Short-Term & Long-Term Disability
  • Student Loan PayDown
  • Tuition Reimbursement, Personal Development & Learning Opportunities
  • Skills Development & Certifications
  • Employee Referral Program
  • Corporate Sponsored Events & Community Outreach
  • Emergency Back-Up Childcare Program
  • Mobility Stipend
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service