
location_on13939, Valley Country Drive, Brookfield, Chantilly, Fairfax County, Virginia, 20151, United States
Guidehouse is a leading professional services firm dedicated to helping clients navigate complex challenges. We are committed to creating a diverse and supportive workplace where every employee can thrive. As an Equal Opportunity Employer, we consider qualified applicants regardless of background, including protected veterans and individuals with disabilities. We adhere to all applicable laws regarding criminal history and recruitment practices, ensuring a fair and transparent hiring process.
The Senior IT Security Auditor serves as a critical bridge between technical security realities and federal compliance requirements. In this role, you will lead stakeholder engagement and technical delivery for efforts supporting federal agencies with IT controls assessments and program evaluations. This position is ideal for professionals with a background in information security, assurance, or IT audit who are passionate about utilizing their expertise to analyze IT control weaknesses, identify root causes, and develop robust remediation plans for the federal government.
Your day-to-day involves conducting deep-dive assessments using industry-standard guidance and leading best practices. You will interact with a wide range of client stakeholders, from Information System Security Officers (ISSOs) and system administrators to senior leadership, to gather insights and communicate findings. A significant portion of your time will be dedicated to reviewing artifacts such as system security plans, SOPs, audit logs, and vulnerability scans to evaluate the implementation and effectiveness of IT controls against federal requirements like FISMA and NIST SP 800.
Beyond technical analysis, you will play a key role in mentoring junior team members and providing subject matter expertise on IT security matters. You will document your findings in a high-quality, consistent manner that allows for easy review and understanding, ensuring that assessment results are clearly summarized and actionable for clients. This role offers the opportunity to work on ad-hoc requests and lead the planning and execution of IT assessments, both individually and as part of a team.
To apply, please submit your resume through our official channels. All communication regarding recruitment will be sent from official Guidehouse email domains (e.g., @guidehouse.com). Please be aware that Guidehouse will never charge a fee or require a money transfer at any stage of the recruitment process. If you require an accommodation to apply or interview, please contact Guidehouse Recruiting at 1-571-633-1711 or via email. All information provided will be kept confidential and used solely to facilitate the accommodation process.
Guidehouse is an Equal Opportunity Employer. We are committed to building a workforce that reflects the diversity of the communities we serve. We consider qualified applicants with criminal histories in a manner consistent with applicable laws, including the Fair Chance Ordinance of Los Angeles and San Francisco. We do not accept unsolicited resumes from search firms or staffing agencies; all such resumes are the property of Guidehouse.
Work model: On-site
13939, Valley Country Drive, Brookfield, Chantilly, Fairfax County, Virginia, 20151, United States
Chantilly, Virginia
Relevant certification such as CISA or CISM. Demonstrated knowledge and experience in IT risk and controls through IT audits, IT controls assessments, or IT security reviews. Working knowledge of FISMA, NIST SP 800 series, FISCAM, and other relevant federal information assurance laws, regulations, and guidance. Experience performing FISMA, OMB Circular A-123, or similar internal control assessments. Experience implementing or auditing access and account management principles, including authorization, provisioning, recertification, and separation of duties. Experience implementing or auditing contingency planning principles, including backups, testing of backups, and alternate processing sites. Experience implementing or auditing configuration management principles, including configuration baseline concepts, baseline deviations, baseline maintenance, change control, and monitoring, and industry-accepted configuration settings such as DISA STIGs. Experience performing audit logging and monitoring, including generation of audit logs, use of audit log aggregation and analysis tools, and audit log monitoring and review.
Guidehouse • Chantilly, Virginia
Peraton • Tampa, Florida
International Physical Therapy Academy IPTA • Huntsville, Alabama
Skills: Fisma, Nist SP 800, Fiscam, Cisa, Cism, Disa Stig, Omb Circular A-123, Ts/sci, Polygraph, Ci.
Education: Bachelor's Degree in a Technical or Business field required.