Jobs › Cybersecurity Consultant
Cybersecurity Consultant
Job at a glance
- Category
- GRC
- Work arrangement
- On-site
- Location
- VA, McLean
- Salary range
- $85,000 to $141,000
- Posted
- Aug 20, 2026
Free. One click to unsubscribe. We never share your address.
Guidehouse is hiring a Cybersecurity Consultant in VA, McLean. This is a GRC job in the governance, risk, and compliance field, with a posted range of $85,000 to $141,000. Review the full details below and apply directly with Guidehouse.
Job Family : Cyber Consulting Travel Required : Up to 25% Clearance Required : Ability to Obtain Public Trust What You Will Do : Lead vulnerability management efforts across a portfolio of client applications, including analyzing findings, identifying affected versions, providing remediation guidance, assigning issues to teams, and tracking vulnerabilities through closure. Build and maintain strong working relationships with business, engineering, and security teams to validate fixes, resolve blockers, and support timely remediation. Support POA&M activities, patching timelines, remediation deadlines, and related federal cybersecurity and compliance requirements. Develop and maintain automated vulnerability reports, dashboards, KPIs, and metrics to track remediation progress, compliance gaps, and asset risk. Prepare reports and briefings for leadership and federal oversight stakeholders. Monitor suspicious activity and security alerts in Splunk and coordinate follow-up actions with relevant teams. Support secure development efforts through security documentation, secure coding guidance, annual training support, and evaluation of security tools and processes. Provide cyber subject matter expertise during information security audits and assessments. What You Will Need : Must be able to OBTAIN and MAINTAIN a Federal or DoD "PUBLIC TRUST"; candidates must obtain approved adjudication of their PUBLIC TRUST prior to onboarding with Guidehouse. Candidates with an ACTIVE PUBLIC TRUST or SUITABILITY and maintain an active HHS/NIH clearance are preferred. Minimum of THREE (3) years of cybersecurity or IT risk management experience, candidates with experience focused on vulnerability management and/or secure configuration are preferred. Minimum of a Bachelors Degree is required. Tools: Hands-on experience with Invicti, Splunk, and Atlassian tools (Jira & Confluence) Knowledge: Deep understanding of NIST SP 800-53, FISMA requirements, and OWASP Top 10. Certifications: Active CompTIA Security+ CE preferred; CISSP, CEH, or cloud-related certifications are a plus. Soft Skills: Strong communication and analytical thinking; ability to manage multiple concurrent priorities and deadlines. What Would Be Nice To Have : Experience developing automated data pipelines or integrating APIs into Power BI dashboards. Knowledge of MITRE ATT&CK framework and vulnerability prioritization methodologies (e.g., EPSS, CVSS v3). Prior experience supporting a federal agency or working in a
Full responsibilities and requirements are on Guidehouse's application page.
Apply for this job →Location and market context
This job is based in VA, McLean on-site. Local candidates benefit from being close to Guidehouse's teams and regional hiring market. Confirm the exact in-office expectation and any relocation support with the employer.
About cybersecurity governance jobs
Cybersecurity governance connects security control frameworks to business and regulatory risk, covering policy, risk assessment, and control assurance rather than hands-on operations. Jobs like this one are typically evaluated against frameworks such as NIST CSF, ISO/IEC 27001, SOC 2, and security risk and control-assurance practices.
How to position yourself for this cybersecurity governance job
Strong candidates emphasize security control frameworks, risk assessment, policy and standards, and translating technical security posture into governance and board-level reporting. In your resume and outreach, tie your experience to how Guidehouse would apply NIST CSF, ISO/IEC 27001, SOC 2, and security risk and control-assurance practices, and lead with concrete outcomes rather than duties.
Similar GRC jobs
More GRC jobs: All GRC jobs · Search by category & location