> Markdown version of [/jobs/ext/2299234-it-security-auditor-consultant](https://www.wearedevelopers.com/jobs/ext/2299234-it-security-auditor-consultant). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # IT Security Auditor - Consultant - **Company:** Guidehouse Inc. - **Location:** Chantilly, VA, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Audit Trail, Backup Devices, Configuration Management, Cyber Security, Information Systems, Information Technology Consulting, Information Security Management, Information Technology Audit, IT General Controls (ITGC), Information Technology, Vulnerability Analysis - **Published:** August 29, 2026 - **Apply:** https://www.techcareers.com/job.asp?id=3369522673&tx=JL7973FFJ&pt=1&aff=0B19D771-A501-4A5E-8338-2A822B784D54&utm_source=Job%20Feed&utm_medium=textkernel&utm_campaign=DE&utm_term=0B19D771-A501-4A5E-8338-2A822B784D54 ## About the Role * An ACTIVE and MAINTAINED TS/SCI Federal or DoD security clearance with a COUNTERINTELLIGENCE (CI) polygraph * Bachelor's Degree in a Technical or Business field * Two (2) + years' experience providing IT consulting. Experience should include but not be limited to: * Experience in consulting with the federal government to include senior government clients * Understanding and knowledge of federal information security and assurance laws, requirements, and guidance (i.e. FISMA, NIST SP 800, FISCAM) What Would Be Nice To Have : * Relevant certification such as the Certified Information Systems Auditor (CISA) or Certified Information Security Manager (CISM) * Demonstrated knowledge and experience in IT risk and controls through IT audits, IT controls assessments, or IT security reviews * Demonstrated ability and working knowledge of: FISMA, NIST SP 800 series, FISCAM, other relevant federal information assurance laws, regulations, and guidance * Experience performing: FISMA, OMB Circular A-123, or similar internal control assessments * Experience implementing or auditing access and account management principles, including authorization, provisioning, recertification, and separation of duties * Experience implementing or auditing contingency planning principles, including backups, testing of backups, and alternate processing sites * Experience implementing or auditing configuration management principles, including configuration baseline concepts, baseline deviations, baseline maintenance, change control, and monitoring, and industry-accepted configuration settings such as DISA STIGs * Experience performing audit logging and monitoring, including generation of audit logs, use of audit log aggregation and analysis tools, and audit log monitoring and review ## Description Performing assessments of IT controls using industry-standard guidance and leading best practices Conducting interviews and discussions with a variety of client stakeholders, including IT system personnel such as Information System Security Officers (ISSOs) and system administrators * Reviewing and analyzing documents and artifacts to assist in IT controls testing such as system security plans, SOPs, audit logs, configuration scans, and vulnerability scans * Evaluating the implementation and effectiveness of IT controls using provided artifacts against federal requirements, industry guidance, and leading best practices * Documenting the results of IT controls testing in a consistent and high-quality manner that would allow others to review and understand the results * Summarizing and communicating IT controls assessment results to a variety of client stakeholders, including senior leadership * Understanding and analyzing known IT control weaknesses, identifying root causes, and developing detailed remediation plans * Providing subject matter expertise to client personnel on a wide range of matters relating to IT security and assurance * Responding to ad-hoc IT security-related requests from client personnel * Planning and executing day-to-day activities of IT assessments and evaluations individually and for the team * Mentoring junior team members in day-to-day IT controls testing responsibilities ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Resilient by Design: Building Robust Architectures in High-Stakes Financial Systems](https://www.wearedevelopers.com/videos/2106-resilient-by-design-building-robust-architectures-in-high-stakes-financial-systems) - [Hate organising your photos? Try it with 5 Terabytes](https://www.wearedevelopers.com/videos/79-hate-organising-your-photos-try-it-with-5-terabytes) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Building Security Champions](https://www.wearedevelopers.com/magazine/87-building-security-champions) - [System change: restart as developer?](https://www.wearedevelopers.com/magazine/39-system-change-restart-as-developer) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)