> Markdown version of [/jobs/ext/2769248-cybersecurity-consultant](https://www.wearedevelopers.com/jobs/ext/2769248-cybersecurity-consultant). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity Consultant - **Company:** Guidehouse Inc. - **Location:** Tysons, VA, United States - **Experience:** Expert - **Salary:** $85,000.0 - $141,000.0 - **Contract:** Permanent contract - **Skills:** Application Integration Architecture, CompTIA Security+, Cyber Security, Power BI, Systems Architecture, Mitre Att&ck, RSA Archer Platform, Data Pipelines, Plan of Action and Milestones - **Published:** September 7, 2026 - **Apply:** https://www.careerjet.com/job/us9126490f1352fcc798071176324d6415/eaa ## About the Role * Must be able to OBTAIN and MAINTAIN a Federal or DoD "PUBLIC TRUST"; candidates must obtain approved adjudication of their PUBLIC TRUST prior to onboarding with Guidehouse. Candidates with an ACTIVE PUBLIC TRUST or SUITABILITY and maintain an active HHS/NIH clearance are preferred. * Minimum of THREE (3) years of cybersecurity or IT risk management experience, candidates with experience focused on cybersecurity risk management are preferred. * Minimum of a Bachelors Degree is required. * Tools: Hands-on experience with GRC platforms. * Knowledge: Deep understanding of NIST SP 800-53, FISMA requirements, and 800-37. * Soft Skills: Strong communication and analytical thinking; ability to manage multiple concurrent priorities and deadlines. What Would Be Nice To Have: * Experience developing automated data pipelines or integrating APIs into Power BI dashboards. * Knowledge of MITRE ATT&CK framework and vulnerability prioritization methodologies (e.g., EPSS, CVSS v3). * Prior experience supporting a federal agency or working in a Public Health environment. * Certifications: Active CompTIA Security+ CE preferred; CISSP, CEH, or cloud-related certifications are a plus. ## Description Travel Required: Up to 25% Clearance Required: Ability to Obtain Public Trust What You Will Do: * Lead cyber risk management efforts across a portfolio of client applications. Manage end-to-end POA&M lifecycle, including creation, tracking, validation, and closure of identified security weaknesses Prioritize remediation activities based on risk severity, compliance requirements, and operational impact Conduct regular POA&M status reviews and coordinate with system owners and O&M teams to track milestone progress Perform BIAs to identify critical systems, functions, dependencies, and recovery time/objectives Collaborate with stakeholders to validate system criticality and align with continuity and contingency planning requirements * Build and maintain strong working relationships with business, engineering, and security teams to validate fixes, resolve blockers, and support timely remediation. * Prepare reports and briefings for leadership and federal oversight stakeholders. * Provide cyber subject matter expertise during information security audits and assessments. * Maintain and update BIA documentation in alignment with evolving system architecture and mission priorities, All communication regarding recruitment for a Guidehouse position will be sent from Guidehouse email domains including @guidehouse.com or . Correspondence received by an applicant from any other domain should be considered unauthorized and will not be honored by Guidehouse. Note that Guidehouse will never charge a fee or require a money transfer at any stage of the recruitment process and does not collect fees from educational institutions for participation in a recruitment event. Never provide your banking information to a third party purporting to need that information to proceed in the hiring process. If any person or organization demands money related to a job opportunity with Guidehouse, please report the matter to Guidehouse's Ethics Hotline. If you want to check the validity of correspondence you have received, please contact . Guidehouse is not responsible for losses incurred (monetary or otherwise) from an applicant's dealings with unauthorized third parties. Guidehouse does not accept unsolicited resumes through or from search firms or staffing agencies. All unsolicited resumes will be considered the property of Guidehouse and Guidehouse will not be obligated to pay a placement fee., Job Family: Cyber Consulting Travel Required: Up to 10% Clearance Required: Ability to Obtain Top Secret (TS) What You Will Do: The Cyber Strategy Consultant will provide r… + 9 days ago ## Related Videos - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Beyond Dashboards: Fixing Text-to-SQL with Semantic RAG](https://www.wearedevelopers.com/videos/2036-beyond-dashboards-fixing-text-to-sql-with-semantic-rag) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [REST, GraphQL, gRPC, and more: A comparison of modern API styles](https://www.wearedevelopers.com/videos/100247-rest-graphql-grpc-and-more-a-comparison-of-modern-api-styles) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Building Security Champions](https://www.wearedevelopers.com/magazine/87-building-security-champions)