> Markdown version of [/jobs/ext/3113394-it-security-specialist-mid-seccm-specialist](https://www.wearedevelopers.com/jobs/ext/3113394-it-security-specialist-mid-seccm-specialist). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # IT Security Specialist - Mid - SecCM Specialist - **Company:** Guidehouse Inc. - **Location:** Washington, DC, United States - **Experience:** Experienced - **Salary:** $98,000.0 - $163,000.0 - **Contract:** Permanent contract - **Skills:** Configuration Management, Cyber Security, Information Systems, System Configuration, Cyber Threat Analysis - **Published:** September 27, 2026 - **Apply:** https://dejobs.org/x/x/141A0A14BD1343E88464CDADF2D69D1B/job/ ## About the Role * An ACTIVE and MAINTAINED SECRET federal security clearance. * US Citizenship is contractually required. * Bachelor's degree from an accredited university. * FIVE (5) or more years of overall work experience. * Experience managing large security projects (cost, schedule, and performance). * The ability to obtain a DOD 8570 Level 1 certification within 6 months of employment, if not already obtained. What Would Be Nice To Have : * Current DOD 8570 Level 1 or equivalent certification. * Broad knowledge of cybersecurity threats. * Broad knowledge of information system technologies. * Experience developing security policy. * Experience with online research techniques. ## Description Guidehouse is looking for an experienced professional with experience in building, managing, and controlling the secure configurations of information systems for federal organizations. Your duties will include managing and controlling secure configurations of over 200 information systems for a federal client with a critical and high-profile mission in accordance with NIST 800-128 guidance and applicable federal and organizational policies to enable security and facilitate the management of risk. You will use Security-Focused Configuration Management (SecCM) to build on the general concepts, processes, and activities of configuration management by attention on the implementation and maintenance of the established security requirements of the organization and systems. You will ensure information security configuration management requirements are integrated into (or complement) existing organizational configuration management processes (e.g., business functions, applications, products) and information systems. Additional SecCM duties and activities include: * Identification and recording of configurations that impact the security posture of the system and the organization. * The consideration of security risks in approving the initial configuration. * The analysis of security implications of changes to the system configuration. * Documentation of the approved/implemented changes. * Qualitative and quantitative research to support work assignments for meeting the deliverable objective. * Qualitative and quantitative analyses for assigned tasks. * Compilation of research, findings, and other information into written formats such as white papers, reports, presentations, and other forms of technical documentation * Participation in policy development for configuration management. * Configuration management planning and management. * Configuration identification. * Configuration management and IT security audits. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Microservices? Monoliths? An Annoying Discussion!](https://www.wearedevelopers.com/videos/970-microservices-monoliths-an-annoying-discussion) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Enterprise Linux as Container Images](https://www.wearedevelopers.com/videos/1610-enterprise-linux-as-container-images) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Giving AI eyes: How to build a dashboard you can't see](https://www.wearedevelopers.com/videos/100193-giving-ai-eyes-how-to-build-a-dashboard-you-can-t-see) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)