> Markdown version of [/jobs/ext/549343-healthcare-security-operations-consultant](https://www.wearedevelopers.com/jobs/ext/549343-healthcare-security-operations-consultant). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Healthcare Security Operations Consultant - **Company:** Guidehouse Inc. - **Location:** Los Angeles, CA, United States - **Experience:** Experienced - **Salary:** $98,000.0 - $163,000.0 - **Contract:** Permanent contract - **Skills:** CompTIA Security+, Cyber Security, Microsoft Security Essentials, Software Vulnerability Management, EHR Systems, Mitre Att&ck, CIS Benchmarks, Splunk, Servicenow - **Published:** June 12, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=531823d27f15cd37 ## About the Role Do you have experience in Vuls?, Do you have a Bachelor's degree?, * Must be able to OBTAIN and MAINTAIN a Federal or DoD "PUBLIC TRUST"; candidates must obtain approved adjudication of their PUBLIC TRUST prior to onboarding with Guidehouse. Candidates with an ACTIVE PUBLIC TRUST or SUITABILITY and maintain an active HHS/NIH clearance are preferred. * Minimum of THREE (3) years of cybersecurity or IT risk management experience, candidates with experience focused on vulnerability management and/or secure configuration are preferred. * Minimum of a Bachelors Degree is required. * Tools: Hands-on experience with Tenable. * Knowledge: Deep understanding of HIPAA and cybersecurity frameworks. * Soft Skills: Strong communication and analytical thinking; ability to manage multiple concurrent priorities and deadlines. * Experience with ServiceNow or Splunk Security Essentials. * Experience supporting security hardening of infrastructure supporting EHR systems. What Would Be Nice To Have: * Certifications: Active CompTIA Security+ CE preferred. Other certifications (CISSP, CEH, or cloud-related) are a plus. * Familiarity with ServiceNow or Splunk Security Essentials. * Knowledge of MITRE ATT&CK framework and vulnerability prioritization methodologies (e.g., EPSS, CVSS v3). * Prior experience within a federal or HHS environment. ## Description * Support vulnerability management and secure configuration operations, ensuring alignment with federal cybersecurity mandates. * Manage, monitor, and monitor vulnerabilities across NIH/HHS systems using tools such as Tenable and coordinate timely remediation activities. * Develop vulnerability prioritization models based on risk, exposure, and asset criticality. * Develop secure configuration baselines and monitoring processes based on CIS Benchmarks. * Ensure compliance with patching timelines and federal vulnerability directives. * Collaborate with infrastructure, application, and security teams to validate remediation actions. * Support preparation of reports for leadership and federal oversight bodies. * Develop KPI metrics for vulnerability and compliance gap closure rates, asset risk scoring, and compliance tracking. ## Related Videos - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) - [Bitcoin SV: The Massively Scaled Blockchain to Meet Developer Needs](https://www.wearedevelopers.com/videos/20-bitcoin-sv-the-massively-scaled-blockchain-to-meet-developer-needs) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [AI in Production: applied AI & enterprise use cases](https://www.wearedevelopers.com/videos/100130-ai-in-production-applied-ai-enterprise-use-cases) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Best Companies to work for in London: Top 25 Companies in 2023](https://www.wearedevelopers.com/magazine/187-best-companies-to-work-for-in-london-top-25-companies-in-2023) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)