Guidehouse logo
GuidehousePosted 2 weeks ago

Security Assessor

On-siteMcLean, Virginia, United States

Full TimeLarge

Job Summary

Conduct security and privacy control assessments for public-sector systems by evaluating control effectiveness, validating evidence, and contributing to formal assessment documentation. Review security documentation and technical evidence, then validate control implementation through evidence inspection, architecture reviews, and interviews with system owners. Contribute to assessment artifacts including SSP updates, SARs, ISRAs, and POA&Ms while documenting results and articulating control gaps. Maintain assessment independence and objectivity throughout the process. Identify opportunities to improve efficiency through standardization, tooling, or automation of evidence collection. Support the use of data-driven or AI-assisted techniques to enhance analysis and reporting. Requires minimum of three years of experience supporting security control assessments, a bachelor's degree, and US citizenship.

Required Qualifications

  • Minimum of THREE (3) years of overall work experience ideally in supporting security control assessments, audits, or authorization activities
  • Bachelors Degree from an accredited university
  • US Citizenship is contractually required
  • Hands‐on experience contributing to formal security assessment documentation (SSPs, SARs, POA&Ms, or equivalents)
  • Working knowledge of NIST SP 800‐53 security and privacy controls
  • Understanding of risk‐based assessment concepts
  • Ability to analyze assessment evidence and clearly document findings

Desired Qualifications

  • Experience supporting government or other regulated environments
  • Exposure to CMS, healthcare, or public‐sector security compliance frameworks
  • Familiarity with A&A, RMF, or Security Control Assessment processes
  • Relevant certifications (CISA, CISSP, CISM, Security+, or similar)
  • Prior background in or exposure to security engineering, cloud security, or system implementation
  • Familiarity with modern architectures (cloud platforms, IAM, logging/monitoring, APIs) and how controls are implemented in those environments
  • Exposure to automation tools, scripting, or GRC platforms supporting assessment or compliance activities
  • Interest in applying AI/automation to improve audit readiness, evidence analysis, or continuous monitoring processes

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce