Senior Risk Management Framework (A&A) Consultant
On-site · McLean, Virginia, United States
Job Summary
Senior RMF / A&A Consultant responsible for executing cybersecurity authorization and compliance activities across cloud and enterprise systems. Leads development of RMF artifacts and A&A documentation (SSPs, control implementation matrices, SARs, POA&Ms, risk acceptance materials), supports cloud service authorization leveraging FedRAMP and agency requirements, coordinates A&A activities with System Owners, ISSOs, IAMs, and third-party assessors, and supports 3PAO readiness, SAR development, and audit documentation. Tracks audit findings and remediation, develops recurring audit progress reports for government leadership, maintains compliance repositories, and ensures documentation remains audit-ready. The role requires ability to obtain and maintain a Federal or DoD Public Trust, with active Public Trust or suitability experience preferred. Travel up to 10% is expected. Strong knowledge of NIST RMF and federal A&A processes, SP 800-37/53, FISMA, and FedRAMP, and experience supporting audits and POA&M management. Mentoring junior team members and operating independently on complex assignments are expected. Optional certifications such as Security+, CAP, or equivalent are a plus. We value experience with ServiceNow, GRC platforms, or audit-tracking tools and familiarity with cloud or financial system authorizations. The position is with Guidehouse, an equal opportunity employer working with government and commercial sectors."},
Required Qualifications
- Must be able to OBTAIN and MAINTAIN a Federal or DoD Public Trust
- Active PUBLIC TRUST or SUITABILITY preferred
- Minimum 3 years hands-on experience with NIST RMF and federal A&A processes
- Strong working knowledge of NIST SP 800-37, 800-53, FISMA, and FedRAMP
- Experience supporting audits, evidence collection, and POA&M management
- Ability to translate technical security requirements into clear, compliant documentation
- Strong organizational, communication, and stakeholder coordination skills
- Security+, CAP, or equivalent certification preferred
- Experience supporting third party assessments or SAR development
- Familiarity with ServiceNow, GRC platforms, or audit tracking tools
- Experience supporting cloud or financial system authorizations
Apply with one swipe on Sorce. We auto-fill applications and apply on your behalf — no cover letters, no 40-minute forms.
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.