Solving big problems, building trust in society, and empowering our clients to shape the future.
IT Audit & Compliance Analyst – Federal Cybersecurity Frameworks
Location
District Of Columbia
Posted
1 day ago
Salary
$98K - $163K / year
Seniority
Senior
Job Description
Job Requirements
- Must be able to OBTAIN and MAINTAIN a Federal or DoD "PUBLIC TRUST"; candidates must obtain approved adjudication of their PUBLIC TRUST prior to onboarding with Guidehouse.
- Candidates with an ACTIVE PUBLIC TRUST or SUITABILITY are preferred.
- Bachelor’s degree in information systems, Cybersecurity, Computer Science, Accounting/IS Audit, or a discipline related to this project.
- Three (3) or more years of IT Audit & Compliance experience.
- Experience implementing or assessing NIST SP 800‑53 control requirements in production environments (cloud and/or on‑prem).
- Knowledge of federal cybersecurity and audit frameworks. (This could include NIST SP 800‑37 (RMF), NIST SP 800‑171, FISMA, FISCAM, OMB Circular A‑123, or FedRAMP.)
- Demonstrated ability to create accurate, assessor‑ready documentation (This could include: SSPs, procedures/SOPs, control narratives, POA&Ms, ConMon reporting, evidence packages).
- Preference will be given to candidate's located within the DC Metropolitan area.
Benefits
- Medical, Rx, Dental & Vision Insurance
- Personal and Family Sick Time & Company Paid Holidays
- Position may be eligible for a discretionary variable incentive bonus
- Parental Leave and Adoption Assistance
- 401(k) Retirement Plan
- Basic Life & Supplemental Life
- Health Savings Account, Dental/Vision & Dependent Care Flexible Spending Accounts
- Short-Term & Long-Term Disability
- Student Loan PayDown
- Tuition Reimbursement, Personal Development & Learning Opportunities
- Skills Development & Certifications
- Employee Referral Program
- Corporate Sponsored Events & Community Outreach
- Emergency Back-Up Childcare Program
- Mobility Stipend
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
The engineer will act as the essential bridge between security and engineering teams, ensuring security is deeply integrated into development processes by participating in RFCs, PRDs, and code reviews. Key duties include providing adversarial threat analysis on features, taking ownership of code vulnerabilities, managing Cloudflare/WAF controls, and uplifting the SIEM system.
Cyber Security Specialist supporting NETT Warrior Project with PEO Soldier
Director managing AWS cloud security operations at Caesars Entertainment
Specialist Engineer designing and deploying enterprise-level Cybersecurity solutions at Caesars Entertainment



