Guidehouse logo
Guidehouse

Solving big problems, building trust in society, and empowering our clients to shape the future.

Security Lead

Security AnalystSecurity AnalystFull TimeRemoteLeadTeam 10,001+Since 2018H1B SponsorCompany SiteLinkedIn

Location

United States

Posted

51 days ago

Salary

$130K - $216K / year

Seniority

Lead

Job Description

Security Lead

Guidehouse

Job Family: Cyber Consulting Travel Required: Up to 10% Clearance Required: Active Secret What You Will Do: - Perform hands-on and advise system development teams, organizations, and clients on cyber governance, risk, and compliance, cloud security, FedRAMP, vulnerability management, policy development, authorization and assessment, and risk management. - Perform comprehensive assessments and reviews of management, operational and technical security controls for audited applications and information systems, subject matter expertise in developing security authorization packages using National Institutes of Standards and Technology (NIST) Publications 800-53A, 800-53, 800-60, 800-30, 800-37, 800-137, FIPS 199, FIPS 200, OMB A-130 Appendix III. - Create and maintain core security artifacts such as System Security Plan (SSP), Plan of Action & Milestones (POA&M), checklists, Security Assessment Plan (SAP), and other documentation in support of the FedRAMP Assessment & Authorization (A&A) process for financial systems. - Leverage Security Risk Management skills and various security assessment tools to perform audits and reviews for Security Compliance, FISMA, A-123, SSAE 16, and Assessment and Authorization. - Provided RMF support towards obtaining an ATO for on-prem and cloud-based systems/applications, to include system categorization, security control selection and tailoring, and supporting the security assessment in accordance with Federal Information Processing Standard (FIPS) 199, NIST SP 800-53, NIST SP 800-60, and NIST SP 800-63. - Identify and collaborate stakeholders to obtain security authorization, including senior management, IT staff, security personnel such as the Authorizing Official, system owners, Information System Security Officers (ISSO), by highlighting potential threats and vulnerabilities that could impact system security. - Perform security control tailoring and apply required overlays beyond the baseline to mitigate risks to acceptable levels. - Coordinated A&A renewal activities with key stakeholders to maintain proper accreditation throughout the life of the system, and lead activities to meet monthly and yearly FedRAMP continuous monitoring requirements. - Ensured security policies, procedures, recommendations comply with FISMA, NIST, Organizational guidelines and technical best practices. - Develop and deliver solutions for establishing security policies and procedures, evaluating enterprise IT security practices, implementing security controls, and identifying and mitigating security risks. - Perform RMF assessment and engage with System Owners and ISSO, providing guidance of evidence needed for security controls, and documenting findings of assessment. What You Will Need: - Minimum of SEVEN (7) years of experience in cybersecurity or information assurance. - Bachelor’s degree in Cybersecurity, Information Technology, or a related field. - Cyber certification: Security+, AWS Certified Solutions Architect, CISSP or CISM - Active and maintained DoD or Federal Secret clearance. - Excellent oral and written communication and presentation skills. - Communicates effectively and demonstrates leadership role with clients and fellow team members. What Would Be Nice To Have: - Certified Cloud Security Professional (CCSP) Certification - Experience managing direct client engagement team to deliver impactful support to Federal clients. - Experience with managing/supporting and/or knowledge of cybersecurity or high value asset program. - Experience developing and maintaining trusted relationships with Federal clients onsite. - Ability to identify obstacles and opportunities that impact the success of plans or initiatives. The annual salary range for this position is $130,000.00-$216,000.00. Compensation decisions depend on a wide range of factors, including but not limited to skill sets, experience and training, security clearances, licensure and certifications, and other business and organizational needs. What We Offer: Guidehouse offers a comprehensive, total rewards package that includes competitive compensation and a flexible benefits package that reflects our commitment to creating a diverse and supportive workplace. Benefits include: - Medical, Rx, Dental & Vision Insurance - Personal and Family Sick Time & Company Paid Holidays - Position may be eligible for a discretionary variable incentive bonus - Parental Leave and Adoption Assistance - 401(k) Retirement Plan - Basic Life & Supplemental Life - Health Savings Account, Dental/Vision & Dependent Care Flexible Spending Accounts - Short-Term & Long-Term Disability - Student Loan PayDown - Tuition Reimbursement, Personal Development & Learning Opportunities - Skills Development & Certifications - Employee Referral Program - Corporate Sponsored Events & Community Outreach - Emergency Back-Up Childcare Program - Mobility Stipend About Guidehouse Guidehouse is an Equal Opportunity Employer–Protected Veterans, Individuals with Disabilities or any other basis protected by law, ordinance, or regulation. Guidehouse will consider for employment qualified applicants with criminal histories in a manner consistent with the requirements of applicable law or ordinance including the Fair Chance Ordinance of Los Angeles and San Francisco. If you have visited our website for information about employment opportunities, or to apply for a position, and you require an accommodation, please contact Guidehouse Recruiting at 1-571-633-1711 or via email at RecruitingAccommodation@guidehouse.com. All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodation. All communication regarding recruitment for a Guidehouse position will be sent from Guidehouse email domains including @guidehouse.com or guidehouse@myworkday.com. Correspondence received by an applicant from any other domain should be considered unauthorized and will not be honored by Guidehouse. Note that Guidehouse will never charge a fee or require a money transfer at any stage of the recruitment process and does not collect fees from educational institutions for participation in a recruitment event. Never provide your banking information to a third party purporting to need that information to proceed in the hiring process. If any person or organization demands money related to a job opportunity with Guidehouse, please report the matter to Guidehouse’s Ethics Hotline. If you want to check the validity of correspondence you have received, please contact recruiting@guidehouse.com. Guidehouse is not responsible for losses incurred (monetary or otherwise) from an applicant’s dealings with unauthorized third parties. Guidehouse does not accept unsolicited resumes through or from search firms or staffing agencies. All unsolicited resumes will be considered the property of Guidehouse and Guidehouse will not be obligated to pay a placement fee.

Related Job Pages

More Security Analyst Jobs

Deutsche Telekom IT Solutions logo

Security Analyst

Deutsche Telekom IT Solutions

As Hungary’s most attractive employer in 2025 (according to Randstad’s representative survey), Deutsche Telekom IT Solutions is a subsidiary of the Deutsche Telekom Group. The company provides a wide portfolio of IT and telecommunications services with more than 5300 employees. We have hundreds of large customers, corporations in Germany and in other European countries. DT-ITS received the Best in Educational Cooperation award from HIPA in 2019, acknowledged as the Most Ethical Multinational Company in 2019. The company continuously develops its four sites in Budapest, Debrecen, Pécs and Szeged and is looking for skilled IT professionals to join its team.

Security Analyst51 days ago
Full TimeRemoteTeam 5,001-10,000

Role Description You don’t want to cry when you hear about WannaCry? Loki isn’t only a German firegod to you? You know what Meltdown/Spectre are, maybe you even know what cryptojacking is? Then the following position is for you! If you join us, your daily tasks will be as follows: - Detection, analysis and management of security incidents - Making and evaluating reports - Monitoring the customer’s environment - Tracking IT security issues (vulnerabilities, 0day exploits, malware) and making/fitting the rules for detecting them in the client's environment - Change and incident management - Analysis of malicious code in sandbox Qualifications - If you love to learn and you have a need for continuous development - If you know network models (OSI, TCP/IP) - If you know how operating systems work (Windows, Linux) - You speak English on business level - You are fluent in Hungarian - It's not a problem if you have to spend about one-third of your working hours in shifts - You have basic knowledge of script languages: python, bash, JS and so on - You are familiar with the logs of security systems: proxy, AV, WAF, IDS, Webserver, DNS - You've done PCAP analysis Additional Information - Please be informed that our remote working possibility is only available within Hungary due to European taxation regulation. Company Description As Hungary’s most attractive employer in 2025 (according to Randstad’s representative survey), Deutsche Telekom IT Solutions is a subsidiary of the Deutsche Telekom Group. The company provides a wide portfolio of IT and telecommunications services with more than 5300 employees. We have hundreds of large customers, corporations in Germany and in other European countries. DT-ITS received the Best in Educational Cooperation award from HIPA in 2019, acknowledged as the Most Ethical Multinational Company in 2019. The company continuously develops its four sites in Budapest, Debrecen, Pécs and Szeged and is looking for skilled IT professionals to join its team.

Hungary
Full TimeRemoteTeam 10,001+Since 2016H1B Sponsor

• Ensure adherence to all organizational compliance frameworks, regulations, and security guidelines. • Provide guidance and support in implementing controls and processes, promoting a culture of compliance throughout the organization. • Coordinate internal and external audits, serving as the primary point of contact and ensuring timely and accurate responses to audit requests. • Work closely with team members to ensure timely delivery of evidence requirements for compliance purposes. • Participate in both internal and external audits, answering questions, and showcasing the controls in place to meet compliance obligations. • Assist in implementing and using LogicGate as the organization's system of truth for GRC-related controls. • Collaborate with cross-functional teams, such as IT, legal, and Finance, to develop and maintain effective compliance programs aligned with various compliance frameworks and security guidelines. • Identify and assess compliance risks and develop strategies to mitigate them in line with applicable compliance frameworks and security guidelines. • Conduct regular reviews and evaluations of compliance controls, processes, and procedures to identify areas for improvement and ensure alignment with relevant compliance frameworks and security guidelines. • Stay up to date with regulatory changes, industry best practices, and evolving compliance requirements to ensure the organization's compliance strategies are current and effective.

India
Job Closed
Full TimeRemoteTeam 10,001+Since 2016H1B Sponsor

• Assist in scanning, identifying, and documenting vulnerabilities across cloud, web applications, endpoints, and on-premises infrastructure • Support prioritization and remediation efforts by working with relevant teams to address identified vulnerabilities • Develop and maintain an accurate inventory of infrastructure components, including domains, applications, and systems, ensuring proper ownership and accountability • Regularly review and contribute to the improvement of Fluke’s security posture and score by ensuring vulnerabilities are addressed promptly and security best practices are followed • Work alongside the Product Security Lead to identify and remediate vulnerabilities in digital products and external-facing assets • Partner with cross-functional teams to implement security controls and enhance visibility into potential risks • Review, analyze, and triage security alerts related to vulnerabilities, escalating critical issues to the appropriate teams • Track and report on vulnerability management metrics, providing regular updates to leadership and stakeholders • Contribute to the creation and improvement of documentation for vulnerability management processes, tools, and policies • Support efforts to streamline vulnerability management workflows and implement automation where possible to enhance efficiency

India
Job Closed
Full TimeRemoteTeam 51-200Since 1991H1B No Sponsor

• Provide continuous monitoring services for CloudWave's Managed Security Services (MSS) program • Analyze events from various data sources including client devices and network sensors • Manage security alerts leveraging automation • Conduct malware analysis and investigate security incidents • Perform vulnerability assessments to identify and remediate security gaps

United States
Job Closed