{"schemaVersion":"jobsearcher.job.v1","id":"7adc0f2c84d5c19f43edc3eb","url":"https://jobsearcher.com/jobs/7adc0f2c84d5c19f43edc3eb","canonicalUrl":"https://jobsearcher.com/jobs/7adc0f2c84d5c19f43edc3eb","title":"IT Security Auditor - Consultant","description":"Job Family:\n\nTechnology Consulting\n\nTravel Required:\n\nUp to 10%\n\nClearance Required:\n\nActive Top Secret SCI with Polygraph\n\nWhat You Will Do:\n\nThe IT Security Auditor will lead stakeholder engagement and technical delivery for efforts supporting federal agencies with IT controls assessments and program evaluations. This is an ideal role for someone with an information security and assurance or IT audit background who is looking to utilize their skills to work with the federal government to analyze IT control weaknesses, identify root causes, and develop remediation plans.\n\nResponsibilities include some or all of the following:\n\nPerforming assessments of IT controls using industry-standard guidance and leading best practices\n\nConducting interviews and discussions with a variety of client stakeholders, including IT system personnel such as Information System Security Officers (ISSOs) and system administrators\n\nReviewing and analyzing documents and artifacts to assist in IT controls testing such as system security plans, SOPs, audit logs, configuration scans, and vulnerability scans\n\nEvaluating the implementation and effectiveness of IT controls using provided artifacts against federal requirements, industry guidance, and leading best practices\n\nDocumenting the results of IT controls testing in a consistent and high-quality manner that would allow others to review and understand the results\n\nSummarizing and communicating IT controls assessment results to a variety of client stakeholders, including senior leadership\n\nUnderstanding and analyzing known IT control weaknesses, identifying root causes, and developing detailed remediation plans\n\nProviding subject matter expertise to client personnel on a wide range of matters relating to IT security and assurance\n\nResponding to ad-hoc IT security-related requests from client personnel\n\nPlanning and executing day-to-day activities of IT assessments and evaluations individually and for the team\n\nMentoring junior team members in day-to-day IT controls testing responsibilities\n\nWhat You Will Need:\n\nAn ACTIVE and MAINTAINED TS/SCI Federal or DoD security clearance with a COUNTERINTELLIGENCE (CI) polygraph\n\nBachelor’s Degree in a Technical or Business field\n\nTwo (2) + years' experience providing IT consulting. Experience should include but not be limited to:\n\nExperience in consulting with the federal government to include senior government clients\n\nUnderstanding and knowledge of federal information security and assurance laws, requirements, and guidance (i.e. FISMA, NIST SP 800, FISCAM)\n\nWhat Would Be Nice To Have:\n\nRelevant certification such as the Certified Information Systems Auditor (CISA) or Certified Information Security Manager (CISM)\n\nDemonstrated knowledge and experience in IT risk and controls through IT audits, IT controls assessments, or IT security reviews\n\nDemonstrated ability and working knowledge of: FISMA, NIST SP 800 series, FISCAM, other relevant federal information assurance laws, regulations, and guidance\n\nExperience performing: FISMA, OMB Circular A-123, or similar internal control assessments\n\nExperience implementing or auditing access and account management principles, including authorization, provisioning, recertification, and separation of duties\n\nExperience implementing or auditing contingency planning principles, including backups, testing of backups, and alternate processing sites\n\nExperience implementing or auditing configuration management principles, including configuration baseline concepts, baseline deviations, baseline maintenance, change control, and monitoring, and industry-accepted configuration settings such as DISA STIGs\n\nExperience performing audit logging and monitoring, including generation of audit logs, use of audit log aggregation and analysis tools, and audit log monitoring and review\n\nWhat We Offer:\n\nGuidehouse offers a comprehensive, total rewards package that includes competitive compensation and a flexible benefits package that reflects our commitment to creating a diverse and supportive workplace.\n\nBenefits include:\n\nMedical, Rx, Dental & Vision Insurance\n\nPersonal and Family Sick Time & Company Paid Holidays\n\nPosition may be eligible for a discretionary variable incentive bonus\n\nParental Leave and Adoption Assistance\n\n401(k) Retirement Plan\n\nBasic Life & Supplemental Life\n\nHealth Savings Account, Dental/Vision & Dependent Care Flexible Spending Accounts\n\nShort-Term & Long-Term Disability\n\nStudent Loan PayDown\n\nTuition Reimbursement, Personal Development & Learning Opportunities\n\nSkills Development & Certifications\n\nEmployee Referral Program\n\nCorporate Sponsored Events & Community Outreach\n\nEmergency Back-Up Childcare Program\n\nMobility Stipend\n\nAbout Guidehouse\n\nGuidehouse is an Equal Opportunity Employer–Protected Veterans, Individuals with Disabilities or any other basis protected by law, ordinance, or regulation.\n\nGuidehouse will consider for employment qualified applicants with criminal histories in a manner consistent with the requirements of applicable law or ordinance including the Fair Chance Ordinance of Los Angeles and San Francisco.\n\nIf you have visited our website for information about employment opportunities, or to apply for a position, and you require an accommodation, please contact Guidehouse Recruiting at 1-571-633-1711 or via email at RecruitingAccommodation@guidehouse.com. All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodation.\n\nAll communication regarding recruitment for a Guidehouse position will be sent from Guidehouse email domains including @guidehouse.com or guidehouse@myworkday.com. Correspondence received by an applicant from any other domain should be considered unauthorized and will not be honored by Guidehouse. Note that Guidehouse will never charge a fee or require a money transfer at any stage of the recruitment process and does not collect fees from educational institutions for participation in a recruitment event. Never provide your banking information to a third party purporting to need that information to proceed in the hiring process.\n\nIf any person or organization demands money related to a job opportunity with Guidehouse, please report the matter to Guidehouse’s Ethics Hotline. If you want to check the validity of correspondence you have received, please contact recruiting@guidehouse.com. Guidehouse is not responsible for losses incurred (monetary or otherwise) from an applicant’s dealings with unauthorized third parties.\n\nGuidehouse does not accept unsolicited resumes through or from search firms or staffing agencies. All unsolicited resumes will be considered the property of Guidehouse and Guidehouse will not be obligated to pay a placement fee.","company":"Guidehouse","rawCompany":"guidehouse","city":"McLean","state":"VA","isRemote":false,"isActive":true,"createdAt":"2026-08-28T06:54:05.138Z","occupations":[{"code":"15-1212.00","title":"Information Security Analysts","slug":"information-security-analysts"},{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"},{"code":"13-1199.07","title":"Security Management Specialists","slug":"security-management-specialists"}],"industries":[{"code":"541690","title":"Other Scientific and Technical Consulting Services","slug":"other-scientific-and-technical-consulting-services"},{"code":"541611","title":"Administrative Management and General Management Consulting Services","slug":"administrative-management-and-general-management-consulting-services"},{"code":"541618","title":"Other Management Consulting Services","slug":"other-management-consulting-services"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"IT Security Auditor - Consultant","description":"Job Family:\n\nTechnology Consulting\n\nTravel Required:\n\nUp to 10%\n\nClearance Required:\n\nActive Top Secret SCI with Polygraph\n\nWhat You Will Do:\n\nThe IT Security Auditor will lead stakeholder engagement and technical delivery for efforts supporting federal agencies with IT controls assessments and program evaluations. This is an ideal role for someone with an information security and assurance or IT audit background who is looking to utilize their skills to work with the federal government to analyze IT control weaknesses, identify root causes, and develop remediation plans.\n\nResponsibilities include some or all of the following:\n\nPerforming assessments of IT controls using industry-standard guidance and leading best practices\n\nConducting interviews and discussions with a variety of client stakeholders, including IT system personnel such as Information System Security Officers (ISSOs) and system administrators\n\nReviewing and analyzing documents and artifacts to assist in IT controls testing such as system security plans, SOPs, audit logs, configuration scans, and vulnerability scans\n\nEvaluating the implementation and effectiveness of IT controls using provided artifacts against federal requirements, industry guidance, and leading best practices\n\nDocumenting the results of IT controls testing in a consistent and high-quality manner that would allow others to review and understand the results\n\nSummarizing and communicating IT controls assessment results to a variety of client stakeholders, including senior leadership\n\nUnderstanding and analyzing known IT control weaknesses, identifying root causes, and developing detailed remediation plans\n\nProviding subject matter expertise to client personnel on a wide range of matters relating to IT security and assurance\n\nResponding to ad-hoc IT security-related requests from client personnel\n\nPlanning and executing day-to-day activities of IT assessments and evaluations individually and for the team\n\nMentoring junior team members in day-to-day IT controls testing responsibilities\n\nWhat You Will Need:\n\nAn ACTIVE and MAINTAINED TS/SCI Federal or DoD security clearance with a COUNTERINTELLIGENCE (CI) polygraph\n\nBachelor’s Degree in a Technical or Business field\n\nTwo (2) + years' experience providing IT consulting. Experience should include but not be limited to:\n\nExperience in consulting with the federal government to include senior government clients\n\nUnderstanding and knowledge of federal information security and assurance laws, requirements, and guidance (i.e. FISMA, NIST SP 800, FISCAM)\n\nWhat Would Be Nice To Have:\n\nRelevant certification such as the Certified Information Systems Auditor (CISA) or Certified Information Security Manager (CISM)\n\nDemonstrated knowledge and experience in IT risk and controls through IT audits, IT controls assessments, or IT security reviews\n\nDemonstrated ability and working knowledge of: FISMA, NIST SP 800 series, FISCAM, other relevant federal information assurance laws, regulations, and guidance\n\nExperience performing: FISMA, OMB Circular A-123, or similar internal control assessments\n\nExperience implementing or auditing access and account management principles, including authorization, provisioning, recertification, and separation of duties\n\nExperience implementing or auditing contingency planning principles, including backups, testing of backups, and alternate processing sites\n\nExperience implementing or auditing configuration management principles, including configuration baseline concepts, baseline deviations, baseline maintenance, change control, and monitoring, and industry-accepted configuration settings such as DISA STIGs\n\nExperience performing audit logging and monitoring, including generation of audit logs, use of audit log aggregation and analysis tools, and audit log monitoring and review\n\nWhat We Offer:\n\nGuidehouse offers a comprehensive, total rewards package that includes competitive compensation and a flexible benefits package that reflects our commitment to creating a diverse and supportive workplace.\n\nBenefits include:\n\nMedical, Rx, Dental & Vision Insurance\n\nPersonal and Family Sick Time & Company Paid Holidays\n\nPosition may be eligible for a discretionary variable incentive bonus\n\nParental Leave and Adoption Assistance\n\n401(k) Retirement Plan\n\nBasic Life & Supplemental Life\n\nHealth Savings Account, Dental/Vision & Dependent Care Flexible Spending Accounts\n\nShort-Term & Long-Term Disability\n\nStudent Loan PayDown\n\nTuition Reimbursement, Personal Development & Learning Opportunities\n\nSkills Development & Certifications\n\nEmployee Referral Program\n\nCorporate Sponsored Events & Community Outreach\n\nEmergency Back-Up Childcare Program\n\nMobility Stipend\n\nAbout Guidehouse\n\nGuidehouse is an Equal Opportunity Employer–Protected Veterans, Individuals with Disabilities or any other basis protected by law, ordinance, or regulation.\n\nGuidehouse will consider for employment qualified applicants with criminal histories in a manner consistent with the requirements of applicable law or ordinance including the Fair Chance Ordinance of Los Angeles and San Francisco.\n\nIf you have visited our website for information about employment opportunities, or to apply for a position, and you require an accommodation, please contact Guidehouse Recruiting at 1-571-633-1711 or via email at RecruitingAccommodation@guidehouse.com. All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodation.\n\nAll communication regarding recruitment for a Guidehouse position will be sent from Guidehouse email domains including @guidehouse.com or guidehouse@myworkday.com. Correspondence received by an applicant from any other domain should be considered unauthorized and will not be honored by Guidehouse. Note that Guidehouse will never charge a fee or require a money transfer at any stage of the recruitment process and does not collect fees from educational institutions for participation in a recruitment event. Never provide your banking information to a third party purporting to need that information to proceed in the hiring process.\n\nIf any person or organization demands money related to a job opportunity with Guidehouse, please report the matter to Guidehouse’s Ethics Hotline. If you want to check the validity of correspondence you have received, please contact recruiting@guidehouse.com. Guidehouse is not responsible for losses incurred (monetary or otherwise) from an applicant’s dealings with unauthorized third parties.\n\nGuidehouse does not accept unsolicited resumes through or from search firms or staffing agencies. All unsolicited resumes will be considered the property of Guidehouse and Guidehouse will not be obligated to pay a placement fee.","datePosted":"2026-08-28T06:54:05.138Z","dateModified":"2026-08-28T06:54:05.138Z","hiringOrganization":{"@type":"Organization","name":"Guidehouse","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"McLean","addressRegion":"VA","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"7adc0f2c84d5c19f43edc3eb"},"url":"https://jobsearcher.com/jobs/7adc0f2c84d5c19f43edc3eb"}}