1

Cyber Consulting Jobs (NOW HIRING)

Business Consulting Services * Administrative and General Management Services * Careers * Employee ... Cyber Intelligence Analyst Level : Mid Location: Joint Base Anacostia-Bolling Remote Work: No ...

Experience: 7+ years in cyber risk analytics, cybersecurity consulting, or insurance-related roles; * Technical Skills: Familiarity with cyber risk modeling tools, threat intelligence platforms, and ...

next page

Showing results 1-20

Cyber Consulting information

See salary details

$68.5K

$128.9K

$162K

How much do cyber consulting jobs pay per year?

As of Jun 18, 2026, the average yearly pay for cyber consulting in the United States is $128,882.00, according to ZipRecruiter salary data. Most workers in this role earn between $113,000.00 and $146,500.00 per year, depending on experience, location, and employer.

How much do cybersecurity consultants earn?

Cybersecurity consultants typically earn between $70,000 and $130,000 annually, depending on experience, certifications, and location. Senior consultants with specialized skills or certifications like CISSP or CISA can earn higher salaries, often exceeding $150,000. Compensation also varies based on whether they work as freelancers, in consulting firms, or within organizations.

Is 40 too old for cyber security?

Cyber consulting and cybersecurity roles do not have age restrictions; individuals can enter the field at any age. Success depends on skills, certifications, and experience, which can be developed through training and continuous learning regardless of age.

What does a cyber consultant do?

A cyber consultant assesses and improves an organization's cybersecurity posture by identifying vulnerabilities, developing security strategies, and implementing protective measures. They often use tools like risk assessments, penetration testing, and security frameworks, and may hold certifications such as CISSP or CISA. Their work involves analyzing systems, advising on best practices, and ensuring compliance with security standards.

Can you make $500,000 a year in cyber security?

Cyber consulting roles in cybersecurity can reach or exceed $500,000 annually for senior-level professionals, especially those with extensive experience, specialized skills, and certifications like CISSP or CISA. High earnings are often associated with leadership positions, consulting firms, or roles involving complex security architecture and strategic planning. However, such salaries are typically achieved after many years of experience and proven expertise in the field.

What is the difference between Cyber Consulting vs Cyber Security Analyst?

AspectCyber ConsultingCyber Security Analyst
Required CredentialsCertifications like CISSP, CISA, CISM; relevant degreesCertifications like CompTIA Security+, CISSP; relevant degrees
Work EnvironmentAdvisory roles, client sites, consulting firmsIn-house security teams, IT departments
Employer & Industry UsageConsulting firms, corporations, government agenciesOrganizations with dedicated security teams
Common Search & ComparisonFocuses on strategic security solutions and risk managementFocuses on monitoring, threat detection, and incident response

Cyber Consulting involves advising organizations on security strategies, compliance, and risk management, often working with multiple clients. Cyber Security Analysts focus on implementing security measures, monitoring systems, and responding to threats within a specific organization. While both roles require similar certifications and work in the cybersecurity industry, their responsibilities and work environments differ significantly.

More about Cyber Consulting jobs
What cities are hiring for Cyber Consulting jobs? Cities with the most Cyber Consulting job openings:
What states have the most Cyber Consulting jobs? States with the most job openings for Cyber Consulting jobs include:
Infographic showing various Cyber Consulting job openings in the United States as of June 2026, with employment types broken down into 33% Internship, 33% Full Time, and 34% Contract. Highlights an 33% In-person, and 67% Remote job distribution, with an average salary of $128,882 per year, or $62 per hour.

Senior Cyber Risk and Vulnerability Assessor

Guidehouse

Mclean, VA • On-site

Full-time

Medical, Dental, Vision, Life, Retirement

Posted 27 days ago


Guidehouse rating

7.5

Company rating: 7.5 out of 10

Based on 26 frontline employees who took The Breakroom Quiz

37th of 57 rated business consultants


Job description

Job Family:
Cyber Consulting
Travel Required:
Up to 10%
Clearance Required:
Active Public Trust
What You Will Do:
Guidehouse's Cybersecurity practice helps federal and regulated clients assess, manage, and reduce cybersecurity risk across high-impact systems and mission-critical environments. Our teams combine deep technical assessment expertise with strong knowledge of federal risk management and authorization processes to support informed risk decisions and system authorization outcomes.
As a Senior Cyber Risk and Vulnerability Assessor , you will lead comprehensive security control assessments for complex, high-impact, and enterprise systems across on-premises, cloud, and hybrid environments. You will oversee assessment strategy and execution, validate remediation effectiveness, and provide authoritative risk determinations in support of Authorizing Officials (AOs) and senior agency leadership.
This role is ideal for a senior assessment professional with strong technical depth, proven leadership experience, and the ability to translate assessment results into clear, defensible risk recommendations aligned to federal cybersecurity requirements.
This role positions you as a senior assessment authority within Guidehouse's Cybersecurity practice, accountable for delivering high-quality security assessments that enable informed authorization decisions and strengthen enterprise risk posture.
Key Responsibilities
  • Lead and oversee security control assessments for moderate- and high-impact information systems, including complex enterprise and mission-critical environments.
  • Direct assessment planning and control testing strategies, ensuring appropriate coverage, rigor, and consistency with system architectures and risk profiles.
  • Conduct and supervise cloud, on-premises, and hybrid system assessments, including IaaS, PaaS, and SaaS environments.
  • Validate the effectiveness of remediation actions, including retesting controls and verifying closure of findings.
  • Analyze assessment results and develop risk determinations, observations, and recommendations suitable for senior decision-makers and AOs.
  • Ensure assessments are executed in alignment with applicable federal frameworks and mandates, including: FISMA, NIST SP 800-37, NIST SP 800-53, OMB guidance and memoranda, Agency-specific cybersecurity policies and procedures.
  • Oversee development and quality of assessment deliverables, including security assessment plans (SAPs), security assessment reports (SARs), POA&Ms, and authorization support documentation.
  • Provide guidance on risk acceptance, remediation prioritization, and continuous monitoring strategies.
  • Serve as a trusted advisor to system owners, ISSOs, and security engineers on assessment findings and control implementation improvements.
  • Coordinate assessment activities across multiple systems or programs, ensuring schedule adherence and stakeholder alignment.
  • Mentor and develop assessors and consultants; provide technical review and quality assurance for assessment work products.
  • Support practice growth through proposal development, technical contributions, and assessment methodology development.

What You Will Need:
  • Must be able to OBTAIN and MAINTAIN a Federal or DoD "PUBLIC TRUST"; candidates must obtain approved adjudication of their PUBLIC TRUST prior to onboarding with Guidehouse. Candidates with an ACTIVE PUBLIC TRUST or SUITABILITY and maintain an active HHS/NIH clearance are preferred.
  • Bachelor's degree in Cybersecurity, Information Systems, Computer Science, or a related field (additional relevant experience may substitute for formal education).
  • Minimum of NINE (9) or more years of progressively responsible experience performing or leading security control assessments, audits, or cybersecurity risk assessments.
  • Required certifications:
    • Certified in Governance, Risk and Compliance (CGRC) (active)
    • Certified Information Systems Security Professional (CISSP) (active)
  • Demonstrated experience conducting assessments under the NIST RMF.
  • Experience assessing high-impact or high-value asset (HVA) systems.
  • Strong understanding of security control implementation and assessment across enterprise, cloud, and hybrid architectures.
  • Proven ability to communicate risk clearly and effectively to technical and executive stakeholders, including Authorizing Officials.
  • Excellent written and verbal communication skills, including formal assessment reporting and executive briefings.

What Would Be Nice to Have:
  • Experience with continuous monitoring programs and control inheritance models.
  • Familiarity with major cloud service providers and their shared responsibility models.
  • Additional certifications such as CISM, CISA, CCSP, HVA Assessment Lead/Technical Lead/Operator, or cloud security credentials.
  • Prior consulting experience with responsibility for delivery quality, stakeholder management, and team leadership.

What We Offer:
Guidehouse offers a comprehensive, total rewards package that includes competitive compensation and a flexible benefits package that reflects our commitment to creating a diverse and supportive workplace.
Benefits include:
  • Medical, Rx, Dental & Vision Insurance
  • Personal and Family Sick Time & Company Paid Holidays
  • Position may be eligible for a discretionary variable incentive bonus
  • Parental Leave and Adoption Assistance
  • 401(k) Retirement Plan
  • Basic Life & Supplemental Life
  • Health Savings Account, Dental/Vision & Dependent Care Flexible Spending Accounts
  • Short-Term & Long-Term Disability
  • Student Loan PayDown
  • Tuition Reimbursement, Personal Development & Learning Opportunities
  • Skills Development & Certifications
  • Employee Referral Program
  • Corporate Sponsored Events & Community Outreach
  • Emergency Back-Up Childcare Program
  • Mobility Stipend

About Guidehouse
Guidehouse is an Equal Opportunity Employer-Protected Veterans, Individuals with Disabilities or any other basis protected by law, ordinance, or regulation.
Guidehouse will consider for employment qualified applicants with criminal histories in a manner consistent with the requirements of applicable law or ordinance including the Fair Chance Ordinance of Los Angeles and San Francisco.
If you have visited our website for information about employment opportunities, or to apply for a position, and you require an accommodation, please contact Guidehouse Recruiting at 1-571-633-1711 or via email at RecruitingAccommodation@guidehouse.com. All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodation.
All communication regarding recruitment for a Guidehouse position will be sent from Guidehouse email domains including @guidehouse.com or guidehouse@myworkday.com. Correspondence received by an applicant from any other domain should be considered unauthorized and will not be honored by Guidehouse. Note that Guidehouse will never charge a fee or require a money transfer at any stage of the recruitment process and does not collect fees from educational institutions for participation in a recruitment event. Never provide your banking information to a third party purporting to need that information to proceed in the hiring process.
If any person or organization demands money related to a job opportunity with Guidehouse, please report the matter to Guidehouse's Ethics Hotline. If you want to check the validity of correspondence you have received, please contact recruiting@guidehouse.com. Guidehouse is not responsible for losses incurred (monetary or otherwise) from an applicant's dealings with unauthorized third parties.
Guidehouse does not accept unsolicited resumes through or from search firms or staffing agencies. All unsolicited resumes will be considered the property of Guidehouse and Guidehouse will not be obligated to pay a placement fee.

What Guidehouse employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom