As a Senior Cyber Risk and Vulnerability Assessor , you will lead comprehensive security control ... This role positions you as a senior assessment authority within Guidehouse's Cybersecurity practice ...
As a Senior Cyber Risk and Vulnerability Assessor , you will lead comprehensive security control ... This role positions you as a senior assessment authority within Guidehouse's Cybersecurity practice ...
As a Senior Cyber Risk and Vulnerability Assessor , you will lead comprehensive security control ... This role positions you as a senior assessment authority within Guidehouse's Cybersecurity practice ...
As a Senior Cyber Risk and Vulnerability Assessor , you will lead comprehensive security control ... This role positions you as a senior assessment authority within Guidehouse's Cybersecurity practice ...
Sr. Cyber Analyst
$97K - $125K/yr
Provides recommendations to activity leadership on processes and methodologies to assess cybersecurity risk on information systems. Works with other Cyber Analysts, SMEs, and SCA-Rs to ensure that ...
Quick apply
Sr. Cyber Analyst
$97K - $125K/yr
Provides recommendations to activity leadership on processes and methodologies to assess cybersecurity risk on information systems. Works with other Cyber Analysts, SMEs, and SCA-Rs to ensure that ...
Cyber Risk Analyst SME
Arlington, VA · On-site +1
Required Qualifications: * 10+ years of experience in cybersecurity risk assessment, vulnerability ... analysis, or cyber mission assurance. * Deep knowledge of NIST SP 800-30, NIST Risk Management ...
Cyber Risk Analyst SME
Arlington, VA · On-site +1
Required Qualifications: * 10+ years of experience in cybersecurity risk assessment, vulnerability ... analysis, or cyber mission assurance. * Deep knowledge of NIST SP 800-30, NIST Risk Management ...
... assess and mitigate cybersecurity risk on information technology within the SCA's appointed authorization boundary. • Works with other Cyber Analysts, SMEs, and SCARs to ensure that all ...
... assess and mitigate cybersecurity risk on information technology within the SCA's appointed authorization boundary. • Works with other Cyber Analysts, SMEs, and SCARs to ensure that all ...
Sr. Analyst, Cybersecurity
$99K - $127K/yr
You will assist the Cybersecurity, technology, compliance, and information risk teams in ... Perform information security risk assessments, understand threats, vulnerabilities and exposures ...
Sr. Analyst, Cybersecurity
$99K - $127K/yr
You will assist the Cybersecurity, technology, compliance, and information risk teams in ... Perform information security risk assessments, understand threats, vulnerabilities and exposures ...
Sr. Analyst, Cybersecurity
Richmond, VA · On-site
$99K - $128K/yr
You will assist the Cybersecurity, technology, compliance, and information risk teams in ... Perform information security risk assessments, understand threats, vulnerabilities and exposures ...
Sr. Analyst, Cybersecurity
Richmond, VA · On-site
$99K - $128K/yr
You will assist the Cybersecurity, technology, compliance, and information risk teams in ... Perform information security risk assessments, understand threats, vulnerabilities and exposures ...
Sr. Analyst, Cybersecurity
Richmond, VA · On-site
$99K - $128K/yr
You will assist the Cybersecurity, technology, compliance, and information risk teams in ... Perform information security risk assessments, understand threats, vulnerabilities and exposures ...
Sr. Analyst, Cybersecurity
Richmond, VA · On-site
$99K - $128K/yr
You will assist the Cybersecurity, technology, compliance, and information risk teams in ... Perform information security risk assessments, understand threats, vulnerabilities and exposures ...
Program Risk Manager
Herndon, VA · On-site
$86K - $138K/yr
Conduct structured risk assessments for proposals, program changes, acquisitions, policy updates, and major milestones to quantify impacts to cost, schedule, performance, cybersecurity, and ...
Program Risk Manager
Herndon, VA · On-site
$86K - $138K/yr
Conduct structured risk assessments for proposals, program changes, acquisitions, policy updates, and major milestones to quantify impacts to cost, schedule, performance, cybersecurity, and ...
Program Risk Manager
Herndon, VA · On-site
$86K - $138K/yr
Conduct structured risk assessments for proposals, program changes, acquisitions, policy updates, and major milestones to quantify impacts to cost, schedule, performance, cybersecurity, and ...
Program Risk Manager
Herndon, VA · On-site
$86K - $138K/yr
Conduct structured risk assessments for proposals, program changes, acquisitions, policy updates, and major milestones to quantify impacts to cost, schedule, performance, cybersecurity, and ...
Program Risk Manager
$86K - $138K/yr
Conduct structured risk assessments for proposals, program changes, acquisitions, policy updates, and major milestones to quantify impacts to cost, schedule, performance, cybersecurity, and ...
Program Risk Manager
$86K - $138K/yr
Conduct structured risk assessments for proposals, program changes, acquisitions, policy updates, and major milestones to quantify impacts to cost, schedule, performance, cybersecurity, and ...
Risk - Business Analyst
Merrifield, VA · On-site
Coordinate risk assessment activities with service provider. Coordinate and prepare documentation, internal communications, and status updates. Requirements : • Experience in cybersecurity risk ...
Risk - Business Analyst
Merrifield, VA · On-site
Coordinate risk assessment activities with service provider. Coordinate and prepare documentation, internal communications, and status updates. Requirements : • Experience in cybersecurity risk ...
Strong skills in system architecture analysis, networking fundamentals, risk assessment, and technical writing * Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or ...
Strong skills in system architecture analysis, networking fundamentals, risk assessment, and technical writing * Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or ...
Risk Assessment: Conduct cybersecurity risk assessments of industrial control systems (ICS) networks, systems, and components to identify vulnerabilities and recommend mitigation strategies.Policies ...
Risk Assessment: Conduct cybersecurity risk assessments of industrial control systems (ICS) networks, systems, and components to identify vulnerabilities and recommend mitigation strategies.Policies ...
Cybersecurity Engineer
Smithfield, VA · On-site
Risk Assessment: Conduct cybersecurity risk assessments of industrial control systems (ICS) networks, systems, and components to identify vulnerabilities and recommend mitigation strategies.
Cybersecurity Engineer
Smithfield, VA · On-site
Risk Assessment: Conduct cybersecurity risk assessments of industrial control systems (ICS) networks, systems, and components to identify vulnerabilities and recommend mitigation strategies.
Cybersecurity Engineer
Suffolk, VA · On-site
Risk Assessment: Conduct cybersecurity risk assessments of industrial control systems (ICS) networks, systems, and components to identify vulnerabilities and recommend mitigation strategies.
Cybersecurity Engineer
Suffolk, VA · On-site
Risk Assessment: Conduct cybersecurity risk assessments of industrial control systems (ICS) networks, systems, and components to identify vulnerabilities and recommend mitigation strategies.
Cybersecurity Solutions Architect
Arlington, VA · Hybrid
$12K - $145K/mo
Cybersecurity Solutions Architect Job Summary Lafayette Group is seeking an experienced ... vendor risk assessment and cyber supply chain mission outcomes. * Lead modernization and ...
Cybersecurity Solutions Architect
Arlington, VA · Hybrid
$12K - $145K/mo
Cybersecurity Solutions Architect Job Summary Lafayette Group is seeking an experienced ... vendor risk assessment and cyber supply chain mission outcomes. * Lead modernization and ...
Cybersecurity Engineer
Smithfield, VA · On-site
Risk Assessment: Conduct cybersecurity risk assessments of industrial control systems (ICS) networks, systems, and components to identify vulnerabilities and recommend mitigation strategies.
Cybersecurity Engineer
Smithfield, VA · On-site
Risk Assessment: Conduct cybersecurity risk assessments of industrial control systems (ICS) networks, systems, and components to identify vulnerabilities and recommend mitigation strategies.
Cybersecurity Administrator
$40 - $55/hr
Perform IT Risk and security Assessments and assist with risk mitigation efforts * Perform Supply Chain Risk Assessments on vendors and subcontractors * Develop approaches to mitigate vulnerabilities ...
Quick apply
Cybersecurity Administrator
$40 - $55/hr
Perform IT Risk and security Assessments and assist with risk mitigation efforts * Perform Supply Chain Risk Assessments on vendors and subcontractors * Develop approaches to mitigate vulnerabilities ...
Contributes toward recommendations on technical/policy changes, processes and methodologies to assess and mitigate cybersecurity risk on information technology within the SCA's appointed ...
Quick apply
Contributes toward recommendations on technical/policy changes, processes and methodologies to assess and mitigate cybersecurity risk on information technology within the SCA's appointed ...
Cyber Security Risk Assessment information
See Virginia salary details
$56.5K - $68.1K
1% of jobs
$68.1K - $79.8K
4% of jobs
$79.8K - $91.4K
5% of jobs
$91.4K - $103K
9% of jobs
$109.4K is the 25th percentile. Wages below this are outliers.
$103K - $114.6K
11% of jobs
$114.6K - $126.3K
10% of jobs
The median wage is $130.7K / yr.
$126.3K - $137.9K
28% of jobs
$144.6K is the 75th percentile. Wages above this are outliers.
$137.9K - $149.5K
14% of jobs
$149.5K - $161.2K
11% of jobs
$161.2K - $172.8K
4% of jobs
$172.8K - $184.4K
4% of jobs
$56.5K
$131.8K
$184.4K
How much do cyber security risk assessment jobs pay per year?
Can you make $500,000 a year in cyber security?
What are the key skills and qualifications needed to thrive in Cyber Security Risk Assessment, and why are they important?
What is the role of risk assessment in cyber security?
What is the difference between Cyber Security Risk Assessment vs Cyber Security Analyst?
| Aspect | Cyber Security Risk Assessment | Cyber Security Analyst |
|---|---|---|
| Primary Focus | Identifying and evaluating security risks and vulnerabilities | Monitoring, analyzing, and responding to security threats |
| Certifications | CompTIA Security+, CISSP, CISA | CompTIA Security+, CISSP, CEH |
| Work Environment | Risk assessment teams, consulting firms, security departments | Security operations centers, IT departments, incident response teams |
While both roles require similar certifications and work within cybersecurity, a Cyber Security Risk Assessment focuses on evaluating potential vulnerabilities and risks to an organization’s assets. In contrast, a Cyber Security Analyst actively monitors and responds to security threats, ensuring ongoing protection. Understanding these differences helps organizations assign the right responsibilities to each role.
Is SOC analyst a high paying job?
What are some common challenges faced by professionals conducting cyber security risk assessments?
What is a cyber security risk assessment?
What is the 80 20 rule in cyber security?

Full-time
Medical, Dental, Vision, Life, Retirement
Posted 20 days ago
Guidehouse rating
7.5
Based on 26 frontline employees who took The Breakroom Quiz
37th of 57 rated business consultants
Job description
Job Family:
Cyber Consulting
Travel Required:
Clearance Required:
What You Will Do:
Guidehouse's Cybersecurity practice helps federal and regulated clients assess, manage, and reduce cybersecurity risk across highimpact systems and missioncritical environments. Our teams combine deep technical assessment expertise with strong knowledge of federal risk management and authorization processes to support informed risk decisions and system authorization outcomes.
As a Senior Cyber Risk and Vulnerability Assessor , you will lead comprehensive security control assessments for complex, highimpact, and enterprise systems across onpremises, cloud, and hybrid environments. You will oversee assessment strategy and execution, validate remediation effectiveness, and provide authoritative risk determinations in support of Authorizing Officials (AOs) and senior agency leadership.
This role is ideal for a senior assessment professional with strong technical depth, proven leadership experience, and the ability to translate assessment results into clear, defensible risk recommendations aligned to federal cybersecurity requirements.
This role positions you as a senior assessment authority within Guidehouse's Cybersecurity practice, accountable for delivering highquality security assessments that enable informed authorization decisions and strengthen enterprise risk posture.
Key Responsibilities
- Lead and oversee security control assessments for moderate and highimpact information systems, including complex enterprise and missioncritical environments.
- Direct assessment planning and control testing strategies, ensuring appropriate coverage, rigor, and consistency with system architectures and risk profiles.
- Conduct and supervise cloud, onpremises, and hybrid system assessments, including IaaS, PaaS, and SaaS environments.
- Validate the effectiveness of remediation actions, including retesting controls and verifying closure of findings.
- Analyze assessment results and develop risk determinations, observations, and recommendations suitable for senior decisionmakers and AOs.
- Ensure assessments are executed in alignment with applicable federal frameworks and mandates, including: FISMA, NIST SP 80037, NIST SP 80053, OMB guidance and memoranda, Agencyspecific cybersecurity policies and procedures.
- Oversee development and quality of assessment deliverables, including security assessment plans (SAPs), security assessment reports (SARs), POA&Ms, and authorization support documentation.
- Provide guidance on risk acceptance, remediation prioritization, and continuous monitoring strategies.
- Serve as a trusted advisor to system owners, ISSOs, and security engineers on assessment findings and control implementation improvements.
- Coordinate assessment activities across multiple systems or programs, ensuring schedule adherence and stakeholder alignment.
- Mentor and develop assessors and consultants; provide technical review and quality assurance for assessment work products.
- Support practice growth through proposal development, technical contributions, and assessment methodology development.
What You Will Need:
- Must be able to OBTAIN and MAINTAIN a Federal or DoD "PUBLIC TRUST"; candidates must obtain approved adjudication of their PUBLIC TRUST prior to onboarding with Guidehouse. Candidates with an ACTIVE PUBLIC TRUST or SUITABILITY and maintain an active HHS/NIH clearance are preferred.
- Bachelor's degree in Cybersecurity, Information Systems, Computer Science, or a related field (additional relevant experience may substitute for formal education).
- Minimum of NINE (9) or more years of progressively responsible experience performing or leading security control assessments, audits, or cybersecurity risk assessments.
- Required certifications:
- Certified in Governance, Risk and Compliance (CGRC) (active)
- Certified Information Systems Security Professional (CISSP) (active)
- Demonstrated experience conducting assessments under the NIST RMF.
- Experience assessing highimpact or highvalue asset (HVA) systems.
- Strong understanding of security control implementation and assessment across enterprise, cloud, and hybrid architectures.
- Proven ability to communicate risk clearly and effectively to technical and executive stakeholders, including Authorizing Officials.
- Excellent written and verbal communication skills, including formal assessment reporting and executive briefings.
What Would Be Nice to Have:
- Experience with continuous monitoring programs and control inheritance models.
- Familiarity with major cloud service providers and their shared responsibility models.
- Additional certifications such as CISM, CISA, CCSP, HVA Assessment Lead/Technical Lead/Operator, or cloud security credentials.
- Prior consulting experience with responsibility for delivery quality, stakeholder management, and team leadership.
What We Offer:
Guidehouse offers a comprehensive, total rewards package that includes competitive compensation and a flexible benefits package that reflects our commitment to creating a diverse and supportive workplace.
Benefits include:
Medical, Rx, Dental & Vision Insurance
Personal and Family Sick Time & Company Paid Holidays
Position may be eligible for a discretionary variable incentive bonus
Parental Leave and Adoption Assistance
401(k) Retirement Plan
Basic Life & Supplemental Life
Health Savings Account, Dental/Vision & Dependent Care Flexible Spending Accounts
Short-Term & Long-Term Disability
Student Loan PayDown
Tuition Reimbursement, Personal Development & Learning Opportunities
Skills Development & Certifications
Employee Referral Program
Corporate Sponsored Events & Community Outreach
Emergency Back-Up Childcare Program
Mobility Stipend
About Guidehouse
Guidehouse is an Equal Opportunity Employer-Protected Veterans, Individuals with Disabilities or any other basis protected by law, ordinance, or regulation.
Guidehouse will consider for employment qualified applicants with criminal histories in a manner consistent with the requirements of applicable law or ordinance including the Fair Chance Ordinance of Los Angeles and San Francisco.
If you have visited our website for information about employment opportunities, or to apply for a position, and you require an accommodation, please contact Guidehouse Recruiting at 1-571-633-1711 or via email at RecruitingAccommodation@guidehouse.com. All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodation.
All communication regarding recruitment for a Guidehouse position will be sent from Guidehouse email domains including @guidehouse.com or guidehouse@myworkday.com. Correspondence received by an applicant from any other domain should be considered unauthorized and will not be honored by Guidehouse. Note that Guidehouse will never charge a fee or require a money transfer at any stage of the recruitment process and does not collect fees from educational institutions for participation in a recruitment event. Never provide your banking information to a third party purporting to need that information to proceed in the hiring process.
If any person or organization demands money related to a job opportunity with Guidehouse, please report the matter to Guidehouse's Ethics Hotline. If you want to check the validity of correspondence you have received, please contact recruiting@guidehouse.com. Guidehouse is not responsible for losses incurred (monetary or otherwise) from an applicant's dealings with unauthorized third parties.
Guidehouse does not accept unsolicited resumes through or from search firms or staffing agencies. All unsolicited resumes will be considered the property of Guidehouse and Guidehouse will not be obligated to pay a placement fee.
What Guidehouse employees say
Pay
Benefits
Hours and flexibility
Workplace
Get the full story on Breakroom
About Guidehouse
Sourced by ZipRecruiter
Industry
Business management consulting
Company size
10,000+ Employees
Headquarters location
Falls Church, VA, US
Year founded
2005