1

It Risk Consultant Jobs in Virginia (NOW HIRING)

IT Audit Senior

Alexandria, VA · On-site

$100K - $132K/yr

IT Audit Senior Are you ready to take the next step in your IT audit career? Join Castro amp ... Identify and Communicate Risk : Analyze IT environments, pinpoint control gaps, and clearly present ...

LoD2: Technology Risk Specialist

Richmond, VA · On-site

$97K/yr

Specific activities may change from time to time. 1. Provides independent risk oversight (i.e ... Expertise in hosting platforms (on-premise and cloud, open systems, mainframe), IT operations, and ...

Showing results 21-40

It Risk Consultant information

See Virginia salary details

$24

$52

$86

How much do it risk consultant jobs pay per hour?

As of Sep 10, 2026, the average hourly pay for it risk consultant in Virginia is $52.51, according to ZipRecruiter salary data. Most workers in this role earn between $43.37 and $57.69 per hour, depending on experience, location, and employer.

How does an IT Risk Consultant typically collaborate with other departments to manage organizational risks?

IT Risk Consultants often work closely with departments such as IT, legal, compliance, and business operations to identify, assess, and mitigate risks. This collaboration involves facilitating risk assessments, developing risk mitigation strategies, and ensuring that all teams understand their roles in maintaining security and compliance. Regular cross-functional meetings and clear communication are key to aligning risk management efforts with business objectives. Successful consultants build strong relationships across the organization to create a culture of proactive risk awareness.

What are the key skills and qualifications needed to thrive as an IT Risk Consultant, and why are they important?

To thrive as an IT Risk Consultant, you need a solid understanding of information security, risk assessment methodologies, and regulatory compliance, typically supported by a degree in information technology or a related field. Familiarity with frameworks such as ISO 27001, NIST, and tools like risk management software and vulnerability scanners—as well as certifications like CISSP or CISA—is highly valuable. Strong analytical thinking, problem-solving, and communication skills help convey risks and collaborate with stakeholders effectively. These competencies are crucial for identifying vulnerabilities, recommending mitigation strategies, and ensuring organizations meet security and compliance requirements.

What is the difference between It Risk Consultant vs Cybersecurity Analyst?

AspectIt Risk ConsultantCybersecurity Analyst
CertificationsISO 27001, CISSP, CISACISSP, CEH, CompTIA Security+
Work EnvironmentConsulting firms, corporate risk teamsSecurity operations centers, IT departments
Industry UsageFinancial, healthcare, governmentTech, finance, retail

While both roles focus on protecting information, an It Risk Consultant assesses overall IT risks and compliance, providing strategic advice, whereas a Cybersecurity Analyst monitors and responds to security threats in real-time. The roles often overlap but differ in scope and daily responsibilities.

Does risk consulting pay well?

Risk consulting, including roles like IT Risk Consultants, generally offers competitive salaries that vary based on experience, certifications, and location. Entry-level positions may start lower, but experienced consultants with specialized skills can earn high compensation, often supplemented by bonuses and benefits. The profession values analytical skills, industry knowledge, and certifications such as CISSP or CISA.

What does an IT risk consultant do?

An IT risk consultant assesses an organization's technology systems to identify vulnerabilities and develop strategies to mitigate cybersecurity threats and data breaches. They analyze security controls, recommend improvements, and often use tools like risk management frameworks and compliance standards such as ISO 27001 or NIST. Their work helps organizations protect sensitive information and ensure regulatory compliance.
Infographic showing various It Risk Consultant job openings in Virginia as of August 2026, with employment types broken down into 1% As Needed, 86% Full Time, 10% Part Time, and 3% Contract. Highlights an 87% Physical, 4% Hybrid, and 9% Remote job distribution, with an average salary of $109,211 per year, or $52.5 per hour.

IT Security Auditor - Consultant

Mclean, VA • On-site

Dovel Technologies, Inc
Software Development • 51 - 200 employees

Other

Medical, Dental, Vision, Life, Retirement

Posted 11 days ago


Job description

Job Family: Technology ConsultingTravel Required: Up to 10%Clearance Required: Active Top Secret SCI with PolygraphWhat You Will Do:

The IT Security Auditor will lead stakeholder engagement and technical delivery for efforts supporting federal agencies with IT controls assessments and program evaluations. This is an ideal role for someone with an information security and assurance or IT audit background who is looking to utilize their skills to work with the federal government to analyze IT control weaknesses, identify root causes, and develop remediation plans.

Responsibilities include some or all of the following:
  • Performing assessments of IT controls using industry-standard guidance and leading best practices
  • Conducting interviews and discussions with a variety of client stakeholders, including IT system personnel such as Information System Security Officers (ISSOs) and system administrators
  • Reviewing and analyzing documents and artifacts to assist in IT controls testing such as system security plans, SOPs, audit logs, configuration scans, and vulnerability scans
  • Evaluating the implementation and effectiveness of IT controls using provided artifacts against federal requirements, industry guidance, and leading best practices
  • Documenting the results of IT controls testing in a consistent and high-quality manner that would allow others to review and understand the results
  • Summarizing and communicating IT controls assessment results to a variety of client stakeholders, including senior leadership
  • Understanding and analyzing known IT control weaknesses, identifying root causes, and developing detailed remediation plans
  • Providing subject matter expertise to client personnel on a wide range of matters relating to IT security and assurance
  • Responding to ad-hoc IT security-related requests from client personnel
  • Planning and executing day-to-day activities of IT assessments and evaluations individually and for the team
  • Mentoring junior team members in day-to-day IT controls testing responsibilities
What You Will Need:
  • An ACTIVE and MAINTAINED TS/SCI Federal or DoD security clearance with a COUNTERINTELLIGENCE (CI) polygraph
  • Bachelor’s Degree in a Technical or Business field
  • Two (2) + years' experience providing IT consulting.

Experience should include but not be limited to: Experience in consulting with the federal government to include senior government clients Understanding and knowledge of federal information security and assurance laws, requirements, and guidance (i.e. FISMA, NIST SP 800, FISCAM)

What Would Be Nice To Have:
  • Relevant certification such as the Certified Information Systems Auditor (CISA) or Certified Information Security Manager (CISM)
  • Demonstrated knowledge and experience in IT risk & controls through IT audits, IT controls assessments, or IT security reviews
  • Demonstrated ability and working knowledge of: FISMA, NIST SP 800 series, FISCAM, other relevant federal information assurance laws, regulations, and guidance
  • Experience performing: FISMA, OMB Circular A-123, or similar internal control assessments
  • Experience implementing or auditing access and account management principles, including authorization, provisioning, recertification, and separation of duties
  • Experience implementing or auditing contingency planning principles, including backups, testing of backups, and alternate processing sites
  • Experience implementing or auditing configuration management principles, including configuration baseline concepts, baseline deviations, baseline maintenance, change control, and monitoring, and industry-accepted configuration settings such as DISA STIGs
  • Experience performing audit logging and monitoring, including generation of audit logs, use of audit log aggregation and analysis tools, and audit log monitoring and review
What We Offer:

Guidehouse offers a comprehensive, total rewards package that includes competitive compensation and a flexible benefits package that reflects our commitment to creating a diverse and supportive workplace.

Benefits include:
  • Medical, Rx, Dental & Vision Insurance
  • Personal and Family Sick Time & Company Paid Holidays
  • Position may be eligible for a discretionary variable incentive bonus
  • Parental Leave and Adoption Assistance
  • 401(k) Retirement Plan
  • Basic Life & Supplemental Life
  • Health Savings Account, Dental/Vision & Dependent Care Flexible Spending Accounts
  • Short-Term & Long-Term Disability
  • Student Loan PayDown Tuition Reimbursement
  • Personal Development & Learning Opportunities
  • Skills Development & Certifications
  • Employee Referral Program
  • Corporate Sponsored Events & Community Outreach
  • Emergency Back-Up Childcare Program
  • Mobility Stipend
About Guidehouse

Guidehouse is an Equal Opportunity Employer–Protected Veterans, Individuals with Disabilities or any other basis protected by law, ordinance, or regulation.

Guidehouse will consider for employment qualified applicants with criminal histories in a manner consistent with the requirements of applicable law or ordinance including the Fair Chance Ordinance of Los Angeles and San Francisco.

If you have visited our website for information about employment opportunities, or to apply for a position, and you require an accommodation, please contact Guidehouse Recruiting at 1-571-633-1711 or via email at RecruitingAccommodation@guidehouse.com.

All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodation.

All communication regarding recruitment for a Guidehouse position will be sent from Guidehouse email domains including @guidehouse.com or guidehouse@myworkday.com.

Correspondence received by an applicant from any other domain should be considered unauthorized and will not be honored by Guidehouse.

Note that Guidehouse will never charge a fee or require a money transfer at any stage of the recruitment process and does not collect fees from educational institutions for participation in a recruitment event.

Never provide your banking information to a third party purporting to need that information to proceed in the hiring process.

If any person or organization demands money related to a job opportunity with Guidehouse, please report the matter to Guidehouse’s Ethics Hotline.

If you want to check the validity of correspondence you have received, please contact recruiting@guidehouse.com.

Guidehouse is not responsible for losses incurred (monetary or otherwise) from an applicant’s dealings with unauthorized third parties.

Guidehouse does not accept unsolicited resumes through or from search firms or staffing agencies.

All unsolicited resumes will be considered the property of Guidehouse and Guidehouse will not be obligated to pay a placement fee.

Guidehouse is a global AI-led professional services firm delivering advisory, technology, and managed services to the commercial and government sectors.

With an integrated business technology approach, Guidehouse drives efficiency and resilience in the healthcare, financial services, energy, infrastructure, and national security markets.

Built to help clients across industries outwit complexity, the firm brings together approximately 18,000 professionals to achieve lasting impact and shape a meaningful future.

guidehouse.com

#J-18808-Ljbffr