Job Family:
IT Cyber Security
Travel Required:
Up to 25%
Clearance Required:
Ability to Obtain Public Trust
What You Will Do:
1. Vulnerability Management
- Lead vulnerability management operations ensuring alignment with BOD 22-01 and federal cybersecurity mandates.
- Manage monitor and report vulnerabilities across NIH/HHS systems using tools such as / and coordinate timely remediation activities.
- Develop vulnerability prioritization models based on risk exposure and asset criticality.
- Ensure compliance with patching timelines and federal vulnerability directives.
- Collaborate with infrastructure cloud and application teams to validate remediation actions.
2. Security Operations & Automation
- Enhance and maintain SecOps workflows through automation and dashboard development.
- Utilize Power BI Python and Power Automate (or similar tools) to automate reporting trend analysis and compliance tracking.
- Develop API integrations with vulnerability management tools (e.g. Tenable Splunk ServiceNow or CSAM) for real-time monitoring dashboards.
- Support automation of vulnerability data ingestion and normalization across multiple environments (cloud and on-premises).
3. Compliance & Policy Alignment
- Ensure continuous compliance with CISAs Binding Operational Directive (BOD) 22-01 NIST SP 800-53 and FISMA requirements.
- Work closely with Risk Management Framework (RMF) and SA&A teams to align vulnerability findings with system security plans (SSPs) POA&Ms and ATO documentation.
- Support preparation of reports for leadership and federal oversight bodies.
4. Reporting & Dashboards
- Build and maintain interactive Power BI dashboards that visualize vulnerabilities risk posture remediation progress and compliance trends.
- Translate technical findings into executive-level risk summaries.
- Develop KPI and SLA metrics for vulnerability closure rates asset risk scoring and compliance tracking.
5. Communication & Coordination
- Communicate complex technical information clearly to both technical and non-technical audiences.
- Collaborate with cross-functional teams (IT Operations Cloud Engineering Privacy and Compliance).
- Provide status briefings and vulnerability insights to leadership.
Deliverables
- Monthly Vulnerability & Risk Posture Reports.
- Automated Power BI dashboard connected to vulnerability management and GRC systems.
- Vulnerability Management SOPs and process documentation.
- POA&M updates tied to vulnerability findings.
- CISA BOD 22-01 compliance tracking reports.
What You Will Need:
- Must be able to OBTAIN and MAINTAIN a Federal or DoD PUBLIC TRUST; candidates must obtain approved adjudication of their PUBLIC TRUST prior to onboarding with Guidehouse. Candidates with an ACTIVE PUBLIC TRUST or SUITABILITY are preferred
- Experience: 46 years of cybersecurity or IT risk management experience with at least 3 years focused on vulnerability management or SecOps.
- Tools: Hands-on experience with Tenable (Nessus or ); familiarity with other tools (BigFix Splunk Sentinel CSAM) preferred.
- Knowledge: Deep understanding of BOD 22-01 NIST 800-53 and FISMA requirements.
- Technical Skills: - Power BI (data modeling report building DAX formulas) - Power Automate / Python / API scripting for automation - Windows and Linux vulnerability management - Cloud security concepts (AWS Azure or Google Cloud)
- Certifications: Active CompTIA Security CE required. Other certifications (CISSP CEH or cloud-related) are a plus.
- Soft Skills: Strong communication and analytical thinking; ability to manage multiple concurrent priorities and deadlines.
- Onsite: Expected 1-2 days onsite at client site (Bethesda MD)
What Would Be Nice To Have:
- Experience developing automated data pipelines or integrating Tenable APIs into Power BI dashboards.
- Familiarity with ServiceNow Vulnerability Response CSAM or Splunk Security Essentials.
- Knowledge of MITRE ATT&CK framework and vulnerability prioritization methodologies (e.g. EPSS CVSS v3).
- Prior experience within a federal or HHS environment.
The annual salary range for this position is $98000.00-$163000.00. Compensation decisions depend on a wide range of factors including but not limited to skill sets experience and training security clearances licensure and certifications and other business and organizational needs.
What We Offer:
Guidehouse offers a comprehensive total rewards package that includes competitive compensation and a flexible benefits package that reflects our commitment to creating a diverse and supportive workplace.
Benefits include:
Medical Rx Dental & Vision Insurance
Personal and Family Sick Time & Company Paid Holidays
Parental Leave
401(k) Retirement Plan
Group Term Life and Travel Assistance
Voluntary Life and AD&D Insurance
Health Savings Account Health Care & Dependent Care Flexible Spending Accounts
Transit and Parking Commuter Benefits
Short-Term & Long-Term Disability
Tuition Reimbursement Personal Development Certifications & Learning Opportunities
Employee Referral Program
Corporate Sponsored Events & Community Outreach
annual membership
Employee Assistance Program
Supplemental Benefits via Corestream (Critical Care Hospital Indemnity Accident Insurance Legal Assistance and ID theft protection etc.)
Position may be eligible for a discretionary variable incentive bonus
About Guidehouse
Guidehouse is an Equal Opportunity EmployerProtected Veterans Individuals with Disabilities or any other basis protected by law ordinance or regulation.
Guidehouse will consider for employment qualified applicants with criminal histories in a manner consistent with the requirements of applicable law or ordinance including the Fair Chance Ordinance of Los Angeles and San Francisco.
If you have visited our website for information about employment opportunities or to apply for a position and you require an accommodation please contact Guidehouse Recruiting at 1- or via email at . All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodation.
All communication regarding recruitment for a Guidehouse position will be sent from Guidehouse email domains including @ or . Correspondence received by an applicant from any other domain should be considered unauthorized and will not be honored by Guidehouse. Note that Guidehouse will never charge a fee or require a money transfer at any stage of the recruitment process and does not collect fees from educational institutions for participation in a recruitment event. Never provide your banking information to a third party purporting to need that information to proceed in the hiring process.
If any person or organization demands money related to a job opportunity with Guidehouse please report the matter to Guidehouses Ethics Hotline. If you want to check the validity of correspondence you have received please contact . Guidehouse is not responsible for losses incurred (monetary or otherwise) from an applicants dealings with unauthorized third parties.
Guidehouse does not accept unsolicited resumes through or from search firms or staffing agencies. All unsolicited resumes will be considered the property of Guidehouse and Guidehouse will not be obligated to pay a placement fee.