IT Risk and Controls Manager
Guidehouse
Job Family :
IT Risk & Controls Consulting
Travel Required :
Up to 10%
Clearance Required :
Ability to Obtain Public Trust
What You Will Do :
The IT Risk and Controls Managing Consultant will support stakeholder engagement and technical delivery for efforts supporting a Department of Homeland Security (DHS) client with IT controls audit/assessments, remediation, and other related support. The client is responsible for coordinating and monitoring internal controls for the organization, including performing assessments in accordance with OMB Circular A-123, the FISCAM, and assisting other program offices with remediation and other related internal controls tasks. This is an ideal role for someone with an IT audit background who is looking to utilize their skills to support clients internally as a consultant rather than as an external auditor.
The IT Risk and Controls Managing Consultant will have a role in working directly with clients and other organizational stakeholders to support IT internal control efforts, including audits/assessments, remediation, and other ad-hoc efforts.
Day-to-day tasks include some or all of the following:
Managing and performing rigorous audits/assessments of IT controls using industry-standard guidance and leading practices
Managing and performing walkthrough interviews and maintaining communication with a variety of client stakeholders, including system personnel such as system and database administrators
Requesting, obtaining, reviewing, and analyzing a variety of artifacts to assist in executing IT controls testing such as security plans, SOPs, system screenshots, and system configuration settings.
Evaluating the design and operating effectiveness of IT controls using provided artifacts, industry-standard guidance, leading practices, and professional judgment.
Professionally documenting the results of IT controls test work in a consistent and high-quality manner that would allow a reviewer to repeat the test and reach the same conclusion.
Summarizing and communicating IT controls assessment results to a variety of client stakeholders, including senior leadership personnel
Planning, executing, and managing day-to-day activities of IT controls assessments individually and for the team.
Working with client personnel to understand and analyze known IT control weaknesses, identify root causes, and develop detailed, robust remediation plans.
Providing subject matter expertise to client personnel on all matters relating to IT controls and responding to ad-hoc IT controls requests from client personnel
Developing documents to support internal control assessment planning decisions and control identification.
Supporting the development of corrective action plans to resolve material weaknesses, significant deficiencies, and control deficiencies.
Reviewing financial system modernization production environment functionality and application controls to provide input regarding audit readiness.
Assessing incremental financial system modernization efforts as well as in-production and in-development environments with regards to audit readiness and future risks
Preparing presentations, briefing materials, standard operating procedures, frequently asked questions, guides, and white papers that effectively support organizational efforts to promote awareness and understanding of OMB A-123 and internal controls.
What You Will Need :
US Citizenship and must be able to OBTAIN and MAINTAIN a Federal or DoD "PUBLIC TRUST"; candidates must obtain approved adjudication of their PUBLIC TRUST prior to onboarding with Guidehouse. Candidates with an ACTIVE PUBLIC TRUST or SUITABILITY are preferred.
Bachelor's Degree
SIX (6) or more years’ experience in IT controls, audit, assessment, and/or remediation.
What Would Be Nice To Have :
Master's Degree
Certified Information Systems Auditor (CISA) certification
Demonstrates knowledge and experience in IT risk and controls through IT audits, IT control assessments, and IT security reviews.
Demonstrates a working knowledge of IT audit, the FISCAM, and other relevant federal information assurance laws, regulations, and guidance.
Experience supporting an internal control program.
Experience managing and performing IT audits, OMB Circular A-123 or similar internal control assessments, and/or remediating and implementing IT controls is preferable.
Experience testing or remediating some or all of the following IT controls topic areas is preferable:
Access and account management, including authorization, provisioning, recertification, and separation.
Segregation of duties, including identifying and defining segregation of duties risks and conflicts, preventive and detective segregation of duties controls, and understanding the difference between segregation of duties and least privilege
Technical account management controls, such as password length, complexity, and expiration
Audit logging and monitoring, including generation of audit logs, use of audit log aggregation and analysis tools, and audit log monitoring and review.
Configuration management, including configuration baseline concepts, baseline deviations, baseline maintenance, monitoring for ongoing compliance with a baseline, and industry-accepted baselines such as DISA STIGs and CIS benchmarks.
Change management, including authorization, development, testing, and deployment of changes.
Contingency planning, including backups, testing of backups, and alternate sites
#LI-DNI
What We Offer :
Guidehouse offers a comprehensive, total rewards package that includes competitive compensation and a flexible benefits package that reflects our commitment to creating a diverse and supportive workplace.
Benefits include:
Medical, Rx, Dental & Vision Insurance
Personal and Family Sick Time & Company Paid Holidays
Position may be eligible for a discretionary variable incentive bonus
Parental Leave and Adoption Assistance
401(k) Retirement Plan
Basic Life & Supplemental Life
Health Savings Account, Dental/Vision & Dependent Care Flexible Spending Accounts
Short-Term & Long-Term Disability
Student Loan PayDown
Tuition Reimbursement, Personal Development & Learning Opportunities
Skills Development & Certifications
Employee Referral Program
Corporate Sponsored Events & Community Outreach
Emergency Back-Up Childcare Program
Mobility Stipend
About Guidehouse
Guidehouse is an Equal Opportunity Employer–Protected Veterans, Individuals with Disabilities or any other basis protected by law, ordinance, or regulation.
Guidehouse will consider for employment qualified applicants with criminal histories in a manner consistent with the requirements of applicable law or ordinance including the Fair Chance Ordinance of Los Angeles and San Francisco.
If you have visited our website for information about employment opportunities, or to apply for a position, and you require an accommodation, please contact Guidehouse Recruiting at View phone number on click.appcast.io or via email at View email address on click.appcast.io . All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodation.
All communication regarding recruitment for a Guidehouse position will be sent from Guidehouse email domains including @guidehouse.com or View email address on click.appcast.io . Correspondence received by an applicant from any other domain should be considered unauthorized and will not be honored by Guidehouse. Note that Guidehouse will never charge a fee or require a money transfer at any stage of the recruitment process and does not collect fees from educational institutions for participation in a recruitment event. Never provide your banking information to a third party purporting to need that information to proceed in the hiring process.
If any person or organization demands money related to a job opportunity with Guidehouse, please report the matter to Guidehouse’s Ethics Hotline. If you want to check the validity of correspondence you have received, please contact View email address on click.appcast.io . Guidehouse is not responsible for losses incurred (monetary or otherwise) from an applicant’s dealings with unauthorized third parties.
Guidehouse does not accept unsolicited resumes through or from search firms or staffing agencies. All unsolicited resumes will be considered the property of Guidehouse and Guidehouse will not be obligated to pay a placement fee.
- ...The Compliance Testing (CT) team conducts risk‑based, independent testing across the... ...efficacy of Freddie Mac’s compliance risk management activities and identify potential non‑... ...assess the adequacy and effectiveness of controls in place to mitigate risk of non‑compliance...RiskWork at office
- Manager, Controls Governance & Testing - Enterprise Services Risk The Enterprise Services Risk organization is expanding with a focus on attracting innovative, pioneering... ...a team of technology control testers evaluating IT controls across cybersecurity, identity and access...RiskLocal area
$125k - $187k
...finance company in McLean, VA is seeking an experienced Enterprise Operational Control Testing Manager. This role is focused on managing IT control testing while ensuring operational risk assurance. Candidates should have a minimum of 8 years' experience, with at least...Risk$125k - $187k
...experience with information technology, operational controls testing, audit, or other operational risk assurance activities, and strong analytical and communication... ...apply to the Enterprise Operational Control Testing Manager role. This position is onsite in McLean, VA. Apply...RiskWork at officeLocal area- ...Information Systems Security Manager-Advanced to support our Cybersecurity... ...information technology (IT) security goals and objectives... ...reduce overall organizational risk. Acquire necessary resources... ...applicable baseline security controls as one of the sources for security...RiskTemporary workFor contractorsWork at officeFlexible hours
$150.45k - $233.45k
...Network Security Controls Senior Manager Company: The Boeing Company The Boeing Company is... ...Units and other information technology (IT) organizations to influence adoption of... ...and performance reviews Provide cost, risk, and impact analysis for network...RiskPermanent employmentContract workRemote workRelocationVisa sponsorshipWork visaRelocation packageFlexible hoursShift work- CoStar Group, Inc. is looking for a SOX & Internal Controls Compliance IT Manager in Arlington, VA. This role focuses on supporting SOX compliance... ...similar. Candidates should have 7-8 years of experience in IT risk management, with strong analytical, problem-solving, and...Risk
$40 - $55 per hour
...IT Risk & Controls Audit Manager Location: Tysons, VA and Arlington, VA (Onsite 3 days/week) Clearance: Must hold at least an interim Secret Clearance Contract: 3-month contract (onsite requirement) Pay Rate: $40–$55/hour About the Role: Join a critical cross-functional...RiskHourly payContract workInterim roleWork at office3 days per week$101.8k - $193.8k
...Overview As a Senior Networking Project Manager you will engage with customer... ...metrics, proactively monitors and tracks risks, ensures timely completion and quality of... ...with team members. Monitoring and Controlling Orchestrates and oversees a broad range...RiskOngoing contractContract workFor contractorsFor subcontractorLocal areaFlexible hours- Visual Lease is seeking an IT Manager for SOX & Internal Controls Compliance in Arlington, VA. This role focuses on managing compliance with SOX, conducting risk assessments, and overseeing internal controls. The ideal candidate will hold a Bachelor's degree and have 7...Risk
- A federal consulting firm is seeking an experienced IT Advisory Manager to lead IT risk and controls assessments for federal agencies. The ideal candidate will have extensive experience in information security and IT audits, focusing on identifying weaknesses and developing...Risk
$151.9k - $173.4k
Manager, Accounting, Retail Bank Agile Controllers Does the idea of working with and leading highly trained accountants and other project management professionals... ...manage the work Proactively identify and remediate risks, issues, and dependencies, escalating where necessary...RiskFull timePart timeLocal area- ...classification for a variety of projects with export control sensitivities. Reporting to the... ...) determinations Strategic Compliance Management: Design and implement enterprise-wide... ..., and classification inquiries Risk Management & Reporting: Conduct comprehensive...Risk
- ...Information Systems Security Manager (ISSM) Location: McLean, VA Clearance: TS/SCI w/ Poly Position Overview... ...with federal regulations, implements robust security controls, and manages risks to maintain the integrity, confidentiality, and...Risk
- Capital One National Association seeks a Manager for Controls Governance & Testing within its Enterprise Services Risk team. The role involves leading a team to evaluate IT controls, ensuring compliance with regulations, and delivering risk management solutions. Candidates...Risk
$4,000 per month
...responsible for the oversight and development of the Quality Control program. The Quality Control Manager will provide coaching and training for staff members to... ..., actionable feedback that addresses areas of elevated risk and improve loan quality. ESSENTIAL DUTIES &...RiskTemporary workFlexible hours- ...leading global professional services company is seeking a motivated Senior Associate in Risk Technology to manage client engagements, focusing on SAP application risk and controls. The role demands communication and project management skills alongside 2-3 years of relevant...RiskFlexible hours
- ...Project Manager An experienced Project Manager excited to join our team in supporting... ...the client and all stakeholders Perform risk management to minimize project risks Oversee... ...in place Participate in the Change Control Board (CCB) and monitor program/system...RiskWork at office
- ...Technical Project Manager We are seeking a motivated Project Manager who has experience... ...Ensuring that all projects are brought to a controlled close, on-time, within scope and budget.... ...for continuous improvement Performing risk management to minimize project risks....RiskCasual workFlexible hours
- ...Alexandria, VA, US Position Summary The IT Project Manager provides executive leadership across... ...and service desk operations. Manage risk, contingency planning, surge staffing,... ...SharePoint for documentation version control and repository needs. Staff should...RiskContract work
- ...experienced Information System Security Manager (ISSM) to support U.S. Navy... ...policies under the Risk Management Framework (RMF).... ...assessments, manage security controls, and Plan of Actions and Milestones... ...Familiarity with Platform IT (PIT) and Weapons Systems cybersecurity...Risk
$116.5k
...Information Systems Security Manager (ISSM) to join its team in Rosslyn... ...be adept at managing security controls, leading incident response... ...management. Collaborate with IT and other departments to... ...informed recommendations. Risk Assessment and Mitigation:...RiskWork experience placement- ...seeking a detail-oriented Principal Process Manager to oversee HR data management and... ...international workforce data, mitigating risks, and executing data destruction activities... ...and experience in data management, risk control, and process management. #J-18808-Ljbffr...Risk
$172.55k - $233.45k
...Cybersecurity - Senior Information System Security Manager (ISSM) Company: The Boeing... ..., guidelines and procedures Manage Risk Management Framework (RMF) processes, product... ...on candidate eligibility. Export Control Requirement: This position must meet...RiskPermanent employmentRelocationVisa sponsorshipWork visaFlexible hoursShift work- ...Information Systems Security Manager (ISSM), Senior Category... ...security operations, managing risk assessments and incident... ...high-quality, scalable, advanced IT solutions in a collaborative,... ...maintain security integrity and control changes to systems. • Strategic...RiskFull timeLocal area
$161.5k - $184.3k
...Senior Manager Data Governance Programs (Global Payments Network) Job Description The Senior Manager, Risk Management will join the Data Governance and Pricing (DGAP) team within... ...to develop processes, programs and controls to mitigate these risks across GPN. The...RiskFull timePart timeLocal area$100k - $150k
...Information System Security Manager (ISSM) - Fairfax, Virginia Salary... ...Support Service (eMASS) and Risk Management Framework (RMF),... ...and sustainment of the security controls to ensure cyber security... ...certifications and authorization of IT systems along with the...RiskPermanent employmentFull time$150.45k - $233.45k
...Information Security Governance Senior Manager Company: The Boeing Company The... ...assessments and implementation of security controls in the SCI and SAP domains. As... ...security technical and policy related to Risk Management Framework activities Develops...RiskPermanent employmentWork experience placementRelocationVisa sponsorshipWork visaRelocation packageFlexible hoursShift workAfternoon shift$100k - $140k
...Role As a Technical Implementation Manager at Knox, you will play a critical role in... ...Engineering teams, driving clarity across controls, runbooks, access models, monitoring, incident... ...readiness. • Proactively identify risks related to FedRAMP controls, operational...RiskNight shift- ...WE LOOKING FOR? We are seeking an AI Risk Governance Consultant to support the... ...combines a strong understanding of risk management principles with a practical knowledge of... ...potential risks, recommend appropriate controls, and help guide initiatives through governance...RiskFull timeLocal area
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to IT Risk and Controls Manager. Be the first to apply!
- information technology manager Springfield, VA
- IT manager Springfield, VA
- IT service manager Springfield, VA
- information technology supervisor Springfield, VA
- risk assurance Springfield, VA
- technology risk Springfield, VA
- information technology Springfield, VA
- information technology instructor Springfield, VA
- IT contractor Springfield, VA
- IT tech Springfield, VA

