Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Defense & Security, IT Risk and Controls Consultant

Guidehouse

Job Family:
IT Risk & Controls Consulting

Travel Required:
Up to 10%

Clearance Required:
Ability to Obtain Public Trust

What You Will Do :

Our professionals help our clients to identify, evaluate, and solve some of their most complex challenges, assisting them in achieving their strategic goals and objectives to fulfill their mission. We help our clients transform their business processes, improve efficiency of operations, evaluate and improve internal controls, strengthen policies and controls, increase transparency and performance management, and comply with Federal laws and regulations.


The nature of our projects can be fluid and requires self-motivated individuals that are willing to develop solutions on their own or in a team of highly skilled professionals. Project team members are provided the opportunity to interact with our clients' senior management, as well as the opportunity to enhance their skills in the area of technical competency, business development, client service, leadership, project management, and people development.

The IT Risk and Controls Consultant will support stakeholder engagement and technical delivery for efforts supporting client organizations with IT controls audit/assessments, remediation, and other related support. The client is responsible for coordinating and monitoring internal controls for the organization, including performing assessments in accordance with OMB Circular A-123, the FISCAM, and assisting other program offices with remediation and other related internal controls tasks. This is an ideal role for someone with an IT audit background who is looking to utilize their skills to support clients internally as a consultant rather than as an external auditor.

The IT Risk and Controls Consultant will have a role in working directly with clients and other organizational stakeholders to support IT internal control efforts, including audits/assessments, remediation, and other ad-hoc efforts.

This role will support a Government agency within the homeland security enterprise with opportunities to expand your support to other national security-related organizations.


Day-to-day tasks include some or all of the following:

  • Performing rigorous audits/assessments of IT controls using industry-standard guidance and leading practices
  • Performing walkthrough interviews and maintaining communication with a variety of client stakeholders, including system personnel such as system and database administrators
  • Requesting, obtaining, reviewing, and analyzing a variety of artifacts to assist in executing IT controls testing such as security plans, SOPs, system screenshots, and system configuration settings
  • Evaluating the design and operating effectiveness of IT controls using provided artifacts, industry-standard guidance, leading practices, and professional judgment
  • Professionally documenting the results of IT controls test work in a consistent and high-quality manner that would allow a reviewer to repeat the test and reach the same conclusion
  • Summarizing and communicating IT controls assessment results to a variety of client stakeholders, including senior leadership personnel
  • Planning and executing day-to-day activities of IT controls assessments individually and for the team
  • Working with client personnel to understand and analyze known IT control weaknesses, identify root causes, and develop detailed, robust remediation plans
  • Providing subject matter expertise to client personnel on all matters relating to IT controls and responding to ad-hoc IT controls requests from client personnel
  • Developing documents to support internal control assessment planning decisions and control identification
  • Supporting the development of corrective action plans to resolve material weaknesses, significant deficiencies, and control deficiencies
  • Reviewing financial system modernization production environment functionality and application controls to provide input regarding audit readiness.
  • Assessing incremental financial system modernization efforts as well as in-production and in-development environments with regards to audit readiness and future risks

  • Preparing presentations, briefing materials, standard operating procedures, frequently asked questions, guides, and white papers that effectively support organizational efforts to promote awareness and understanding of OMB A-123 and internal controls
What You Will Need:
  • Must be able to OBTAIN and MAINTAIN a Federal or DoD "PUBLIC TRUST"; candidates must obtain approved adjudication of their PUBLIC TRUST prior to onboarding with Guidehouse. Candidates with an ACTIVE PUBLIC TRUST or SUITABILITY are preferred.
  • Bachelor's Degree
  • TWO (2) or more year' experience in IT controls, audit, assessment, AND/OR remediation
What Would Be Nice To Have:
  • Master's Degree
  • Certified Information Systems Auditor (CISA) certification
  • Demonstrates knowledge and experience in IT risk and controls through IT audits, IT control assessments, and IT security reviews. Demonstrates a working knowledge of IT audit, the FISCAM, and other relevant federal information assurance laws, regulations, and guidance.
  • Experience supporting an internal control program
  • Experience performing IT audits, OMB Circular A-123 or similar internal control assessments, and/or remediating and implementing IT controls is preferable. Experience testing or remediating some or all of the following IT controls topic areas is preferable:
  • Access and account management, including authorization, provisioning, recertification, and separation
  • Segregation of duties, including identifying and defining segregation of duties risks and conflicts, preventive and detective segregation of duties controls, and understanding the difference between segregation of duties and least privilege
  • Technical account management controls, such as password length, complexity, and expiration
  • Audit logging and monitoring, including generation of audit logs, use of audit log aggregation and analysis tools, and audit log monitoring and review
  • Configuration management, including configuration baseline concepts, baseline deviations, baseline maintenance, monitoring for ongoing compliance with a baseline, and industry-accepted baselines such as DISA STIGs and CIS benchmarks
  • Change management, including authorization, development, testing, and deployment of changes
  • Contingency planning, including backups, testing of backups, and alternate site
What We Offer:

Guidehouse offers a comprehensive, total rewards package that includes competitive compensation and a flexible benefits package that reflects our commitment to creating a diverse and supportive workplace.

Benefits include:
  • Medical, Rx, Dental & Vision Insurance
  • Personal and Family Sick Time & Company Paid Holidays
  • Position may be eligible for a discretionary variable incentive bonus
  • Parental Leave and Adoption Assistance
  • 401(k) Retirement Plan
  • Basic Life & Supplemental Life
  • Health Savings Account, Dental/Vision & Dependent Care Flexible Spending Accounts
  • Short-Term & Long-Term Disability
  • Student Loan PayDown
  • Tuition Reimbursement, Personal Development & Learning Opportunities
  • Skills Development & Certifications
  • Employee Referral Program
  • Corporate Sponsored Events & Community Outreach
  • Emergency Back-Up Childcare Program
  • Mobility Stipend


About Guidehouse

Guidehouse is an Equal Opportunity Employer-Protected Veterans, Individuals with Disabilities or any other basis protected by law, ordinance, or regulation.

Guidehouse will consider for employment qualified applicants with criminal histories in a manner consistent with the requirements of applicable law or ordinance including the Fair Chance Ordinance of Los Angeles and San Francisco.

If you have visited our website for information about employment opportunities, or to apply for a position, and you require an accommodation, please contact Guidehouse Recruiting at View phone number on click.appcast.io or via email at View email address on click.appcast.io. All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodation.

All communication regarding recruitment for a Guidehouse position will be sent from Guidehouse email domains including @guidehouse.com or View email address on click.appcast.io. Correspondence received by an applicant from any other domain should be considered unauthorized and will not be honored by Guidehouse. Note that Guidehouse will never charge a fee or require a money transfer at any stage of the recruitment process and does not collect fees from educational institutions for participation in a recruitment event. Never provide your banking information to a third party purporting to need that information to proceed in the hiring process.

If any person or organization demands money related to a job opportunity with Guidehouse, please report the matter to Guidehouse's Ethics Hotline. If you want to check the validity of correspondence you have received, please contact View email address on click.appcast.io. Guidehouse is not responsible for losses incurred (monetary or otherwise) from an applicant's dealings with unauthorized third parties.

Guidehouse does not accept unsolicited resumes through or from search firms or staffing agencies. All unsolicited resumes will be considered the property of Guidehouse and Guidehouse will not be obligated to pay a placement fee.
Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the Defense & Security, IT Risk and Controls Consultant in Arlington, VA vacancy
  •  ...Obtain SecretWhat You Will Do:Our 2026 Campus Defense & Security Federal Audit Readiness and Internal Control consultants help our clients within Defense & National Security...  ...programsConducting entity level controls, risk management, and fraud risk assessmentsProviding... 
    Risk
    Summer work
    Flexible hours

    Guidehouse-Inc.

    Mc Lean, VA
    3 days ago
  •  ...Technologies, Inc in McLean, VA is looking for a Consultant - Financial Management to join their...  ...management structure, focusing on Defense & National Security. Your responsibilities will include performing IT risk and controls assessments, ensuring compliance with federal... 
    Risk

    Dovel Technologies, Inc

    Mc Lean, VA
    23 hours ago
  •  ...in the Capital Region The Defense Health Agency's (DHA) National...  ...exercises authority, direction, and control over the Walter Reed National...  .... The Medical Device Systems Security Program Management Office...  ...prescribes MHS GENESIS readiness, Risk Management Framework (RMF)/... 
    Risk
    Work at office

    The Cleaning Authority

    Falls Church, VA
    1 day ago
  • $150.45k - $233.45k

     ...currently seeking a Network Security Controls Senior Manager to...  ...Cyber Protection and Defense (CPD) organization,...  ...Security organizational consultant to Business Units and...  ...information technology (IT) organizations to...  ...reviews Provide cost, risk, and impact analysis for... 
    Risk
    Permanent employment
    Contract work
    Remote work
    Relocation
    Visa sponsorship
    Work visa
    Relocation package
    Flexible hours
    Shift work
    Day shift

    The Boeing Company

    Arlington, VA
    4 days ago
  •  ...cybersecurity for Operational Technology (OT) and Defense Critical Infrastructure (DCI) systems. Provide expert guidance on securing industrial control systems (ICS), SCADA environments, and...  ...and engineering teams on compliance, risk management, and advanced threat... 
    Risk
    Local area

    Booz Allen Hamilton

    Arlington, VA
    3 days ago
  • $141.5k - $236k

     ...Enterprise Ai Security Engineer Elevate your career...  ...intelligence, the Department of Defense, and Federal Civilian...  ..., Cybersecurity, IT, Data Analytics and Software...  ...Accreditation (A&A), Risk Management Framework (...  ...-aware access control. Manage compliance documentation... 
    Risk
    Hourly pay
    Contract work
    Temporary work
    Work experience placement
    Work at office
    Local area
    Remote work

    ManTech

    Washington DC
    23 hours ago
  • $85k - $110k

     ...cybersecurity activities and manage risk. CPMG offers flexible,...  ...solutions for Department of Defense (DoD) contractors, among others...  ...technology, electronic security surveillance, and support services...  ...motivated and detail-oriented Junior Consultant/Analyst to support the United... 
    Risk
    Contract work
    For contractors
    Work at office
    Flexible hours

    Goldbelt

    Washington DC
    1 day ago
  • Dovel Technologies, Inc is looking for a Consultant in McLean, Virginia to support government agency initiatives in internal controls and risk management. This full-time position involves evaluating financial processes, supporting audit activities, and developing solutions... 
    Risk
    Full time

    Dovel Technologies, Inc

    Mc Lean, VA
    23 hours ago
  • $75k - $95k

     ...cybersecurity activities and manage risk. CPMG offers flexible,...  ...solutions for Department of Defense (DoD) contractors, among others...  ...technology, electronic security surveillance, and support services...  ...We are seeking an entry-level Consultant/Analyst 1 to support the... 
    Risk
    Contract work
    For contractors
    Work at office
    Flexible hours

    Goldbelt

    Washington DC
    1 day ago
  • $95k - $120k

     ...cybersecurity activities and manage risk. CPMG offers flexible,...  ...solutions for Department of Defense (DoD) contractors, among others...  ...technology, electronic security surveillance, and support services...  ...We are seeking a skilled Consultant / Analyst 3 to support the United... 
    Risk
    Contract work
    For contractors
    Work at office
    Flexible hours

    Goldbelt

    Washington DC
    1 day ago
  •  ...Risk And Vulnerability Analyst Ii Founded in 1989, SOSi is among the largest private...  ...technology and services integrators in the defense and government services industry. We...  ..., and trusted results to enable national security missions worldwide. Job Description... 
    Risk
    Contract work
    Work at office
    Worldwide
    Monday to Friday
    Weekend work
    Afternoon shift

    SOSi

    Washington DC
    23 hours ago
  • ## Consultant - Financial Management (FM) IT Risk and Controls - Defense & Security - Campus 2026Applylocations: US - VA, McLean: US - IN, Indianapolis: US - TX, San Antonio: US - FL, Tampa: US - AL, Huntsvilletime type: Full timeposted on: Posted Yesterdayjob requisition... 
    Risk
    Temporary work
    Summer work
    Flexible hours

    Dovel Technologies, Inc

    Mc Lean, VA
    23 hours ago
  • Guidehouse-Inc. is seeking new consultants for their 2026 Campus Defense & Security Federal Audit Readiness program. The role focuses on optimizing financial...  ...structures and involves evaluating business process controls, conducting audits, and collaborating on high-impact... 

    Guidehouse-Inc.

    Mc Lean, VA
    3 days ago
  •  ...and services integrators in the defense and government services...  ...trusted results to enable national security missions worldwide. Job Description...  ...is seeking a highly qualified Risk Mitigation Specialist to...  ...with Foreign Ownership, Control, or Influence (FOCI) across the... 
    Risk
    Contract work
    Work at office
    Worldwide

    SOSi

    Washington DC
    10 days ago
  • $113.35k - $277.49k

    Overview The Institute for Defense Analyses (IDA) is a Federally-Funded...  ...analyses of national security issues and related national challenges...  ...cost estimation, schedule risk assessment, and evaluation of...  ...for continued access to SCI controlled programs. Compensation We... 
    Risk

    RPMGlobal

    Alexandria, VA
    4 days ago
  •  ...evaluate and improve internal controls, strengthen policies and...  ...Government agency within the homeland security enterprise with opportunities...  ...to be performed based on the risk profile of the organization...  ...covering a broad set of consulting capabilities, including:Apply... 
    Risk
    Flexible hours

    Guidehouse-Inc.

    Mc Lean, VA
    4 days ago
  • $60k

     ...critical programs across national security, defense, and public service delivery....  ...Project Coordinator supports IT operations by coordinating...  ...project visibility, risk management, release coordination...  ...Maximus TCS (Technology and Consulting Services) Internal Job Profile... 
    Risk
    Contract work
    Work experience placement
    Remote work
    Flexible hours

    MAXIMUS

    Washington DC
    6 days ago
  •  ...cyber space operations, cyber defense and resiliency, vulnerability...  ...Nightwing is seeking a Cloud Security Analyst to support this...  ..., compliance validation, and risk mitigation for cloud-enabled...  ...- Implement cloud security controls and monitoring solutions... 
    Risk
    Contract work
    Local area
    Immediate start

    Nightwing

    Arlington, VA
    2 days ago
  •  ...Visual Lease is seeking an IT Manager for SOX & Internal Controls Compliance in Arlington, VA. This role focuses on managing compliance with SOX, conducting risk assessments, and overseeing internal controls. The ideal candidate will hold a Bachelor's degree and have... 
    Risk

    Visual Lease Services Inc

    Arlington, VA
    23 hours ago
  • $86.8k - $198k

    ## Cyber Defense Infrastructure Support SpecialistApplylocations: Arlington...  ...:**When our country’s cyber security is on the line, simply...  ...those policies, and areas of risks. You’ll evaluate how policies...  ...as they navigate an evolving IT environment.Work with us as we... 
    Risk
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    Arlington, VA
    3 days ago
  • $86 - $95 per hour

     ...Functional Specialist - RMC (Security Controls) Complete Description:...  ...Configure and manage Oracle Risk Management Cloud modules (Advanced...  ...Collaborate with internal audit, IT security, and compliance...  ...AHU Technologies INC is an IT consulting and permanent staffing firm... 
    Risk
    Hourly pay
    Permanent employment
    Work from home
    Flexible hours

    AHU Technologies, Inc.

    Washington DC
    2 days ago
  •  ...Overview Nakupuna Consulting is seeking anOn-Site DeliveryLeadtoact...  ...ourDepartment of Defense (DoD) customer, the...  ...DoD governance, security, and contractual requirements...  ...to align priorities, risks, and expectations....  ...requirements, and security controls. Support release... 
    Risk
    Contract work
    For contractors
    Local area

    Nakupuna Companies

    Arlington, VA
    4 days ago
  •  ...Job Description Job Description HETI is a national and international risk management consulting firm. We primarily service the insurance industry with field risk assessments and industrial hygiene services. We provide these services through our network of highly qualified... 
    Risk
    Work from home
    Flexible hours

    HYDRO-ENVIRONMENTAL TECHNOLOGIES INC

    Washington DC
    12 days ago
  • $120k - $160k

     ...technical execution, customer engagement, staffing, risk management, and contract performance. About the Company...  ...management solutions to the U.S. Department of Defense, Department of State, and national security community. Expression’s “Perpetual Innovation” culture... 
    Risk
    Contract work
    For contractors
    For subcontractor
    Interim role
    Work at office
    Immediate start

    Hatchit Co

    Washington DC
    23 hours ago
  • $115k

     ..., prioritization, risk‑based remediation,...  ...systems, ensuring secure, timely, and compliant...  ...security, defense, and public service...  ...TCS (Technology and Consulting Services) Internal...  ...document compensating controls and mitigations...  ...coverage across all IT and OT... 
    Risk
    Contract work
    Remote work

    MAXIMUS

    Washington DC
    1 day ago
  •  ...well as the Command & Control software to mobilize swarms...  ...startups, negotiated defense deals worth billions of...  ...hiring an Information Security Lead / AWS Security Architect...  ...to sit within the IT organization and own...  ...Support supply-chain risk management, vulnerability... 
    Risk
    Work at office

    Swarm Aero

    Washington DC
    3 days ago
  • $93k - $125k

     ...Operational Technology And Control Systems Cybersecurity...  ...Analyst to provide consulting, program...  ...related cybersecurity risk management program for...  ...collaboration, LMI serves the defense, space, healthcare, and...  ...changes. This will include security impacts, requirements... 
    Risk
    Contract work
    Work at office

    LMI

    Arlington, VA
    4 days ago
  •  ...federal government's most critical national security and defense priorities, helping protect the nation,...  ...and maintaining network security controls aligned with NIST SP 800-53, NIST SP 80...  ...including participation in monitoring, risk mitigation, and maintaining network security... 
    Risk
    Work at office
    Local area
    Flexible hours

    Ardent Services

    Washington DC
    3 days ago
  • $150k - $200k

     ...program execution, compliance, risk management, and stakeholder...  ...operations. You’ll ensure delivery of secure, compliant, and high‑quality...  ...programs across civilian and defense sectors, including health,...  ...and analytics, and enterprise IT support. Our teams are experienced... 
    Risk
    Temporary work

    Blu Omega LLC

    Washington DC
    3 days ago
  •  ...Web Developer Security Engineer At Ardent, we hire people who want...  ...national security and defense priorities, helping protect the...  ...initiatives, and implementing security controls that help ensure applications...  ...remediation validation, and risk reduction efforts.... 
    Risk
    Local area
    Remote work
    Flexible hours

    Ardent Services

    Washington DC
    9 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Defense & Security, IT Risk and Controls Consultant. Be the first to apply!