IT Advisory Manager

Guidehouse - Chantilly, VA

Hiring: IT Advisory Manager Company: Guidehouse Location: Chantilly, VA Job Posted Time: 2026-09-10 11:03:33 Target Skills & Keywords : Change Management, Configuration Management, Security Clearance About the job Required Skills: •Leading a team of IT security auditors performing IT risk and controls assessments •Performing rigorous assessments of IT controls using industry-standard guidance and leading practices •Performing walkthrough interviews and maintaining communication with a variety of client stakeholders, including system personnel such as system and database administrators •Requesting, obtaining, reviewing, and analyzing a variety of artifacts to assist in executing IT controls testing such as security plans, SOPs, system screenshots, and system configuration settings •Evaluating the design and operating effectiveness of IT controls using provided artifacts, industry-standard guidance, leading practices, and professional judgement •Documenting the results of IT controls test work in a consistent and high-quality manner that would allow a reviewer to repeat the test and reach the same conclusion •Summarizing and communicating IT controls assessment results to a variety of client stakeholders, including senior leadership personnel •Planning and executing day-to-day activities of IT controls assessments individually and for the team Qualifications: •An Active DoD 8570.01-M (IAT III) certification (i.e. CASP+CE, CISSP, CISA, GCED, GCIH, CCSP) •Individual should demonstrate knowledge and experience in IT risk and controls through IT audits, IT control assessments, and IT security reviews. It is desired that individual maintains a relevant certification such as the Certified Information Systems Auditor (CISA) or is eligible to attain certification. •Individual should demonstrate a working knowledge of FISMA, NIST SP 800 series, FISCAM, and other relevant Federal information assurance laws, regulations, and guidance. Experience performing FISMA, OMB Circular A-123, or similar internal control assessments is preferred. Experience remediating and implementing IT controls is beneficial. •Access and account management, including authorization, provisioning, recertification, and separation •Segregation of duties, including identifying and defining segregation of duties risks and conflicts, preventive and detective segregation of duties controls, and understanding the difference between segregation of duties and least privilege •Technical account management controls, such as password length, complexity, and expiration •Audit logging and monitoring, including generation of audit logs, use of audit log aggregation and analysis tools, and audit log monitoring and review •Configuration management, including configuration baseline concepts, baseline deviations, baseline maintenance, monitoring for ongoing compliance with a baseline, and industry-accepted baselines such as DISA STIGs and CIS benchmarks •Change management, including authorization, development, testing, and deployment of changes •Contingency planning, including backups, testing of backups, and alternate sites Compensation: •Medical, Rx, Dental & Vision Insurance Interested candidates, please apply directly through the job posting on company's career page or try via AI auto apply on this platform. Don't miss this opportunity to join a forward-thinking team!