Guidehouse

Vulnerability Management & SecOps Specialist

US - MD, Bethesda Full time

Job Family:

IT Cyber Security


Travel Required:

Up to 25%


Clearance Required:

Ability to Obtain Public Trust

What You Will Do:

1. Vulnerability Management

  • Lead vulnerability management operations, ensuring alignment with BOD 22-01 and federal cybersecurity mandates.
  • Manage, monitor, and report vulnerabilities across NIH/HHS systems using tools such as Tenable.sc / Tenable.io, and coordinate timely remediation activities.
  • Develop vulnerability prioritization models based on risk, exposure, and asset criticality.
  • Ensure compliance with patching timelines and federal vulnerability directives.
  • Collaborate with infrastructure, cloud, and application teams to validate remediation actions.

2. Security Operations & Automation

  • Enhance and maintain SecOps workflows through automation and dashboard development.
  • Utilize Power BI, Python, and Power Automate (or similar tools) to automate reporting, trend analysis, and compliance tracking.
  • Develop API integrations with vulnerability management tools (e.g., Tenable, Splunk, ServiceNow, or CSAM) for real-time monitoring dashboards.
  • Support automation of vulnerability data ingestion and normalization across multiple environments (cloud and on-premises).

3. Compliance & Policy Alignment

  • Ensure continuous compliance with CISA’s Binding Operational Directive (BOD) 22-01, NIST SP 800-53, and FISMA requirements.
  • Work closely with Risk Management Framework (RMF) and SA&A teams to align vulnerability findings with system security plans (SSPs), POA&Ms, and ATO documentation.
  • Support preparation of reports for leadership and federal oversight bodies.

4. Reporting & Dashboards

  • Build and maintain interactive Power BI dashboards that visualize vulnerabilities, risk posture, remediation progress, and compliance trends.
  • Translate technical findings into executive-level risk summaries.
  • Develop KPI and SLA metrics for vulnerability closure rates, asset risk scoring, and compliance tracking.

5. Communication & Coordination

  • Communicate complex technical information clearly to both technical and non-technical audiences.
  • Collaborate with cross-functional teams (IT Operations, Cloud Engineering, Privacy, and Compliance).
  • Provide status briefings and vulnerability insights to leadership.

Deliverables

  • Monthly Vulnerability & Risk Posture Reports.
  • Automated Power BI dashboard connected to vulnerability management and GRC systems.
  • Vulnerability Management SOPs and process documentation.
  • POA&M updates tied to vulnerability findings.
  • CISA BOD 22-01 compliance tracking reports.


What You Will Need:

  • Must be able to OBTAIN and MAINTAIN a Federal or DoD "PUBLIC TRUST"; candidates must obtain approved adjudication of their PUBLIC TRUST prior to onboarding with Guidehouse. Candidates with an ACTIVE PUBLIC TRUST or SUITABILITY are preferred
  • Experience: 4–6 years of cybersecurity or IT risk management experience, with at least 3 years focused on vulnerability management or SecOps.
  • Tools: Hands-on experience with Tenable (Nessus, Tenable.sc, or Tenable.io); familiarity with other tools (BigFix, Splunk, Sentinel, CSAM) preferred.
  • Knowledge: Deep understanding of BOD 22-01, NIST 800-53, and FISMA requirements.
  • Technical Skills: - Power BI (data modeling, report building, DAX formulas) - Power Automate / Python / API scripting for automation - Windows and Linux vulnerability management  - Cloud security concepts (AWS, Azure, or Google Cloud)
  • Certifications: Active CompTIA Security+ CE required. Other certifications (CISSP, CEH, or cloud-related) are a plus.
  • Soft Skills: Strong communication and analytical thinking; ability to manage multiple concurrent priorities and deadlines.
  • Onsite: Expected 1-2 days onsite at client site (Bethesda, MD)

What Would Be Nice To Have:

  • Experience developing automated data pipelines or integrating Tenable APIs into Power BI dashboards.
  • Familiarity with ServiceNow Vulnerability Response, CSAM, or Splunk Security Essentials.
  • Knowledge of MITRE ATT&CK framework and vulnerability prioritization methodologies (e.g., EPSS, CVSS v3).
  • Prior experience within a federal or HHS environment.

The annual salary range for this position is $98,000.00-$163,000.00. Compensation decisions depend on a wide range of factors, including but not limited to skill sets, experience and training, security clearances, licensure and certifications, and other business and organizational needs.


What We Offer:

Guidehouse offers a comprehensive, total rewards package that includes competitive compensation and a flexible benefits package that reflects our commitment to creating a diverse and supportive workplace.

Benefits include:

  • Medical, Rx, Dental & Vision Insurance

  • Personal and Family Sick Time & Company Paid Holidays

  • Parental Leave

  • 401(k) Retirement Plan

  • Group Term Life and Travel Assistance

  • Voluntary Life and AD&D Insurance

  • Health Savings Account, Health Care & Dependent Care Flexible Spending Accounts

  • Transit and Parking Commuter Benefits

  • Short-Term & Long-Term Disability

  • Tuition Reimbursement, Personal Development, Certifications & Learning Opportunities

  • Employee Referral Program

  • Corporate Sponsored Events & Community Outreach

  • Care.com annual membership

  • Employee Assistance Program

  • Supplemental Benefits via Corestream (Critical Care, Hospital Indemnity, Accident Insurance, Legal Assistance and ID theft protection, etc.)

  • Position may be eligible for a discretionary variable incentive bonus

About Guidehouse

Guidehouse is an Equal Opportunity Employer–Protected Veterans, Individuals with Disabilities or any other basis protected by law, ordinance, or regulation.

Guidehouse will consider for employment qualified applicants with criminal histories in a manner consistent with the requirements of applicable law or ordinance including the Fair Chance Ordinance of Los Angeles and San Francisco.

If you have visited our website for information about employment opportunities, or to apply for a position, and you require an accommodation, please contact Guidehouse Recruiting at 1-571-633-1711 or via email at RecruitingAccommodation@guidehouse.com. All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodation.

All communication regarding recruitment for a Guidehouse position will be sent from Guidehouse email domains including @guidehouse.com or guidehouse@myworkday.com.  Correspondence received by an applicant from any other domain should be considered unauthorized and will not be honored by Guidehouse.  Note that Guidehouse will never charge a fee or require a money transfer at any stage of the recruitment process and does not collect fees from educational institutions for participation in a recruitment event. Never provide your banking information to a third party purporting to need that information to proceed in the hiring process.

If any person or organization demands money related to a job opportunity with Guidehouse, please report the matter to Guidehouse’s Ethics Hotline. If you want to check the validity of correspondence you have received, please contact recruiting@guidehouse.com. Guidehouse is not responsible for losses incurred (monetary or otherwise) from an applicant’s dealings with unauthorized third parties.

Guidehouse does not accept unsolicited resumes through or from search firms or staffing agencies. All unsolicited resumes will be considered the property of Guidehouse and Guidehouse will not be obligated to pay a placement fee.