Overview
Guidehouse is seeking an experienced Cybersecurity Governance, Risk, and Compliance (GRC) Program Manager to lead a large, complex federal cybersecurity program supporting enterprise security operations, cybersecurity governance, risk management, compliance, authorization, continuous monitoring, and cyber engineering activities.
The Managing Consultant will serve as the primary contractor Program Manager and authorized interface between Guidehouse, the Contracting Officer's Representative (COR), Government Program Manager (GPM), government stakeholders, and customer agency leadership.
This position requires onsite client support five (5) days per week in the Washington Metropolitan Area.
Key Responsibilities
- •Serve as the primary client-facing lead and trusted advisor for the cybersecurity program, managing relationships with executive stakeholders, government leadership, and customer representatives.
- •Act as the contractor's authorized representative for all programmatic, operational, technical, staffing, and contractual matters.
- •Provide overall leadership, direction, and management of program personnel, subcontractors, and program resources.
- •Formulate and enforce work standards, operating procedures, quality control processes, and performance metrics across all contract activities.
- •Manage staffing plans, workforce utilization, employee development, performance management, and resource allocation to ensure successful contract execution.
- •Plan, organize, prioritize, and oversee multiple cybersecurity initiatives, ensuring delivery of all contract requirements within schedule, scope, quality, and budget constraints.
- •Oversee program financial management, including labor forecasting, resource planning, budget monitoring, and contract performance management.
- •Lead program governance activities, including executive briefings, status reporting, risk management, issue resolution, and strategic planning discussions with government leadership.
- •Review, approve, and ensure quality of all program deliverables, reports, security documentation, and work products prior to submission to the client.
- •Coordinate enterprise cybersecurity planning, authorization, risk management, continuous monitoring, engineering, operations, and incident response activities across multiple stakeholders and technical teams.
- •Ensure alignment with federal cybersecurity mandates and frameworks including NIST RMF, FISMA, OMB guidance, CISA directives, Zero Trust initiatives, and agency-specific cybersecurity requirements.
- •Lead cross-functional teams supporting: Cybersecurity Governance, Risk Management, Security Authorization (ATO), Continuous Monitoring, Security Control Assessments, POA&M Management, Vulnerability Management, Incident Response Coordination, Cybersecurity Engineering, and Enterprise Security Operations.
- •Establish and maintain effective communication channels with government stakeholders to proactively identify and resolve programmatic, operational, and technical issues.
- •Develop and maintain integrated project schedules, performance metrics, staffing plans, and program roadmaps.
- •Identify program risks and develop mitigation strategies while ensuring compliance with contractual, regulatory, and organizational requirements.
- •Contribute to Guidehouse growth initiatives through thought leadership, proposal support, recruiting, mentoring, and business development activities.
Requirements
- •Active and maintained Secret (or higher) federal security clearance; Top Secret preferred.
- •US citizenship required.
- •Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, Engineering, Business Administration, or related field.
- •Minimum 10 years of progressive experience leading cybersecurity, risk management, compliance, or information security programs.
- •Minimum 5 years of experience managing large federal cybersecurity contracts, programs, or operations.
- •Demonstrated experience serving as a Program Manager, Task Order Manager, Engagement Manager, or equivalent leadership role supporting federal government clients.
- •Proven experience leading multidisciplinary teams across cybersecurity operations, governance, risk management, compliance, engineering, and security assessment functions.
- •Strong understanding of NIST RMF, FISMA, NIST SP 800 Series, Continuous Monitoring Programs, Security Authorization Processes, and federal cybersecurity compliance requirements.
- •DoD 8570/8140 IAM Level II certification minimum required; IAM Level III preferred. Examples include CISSP, CISM, GSLC, CCISO, CASP+.
- •Exceptional leadership, organizational, analytical, and communication skills.
Nice to Have
- •Master's degree in Cybersecurity, Information Technology, Information Assurance, Public Administration, Business Administration, or related discipline.
- •Project Management Professional (PMP) certification.
- •Experience supporting Cabinet-level agencies, Department of State, DHS, DoD, or other federal civilian agencies.
- •Experience leading large cybersecurity governance and compliance programs exceeding 20+ personnel.
- •Experience supporting enterprise cyber modernization, Zero Trust, CDM, or SOC initiatives.
- •Experience managing hybrid teams of cybersecurity engineers, ISSOs, assessors, analysts, and compliance specialists.
- •Familiarity with FedRAMP, CMMC, cloud security governance, and emerging federal cybersecurity mandates.
Compensation and Benefits
The annual salary range for this position is $130,000 to $216,000. Compensation decisions depend on skill sets, experience, security clearances, certifications, and other organizational needs.
Benefits include medical, dental, and vision insurance, personal and family sick time, company paid holidays, parental leave and adoption assistance, 401(k) retirement plan, life insurance, health savings account, flexible spending accounts, short-term and long-term disability, student loan paydown, tuition reimbursement, skills development and certifications, employee referral program, and an emergency back-up childcare program.