Cybersecurity Third-Party Risk Management Consultant leading risk assessments and compliance tracking for NIH/HHS systems. Managing third-party risk with a focus on federal cybersecurity mandates.
Responsibilities
Lead third-party risk management operations, ensuring alignment with federal cybersecurity mandates.
Conduct thorough risk assessments of potential third-party vendors to identify risks and potential impacts to client organizations.
Manage, monitor, and remediate third-party risk across NIH/HHS systems and coordinate timely mitigation activities.
Conduct training and provide guidance to stakeholders on industry trends related to third-party risk management.
Manage and maintain related procedures based on third-party risk management industry trends.
Develop KPI metrics for third-party risk and compliance tracking.
Requirements
Must be able to OBTAIN and MAINTAIN a Federal or DoD "PUBLIC TRUST"; candidates must obtain approved adjudication of their PUBLIC TRUST prior to onboarding with Guidehouse.
Candidates with an ACTIVE PUBLIC TRUST or SUITABILITY and maintain an active HHS/NIH clearance are preferred.
Minimum of THREE (3) years of cybersecurity or IT risk management experience; candidates with experience focused on third-party risk management are preferred.
Deep understanding of NIST SP 800-53, and FISMA requirements.
Strong communication and analytical thinking; ability to manage multiple concurrent priorities and deadlines.
Familiarity with ServiceNow, Jira, GRC tools preferred.
Active CompTIA Security+ CE preferred; Other certifications (CISSP, CEH, or cloud-related) are a plus.
Prior experience within a federal or HHS environment.
Benefits
Medical, Rx, Dental & Vision Insurance
Personal and Family Sick Time & Company Paid Holidays
Position may be eligible for a discretionary variable incentive bonus
Parental Leave and Adoption Assistance
401(k) Retirement Plan
Basic Life & Supplemental Life
Health Savings Account, Dental/Vision & Dependent Care Flexible Spending Accounts
Short-Term & Long-Term Disability
Student Loan PayDown
Tuition Reimbursement, Personal Development & Learning Opportunities
Entry - Level Network Security Engineer assisting IT security team with firewall implementation and monitoring. Focused on maintaining network integrity in a hybrid work environment.
Cybersecurity Designer executing and proposing process improvements at Bancolombia. Collaborating on cybersecurity functions to enhance client protection and information security.
Microsoft Security Specialist role at Syntax focused on delivering Microsoft security workshops and advisory engagements. Collaborating on technology implementation while ensuring customer security success.
Cybersecurity Specialist developing IT resilience and disaster recovery concepts for a global scale in secure IT services. Collaborating across borders in shaping organizational security standards.
Senior Cybersecurity Scrum Master focusing on release management at AT&T, collaborating across teams and managing production change requests with an Agile mindset.
BISO responsible for planning and executing enterprise - wide information security initiatives at Elsevier. Driving cybersecurity awareness and managing technical risk assessments for organizational improvements.
Develop innovative Cloud architectures on Microsoft Azure platforms. Secure cloud infrastructure and applications against various threats while working in a project team.
Analista Pleno de Segurança Patrimonial na Hershey Brasil, responsável por suporte de segurança física e gestão de serviços de segurança. Atuará em conformidade e gestão de crise em São Roque.
Regional Information Security Officer managing security protocols and compliance for KARL STORZ. Leading local ISOs and enhancing information security measures across subsidiaries.