Job Title: Security Consultant (FISMA / FedRAMP) Onsite | MD/VA
Location: Rockville, MD / Tyson, VA (5 days onsite)
Interview Process:
Round 1: 1.30-min Phone/Virtual
Round 2: In-person (Rockville, MD / Tyson, VA)
Note: Candidates must be local to the MVD area at the time of interview
Role Overview
Seeking a Security Consultant to join a high-performing team delivering security assessments and advisory services for federal and commercial clients.
This role focuses on helping organizations achieve and maintain FISMA and FedRAMP compliance, while working with modern cloud, AI, and enterprise security technologies.
You will collaborate with stakeholders to strengthen security posture through risk-based security programs and regulatory frameworks.
Responsibilities
Develop Security Authorization Packages aligned with FISMA and FedRAMP
Create and maintain key artifacts: SSP, Contingency Plans, CMP, IR Plans, PIA, SAP, SAR
Review authorization packages for completeness and compliance
Conduct client interviews and working sessions for security assessments
Maintain and update security documentation across system lifecycle
Analyze vulnerability scan results (SentinelOne, Qualys, AppDetective, WebInspect, AppScan, Burp Suite)
Define risk mitigation strategies and remediation priorities
Build strong client relationships as a trusted security advisor
Lead working sessions to align scope, timelines, and deliverables
Improve security controls, standards, and procedures
Support end-to-end project delivery
Stay updated on regulatory frameworks, cloud security, and emerging threats
Required Skills
3 5 years in information security, risk, or compliance consulting
Strong knowledge of FISMA and NIST frameworks (800-30, 800-37, 800-53, 800-53A, 800-60)
Experience supporting FedRAMP or federal compliance initiatives
Strong understanding of risk assessments and control implementation
Excellent communication and client-facing skills
Strong analytical and problem-solving abilities
Ability to work in fast-paced, client-driven environments
Preferred Skills
Certifications: CISSP, CEH, CAP, Security+, GSEC, CCNA, CCNP, CASP, AWS
Experience with SOC 2, PCI-DSS, Reg SCI
Cloud experience (AWS or Azure)
Familiarity with tools like Splunk, ServiceNow
Exposure to AI or cloud-native security programs
Prior consulting/client-facing experience