Guidehouse
Security Analyst (Security Control Assessor/Technical Evaluator - Privacy)
Full details on LinkedIn
The complete job description, requirements, and application details are available on the original posting.
About Guidehouse
Guidehouse is a global professional services firm that specializes in advisory, technology, and managed services for both commercial and government sectors. With a strong focus on highly regulated industries such as healthcare, financial services, energy, infrastructure, and national security, Guidehouse addresses complex challenges through an integrated model of management consulting, technology services, and AI-led solutions. Founded in 2018, Guidehouse has grown significantly through strategic acquisitions, including Navigant Consulting and Dovel Technologies. Headquartered in Tysons, Virginia, the firm employs over 18,000 professionals across more than 55 offices worldwide. Guidehouse's services emphasize mission-critical optimization, technology modernization, financial management, and cybersecurity, helping clients navigate regulatory compliance and drive innovation. The firm serves a diverse range of clients, including government agencies and commercial entities, leveraging its expertise to foster transformational change.
Security at Guidehouse
Compiled from public job postings, careers pages, and company materials. Data may not reflect current state — verify during interviews.
Security Philosophy
“Information regarding Guidehouse's explicit AppSec team mission statement, specific 'shift-left' practices, or a detailed risk philosophy for application security is not publicly available. However, their broader cybersecurity services emphasize delivering solutions from strategy through implementation, and job postings mention 'DevSecOps' and alignment with frameworks like NIST, ISO 27001, and CIS controls.”
Security Team
- Amy Howland is listed as the Chief Information Security Officer (CISO) at Guidehouse, responsible for 'overarching cybersecurity compliance and risk management'.
- Public information does not provide a verifiable AppSec team size, organizational chart showing reporting lines, or explicit AppSec-specific job postings.
- Most related job postings are for broader cybersecurity roles.
Key Initiatives
- Guidehouse has 'established an enterprise vulnerability assessment program team' and performs 'enterprise vulnerability scanning across all system enclaves'.
- However, public information does not include evidence of a named Security Champions program, specific 'shift-left' practices tied to IDE/pre-commit/CI steps for application teams, or detailed secure SDLC artifacts beyond general cybersecurity service framing.
Preparing for an AppSec interview?
Get the weekly briefing 2,000+ security pros trust.