Cybersecurity Compliance & Continuous Monitoring Analyst

General Dynamics Information Technology, Inc.

$158K — $215K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • Active Top Secret clearance required
  • 8+ years of relevant experience
  • Hands-on experience with Tenable.sc and Tenable Nessus
  • Deep understanding of NIST SP 800 series and risk management principles
  • Direct experience as an ISSO or ISSM for classified systems

Responsibilities

  • Support full RMF and Assessment & Authorization lifecycle for secure enclaves
  • Maintain FedRAMP compliance documentation and monitoring
  • Collaborate with security teams to validate controls against compliance requirements
  • Identify and remediate system vulnerabilities using various security tools
  • Lead security control audits and validations for compliance assurance
  • Manage continuous monitoring and risk management program
  • Support risk assessments and incident response recommendations

Benefits

  • Various medical plan options including HSAs
  • Dental and vision plan options
  • 401(k) plan with company match
  • Flexible work schedule initiatives
  • Comprehensive paid time off plans including vacation and holidays
  • Disability and life insurance options
  • Regular reviews of benefits to stay competitive
Full Job Description

Type of Requisition:

Regular

Clearance Level Must Currently Possess:

Top Secret

Clearance Level Must Be Able to Obtain:

Top Secret/SCI

Public Trust/Other Required:

None

Job Family:

Cyber and IT Risk Management

Job Qualifications:

Skills:

Continuous Monitoring, Cybersecurity Compliance, DISA STIG, Federal Risk and Authorization Management Program (FedRAMP)

Certifications:

None

Experience:

8 + years of related experience

US Citizenship Required:

Yes

Job Description:

CYBER TECHNICAL ANALYST SR PRINCIPAL

MEANINGFUL WORK AND PERSONAL IMPACT

As a Cyber Technical Analyst Sr Principal, the work you’ll do at GDIT will be impactful to the mission of our customer’s classified commercial cloud environment. You will play a crucial role in securing and continuously monitoring a classified workstation secure enclave, ensuring it meets stringent FedRAMP and CNSSI 1253 requirements while enabling mission-critical operations.

  • Support the fullRMF and Assessment & Authorization (A&A) lifecyclefor the workstation secure enclave, including control implementation, assessment, authorization, and continuous monitoring.
  • Maintain a comprehensivebody of evidencefor FedRAMP/DoW A&A packages and continuous monitoring requirements, includingPOA&Mtracking, reporting, and remediation.
  • Collaborate withsecurity engineers, system administrators, ISSO/ISSM, vendors, and leadershipto integrate and validate security controls and align operations withFedRAMP, DoD, and CNSSI 1253requirements.
  • Identify, assess, and remediate vulnerabilities usingTenable Nessus, Tenable.sc, SCC, STIG tooling, and related security tools; ensure host inventory and scan policies are accurate and complete.
  • Reviewscan results, STIG findings, and patching activitiesto ensure accurate, actionable data and effective hardening of operating systems, network devices, and applications.
  • Evaluatesystem designs, network architectures, firewall rules, and PPSM submissionsto ensure security principles are integrated from the outset and architecture risks are addressed.
  • Lead preparation and execution ofsecurity control audits and FedRAMP 3PAO assessments, reviewing artifacts, logs, and configurations to validate evidence of compliance and a strong security posture.
  • Providesecurity control assessment and audit oversight, including reviewing and validating implementation work performed by engineers and system administrators.
  • Manage a robustcontinuous monitoring and GRC program, aggregating and analyzing security data to identify trends, anomalies, and potential incidents and providing actionable risk insights to leadership.
  • Supportrisk assessments and incident response, recommending mitigating controls and assisting the ISSM and incident response team with artifacts and deep system/security expertise.

WHAT YOU92LL NEED TO SUCCEED

Bring your cyber expertise and drive for innovation to GDIT. The Cyber Technical Analyst Sr Principal must have:

 Education: Bachelor of Arts/Bachelor of Science

 Experience: 8+ years of related experience

 Technical skills:

  • Hands-on experience with Tenable.sc and Tenable Nessus
  • Progressive experience in information assurance and cybersecurity roles
  • Minimum of 5 years of direct, hands-on experience as an ISSO or ISSM with a proven track record of achieving and maintaining ATO for classified systems
  • Expert-level knowledge of the NIST SP 800 series (especially 800-37, 800-53, 800-30) and risk management principles
  • Experience with FedRAMP and CNSSI 1253 baselines, continuous monitoring, POA&M management, and A&A body-of-evidence documentation

 Security clearance level: Active Top Secret

 Role requirements:

  • On-site McLean, VA
  • Must be DoD 8140 / 8570.01-M compliant
  • CISSP strongly preferred

The likely salary range for this position is $158,950 - $215,050. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.

Scheduled Weekly Hours:

40

Travel Required:

Less than 10%

Telecommuting Options:

Onsite

Work Location:

USA VA McLean

Additional Work Locations:

Total Rewards at GDIT:

Our benefits package for all US-based employees includes a variety of medical plan options, some with Health Savings Accounts, dental plan options, a vision plan, and a 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match. To encourage work/life balance, GDIT offers employees full flex work weeks where possible and a variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave. To ensure our employees are able to protect their income, other offerings such as short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available. We regularly review our Total Rewards package to ensure our offerings are competitive and reflect what our employees have told us they value most.


Our Identity Verification Process:

As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during virtual interviews. We reserve the right to take your picture to verify your identity and prevent fraud. By proceeding, you authorize the collection, processing, and use of your biometric data for identity verification and security purposes.

Similar Jobs

More Jobs at General Dynamics Information Technology, Inc.

More Information Technology Jobs

Find similar Cybersecurity Compliance & Continuous Monitoring Analyst jobs: