Senior Continuous Monitoring (ConMon) Analyst

RiVidium, Inc

$110K — $130K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Cybersecurity, Information Systems, Computer Science, Information Assurance, or related field.
  • Professional experience in cybersecurity and compliance programs.
  • Strong knowledge of the NIST Risk Management Framework (RMF) and NIST standards.
  • Experience in security controls and vulnerability management.
  • Ability to analyze security documentation for compliance and posture assessment.
  • Experience working with various cybersecurity stakeholders and technical teams.
  • Excellent communication skills for technical and executive reporting.

Responsibilities

  • Perform continuous monitoring to assess system security posture and vulnerabilities.
  • Support and implement Continuous Monitoring strategies per federal requirements.
  • Monitor and assess security controls and their effectiveness through documentation reviews.
  • Review and analyze security assessments, vulnerabilities, and compliance gaps.
  • Track and report on security weaknesses and develop remediation plans.
  • Coordinate remediation efforts with cybersecurity team members and stakeholders.
  • Maintain cybersecurity documentation and update compliance reporting.

Benefits

  • Comprehensive health insurance plans.
  • 401(k) retirement plan with company matching.
  • Paid time off and holidays.
  • Professional development and training opportunities.
  • Flexible work schedule options.
Full Job Description
Full-Time/Part-Time
Full-Time

Description

RiVidium Inc. seeking a Senior Continuous Monitoring (ConMon) Analyst to support federal cybersecurity and Risk Management Framework (RMF) activities. The Senior ConMon Analyst will provide cybersecurity continuous monitoring, security assessment, risk analysis, and compliance support to ensure information systems remain compliant with applicable federal security requirements.

The ideal candidate will have strong experience with RMF, security controls, continuous monitoring, vulnerability management, POA&M management, security documentation, and Governance, Risk, and Compliance (GRC) tools. This position requires the ability to work closely with Information System Security Officers (ISSOs), Information System Security Managers (ISSMs), Security Control Assessors (SCAs), system owners, engineers, and government stakeholders.

Key Responsibilities
  • Perform continuous monitoring of information systems to identify changes in security posture, vulnerabilities, risks, and compliance status.
  • Support implementation and execution of Continuous Monitoring (ConMon) strategies in accordance with federal cybersecurity requirements and organizational policies.
  • Monitor security controls and assess ongoing control effectiveness through documentation reviews, technical evidence, vulnerability data, and other assessment activities.
  • Support NIST Risk Management Framework (RMF) activities throughout the system lifecycle.
  • Review security controls, assessment results, system changes, vulnerabilities, and security-related artifacts to identify potential risks and compliance gaps.
  • Track, analyze, and report security weaknesses, vulnerabilities, and Plans of Action and Milestones (POA&Ms).
  • Coordinate with ISSOs, ISSMs, SCAs, system owners, and technical teams to ensure identified security deficiencies are properly documented and remediated.
  • Maintain and update cybersecurity documentation, including security assessment evidence, control implementation statements, POA&Ms, risk assessments, and continuous monitoring reports.
  • Review vulnerability scan results and other security assessment data to determine potential impact to system security posture.
  • Support security impact analyses for system changes, configuration changes, new technologies, and changes to the operational environment.
  • Assist with preparation of recurring security and compliance reports for government leadership and cybersecurity stakeholders.
  • Analyze security metrics and trends to identify recurring weaknesses and recommend risk mitigation strategies.
  • Support security control testing, assessment, and validation activities as required.
  • Ensure continuous monitoring activities are properly documented and aligned with applicable policies, standards, and federal regulations.
  • Use GRC and cybersecurity tools to maintain system security information, control status, assessment findings, POA&Ms, and compliance documentation.
  • Participate in cybersecurity working groups, risk reviews, security meetings, and technical discussions with government and contractor stakeholders.
  • Provide recommendations to improve cybersecurity processes, control effectiveness, risk management, and compliance posture.
  • Stay current on evolving federal cybersecurity policies, NIST guidance, threats, vulnerabilities, and security best practices.

Required Qualifications
  • Bachelor's degree in Cybersecurity, Information Systems, Computer Science, Information Assurance, or a related field.
  • Demonstrated professional experience supporting cybersecurity, continuous monitoring, RMF, security compliance, or information assurance programs.
  • Strong understanding of the NIST Risk Management Framework (RMF) and NIST cybersecurity standards.
  • Experience with security controls, security assessments, vulnerability management, risk management, and POA&M tracking.
  • Experience analyzing security documentation and technical evidence to determine control compliance and system security posture.
  • Experience working with cybersecurity stakeholders, including ISSOs, ISSMs, SCAs, system owners, and system administrators/engineers.
  • Strong written and verbal communication skills with the ability to prepare clear technical and executive-level security reports.
  • Ability to manage multiple systems, security requirements, findings, and competing priorities in a federal environment.

Preferred Qualifications
  • CISM, CAP, or equivalent GRC/cybersecurity certification.
  • Experience with GRC platforms such as RSA Archer, ServiceNow GRC, eMASS, or equivalent tools.
  • Experience supporting federal civilian or Department of Defense cybersecurity programs.
  • Knowledge of NIST SP 800-37, NIST SP 800-53, NIST SP 800-30, NIST SP 800-137, FISMA, and related federal cybersecurity requirements.
  • Experience with vulnerability management and security scanning tools.
  • Experience developing dashboards, metrics, and cybersecurity status reports.
  • Experience supporting ATO, continuous authorization, security assessment, and ongoing authorization activities.
  • Familiarity with federal cybersecurity policies, standards, and compliance requirements.

Desired Skills
  • Risk Management Framework (RMF)
  • Continuous Monitoring (ConMon)
  • NIST 800-53 security controls
  • Security Assessment & Authorization (A&A)
  • Authority to Operate (ATO)
  • POA&M management
  • Vulnerability Management
  • Risk Assessment
  • Security Control Assessment
  • GRC tools
  • Cybersecurity compliance
  • Security documentation
  • Security metrics and reporting
  • Federal cybersecurity policies and standards

Education & Certification

Required:
  • Bachelor's degree in Cybersecurity, Information Systems, Computer Science, Information Assurance, or related field.

Preferred:
  • Certified Information Security Manager (CISM)
  • Certified Authorization Professional (CAP)
  • Equivalent GRC, cybersecurity, or information assurance certification


RiVidium Inc is seeking a 'Senior Continuous Monitoring (ConMon) Analyst' to support a federal client. This position is contingent upon contract award and funding approval. As such, this job posting is intended to identify qualified candidates for a potential future opportunity and does not represent a currently available position. Compensation has not yet been determined and will be established based on contract requirements, candidate qualifications, experience, and applicable market conditions.

This position is currently accepting applications.

Similar Jobs

More Jobs at RiVidium, Inc

More Information Technology Jobs

Find similar Senior Continuous Monitoring (ConMon) Analyst jobs: