Type of Requisition:Regular
Clearance Level Must Currently Possess:None
Clearance Level Must Be Able to Obtain:None
Public Trust/Other Required:NACI (T1)
Job Family:Cyber and IT Risk Management
Job Qualifications:Skills:Assessment & Authorization (A&A), CISSP, Cyber Security Governance, Governance Risk Compliance (GRC), NIST 800-53
Certifications:None
Experience:10 + years of related experience
US Citizenship Required:No
Job Description:Technical Lead Cybersecurity Operations
Advance your career while impacting security of our hosting environment as a Governance, Risk & Compliance (GRC) Lead at GDIT. Here, technologists have many paths to grow a meaningful career supporting cyber missions and operations across the federal government.
MEANINGFUL WORK AND PERSONAL IMPACT
As the Governance, Risk & Compliance (GRC) Lead, the work you'll do at GDIT will be impactful to the mission of the customer. The GRC Lead oversees all GRC-related functions supporting NCI's cybersecurity governance framework, ensuring consistent implementation of policies, processes, and enterprise-wide compliance efforts. This position leads teams that design, document, automate, and enhance governance workflows, system inventories, common controls, policy frameworks, and enterprise risk processes. The role mirrors senior GRC leadership positions at large federal contractors.
Bring your program management expertise along with a drive for innovation to GDIT.
Responsibilities
- Lead NCI's enterprise cybersecurity governance program, ensuring alignment with NIH, HHS, FISMA, and NIST RMF requirements.
- Develop and maintain cybersecurity policies, SOPs, standards, templates, and procedural documentation.
- Oversee FISMA system inventory accuracy and integration with ServiceNow CMDB modules.
- Lead the development and optimization of GRC automation tools, including ServiceNow modules (e.g., FAST, eGRC integrations).
- Provide expert consulting to system owners, development teams, and stakeholders on governance practices, risk mitigation, and compliance requirements.
- Support security audits, internal assessments, OIG/GAO readiness, and CAP tracking.
- Lead common controls program activities including documentation, tailoring, assessment, and inheritance guidance.
- Analyze enterprise risks, identify trends, and prepare reports and dashboards for leadership decision-making.
Qualifications
- Education: Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field
- Experience: 5+ years leading cybersecurity governance programs for federal agencies.
- Certification: Possess at least one of the following CISSP, CISM, CRISC, CISA, GSLC
- Security clearance level: the ability to obtain a Public Trust
Skills
- Experience applying NIST risk assessment methodologies.
- Experience managing cybersecurity teams and prioritizing workloads and risks.
- Experience with eGRC tools (JCAM, Archer, or equivalent).
- ITIL Foundations certification (or ability to obtain within 3 months).
- Demonstrated experience developing A&A and governance streamlining processes.
- Experience with ServiceNow GRC, CMDB, or custom workflow development.
- Experience supporting federal research or health-science organizations.
- Familiarity with OSCAL, control inheritance models, and continuous monitoring frameworks.
- Policy development and governance strategy
- Risk analysis & risk communication
- Process design and automation leadership
- Strong written communication and documentation skills
- Cross-team collaboration and change management
The likely salary range for this position is $142,792 - $184,000. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.
Scheduled Weekly Hours:40
Travel Required:None
Telecommuting Options:Onsite
Work Location:USA MD Rockville
Additional Work Locations:Total Rewards at GDIT:Our benefits package for all US-based employees includes a variety of medical plan options, some with Health Savings Accounts, dental plan options, a vision plan, and a 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match. To encourage work/life balance, GDIT offers employees full flex work weeks where possible and a variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave. To ensure our employees are able to protect their income, other offerings such as short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available. We regularly review our Total Rewards package to ensure our offerings are competitive and reflect what our employees have told us they value most.
Our Identity Verification Process:As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during virtual interviews. We reserve the right to take your picture to verify your identity and prevent fraud. By proceeding, you authorize the collection, processing, and use of your biometric data for identity verification and security purposes.