Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Cybersecurity Compliance & Continuous Monitoring Analyst

$158.95k - $215.05k
Full-time

Gdit

Responsibilities for this Position

Location: USA VA McLean
Full Part/Time: Full time
Job Req: RQ227719

Type of Requisition:
Regular

Clearance Level Must Currently Possess:
Top Secret

Clearance Level Must Be Able to Obtain:
Top Secret/SCI

Public Trust/Other Required:
None

Job Family:
Cyber and IT Risk Management

Job Qualifications:

Skills:
Continuous Monitoring, Control Assessment, Federal Risk and Authorization Management Program (FedRAMP), Security Controls
Certifications:
None
Experience:
8 + years of related experience
US Citizenship Required:
Yes

Job Description:

CYBER TECHNICAL ANALYST SR PRINCIPAL

Advance your career while impacting our national security in cyber as a Cyber Technical Analyst Sr Principal at GDIT. Here, technologists have many paths to grow a meaningful career supporting cyber missions and operations across the federal government.

MEANINGFUL WORK AND PERSONAL IMPACT

As a Cyber Technical Analyst Sr Principal, the work you'll do at GDIT will be impactful to the mission of our customer's classified commercial cloud environment. You will play a crucial role in securing and continuously monitoring a classified workstation secure enclave, ensuring it meets stringent FedRAMP and CNSSI 1253 requirements while enabling mission-critical operations.

  • Support the full RMF and Assessment & Authorization (A&A) lifecycle for the workstation secure enclave, including control implementation, assessment, authorization, and continuous monitoring.
  • Maintain a comprehensive body of evidence for FedRAMP/DoW A&A packages and continuous monitoring requirements, including POA&M tracking, reporting, and remediation.
  • Collaborate with security engineers, system administrators, ISSO/ISSM, vendors, and leadership to integrate and validate security controls and align operations with FedRAMP, DoD, and CNSSI 1253 requirements.
  • Identify, assess, and remediate vulnerabilities using Tenable Nessus, Tenable.sc, SCC, STIG tooling, and related security tools; ensure host inventory and scan policies are accurate and complete.
  • Review scan results, STIG findings, and patching activities to ensure accurate, actionable data and effective hardening of operating systems, network devices, and applications.
  • Evaluate system designs, network architectures, firewall rules, and PPSM submissions to ensure security principles are integrated from the outset and architecture risks are addressed.
  • Lead preparation and execution of security control audits and FedRAMP 3PAO assessments, reviewing artifacts, logs, and configurations to validate evidence of compliance and a strong security posture.
  • Provide security control assessment and audit oversight, including reviewing and validating implementation work performed by engineers and system administrators.
  • Manage a robust continuous monitoring and GRC program, aggregating and analyzing security data to identify trends, anomalies, and potential incidents and providing actionable risk insights to leadership.
  • Support risk assessments and incident response, recommending mitigating controls and assisting the ISSM and incident response team with artifacts and deep system/security expertise.

WHAT YOU'LL NEED TO SUCCEED

Bring your cyber expertise and drive for innovation to GDIT. The Cyber Technical Analyst Sr Principal must have:

Education: Bachelor of Arts/Bachelor of Science

Experience: 8+ years of related experience

Technical skills:
  • Hands-on experience with Tenable.sc and Tenable Nessus
  • Progressive experience in information assurance and cybersecurity roles
  • Minimum of 5 years of direct, hands-on experience as an ISSO or ISSM with a proven track record of achieving and maintaining ATO for classified systems
  • Expert-level knowledge of the NIST SP 800 series (especially 800-37, 800-53, 800-30) and risk management principles
  • Experience with FedRAMP and CNSSI 1253 baselines, continuous monitoring, POA&M management, and A&A body-of-evidence documentation
Security clearance level: Active Top Secret

Role requirements:
  • On-site McLean, VA
  • Must be DoD 8140 / 8570.01-M compliant
  • CISSP strongly preferred

GDIT IS YOUR PLACE

At GDIT, the mission is our purpose, and our people are at the center of everything we do.

Growth: AI-powered career tool that identifies career steps and learning opportunities

Support: An internal mobility team focused on helping you achieve your career goals

Rewards: Comprehensive benefits and wellness packages, 401K with company match, and competitive pay and paid time off

Community: Award-winning culture of innovation and a military-friendly workplace

OWN YOUR OPPORTUNITY

Explore a career in cyber at GDIT and you'll find endless opportunities to grow alongside colleagues who share your focus on defending and protecting what matters.

The likely salary range for this position is $158,950 - $215,050. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.

Scheduled Weekly Hours:
40

Travel Required:
Less than 10%

Telecommuting Options:
Onsite

Work Location:
USA VA McLean

Additional Work Locations:

Total Rewards at GDIT:
Our benefits package for all US-based employees includes a variety of medical plan options, some with Health Savings Accounts, dental plan options, a vision plan, and a 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match. To encourage work/life balance, GDIT offers employees full flex work weeks where possible and a variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave. To ensure our employees are able to protect their income, other offerings such as short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available. We regularly review our Total Rewards package to ensure our offerings are competitive and reflect what our employees have told us they value most.

Our Identity Verification Process:
As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during virtual interviews. We reserve the right to take your picture to verify your identity and prevent fraud. By proceeding, you authorize the collection, processing, and use of your biometric data for identity verification and security purposes.

About Our Work:
We are GDIT. A global technology and professional services company that delivers technology solutions and mission services to every major agency across the U.S. government, defense and intelligence community. Our 26,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. We operate across 50+ countries worldwide, offering leading mission-ready capabilities in AI, cloud, cyber and software development.

Join our Talent Community to stay up to date on our career opportunities and events at
gdit.com/tc .

Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans



PI286926366






CYBER TECHNICAL ANALYST SR PRINCIPAL




Advance your career while impacting our national security in cyber as a Cyber Technical Analyst Sr Principal at GDIT. Here, technologists have many paths to grow a meaningful career supporting cyber missions and operations across the federal government.




MEANINGFUL WORK AND PERSONAL IMPACT




As a Cyber Technical Analyst Sr Principal, the work you'll do at GDIT will be impactful to the mission of our customer's classified commercial cloud environment. You will play a crucial role in securing and continuously monitoring a classified workstation secure enclave, ensuring it meets stringent FedRAMP and CNSSI 1253 requirements while enabling mission-critical operations.







  • Support the full RMF and Assessment & Authorization (A&A) lifecycle for the workstation secure enclave, including control implementation, assessment, authorization, and continuous monitoring.
  • Maintain a comprehensive body of evidence for FedRAMP/DoW A&A packages and continuous monitoring requirements, including POA&M tracking, reporting, and remediation.
  • Collaborate with security engineers, system administrators, ISSO/ISSM, vendors, and leadership to integrate and validate security controls and align operations with FedRAMP, DoD, and CNSSI 1253 requirements.
  • Identify, assess, and remediate vulnerabilities using Tenable Nessus, Tenable.sc, SCC, STIG tooling, and related security tools; ensure host inventory and scan policies are accurate and complete.
  • Review scan results, STIG findings, and patching activities to ensure accurate, actionable data and effective hardening of operating systems, network devices, and applications.
  • Evaluate system designs, network architectures, firewall rules, and PPSM submissions to ensure security principles are integrated from the outset and architecture risks are addressed.
  • Lead preparation and execution of security control audits and FedRAMP 3PAO assessments, reviewing artifacts, logs, and configurations to validate evidence of compliance and a strong security posture.
  • Provide security control assessment and audit oversight, including reviewing and validating implementation work performed by engineers and system administrators.
  • Manage a robust continuous monitoring and GRC program, aggregating and analyzing security data to identify trends, anomalies, and potential incidents and providing actionable risk insights to leadership.
  • Support risk assessments and incident response, recommending mitigating controls and assisting the ISSM and incident response team with artifacts and deep system/security expertise.





WHAT YOU'LL NEED TO SUCCEED




Bring your cyber expertise and drive for innovation to GDIT. The Cyber Technical Analyst Sr Principal must have:




Education: Bachelor of Arts/Bachelor of Science




Experience: 8+ years of related experience




Technical skills:



  • Hands-on experience with Tenable.sc and Tenable Nessus
  • Progressive experience in information assurance and cybersecurity roles
  • Minimum of 5 years of direct, hands-on experience as an ISSO or ISSM with a proven track record of achieving and maintaining ATO for classified systems
  • Expert-level knowledge of the NIST SP 800 series (especially 800-37, 800-53, 800-30) and risk management principles
  • Experience with FedRAMP and CNSSI 1253 baselines, continuous monitoring, POA&M management, and A&A body-of-evidence documentation

Security clearance level: Active Top Secret




Role requirements:



  • On-site McLean, VA
  • Must be DoD 8140 / 8570.01-M compliant
  • CISSP strongly preferred





GDIT IS YOUR PLACE




At GDIT, the mission is our purpose, and our people are at the center of everything we do.




Growth: AI-powered career tool that identifies career steps and learning opportunities




Support: An internal mobility team focused on helping you achieve your career goals




Rewards: Comprehensive benefits and wellness packages, 401K with company match, and competitive pay and paid time off




Community: Award-winning culture of innovation and a military-friendly workplace




OWN YOUR OPPORTUNITY




Explore a career in cyber at GDIT and you'll find endless opportunities to grow alongside colleagues who share your focus on defending and protecting what matters.




The likely salary range for this position is $158,950 - $215,050. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.







Scheduled Weekly Hours:
40







Travel Required:
Less than 10%







Telecommuting Options:
Onsite







Work Location:
USA VA McLean







Additional Work Locations:







Total Rewards at GDIT:
Our benefits package for all US-based employees includes a variety of medical plan options, some with Health Savings Accounts, dental plan options, a vision plan, and a 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match. To encourage work/life balance, GDIT offers employees full flex work weeks where possible and a variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave. To ensure our employees are able to protect their income, other offerings such as short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available. We regularly review our Total Rewards package to ensure our offerings are competitive and reflect what our employees have told us they value most.







Our Identity Verification Process:
As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during virtual interviews. We reserve the right to take your picture to verify your identity and prevent fraud. By proceeding, you authorize the collection, processing, and use of your biometric data for identity verification and security purposes.







About Our Work:
We are GDIT. A global technology and professional services company that delivers technology solutions and mission services to every major agency across the U.S. government, defense and intelligence community. Our 26,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. We operate across 50+ countries worldwide, offering leading mission-ready capabilities in AI, cloud, cyber and software development.




Join our Talent Community to stay up to date on our career opportunities and events at


gdit.com/tc .




Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans















PI286926366

Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the Cybersecurity Compliance & Continuous Monitoring Analyst in McLean, VA vacancy
  •  ...industry recognized and award-winning cybersecurity services firm with a focus on high...  ...insurance premium covered, 401k, continued education, certifications...  ...looking for: We are seeking Compliance and Continuous Monitoring Engineer - Vulnerability Management... 
    Suggested

    ShorePoint

    Washington DC
    14 days ago
  •  ...Description CYBER TECHNICAL ANALYST SR PRINCIPAL Advance...  ...role in securing and continuously monitoring a classified workstation secure...  ...to validate evidence of compliance and a strong security...  ...information assurance and cybersecurity roles Minimum of 5 years... 
    Suggested

    General Dynamics Information Technology

    McLean, VA
    4 days ago
  • $99k - $225k

     ...ensure effective risk management and cybersecurity resilience.You’ll work with your client...  ...cybersecurity policiesKnowledge of compliance testing tools such as ACAS, SCAP, STIGs...  ...POA&Ms, SAPs, risk assessments, and continuous monitoring TS/SCI clearanceHS diploma or GEDDoD... 
    Suggested
    Full time
    Contract work
    Part time
    For contractors
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    McLean, VA
    4 days ago
  • $100k - $150k

     ...Cybersecurity Risk Analyst Salary Range: $100,000 – $150,000 Clearance: TS/SCI + CI Poly Location...  .... Provide recommendations for continuous improvement of the processes and...  ...RMF, ATO, NIST SP 800-53, continuous monitoring, vulnerability management, or SOC/SIEM... 
    Suggested
    Full time
    Contract work

    Ops Tech Alliance

    McLean, VA
    a month ago
  • Req ID: 40432 Summary Cybersecurity Analyst (Vulnerability Management & Continuous Monitoring) Oakton, VA Are you ready to enhance your skills and build your career...  ...executing vulnerability management, security compliance, and Continuous Monitoring (ConMon) activities... 
    Suggested

    Njvc LLC

    Oakton, VA
    3 days ago
  • $104k - $166k

     ...Senior Risk and Vulnerability Analyst.Location: Chandler, AZ or...  .... This role ensures continuous visibility, compliance, and timely remediation to...  ...continuous vulnerability monitoring and risk analysis.Execute...  ...: Bachelor’s degree in Cybersecurity, Information Technology,... 
    Contract work
    Shift work

    Peraton Corporation

    Washington DC
    1 day ago
  •  ...Security (OIT/OIS) program covering enterprise cybersecurity architecture and engineering. We are seeking Risk and Compliance Analysts to own the risk, compliance, and supply...  ...modernization with risk analysis and continuous monitoring.REQUIRED QUALIFICATIONS- Minimum 7 years... 
    Full time
    Contract work
    Interim role
    Work at office
    Remote work

    Triumph Enterprises

    Washington DC
    1 day ago
  •  ...Effectiveness ConsultingTravel Required:Up to 10%Clearance Required:Active SecretWhat You Will Do:Guidehouse is seeking a Monitoring and Evaluation (M&E) Analyst to provide M&E technical and advisory services to the Department of State. The M&E Analyst will help strengthen... 
    Full time
    Work at office
    Flexible hours

    Guidehouse

    Arlington, VA
    1 day ago
  • $95k - $105k

     ...support Connected Logistics is seeking a senior Risk and Compliance Analyst to support cybersecurity governance, enterprise risk management, compliance oversight, audit readiness, and continuous monitoring activities supporting the VA COSE mission. This individual... 
    Contract work
    Remote work

    Connected Logistics

    Springfield, VA
    1 day ago
  • $144.2k - $164.6k

    Cyber Security Log Management Analyst Capital One is looking for a...  ...comprehensive cyber monitoring. We ensure standard log events...  ...requirements and standards. Track compliance and escalate non-compliance...  ...and high-impact enterprise cybersecurity projects with cross-functional... 
    Full time
    Part time
    H1b
    Local area

    Capital One National Association

    Mc Lean, VA
    4 days ago
  •  ...is recruiting for a Business Analyst / Project Manager to support...  ...integrations. Experience monitoring project risks, POA&Ms, and milestones for FedRAMP compliance, Zero Trust controls, and enterprise...  ..., Operations & Maintenance, Cybersecurity, and Training and Audio/... 
    Contract work
    Temporary work
    Local area

    LinTech Global

    Arlington, VA
    2 days ago
  •  ...Digital Integrity (TDI) is a cybersecurity firm built for high‑...  ...a Senior Incident Response Analyst to join our team in support...  ...Operations Center, you will help monitor, detect, investigate, and respond...  ...effectiveness and support continuous improvement. QUALIFICATIONS:... 
    Permanent employment

    Tetrad Digital Integrity

    Arlington, VA
    1 day ago
  •  ...announce the opening for a Senior Analyst, who will join our...  ...operating in missile defense, cybersecurity, test range modernization, biotechnology...  ...learning models. Lead the continuous improvement, rearchitecting,...  ...validation, deployment, and monitoring of models at scale. You will... 
    Temporary work
    Work experience placement
    Flexible hours

    nou Systems

    Arlington, VA
    13 hours ago
  •  ...Description ENTERPRISE MONITORING SYSTEMS ADMINISTRATOR...  ...Together, we’ll strengthen continuity and drive the next generation...  ...system performance, improves cybersecurity posture, and ensures reliable...  ...using automated deployment and compliance technologies Review... 

    General Dynamics Information Technology

    Washington DC
    a month ago
  •  ...Job Description Job Description The Continuous Monitoring Specialist ? Level III provides senior-level cybersecurity continuous monitoring support across the Department...  ..., vulnerability management, security compliance, and cybersecurity reporting within classified... 

    RIVIDIUM

    Washington DC
    5 days ago
  •  ...the annual statement of assurance, and continuously curates risk management related data to...  ...DCSA direction for the FOCI program by monitoring performance reports on workload and utilization...  ...statistical documentation to ensure compliance with FOCI policies and emplaced... 
    Local area

    Celestar

    Arlington, VA
    13 hours ago
  •  ...Business Corporation (THTBC) seeks a Senior Cybersecurity Analyst to join our risk-based, defense-in-...  ...with IT leadership, system admins, compliance personnel, vendors, auditors, and...  ...regulatory compliance. The role includes monitoring threats, implementing controls,... 
    Remote job

    Tlingit Haida Tribal Business Corporation

    Falls Church, VA
    2 days ago
  •  ...to federal customers. While cybersecurity is our specialty, we also focus...  ...dream workplace, Business Analyst II Responsibilities and...  ...efficiency, automation, and continuous improvement. Support requirements...  ...coordination, and milestone monitoring. Work closely with technical... 
    For contractors
    Work at office

    Electrosoft

    Arlington, VA
    3 days ago
  •  ...Business Analyst Date Needed By: 6/8/2026 Category: Information...  ...design, documentation, and continuous improvement of enterprise IT...  ...initiatives in a fast-paced, compliance-driven environment. This role...  ...federal standards and continuous monitoring expectations. The role also... 
    Full time
    For contractors
    Work at office
    Remote work
    Flexible hours

    CTAC

    Falls Church, VA
    3 days ago
  • Chenega MIOS is hiring a Security Operations Center Analyst II (SOC) in Arlington, VA. The role focuses on monitoring, incident handling, and threat response within DoD/government-grade networks using SIEM tools and a suite of security technologies. Qualified candidates... 

    NJVC

    Arlington, VA
    13 hours ago
  • $104k - $166k

     ...seeking an experienced Data Analyst/Cyber Analytics professional...  ...you'll work with large-scale cybersecurity and operational datasets to...  ...analysis to support operational monitoring, situational awareness, and...  ...before start date. Continued certification required as a... 
    Contract work
    Shift work

    Peraton Corporation

    Arlington, VA
    4 days ago
  • $120k - $160k

     ...IT Business Systems Analyst Consultant , you will...  ...improve efficiency, compliance, and customer experience...  ...solutions align with cybersecurity, privacy, regulatory,...  ...contribute to the continuous improvement of business...  ...with application monitoring and troubleshooting tools... 
    Remote work

    Kalles Group

    Washington DC
    6 days ago
  • $100k - $129.02k

     ...Management Analyst II This position requires an active Secret clearance...  ..., fiscal review, and compliance - while staying ahead of regional...  ...program offices as monitoring results warrant. Build and maintain...  ...Artificial Intelligence Cybersecurity Foreign Policy Legal Disclaimer... 
    Full time
    Contract work
    Work at office

    Cherokee Federal

    Washington DC
    1 day ago
  • Dovel Technologies, Inc is seeking a Monitoring & Evaluation Analyst to provide critical technical services for security programs. The role demands expertise in M&E frameworks, strong analytical skills, and the ability to produce detailed reports that inform leadership.... 
    Flexible hours

    Dovel Technologies

    Arlington, VA
    2 days ago
  •  ....Ensuring consistency and compliance across multi‑tenant GRC environments...  ..., and sustain reliable continuous monitoring.Collaborating across Agile...  ...(5) years of relevant cybersecurity experience, OR a Master’s...  ...as an RMF or POAM Analyst (current or past)Excellent... 
    Work at office
    Flexible hours

    Guidehouse

    McLean, VA
    4 hours ago
  •  ...through collaboration, mentorship, continuous learning, and meaningful...  ...Forces is seeking a Program Evaluation Analyst to support a federal cybersecurity grants program focused on program...  ...measurement, research, data analysis, monitoring and evaluation, or a related area... 

    Partner Forces

    Arlington, VA
    2 days ago
  •  ...Data Risk Analyst Location: Vienna, VA Work Arrangement: On-site...  ...quality, data use, and regulatory compliance. You will support the...  ...policies, standards, and procedures Monitor compliance with internal data...  ...changes Contribute to continuous improvement of data risk documentation... 
    Work at office
    Local area

    Page Mechanical Group Inc

    Vienna, VA
    3 days ago
  • $101.1k - $115.4k

     ...Overview Sr. Business Analyst - Global Payment Network Summary...  ...actionable insights. From monitoring billions of transactions to...  ...responsibility, promotes continuous learning, and rewards innovation...  ...to non-discrimination in compliance with applicable federal, state... 
    Full time
    Temporary work
    Part time
    Local area

    Capital One

    McLean, VA
    15 days ago
  • $90k - $155k

     ...community of innovators, engineers, analysts and business professionals...  ...Data Science fields. As we continue to grow at a rapid pace, we...  ...Anacostia-Bolling. Spanning cybersecurity, engineering, enterprise...  ...analysis, remediation, and compliance activities across Air Force... 
    Contract work
    Remote work
    Flexible hours

    Absolute Business Solutions Corp

    Arlington, VA
    1 day ago
  • $120.8k - $137.9k

     ...Overview Principal Risk Associate - Business Continuity Management As a Commercial Risk...  ...and recovery solutions while ensuring compliance with Enterprise Policy requirements and...  ...and presenting to senior leadership Monitor and report on key risk indicators (KRIs)... 
    Full time
    Part time
    Work at office
    Local area

    Capital One

    McLean, VA
    8 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Cybersecurity Compliance & Continuous Monitoring Analyst. Be the first to apply!