Cybersecurity Compliance & Continuous Monitoring Analyst
$158.95k - $215.05kFull-time
Gdit
Responsibilities for this Position
Location: USA VA McLeanFull Part/Time: Full time
Job Req: RQ227719 Type of Requisition:
Regular Clearance Level Must Currently Possess:
Top Secret Clearance Level Must Be Able to Obtain:
Top Secret/SCI Public Trust/Other Required:
None Job Family:
Cyber and IT Risk Management Job Qualifications: Skills:
Continuous Monitoring, Control Assessment, Federal Risk and Authorization Management Program (FedRAMP), Security Controls
Certifications:
None
Experience:
8 + years of related experience
US Citizenship Required:
Yes Job Description: CYBER TECHNICAL ANALYST SR PRINCIPAL Advance your career while impacting our national security in cyber as a Cyber Technical Analyst Sr Principal at GDIT. Here, technologists have many paths to grow a meaningful career supporting cyber missions and operations across the federal government. MEANINGFUL WORK AND PERSONAL IMPACT As a Cyber Technical Analyst Sr Principal, the work you'll do at GDIT will be impactful to the mission of our customer's classified commercial cloud environment. You will play a crucial role in securing and continuously monitoring a classified workstation secure enclave, ensuring it meets stringent FedRAMP and CNSSI 1253 requirements while enabling mission-critical operations.
- Support the full RMF and Assessment & Authorization (A&A) lifecycle for the workstation secure enclave, including control implementation, assessment, authorization, and continuous monitoring.
- Maintain a comprehensive body of evidence for FedRAMP/DoW A&A packages and continuous monitoring requirements, including POA&M tracking, reporting, and remediation.
- Collaborate with security engineers, system administrators, ISSO/ISSM, vendors, and leadership to integrate and validate security controls and align operations with FedRAMP, DoD, and CNSSI 1253 requirements.
- Identify, assess, and remediate vulnerabilities using Tenable Nessus, Tenable.sc, SCC, STIG tooling, and related security tools; ensure host inventory and scan policies are accurate and complete.
- Review scan results, STIG findings, and patching activities to ensure accurate, actionable data and effective hardening of operating systems, network devices, and applications.
- Evaluate system designs, network architectures, firewall rules, and PPSM submissions to ensure security principles are integrated from the outset and architecture risks are addressed.
- Lead preparation and execution of security control audits and FedRAMP 3PAO assessments, reviewing artifacts, logs, and configurations to validate evidence of compliance and a strong security posture.
- Provide security control assessment and audit oversight, including reviewing and validating implementation work performed by engineers and system administrators.
- Manage a robust continuous monitoring and GRC program, aggregating and analyzing security data to identify trends, anomalies, and potential incidents and providing actionable risk insights to leadership.
- Support risk assessments and incident response, recommending mitigating controls and assisting the ISSM and incident response team with artifacts and deep system/security expertise.
- Hands-on experience with Tenable.sc and Tenable Nessus
- Progressive experience in information assurance and cybersecurity roles
- Minimum of 5 years of direct, hands-on experience as an ISSO or ISSM with a proven track record of achieving and maintaining ATO for classified systems
- Expert-level knowledge of the NIST SP 800 series (especially 800-37, 800-53, 800-30) and risk management principles
- Experience with FedRAMP and CNSSI 1253 baselines, continuous monitoring, POA&M management, and A&A body-of-evidence documentation
- On-site McLean, VA
- Must be DoD 8140 / 8570.01-M compliant
- CISSP strongly preferred
40 Travel Required:
Less than 10% Telecommuting Options:
Onsite Work Location:
USA VA McLean Additional Work Locations: Total Rewards at GDIT:
Our benefits package for all US-based employees includes a variety of medical plan options, some with Health Savings Accounts, dental plan options, a vision plan, and a 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match. To encourage work/life balance, GDIT offers employees full flex work weeks where possible and a variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave. To ensure our employees are able to protect their income, other offerings such as short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available. We regularly review our Total Rewards package to ensure our offerings are competitive and reflect what our employees have told us they value most. Our Identity Verification Process:
As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during virtual interviews. We reserve the right to take your picture to verify your identity and prevent fraud. By proceeding, you authorize the collection, processing, and use of your biometric data for identity verification and security purposes. About Our Work:
We are GDIT. A global technology and professional services company that delivers technology solutions and mission services to every major agency across the U.S. government, defense and intelligence community. Our 26,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. We operate across 50+ countries worldwide, offering leading mission-ready capabilities in AI, cloud, cyber and software development. Join our Talent Community to stay up to date on our career opportunities and events at
gdit.com/tc . Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans
PI286926366
CYBER TECHNICAL ANALYST SR PRINCIPAL
Advance your career while impacting our national security in cyber as a Cyber Technical Analyst Sr Principal at GDIT. Here, technologists have many paths to grow a meaningful career supporting cyber missions and operations across the federal government.
MEANINGFUL WORK AND PERSONAL IMPACT
As a Cyber Technical Analyst Sr Principal, the work you'll do at GDIT will be impactful to the mission of our customer's classified commercial cloud environment. You will play a crucial role in securing and continuously monitoring a classified workstation secure enclave, ensuring it meets stringent FedRAMP and CNSSI 1253 requirements while enabling mission-critical operations.
- Support the full RMF and Assessment & Authorization (A&A) lifecycle for the workstation secure enclave, including control implementation, assessment, authorization, and continuous monitoring.
- Maintain a comprehensive body of evidence for FedRAMP/DoW A&A packages and continuous monitoring requirements, including POA&M tracking, reporting, and remediation.
- Collaborate with security engineers, system administrators, ISSO/ISSM, vendors, and leadership to integrate and validate security controls and align operations with FedRAMP, DoD, and CNSSI 1253 requirements.
- Identify, assess, and remediate vulnerabilities using Tenable Nessus, Tenable.sc, SCC, STIG tooling, and related security tools; ensure host inventory and scan policies are accurate and complete.
- Review scan results, STIG findings, and patching activities to ensure accurate, actionable data and effective hardening of operating systems, network devices, and applications.
- Evaluate system designs, network architectures, firewall rules, and PPSM submissions to ensure security principles are integrated from the outset and architecture risks are addressed.
- Lead preparation and execution of security control audits and FedRAMP 3PAO assessments, reviewing artifacts, logs, and configurations to validate evidence of compliance and a strong security posture.
- Provide security control assessment and audit oversight, including reviewing and validating implementation work performed by engineers and system administrators.
- Manage a robust continuous monitoring and GRC program, aggregating and analyzing security data to identify trends, anomalies, and potential incidents and providing actionable risk insights to leadership.
- Support risk assessments and incident response, recommending mitigating controls and assisting the ISSM and incident response team with artifacts and deep system/security expertise.
WHAT YOU'LL NEED TO SUCCEED
Bring your cyber expertise and drive for innovation to GDIT. The Cyber Technical Analyst Sr Principal must have:
Education: Bachelor of Arts/Bachelor of Science
Experience: 8+ years of related experience
Technical skills:
- Hands-on experience with Tenable.sc and Tenable Nessus
- Progressive experience in information assurance and cybersecurity roles
- Minimum of 5 years of direct, hands-on experience as an ISSO or ISSM with a proven track record of achieving and maintaining ATO for classified systems
- Expert-level knowledge of the NIST SP 800 series (especially 800-37, 800-53, 800-30) and risk management principles
- Experience with FedRAMP and CNSSI 1253 baselines, continuous monitoring, POA&M management, and A&A body-of-evidence documentation
Security clearance level: Active Top Secret
Role requirements:
- On-site McLean, VA
- Must be DoD 8140 / 8570.01-M compliant
- CISSP strongly preferred
GDIT IS YOUR PLACE
At GDIT, the mission is our purpose, and our people are at the center of everything we do.
Growth: AI-powered career tool that identifies career steps and learning opportunities
Support: An internal mobility team focused on helping you achieve your career goals
Rewards: Comprehensive benefits and wellness packages, 401K with company match, and competitive pay and paid time off
Community: Award-winning culture of innovation and a military-friendly workplace
OWN YOUR OPPORTUNITY
Explore a career in cyber at GDIT and you'll find endless opportunities to grow alongside colleagues who share your focus on defending and protecting what matters.
The likely salary range for this position is $158,950 - $215,050. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.
Scheduled Weekly Hours:
40
Travel Required:
Less than 10%
Telecommuting Options:
Onsite
Work Location:
USA VA McLean
Additional Work Locations:
Total Rewards at GDIT:
Our benefits package for all US-based employees includes a variety of medical plan options, some with Health Savings Accounts, dental plan options, a vision plan, and a 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match. To encourage work/life balance, GDIT offers employees full flex work weeks where possible and a variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave. To ensure our employees are able to protect their income, other offerings such as short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available. We regularly review our Total Rewards package to ensure our offerings are competitive and reflect what our employees have told us they value most.
Our Identity Verification Process:
As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during virtual interviews. We reserve the right to take your picture to verify your identity and prevent fraud. By proceeding, you authorize the collection, processing, and use of your biometric data for identity verification and security purposes.
About Our Work:
We are GDIT. A global technology and professional services company that delivers technology solutions and mission services to every major agency across the U.S. government, defense and intelligence community. Our 26,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. We operate across 50+ countries worldwide, offering leading mission-ready capabilities in AI, cloud, cyber and software development.
Join our Talent Community to stay up to date on our career opportunities and events at
gdit.com/tc .
Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans
PI286926366
Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the Cybersecurity Compliance & Continuous Monitoring Analyst in McLean, VA vacancy
- ...industry recognized and award-winning cybersecurity services firm with a focus on high... ...insurance premium covered, 401k, continued education, certifications... ...looking for: We are seeking Compliance and Continuous Monitoring Engineer - Vulnerability Management...Suggested
- ...Description CYBER TECHNICAL ANALYST SR PRINCIPAL Advance... ...role in securing and continuously monitoring a classified workstation secure... ...to validate evidence of compliance and a strong security... ...information assurance and cybersecurity roles Minimum of 5 years...Suggested
$99k - $225k
...ensure effective risk management and cybersecurity resilience.You’ll work with your client... ...cybersecurity policiesKnowledge of compliance testing tools such as ACAS, SCAP, STIGs... ...POA&Ms, SAPs, risk assessments, and continuous monitoring TS/SCI clearanceHS diploma or GEDDoD...SuggestedFull timeContract workPart timeFor contractorsWork at officeLocal areaRemote work$100k - $150k
...Cybersecurity Risk Analyst Salary Range: $100,000 – $150,000 Clearance: TS/SCI + CI Poly Location... .... Provide recommendations for continuous improvement of the processes and... ...RMF, ATO, NIST SP 800-53, continuous monitoring, vulnerability management, or SOC/SIEM...SuggestedFull timeContract work- Req ID: 40432 Summary Cybersecurity Analyst (Vulnerability Management & Continuous Monitoring) Oakton, VA Are you ready to enhance your skills and build your career... ...executing vulnerability management, security compliance, and Continuous Monitoring (ConMon) activities...Suggested
$104k - $166k
...Senior Risk and Vulnerability Analyst.Location: Chandler, AZ or... .... This role ensures continuous visibility, compliance, and timely remediation to... ...continuous vulnerability monitoring and risk analysis.Execute... ...: Bachelor’s degree in Cybersecurity, Information Technology,...Contract workShift work- ...Security (OIT/OIS) program covering enterprise cybersecurity architecture and engineering. We are seeking Risk and Compliance Analysts to own the risk, compliance, and supply... ...modernization with risk analysis and continuous monitoring.REQUIRED QUALIFICATIONS- Minimum 7 years...Full timeContract workInterim roleWork at officeRemote work
- ...Effectiveness ConsultingTravel Required:Up to 10%Clearance Required:Active SecretWhat You Will Do:Guidehouse is seeking a Monitoring and Evaluation (M&E) Analyst to provide M&E technical and advisory services to the Department of State. The M&E Analyst will help strengthen...Full timeWork at officeFlexible hours
$95k - $105k
...support Connected Logistics is seeking a senior Risk and Compliance Analyst to support cybersecurity governance, enterprise risk management, compliance oversight, audit readiness, and continuous monitoring activities supporting the VA COSE mission. This individual...Contract workRemote work$144.2k - $164.6k
Cyber Security Log Management Analyst Capital One is looking for a... ...comprehensive cyber monitoring. We ensure standard log events... ...requirements and standards. Track compliance and escalate non-compliance... ...and high-impact enterprise cybersecurity projects with cross-functional...Full timePart timeH1bLocal area- ...is recruiting for a Business Analyst / Project Manager to support... ...integrations. Experience monitoring project risks, POA&Ms, and milestones for FedRAMP compliance, Zero Trust controls, and enterprise... ..., Operations & Maintenance, Cybersecurity, and Training and Audio/...Contract workTemporary workLocal area
- ...Digital Integrity (TDI) is a cybersecurity firm built for high‑... ...a Senior Incident Response Analyst to join our team in support... ...Operations Center, you will help monitor, detect, investigate, and respond... ...effectiveness and support continuous improvement. QUALIFICATIONS:...Permanent employment
- ...announce the opening for a Senior Analyst, who will join our... ...operating in missile defense, cybersecurity, test range modernization, biotechnology... ...learning models. Lead the continuous improvement, rearchitecting,... ...validation, deployment, and monitoring of models at scale. You will...Temporary workWork experience placementFlexible hours
- ...Description ENTERPRISE MONITORING SYSTEMS ADMINISTRATOR... ...Together, we’ll strengthen continuity and drive the next generation... ...system performance, improves cybersecurity posture, and ensures reliable... ...using automated deployment and compliance technologies Review...
- ...Job Description Job Description The Continuous Monitoring Specialist ? Level III provides senior-level cybersecurity continuous monitoring support across the Department... ..., vulnerability management, security compliance, and cybersecurity reporting within classified...
- ...the annual statement of assurance, and continuously curates risk management related data to... ...DCSA direction for the FOCI program by monitoring performance reports on workload and utilization... ...statistical documentation to ensure compliance with FOCI policies and emplaced...Local area
- ...Business Corporation (THTBC) seeks a Senior Cybersecurity Analyst to join our risk-based, defense-in-... ...with IT leadership, system admins, compliance personnel, vendors, auditors, and... ...regulatory compliance. The role includes monitoring threats, implementing controls,...Remote job
- ...to federal customers. While cybersecurity is our specialty, we also focus... ...dream workplace, Business Analyst II Responsibilities and... ...efficiency, automation, and continuous improvement. Support requirements... ...coordination, and milestone monitoring. Work closely with technical...For contractorsWork at office
- ...Business Analyst Date Needed By: 6/8/2026 Category: Information... ...design, documentation, and continuous improvement of enterprise IT... ...initiatives in a fast-paced, compliance-driven environment. This role... ...federal standards and continuous monitoring expectations. The role also...Full timeFor contractorsWork at officeRemote workFlexible hours
- Chenega MIOS is hiring a Security Operations Center Analyst II (SOC) in Arlington, VA. The role focuses on monitoring, incident handling, and threat response within DoD/government-grade networks using SIEM tools and a suite of security technologies. Qualified candidates...
$104k - $166k
...seeking an experienced Data Analyst/Cyber Analytics professional... ...you'll work with large-scale cybersecurity and operational datasets to... ...analysis to support operational monitoring, situational awareness, and... ...before start date. Continued certification required as a...Contract workShift work$120k - $160k
...IT Business Systems Analyst Consultant , you will... ...improve efficiency, compliance, and customer experience... ...solutions align with cybersecurity, privacy, regulatory,... ...contribute to the continuous improvement of business... ...with application monitoring and troubleshooting tools...Remote work$100k - $129.02k
...Management Analyst II This position requires an active Secret clearance... ..., fiscal review, and compliance - while staying ahead of regional... ...program offices as monitoring results warrant. Build and maintain... ...Artificial Intelligence Cybersecurity Foreign Policy Legal Disclaimer...Full timeContract workWork at office- Dovel Technologies, Inc is seeking a Monitoring & Evaluation Analyst to provide critical technical services for security programs. The role demands expertise in M&E frameworks, strong analytical skills, and the ability to produce detailed reports that inform leadership....Flexible hours
- ....Ensuring consistency and compliance across multi‑tenant GRC environments... ..., and sustain reliable continuous monitoring.Collaborating across Agile... ...(5) years of relevant cybersecurity experience, OR a Master’s... ...as an RMF or POAM Analyst (current or past)Excellent...Work at officeFlexible hours
- ...through collaboration, mentorship, continuous learning, and meaningful... ...Forces is seeking a Program Evaluation Analyst to support a federal cybersecurity grants program focused on program... ...measurement, research, data analysis, monitoring and evaluation, or a related area...
- ...Data Risk Analyst Location: Vienna, VA Work Arrangement: On-site... ...quality, data use, and regulatory compliance. You will support the... ...policies, standards, and procedures Monitor compliance with internal data... ...changes Contribute to continuous improvement of data risk documentation...Work at officeLocal area
$101.1k - $115.4k
...Overview Sr. Business Analyst - Global Payment Network Summary... ...actionable insights. From monitoring billions of transactions to... ...responsibility, promotes continuous learning, and rewards innovation... ...to non-discrimination in compliance with applicable federal, state...Full timeTemporary workPart timeLocal area$90k - $155k
...community of innovators, engineers, analysts and business professionals... ...Data Science fields. As we continue to grow at a rapid pace, we... ...Anacostia-Bolling. Spanning cybersecurity, engineering, enterprise... ...analysis, remediation, and compliance activities across Air Force...Contract workRemote workFlexible hours$120.8k - $137.9k
...Overview Principal Risk Associate - Business Continuity Management As a Commercial Risk... ...and recovery solutions while ensuring compliance with Enterprise Policy requirements and... ...and presenting to senior leadership Monitor and report on key risk indicators (KRIs)...Full timePart timeWork at officeLocal area
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Cybersecurity Compliance & Continuous Monitoring Analyst. Be the first to apply!
Related searches
- cyber security consultant McLean, VA
- cyber security specialist McLean, VA
- compliance analyst McLean, VA
- regulatory compliance specialist McLean, VA
- regulatory affairs specialist McLean, VA
- regulatory compliance associate McLean, VA
- compliance specialist McLean, VA
- coding compliance specialist McLean, VA
- compliance consultant McLean, VA
- compliance associate McLean, VA


