IT and Cyber Risk Auditor
Gdit
Public Trust: None
Requisition Type: Regular
Your Impact
Own your opportunity to be at the center of GDIT’s business operations. Make an impact by collaborating across functions to make mission success achievable.
Job Description
Help safeguard critical government systems by applying your hands-on ISSM/ISSO experience to security governance, risk evaluation, and compliance oversight. As an IT and Cyber Risk Auditor at GDIT, you will leverage your background managing RMF controls, system documentation, and continuous monitoring activities to deliver thorough, accurate, and mission‑focused security assessments.
This role is ideal for cybersecurity professionals who have previously served as an ISSM or ISSO and are seeking to transition into a dedicated risk, audit, and compliance position where they can influence security posture across multiple systems and programs.
MEANINGFUL WORK AND PERSONAL IMPACT
As an IT and Cyber Risk Auditor, the work you do at GDIT will have a direct and measurable impact on our customer’s mission. You’ll help ensure the integrity, security, and compliance of their IT systems by identifying potential risks, validating critical controls, and supporting continuous improvement efforts. Your work will enhance operational resilience and enable the customer to execute their mission with confidence.
● Conduct comprehensive security audits and RMF control assessments in accordance with DCSA, JSIG, and SAP security requirements, leveraging prior ISSO/ISSM experience.
● Review, validate, and improve security documentation and artifacts such as SSPs, POA&Ms, Continuous Monitoring outputs, and other evidence required by RMF and DCSA assessment standards.
● Develop, implement, and oversee operational information system security policies and guidelines aligned with the Risk Management Framework (RMF), JSIG, and applicable DCSA directives.
● Evaluate system security controls for effectiveness, completeness, and compliance with NIST SP 800‑53, DCSA/DoW requirements, JSIG standards, and internal organizational policies.
● Collaborate with ISSOs, ISSMs, SAP security personnel, and technical teams to analyze findings, recommend remediation actions, and ensure timely correction of identified vulnerabilities.
● Analyze system changes, configuration updates, and vulnerability data to determine authorization impacts, risk‑level changes, and required updates under RMF and JSIG/SAP processes.
● Support ongoing ATO and SAP authorization maintenance by tracking assessments, evidence submissions, and documentation required throughout the RMF and JSIG lifecycles.
● Prepare and deliver clear, risk‑focused briefings to system owners, DCSA assessors, SAP authorities, and other stakeholders regarding compliance status, audit results, and security‑related decisions.
WHAT YOU’LL NEED TO SUCCEED
Bring your cyber expertise and drive for innovation to GDIT. The IT and Cyber Risk Auditor must have:
● Education: Bachelors degree
● Experience: 2+ years of related experience as a prior ISSO/ISSM. In lieu of degree, additional 4+ years of work experience/training/education will be required
● Certifications: IAT II (Security +, SSCP, CCNA Security)
● Technical skills: Strong understanding of NIST SP 800-53, DoW cybersecurity requirements, and control implementation/assessment practices. Familiarity with Windows/Linux environments, vulnerability tools, and security baselines.
● Prior SAP experience desired
● Security clearance: Must have an active Top Secret clearance in order to be considered, and the ability to obtain and maintain TS/SCI clearance.
● US citizenship required
● Role requirements: Onsite, 5 days/week in Falls Church, VA office location
GDIT IS YOUR PLACE
At GDIT, the mission is our purpose, and our people are at the center of everything we do.
● Growth: AI-powered career tool that identifies career steps and learning opportunities.
● Support: An internal mobility team focused on helping you achieve your career goals.
● Rewards: Comprehensive benefits and wellness packages, 401K with company match, and competitive pay and paid time off.
● Community: Award-winning culture of innovation and a military-friendly workplace.
Explore a career in cyber at GDIT and you’ll find endless opportunities to grow alongside colleagues who share your focus on defending and protecting what matters.
Work Requirements
Years of Experience
2 + years of related experience
* may vary based on technical training, certification(s), or degree
Certification
CompTIA Security+ CE | CompTIA - CompTIA
Travel Required
Less than 10%
Citizenship
U.S. Citizenship Required
- ...adversaries, and partner with federal stakeholders to strengthen cyber resilience across complex infrastructures. Key... ...and hands‑on attack simulations. Deliver technical reporting, risk articulation, and executive‑level briefings. Collaborate with...CyberRiskFull time
- ...Auditor The Auditor will work within a team consulting and auditing both financials and... ...Standards. Review and evaluate financial risk, financial reporting and accounting... ...that specializes in Information Technology (IT), Cyber Security, Accounting & Finance, Business...CyberRiskTemporary workLocal area
$120.64k - $197.6k
...plays a hands-on role securing systems that support critical Defense and Intelligence missions. This position is focused on applying risk management frameworks, engineering security controls, and maintaining system authorizations for cloud and on-prem environments....CyberRiskFull timeRelocationRelocation package$190k - $232k
...organizations understand and manage commercial data risks, shape their digital signatures, and... ...the job here. Veilant is rethinking how cyber security and assurance get delivered... ...justifications; assembling evidence; walking auditors through reviews; answering the government...CyberRiskFull timeContract workFor contractorsWork at officeRemote workFlexible hoursShift work- ...providing administrative, technical, and analytical expertise of the Risk Management Framework with knowledge of network operations and... ...CCMD equities and participating in the regularly scheduled CCMD Cyber Scorecard Sync, and other DoW Cyber Hardening/ Hygiene Scorecard...CyberRisk
- ...support of major networks; reviews and evaluates network performance, risk and financial analysis feasibility studies. Oversees the... ...consulting solutions in the areas of national defense, homeland and cyber security. TENICA provides knowledgeable and experienced subject...CyberRiskWork at office
$107.9k - $195.05k
...team to identify, assess, and prioritize risks to DISA and DoD mission partners, as well... ...Configuration Management documentation. Conduct cyber situational awareness activities and... .... Recommend and implement changes to IT systems in accordance with DoD directives....CyberRisk- ...high-consequence environments where mission, complexity, and trust intersect. Our single focus has been delivering cyber solutions to effectively manage risk & the business of cyber for 25 years! The Geospatial Enterprise Open Data Store (GEODS) contract provides...CyberRiskPermanent employmentFull timeContract work
- ...operations, AI/ML integration, cloud modernization, data governance, and risk management. With a proven track record supporting agencies like... ...innovative solutions that maximize efficiency and strengthen cyber resilience. At our core, we are dedicated partners committed to...CyberRiskFull time
- ...compliance with STIGs for Linux, Windows, and network devices Monitor systems for security events and support incident response and risk mitigation activities Assess security impacts of system changes and support configuration control boards (CCBs) Collaborate...CyberRiskFull timeContract workTemporary work
- ...Cyber Program Manager Capital One’s fast‑paced Cyber Execution and Transformation (CET) team is seeking a highly organized, process‑focused... ...key cyber initiatives, bridging gaps between technical teams, risk professionals, and executives. Our Program Managers act as...CyberRiskLocal area
$185.1k - $273.2k
...world’s most critical data and networks against the most complex cyber threats imaginable for more than 25 years. As trailblazers in... ...we do. Our suite of cross domain, threat protection and insider risk solutions empower governments and enterprise organizations to use...CyberRiskPermanent employmentFor contractorsLocal areaFlexible hoursShift work$87.1k - $157.45k
...Enabling Architecture (TENA) program at Leidos is looking to add a Cyber Security Systems Engineer. Our mission is to develop tools for... ...and reviewing security systems security plans, security risk assessments, contingency plans, or configuration management plans...CyberRiskFull timeWork at office$80k - $90k
...environments. This role blends hands‑on technical response, threat hunting, network analysis, and cross‑functional coordination to reduce risk and improve security posture. Responsibilities Incident Response and Network Forensics: Triage, containment, eradication, and...CyberRiskFull timePart time- ...to protecting complicated data and distribution systems and providing decision makers with the most accurate assessment of residual risk possible. We work with our clients to solve the toughest challenges in the ever-evolving digital landscape. Our services include network...CyberRisk
$105k - $195k
...’s Mission Technologies division. Warfare Systems comprises cyber and mission IT; electronic warfare; and C5ISR systems. HII works within our... ...’ll facilitate team discussions, monitor progress, manage risks and issues, and provide timely updates to leaders and contributors...CyberRiskFull timeWork experience placementLocal areaWorldwide- ...Tysons, Virginia location. The Enterprise IT Security Architect is a senior security architecture... ...outcomes while meeting enterprise risk and compliance obligations. The architect... ...between First Line IT and Second Line Cyber Security, ensuring second‑line control requirements...CyberRiskWork at office
- ...Environment: Office Amount of travel: 10% The Cyber Security Specialist will support the DTRA... ...environment. Working with the DTRA IT, Cybersecurity Service Provider (CSSP)... ...mitigations, monitor for attacks, and assess risk while providing cyber based Situational...CyberRiskContract workWork at officeWeekend workAfternoon shift
- ...handling of USG data. Supports security planning, assessment, risk analysis, and risk management using the RMF in execution of the... ...with Logistician; ensures proper identification and mitigation of cyber‑supply chain risks. Required Qualifications & Skills...CyberRiskFlexible hours
- ...stakeholders Escalate impediments Help manage risk Drive relentless improvement Help with... ...program management, including managing complex IT projects Top Secret clearance Bachelor’s... ...or IT DoDM 8140.03 for Defensive Cyber Workforce (DCWF) Work Role 801 Advanced Level...CyberRisk
$183.6k - $221.6k
## Principal Cyber Engineer (TS/SCI Required)Applylocations: USA\_VA\_Onsitetime type: Full timeposted on: Posted 30 Days Agojob requisition... ...we do. Our suite of cross domain, threat protection and insider risk solutions empower governments and enterprise organizations to...CyberRiskPermanent employmentFull timeFor contractorsLocal areaRemote workMonday to FridayFlexible hours- ...MartinFed is seeking a highly experienced Lead Cyber Security Engineer to provide technical... ...engineering, vulnerability management, risk assessment, incident response, and secure... ...software developers, system engineers, and IT personnel to integrate security throughout...CyberRiskWork at officeLocal area
- ...information technology systems through the full life cycle of the Risk Management Framework (RMF) process to achieve/renew Authority to... ...: 8 years direct cybersecurity work; experience evaluating the cyber compliance of a system against current RMF and DoW Cybersecurity...CyberRiskWork at office
$177.7k - $202.8k
## Senior Cyber Program ManagerApplylocations: McLean, VA: Richmond, VAtime type: Full timeposted on: Posted Todayjob requisition id:... ...and Reporting team, you will be immersed in cyber and technology risks, which will allow our cyber organization and partners to pinpoint...CyberRiskFull timePart timeH1bLocal areaImmediate start$100k - $115k
...could detect and respond to novel, real-time cyber threats. That approach matters more than... ...role, you will partner with security, IT, and technical stakeholders to turn deployment... ...into daily security operations, reduce risk, and achieve measurable outcomes. You will...CyberRiskWork at officeLocal area3 days per week$150.45k - $233.45k
...and bench-strength builder across Boeing’s cyber leadership cadre. Position... ...stakeholders (program management, engineering, IT, legal, contracting, security) to deliver... ...cybersecurity policies and implementation of Risk Management Framework (RMF): e.g. DAAPM, CNSSI...CyberRiskPermanent employmentRelocationVisa sponsorshipWork visaRelocation packageFlexible hoursShift workDay shift$120k - $130k
TechFlow Inc. is seeking a Cyber Security Analyst II to support a mission-critical DOD platform... ...operations by monitoring cybersecurity risks, implementing security controls,... ...alongside systems administrators, engineers, and IT professionals, you will play a key role in...CyberRiskRemote work$100k - $150k
Position is contingent upon contract award Cybersecurity Risk Analyst Salary Range: $100,000 - $150,000 Clearance: TS/SCI + CI Poly Location... ...Risk Analyst to support enterprise cybersecurity and cyber defense operations in the Washington, D.C. metropolitan area. This...CyberRiskFull timeContract work- ...provides technically advanced full-spectrum cyber, data operations, systems integration and... ...development- Knowledge in various IT fields that include but are not limited to... ...preferred)- Experience and/or familiarity of the Risk Management Framework (RMF) and security and...CyberRiskContract workImmediate start
$86.8k - $198k
The Opportunity As a cyber security specialist, you will utilize experience in Risk Management Framework (RMF), system updates, patches, and scans to maintain cyber compliance, while performing eMASS administration to support next‑gen software solutions for the U.S. military...CyberRiskFull timePart timeInterim roleLocal area
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to IT and Cyber Risk Auditor. Be the first to apply!
- cyber Falls Church, VA
- risk Falls Church, VA
- risk adjustment Falls Church, VA
- technology risk Falls Church, VA
- risk assurance Falls Church, VA
- high risk Falls Church, VA
- information technology support Falls Church, VA
- IT analyst Falls Church, VA
- it operations coordinator Falls Church, VA
- IT governance analyst Falls Church, VA



