Cybersecurity Compliance & Continuous Monitoring Analyst
$158.95k - $215.05kFull-time
GDIT
Responsibilities for this Position
Location: USA VA McLeanFull Part/Time: Full time
Job Req: RQ227716 Type of Requisition:
Regular Clearance Level Must Currently Possess:
Top Secret Clearance Level Must Be Able to Obtain:
Top Secret/SCI Public Trust/Other Required:
None Job Family:
Cyber and IT Risk Management Job Qualifications: Skills:
Continuous Monitoring, Cybersecurity Compliance, DISA STIG, Federal Risk and Authorization Management Program (FedRAMP)
Certifications:
None
Experience:
8 + years of related experience
US Citizenship Required:
Yes Job Description: CYBER TECHNICAL ANALYST SR PRINCIPAL Advance your career while impacting our national security in cyber as a Cyber Technical Analyst Sr Principal at GDIT. Here, technologists have many paths to grow a meaningful career supporting cyber missions and operations across the federal government. MEANINGFUL WORK AND PERSONAL IMPACT As a Cyber Technical Analyst Sr Principal, the work you'll do at GDIT will be impactful to the mission of our customer's classified commercial cloud environment. You will play a crucial role in securing and continuously monitoring a classified workstation secure enclave, ensuring it meets stringent FedRAMP and CNSSI 1253 requirements while enabling mission-critical operations.
- Support the full RMF and Assessment & Authorization (A&A) lifecycle for the workstation secure enclave, including control implementation, assessment, authorization, and continuous monitoring.
- Maintain a comprehensive body of evidence for FedRAMP/DoW A&A packages and continuous monitoring requirements, including POA&M tracking, reporting, and remediation.
- Collaborate with security engineers, system administrators, ISSO/ISSM, vendors, and leadership to integrate and validate security controls and align operations with FedRAMP, DoD, and CNSSI 1253 requirements.
- Identify, assess, and remediate vulnerabilities using Tenable Nessus, Tenable.sc, SCC, STIG tooling, and related security tools; ensure host inventory and scan policies are accurate and complete.
- Review scan results, STIG findings, and patching activities to ensure accurate, actionable data and effective hardening of operating systems, network devices, and applications.
- Evaluate system designs, network architectures, firewall rules, and PPSM submissions to ensure security principles are integrated from the outset and architecture risks are addressed.
- Lead preparation and execution of security control audits and FedRAMP 3PAO assessments, reviewing artifacts, logs, and configurations to validate evidence of compliance and a strong security posture.
- Provide security control assessment and audit oversight, including reviewing and validating implementation work performed by engineers and system administrators.
- Manage a robust continuous monitoring and GRC program, aggregating and analyzing security data to identify trends, anomalies, and potential incidents and providing actionable risk insights to leadership.
- Support risk assessments and incident response, recommending mitigating controls and assisting the ISSM and incident response team with artifacts and deep system/security expertise.
- Hands-on experience with Tenable.sc and Tenable Nessus
- Progressive experience in information assurance and cybersecurity roles
- Minimum of 5 years of direct, hands-on experience as an ISSO or ISSM with a proven track record of achieving and maintaining ATO for classified systems
- Expert-level knowledge of the NIST SP 800 series (especially 800-37, 800-53, 800-30) and risk management principles
- Experience with FedRAMP and CNSSI 1253 baselines, continuous monitoring, POA&M management, and A&A body-of-evidence documentation
- On-site McLean, VA
- Must be DoD 8140 / 8570.01-M compliant
- CISSP strongly preferred
40 Travel Required:
Less than 10% Telecommuting Options:
Onsite Work Location:
USA VA McLean Additional Work Locations: Total Rewards at GDIT:
Our benefits package for all US-based employees includes a variety of medical plan options, some with Health Savings Accounts, dental plan options, a vision plan, and a 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match. To encourage work/life balance, GDIT offers employees full flex work weeks where possible and a variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave. To ensure our employees are able to protect their income, other offerings such as short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available. We regularly review our Total Rewards package to ensure our offerings are competitive and reflect what our employees have told us they value most. Our Identity Verification Process:
As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during virtual interviews. We reserve the right to take your picture to verify your identity and prevent fraud. By proceeding, you authorize the collection, processing, and use of your biometric data for identity verification and security purposes. About Our Work:
We are GDIT. A global technology and professional services company that delivers technology solutions and mission services to every major agency across the U.S. government, defense and intelligence community. Our 26,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. We operate across 50+ countries worldwide, offering leading mission-ready capabilities in AI, cloud, cyber and software development. Join our Talent Community to stay up to date on our career opportunities and events at
gdit.com/tc . Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans
PI286926365
CYBER TECHNICAL ANALYST SR PRINCIPAL
Advance your career while impacting our national security in cyber as a Cyber Technical Analyst Sr Principal at GDIT. Here, technologists have many paths to grow a meaningful career supporting cyber missions and operations across the federal government.
MEANINGFUL WORK AND PERSONAL IMPACT
As a Cyber Technical Analyst Sr Principal, the work you'll do at GDIT will be impactful to the mission of our customer's classified commercial cloud environment. You will play a crucial role in securing and continuously monitoring a classified workstation secure enclave, ensuring it meets stringent FedRAMP and CNSSI 1253 requirements while enabling mission-critical operations.
- Support the full RMF and Assessment & Authorization (A&A) lifecycle for the workstation secure enclave, including control implementation, assessment, authorization, and continuous monitoring.
- Maintain a comprehensive body of evidence for FedRAMP/DoW A&A packages and continuous monitoring requirements, including POA&M tracking, reporting, and remediation.
- Collaborate with security engineers, system administrators, ISSO/ISSM, vendors, and leadership to integrate and validate security controls and align operations with FedRAMP, DoD, and CNSSI 1253 requirements.
- Identify, assess, and remediate vulnerabilities using Tenable Nessus, Tenable.sc, SCC, STIG tooling, and related security tools; ensure host inventory and scan policies are accurate and complete.
- Review scan results, STIG findings, and patching activities to ensure accurate, actionable data and effective hardening of operating systems, network devices, and applications.
- Evaluate system designs, network architectures, firewall rules, and PPSM submissions to ensure security principles are integrated from the outset and architecture risks are addressed.
- Lead preparation and execution of security control audits and FedRAMP 3PAO assessments, reviewing artifacts, logs, and configurations to validate evidence of compliance and a strong security posture.
- Provide security control assessment and audit oversight, including reviewing and validating implementation work performed by engineers and system administrators.
- Manage a robust continuous monitoring and GRC program, aggregating and analyzing security data to identify trends, anomalies, and potential incidents and providing actionable risk insights to leadership.
- Support risk assessments and incident response, recommending mitigating controls and assisting the ISSM and incident response team with artifacts and deep system/security expertise.
WHAT YOU'LL NEED TO SUCCEED
Bring your cyber expertise and drive for innovation to GDIT. The Cyber Technical Analyst Sr Principal must have:
Education: Bachelor of Arts/Bachelor of Science
Experience: 8+ years of related experience
Technical skills:
- Hands-on experience with Tenable.sc and Tenable Nessus
- Progressive experience in information assurance and cybersecurity roles
- Minimum of 5 years of direct, hands-on experience as an ISSO or ISSM with a proven track record of achieving and maintaining ATO for classified systems
- Expert-level knowledge of the NIST SP 800 series (especially 800-37, 800-53, 800-30) and risk management principles
- Experience with FedRAMP and CNSSI 1253 baselines, continuous monitoring, POA&M management, and A&A body-of-evidence documentation
Security clearance level: Active Top Secret
Role requirements:
- On-site McLean, VA
- Must be DoD 8140 / 8570.01-M compliant
- CISSP strongly preferred
GDIT IS YOUR PLACE
At GDIT, the mission is our purpose, and our people are at the center of everything we do.
Growth: AI-powered career tool that identifies career steps and learning opportunities
Support: An internal mobility team focused on helping you achieve your career goals
Rewards: Comprehensive benefits and wellness packages, 401K with company match, and competitive pay and paid time off
Community: Award-winning culture of innovation and a military-friendly workplace
OWN YOUR OPPORTUNITY
Explore a career in cyber at GDIT and you'll find endless opportunities to grow alongside colleagues who share your focus on defending and protecting what matters.
The likely salary range for this position is $158,950 - $215,050. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.
Scheduled Weekly Hours:
40
Travel Required:
Less than 10%
Telecommuting Options:
Onsite
Work Location:
USA VA McLean
Additional Work Locations:
Total Rewards at GDIT:
Our benefits package for all US-based employees includes a variety of medical plan options, some with Health Savings Accounts, dental plan options, a vision plan, and a 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match. To encourage work/life balance, GDIT offers employees full flex work weeks where possible and a variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave. To ensure our employees are able to protect their income, other offerings such as short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available. We regularly review our Total Rewards package to ensure our offerings are competitive and reflect what our employees have told us they value most.
Our Identity Verification Process:
As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during virtual interviews. We reserve the right to take your picture to verify your identity and prevent fraud. By proceeding, you authorize the collection, processing, and use of your biometric data for identity verification and security purposes.
About Our Work:
We are GDIT. A global technology and professional services company that delivers technology solutions and mission services to every major agency across the U.S. government, defense and intelligence community. Our 26,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. We operate across 50+ countries worldwide, offering leading mission-ready capabilities in AI, cloud, cyber and software development.
Join our Talent Community to stay up to date on our career opportunities and events at
gdit.com/tc .
Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans
PI286926365
Vacancy posted a month ago
Similar jobs that could be interesting for youBased on the Cybersecurity Compliance & Continuous Monitoring Analyst in McLean, VA vacancy
- ...federal and commercial clients. We deliver mission-focused solutions in data, cloud, cybersecurity, and program management. Position Overview The Continuous Monitoring (ISCM) Analyst runs the monthly control review, SAR, and RAM cycle for the 15 systems in the...Suggested
$158.95k - $215.05k
...Qualifications: Skills: Continuous Monitoring, Control Assessment,... ...Description: CYBER TECHNICAL ANALYST SR PRINCIPAL Advance... ...to validate evidence of compliance and a strong security posture... ...information assurance and cybersecurity roles Minimum of 5...SuggestedFull timeTemporary workPart timeImmediate startRemote workWorldwideFlexible hours$95k - $125k
...seeking an AI Governance Analyst to operationalize a... ...a living Mandate Compliance Matrix, AI governance... ...bias identification/monitoring, data handling/retention... ...use cases to confirm continued complianceMonitor policy... ..., Data Ethics, Cybersecurity, Law, or a related field...Suggested$99k - $225k
...ensure effective risk management and cybersecurity resilience. You’ll work with your... ...cybersecurity policies ~ Knowledge of compliance testing tools such as ACAS, SCAP,... ...POA&Ms, SAPs, risk assessments, and continuous monitoring ~ TS/SCI clearance ~ HS diploma or...SuggestedFull timeContract workPart timeFor contractorsWork at officeLocal areaRemote work- ...industry recognized and award-winning cybersecurity services firm with a focus on high... ...insurance premium covered, 401k, continued education, certifications... ...looking for: We are seeking Compliance and Continuous Monitoring Engineer - Vulnerability Management...Suggested
- ...Auditor / Government & Risk Compliance ConsultantJob location-... ...Hybrid)Role is surrounding a continuous controls monitoring program that they're trying to stand up within cybersecurity. They're looking to build... ...requirements for the data analyst. Issues with candidates so...
- US Cybersecurity and Infrastructure Security Agency (CISA) in Arlington, VA, seeks an Information Technology Cybersecurity Specialist, GS-2210-13/14, under Direct Hire Authority. The role requires IT-related experience and demonstrated competencies across detail, customer...
$80k - $128k
...a Risk and Vulnerability Analyst.Location: Chandler, AZ or... ...environments. This role ensures continuous visibility, compliance, and timely remediation... ...continuous vulnerability monitoring and risk analysis.Execute... ...: Bachelor’s degree in Cybersecurity, Information Technology,...Contract workShift work- ...Job Description Job Description Overview Cybersecurity Analyst (Vulnerability Management & Continuous Monitoring) Oakton, VA Are you ready to... ...executing vulnerability management, security compliance, and Continuous Monitoring (ConMon) activities...
- ...Vulnerability Management Analyst ID 2025-3164... ...to support enterprise cybersecurity operations across a... ...cybersecurity controls by continuously identifying, validating, and monitoring vulnerabilities across... ...support configuration compliance checks. ~ Maintain...Full timeContract workFor contractorsLocal areaRemote work
- The Senior Security Analyst is responsible for supporting functions... ...and Governance & Compliance operations. This role will... ...work across enterprise-wide cybersecurity initiatives, balancing strategic... ...Provide authorization and continuous monitoring activities for information...Full timeTemporary workFor contractorsWork experience placementFor subcontractorLocal areaImmediate start
$131k - $218.3k
...and opportunities businesses face in cybersecurity. Join our team to deliver powerful solutions... ...on cyber risk posture and RMF compliance strategies aligned to FISMA, NIST, and... ..., security assessment, or continuous-monitoring activities, including 1+ year applying...Work at officeLocal areaRelocationNight shift- ...Security (OIT/OIS) program covering enterprise cybersecurity architecture and engineering. We are seeking Risk and Compliance Analysts to own the risk, compliance, and supply... ...modernization with risk analysis and continuous monitoring.REQUIRED QUALIFICATIONS- Minimum 7 years...Full timeContract workInterim roleWork at officeRemote work
- ...Effectiveness ConsultingTravel Required:Up to 10%Clearance Required:Active SecretWhat You Will Do:Guidehouse is seeking a Monitoring and Evaluation (M&E) Analyst to provide M&E technical and advisory services to the Department of State. The M&E Analyst will help strengthen...Full timeWork at officeFlexible hours
$180k - $250k
...announce the opening for a Senior Analyst, who will join our... ...operating in missile defense, cybersecurity, test range modernization, biotechnology... ...learning models Lead the continuous improvement, rearchitecting,... ...validation, deployment, and monitoring of models at scale. You...Temporary workWork experience placementFlexible hours- ...Senior Analyst, Cybersecurity GRC, Washington, DC The Senior Analyst, Cybersecurity GRC will administer the completion of compliance-related client requests to assess security policies and... ...initial, reassessments and ongoing monitoring) and supporting broader GRC...Work experience placement
$120k - $135k
...Digital Integrity (TDI) is a cybersecurity firm built for high-... ...a Senior Incident Response Analyst to join our team in support... ...Operations Center, you will help monitor, detect, investigate, and respond... ...effectiveness and support continuous improvement. QUALIFICATIONS...Permanent employmentContract workRemote work2 days per week$73.49k
...including managed mobility, cloud, cybersecurity, network operations, and... ...Opportunity DMI, LLCis seeking a NOC Analyst to join us. The NOC Analyst provides 24x7 monitoring support for the city-wide... ...and field operations. Support continual service improvement along with...Remote workNight shiftRotating shift$100k - $150k
...Cybersecurity Risk Analyst Salary Range: $100,000 – $150,000 Clearance: TS/SCI + CI Poly Location... .... Provide recommendations for continuous improvement of the processes and... ...RMF, ATO, NIST SP 800-53, continuous monitoring, vulnerability management, or SOC/SIEM...Full timeContract work- ...programmatic, acquisition, compliance, and financial services for... ...is seeking a Senior Research Analyst (Intelligent and Autonomous... ...deliverable tracking, performance monitoring, transition planning, data... ...accordance with policy, and continuously enhancing program...Full timeContract workWork experience placementWork at officeRemote work3 days per week
$101.1k - $115.4k
...Sr. Business Analyst - Global Payment Network Summary:... ...into actionable insights. From monitoring billions of transactions to... ...new responsibility, promotes continuous learning, and rewards innovation... ...committed to non-discrimination in compliance with applicable federal,...Full timeTemporary workPart timeLocal area$104k - $166k
...seeking an experienced Data Analyst/Cyber Analytics professional... ...you'll work with large-scale cybersecurity and operational datasets to... ...analysis to support operational monitoring, situational awareness, and... ...before start date. Continued certification required as a...Contract workShift work$115.5k - $180.53k
ResponsibilitiesPosition OverviewWe are seeking a detail-oriented cybersecurity compliance professional to support system authorization and continuous monitoring activities within a Federal environment. This role is responsible for managing the security authorization lifecycle...Permanent employmentFull timeContract workPart timeWork at officeLocal areaRemote work- ...Business Analyst Job Description The Business Analyst / Content... ...design, documentation, and continuous improvement of enterprise IT... ...initiatives in a fast-paced, compliance-driven environment. This role... ...federal standards and continuous monitoring expectations. The role also...For contractorsWork at officeRemote workFlexible hours
$111.2k - $126.9k
...AnalystAs a Senior Business Analyst at Capital One, you will apply... ...responsibility, promotes continuous learning, and rewards innovation... ...hypotheses using rigorous monitoring and analysisExecution:... ...committed to non-discrimination in compliance with applicable federal,...Full timeTemporary workPart timeLocal area- Dovel Technologies, Inc is seeking a Monitoring & Evaluation Analyst to provide critical technical services for security programs. The role demands expertise in M&E frameworks, strong analytical skills, and the ability to produce detailed reports that inform leadership....Flexible hours
$110.18k - $183.63k
...apply now.We are currently seeking a Cybersecurity and Risk Analyst to join our team in Arlington,... ...threat intelligence, and supporting compliance efforts to ensure confidentiality, integrity... ...response readiness, business continuity, and disaster recovery planning.Review...Full timeTemporary workWork at officeRemote workFlexible hours- ...SkyePoint Decisions is a leading Cybersecurity Architecture and Engineering... ...is seeking a Cyber Data Analyst to support the Diplomatic... ...analysis to support operational monitoring, situational awareness, and... ...in gratitude, SkyePoint can continue to spread living in...Contract workRemote work
$120k - $130k
...Senior Information Assurance (IA) Analyst / Program Manager (PM) to... ...provide Information Assurance/Cybersecurity leadership supporting systems... ...and will oversee cybersecurity compliance, Risk Management Framework (RMF), continuous monitoring, Security Technical...Permanent employmentFull timeContract workFor contractorsWork at officeRemote workFlexible hours$111.2k - $126.9k
...Overview Senior Business Analyst, Credit Loss Forecasting... ...new responsibility, promotes continuous learning, and rewards innovation... ...testing hypotheses using rigorous monitoring and analysis Execution:... ...to non-discrimination in compliance with applicable federal,...Full timeTemporary workPart timeLocal area
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Cybersecurity Compliance & Continuous Monitoring Analyst. Be the first to apply!
Related searches
- cyber security consultant McLean, VA
- cyber security specialist McLean, VA
- compliance analyst McLean, VA
- aml compliance analyst McLean, VA
- risk and compliance analyst McLean, VA
- regulatory affairs consultant McLean, VA
- research compliance officer McLean, VA
- information security compliance analyst McLean, VA
- compliance officer McLean, VA
- regulatory compliance associate McLean, VA




