Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Cybersecurity Compliance & Continuous Monitoring Analyst

$158.95k - $215.05k
Full-time

GDIT

Responsibilities for this Position

Location: USA VA McLean
Full Part/Time: Full time
Job Req: RQ227719

Type of Requisition:
Regular

Clearance Level Must Currently Possess:
Top Secret

Clearance Level Must Be Able to Obtain:
Top Secret/SCI

Public Trust/Other Required:
None

Job Family:
Cyber and IT Risk Management

Job Qualifications:

Skills:
Continuous Monitoring, Control Assessment, Federal Risk and Authorization Management Program (FedRAMP), Security Controls
Certifications:
None
Experience:
8 + years of related experience
US Citizenship Required:
Yes

Job Description:

CYBER TECHNICAL ANALYST SR PRINCIPAL

Advance your career while impacting our national security in cyber as a Cyber Technical Analyst Sr Principal at GDIT. Here, technologists have many paths to grow a meaningful career supporting cyber missions and operations across the federal government.

MEANINGFUL WORK AND PERSONAL IMPACT

As a Cyber Technical Analyst Sr Principal, the work you'll do at GDIT will be impactful to the mission of our customer's classified commercial cloud environment. You will play a crucial role in securing and continuously monitoring a classified workstation secure enclave, ensuring it meets stringent FedRAMP and CNSSI 1253 requirements while enabling mission-critical operations.

  • Support the full RMF and Assessment & Authorization (A&A) lifecycle for the workstation secure enclave, including control implementation, assessment, authorization, and continuous monitoring.
  • Maintain a comprehensive body of evidence for FedRAMP/DoW A&A packages and continuous monitoring requirements, including POA&M tracking, reporting, and remediation.
  • Collaborate with security engineers, system administrators, ISSO/ISSM, vendors, and leadership to integrate and validate security controls and align operations with FedRAMP, DoD, and CNSSI 1253 requirements.
  • Identify, assess, and remediate vulnerabilities using Tenable Nessus, Tenable.sc, SCC, STIG tooling, and related security tools; ensure host inventory and scan policies are accurate and complete.
  • Review scan results, STIG findings, and patching activities to ensure accurate, actionable data and effective hardening of operating systems, network devices, and applications.
  • Evaluate system designs, network architectures, firewall rules, and PPSM submissions to ensure security principles are integrated from the outset and architecture risks are addressed.
  • Lead preparation and execution of security control audits and FedRAMP 3PAO assessments, reviewing artifacts, logs, and configurations to validate evidence of compliance and a strong security posture.
  • Provide security control assessment and audit oversight, including reviewing and validating implementation work performed by engineers and system administrators.
  • Manage a robust continuous monitoring and GRC program, aggregating and analyzing security data to identify trends, anomalies, and potential incidents and providing actionable risk insights to leadership.
  • Support risk assessments and incident response, recommending mitigating controls and assisting the ISSM and incident response team with artifacts and deep system/security expertise.

WHAT YOU'LL NEED TO SUCCEED

Bring your cyber expertise and drive for innovation to GDIT. The Cyber Technical Analyst Sr Principal must have:

Education: Bachelor of Arts/Bachelor of Science

Experience: 8+ years of related experience

Technical skills:
  • Hands-on experience with Tenable.sc and Tenable Nessus
  • Progressive experience in information assurance and cybersecurity roles
  • Minimum of 5 years of direct, hands-on experience as an ISSO or ISSM with a proven track record of achieving and maintaining ATO for classified systems
  • Expert-level knowledge of the NIST SP 800 series (especially 800-37, 800-53, 800-30) and risk management principles
  • Experience with FedRAMP and CNSSI 1253 baselines, continuous monitoring, POA&M management, and A&A body-of-evidence documentation
Security clearance level: Active Top Secret

Role requirements:
  • On-site McLean, VA
  • Must be DoD 8140 / 8570.01-M compliant
  • CISSP strongly preferred

GDIT IS YOUR PLACE

At GDIT, the mission is our purpose, and our people are at the center of everything we do.

Growth: AI-powered career tool that identifies career steps and learning opportunities

Support: An internal mobility team focused on helping you achieve your career goals

Rewards: Comprehensive benefits and wellness packages, 401K with company match, and competitive pay and paid time off

Community: Award-winning culture of innovation and a military-friendly workplace

OWN YOUR OPPORTUNITY

Explore a career in cyber at GDIT and you'll find endless opportunities to grow alongside colleagues who share your focus on defending and protecting what matters.

The likely salary range for this position is $158,950 - $215,050. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.

Scheduled Weekly Hours:
40

Travel Required:
Less than 10%

Telecommuting Options:
Onsite

Work Location:
USA VA McLean

Additional Work Locations:

Total Rewards at GDIT:
Our benefits package for all US-based employees includes a variety of medical plan options, some with Health Savings Accounts, dental plan options, a vision plan, and a 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match. To encourage work/life balance, GDIT offers employees full flex work weeks where possible and a variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave. To ensure our employees are able to protect their income, other offerings such as short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available. We regularly review our Total Rewards package to ensure our offerings are competitive and reflect what our employees have told us they value most.

Our Identity Verification Process:
As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during virtual interviews. We reserve the right to take your picture to verify your identity and prevent fraud. By proceeding, you authorize the collection, processing, and use of your biometric data for identity verification and security purposes.

About Our Work:
We are GDIT. A global technology and professional services company that delivers technology solutions and mission services to every major agency across the U.S. government, defense and intelligence community. Our 26,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. We operate across 50+ countries worldwide, offering leading mission-ready capabilities in AI, cloud, cyber and software development.

Join our Talent Community to stay up to date on our career opportunities and events at
gdit.com/tc .

Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans



PI286926366




CYBER TECHNICAL ANALYST SR PRINCIPAL


Advance your career while impacting our national security in cyber as a Cyber Technical Analyst Sr Principal at GDIT. Here, technologists have many paths to grow a meaningful career supporting cyber missions and operations across the federal government.


MEANINGFUL WORK AND PERSONAL IMPACT


As a Cyber Technical Analyst Sr Principal, the work you'll do at GDIT will be impactful to the mission of our customer's classified commercial cloud environment. You will play a crucial role in securing and continuously monitoring a classified workstation secure enclave, ensuring it meets stringent FedRAMP and CNSSI 1253 requirements while enabling mission-critical operations.



  • Support the full RMF and Assessment & Authorization (A&A) lifecycle for the workstation secure enclave, including control implementation, assessment, authorization, and continuous monitoring.
  • Maintain a comprehensive body of evidence for FedRAMP/DoW A&A packages and continuous monitoring requirements, including POA&M tracking, reporting, and remediation.
  • Collaborate with security engineers, system administrators, ISSO/ISSM, vendors, and leadership to integrate and validate security controls and align operations with FedRAMP, DoD, and CNSSI 1253 requirements.
  • Identify, assess, and remediate vulnerabilities using Tenable Nessus, Tenable.sc, SCC, STIG tooling, and related security tools; ensure host inventory and scan policies are accurate and complete.
  • Review scan results, STIG findings, and patching activities to ensure accurate, actionable data and effective hardening of operating systems, network devices, and applications.
  • Evaluate system designs, network architectures, firewall rules, and PPSM submissions to ensure security principles are integrated from the outset and architecture risks are addressed.
  • Lead preparation and execution of security control audits and FedRAMP 3PAO assessments, reviewing artifacts, logs, and configurations to validate evidence of compliance and a strong security posture.
  • Provide security control assessment and audit oversight, including reviewing and validating implementation work performed by engineers and system administrators.
  • Manage a robust continuous monitoring and GRC program, aggregating and analyzing security data to identify trends, anomalies, and potential incidents and providing actionable risk insights to leadership.
  • Support risk assessments and incident response, recommending mitigating controls and assisting the ISSM and incident response team with artifacts and deep system/security expertise.



WHAT YOU'LL NEED TO SUCCEED


Bring your cyber expertise and drive for innovation to GDIT. The Cyber Technical Analyst Sr Principal must have:


Education: Bachelor of Arts/Bachelor of Science


Experience: 8+ years of related experience


Technical skills:

  • Hands-on experience with Tenable.sc and Tenable Nessus
  • Progressive experience in information assurance and cybersecurity roles
  • Minimum of 5 years of direct, hands-on experience as an ISSO or ISSM with a proven track record of achieving and maintaining ATO for classified systems
  • Expert-level knowledge of the NIST SP 800 series (especially 800-37, 800-53, 800-30) and risk management principles
  • Experience with FedRAMP and CNSSI 1253 baselines, continuous monitoring, POA&M management, and A&A body-of-evidence documentation

Security clearance level: Active Top Secret


Role requirements:

  • On-site McLean, VA
  • Must be DoD 8140 / 8570.01-M compliant
  • CISSP strongly preferred



GDIT IS YOUR PLACE


At GDIT, the mission is our purpose, and our people are at the center of everything we do.


Growth: AI-powered career tool that identifies career steps and learning opportunities


Support: An internal mobility team focused on helping you achieve your career goals


Rewards: Comprehensive benefits and wellness packages, 401K with company match, and competitive pay and paid time off


Community: Award-winning culture of innovation and a military-friendly workplace


OWN YOUR OPPORTUNITY


Explore a career in cyber at GDIT and you'll find endless opportunities to grow alongside colleagues who share your focus on defending and protecting what matters.


The likely salary range for this position is $158,950 - $215,050. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.



Scheduled Weekly Hours:
40



Travel Required:
Less than 10%



Telecommuting Options:
Onsite



Work Location:
USA VA McLean



Additional Work Locations:



Total Rewards at GDIT:
Our benefits package for all US-based employees includes a variety of medical plan options, some with Health Savings Accounts, dental plan options, a vision plan, and a 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match. To encourage work/life balance, GDIT offers employees full flex work weeks where possible and a variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave. To ensure our employees are able to protect their income, other offerings such as short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available. We regularly review our Total Rewards package to ensure our offerings are competitive and reflect what our employees have told us they value most.



Our Identity Verification Process:
As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during virtual interviews. We reserve the right to take your picture to verify your identity and prevent fraud. By proceeding, you authorize the collection, processing, and use of your biometric data for identity verification and security purposes.



About Our Work:
We are GDIT. A global technology and professional services company that delivers technology solutions and mission services to every major agency across the U.S. government, defense and intelligence community. Our 26,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. We operate across 50+ countries worldwide, offering leading mission-ready capabilities in AI, cloud, cyber and software development.


Join our Talent Community to stay up to date on our career opportunities and events at

gdit.com/tc .


Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans







PI286926366

Vacancy posted a month ago
Similar jobs that could be interesting for youBased on the Cybersecurity Compliance & Continuous Monitoring Analyst in McLean, VA vacancy
  •  ...federal and commercial clients. We deliver mission-focused solutions in data, cloud, cybersecurity, and program management. Position Overview The Continuous Monitoring (ISCM) Analyst runs the monthly control review, SAR, and RAM cycle for the 15 systems in the... 
    Suggested

    Big Impact Tech (BIT)

    Washington DC
    17 hours ago
  • $95k - $125k

     ...seeking an AI Governance Analyst to operationalize a...  ...a living Mandate Compliance Matrix, AI governance...  ...bias identification/monitoring, data handling/retention...  ...use cases to confirm continued complianceMonitor policy...  ..., Data Ethics, Cybersecurity, Law, or a related field... 
    Suggested

    Steampunk

    McLean, VA
    4 days ago
  • $99k - $225k

     ...ensure effective risk management and cybersecurity resilience. You’ll work with your...  ...cybersecurity policies ~ Knowledge of compliance testing tools such as ACAS, SCAP,...  ...POA&Ms, SAPs, risk assessments, and continuous monitoring ~ TS/SCI clearance ~ HS diploma or... 
    Suggested
    Full time
    Contract work
    Part time
    For contractors
    Work at office
    Local area
    Remote work

    Talentify.io

    McLean, VA
    2 days ago
  •  ...industry recognized and award-winning cybersecurity services firm with a focus on high...  ...insurance premium covered, 401k, continued education, certifications...  ...looking for: We are seeking Compliance and Continuous Monitoring Engineer - Vulnerability Management... 
    Suggested

    ShorePoint

    Washington DC
    6 days ago
  • US Cybersecurity and Infrastructure Security Agency (CISA) in Arlington, VA, seeks an Information Technology Cybersecurity Specialist, GS-2210-13/14, under Direct Hire Authority. The role requires IT-related experience and demonstrated competencies across detail, customer... 
    Suggested

    US Cybersecurity and Infrastructure Security Agency

    Arlington, VA
    4 days ago
  •  ...Auditor / Government & Risk Compliance ConsultantJob location-...  ...Hybrid)Role is surrounding a continuous controls monitoring program that they're trying to stand up within cybersecurity. They're looking to build...  ...requirements for the data analyst. Issues with candidates so... 

    RIT Solutions

    McLean, VA
    2 days ago
  • $80k - $128k

     ...a Risk and Vulnerability Analyst.Location: Chandler, AZ or...  ...environments. This role ensures continuous visibility, compliance, and timely remediation...  ...continuous vulnerability monitoring and risk analysis.Execute...  ...: Bachelor’s degree in Cybersecurity, Information Technology,... 
    Contract work
    Shift work

    Peraton Corporation

    Washington DC
    2 days ago
  •  ...Job Description Job Description Overview Cybersecurity Analyst (Vulnerability Management & Continuous Monitoring)   Oakton, VA   Are you ready to...  ...executing vulnerability management, security compliance, and Continuous Monitoring (ConMon) activities... 

    Chenega Corporation

    Oakton, VA
    18 days ago
  •  ...Vulnerability Management Analyst ID 2025-3164...  ...to support enterprise cybersecurity operations across a...  ...cybersecurity controls by continuously identifying, validating, and monitoring vulnerabilities across...  ...support configuration compliance checks. ~ Maintain... 
    Full time
    Contract work
    For contractors
    Local area
    Remote work

    Decision Point

    Reston, VA
    2 days ago
  • The Senior Security Analyst is responsible for supporting functions...  ...and Governance & Compliance operations. This role will...  ...work across enterprise-wide cybersecurity initiatives, balancing strategic...  ...Provide authorization and continuous monitoring activities for information... 
    Full time
    Temporary work
    For contractors
    Work experience placement
    For subcontractor
    Local area
    Immediate start

    Financial Industry Regulatory Authority

    Rockville, MD
    16 hours ago
  • $131k - $218.3k

     ...and opportunities businesses face in cybersecurity. Join our team to deliver powerful solutions...  ...on cyber risk posture and RMF compliance strategies aligned to FISMA, NIST, and...  ..., security assessment, or continuous-monitoring activities, including 1+ year applying... 
    Work at office
    Local area
    Relocation
    Night shift

    Deloitte

    Rosslyn, VA
    23 hours ago
  •  ...Security (OIT/OIS) program covering enterprise cybersecurity architecture and engineering. We are seeking Risk and Compliance Analysts to own the risk, compliance, and supply...  ...modernization with risk analysis and continuous monitoring.REQUIRED QUALIFICATIONS- Minimum 7 years... 
    Full time
    Contract work
    Interim role
    Work at office
    Remote work

    Triumph Enterprises

    Washington DC
    4 days ago
  •  ...Effectiveness ConsultingTravel Required:Up to 10%Clearance Required:Active SecretWhat You Will Do:Guidehouse is seeking a Monitoring and Evaluation (M&E) Analyst to provide M&E technical and advisory services to the Department of State. The M&E Analyst will help strengthen... 
    Full time
    Work at office
    Flexible hours

    Guidehouse

    Arlington, VA
    2 days ago
  • $180k - $250k

     ...announce the opening for a Senior Analyst, who will join our...  ...operating in missile defense, cybersecurity, test range modernization, biotechnology...  ...learning models Lead the continuous improvement, rearchitecting,...  ...validation, deployment, and monitoring of models at scale. You... 
    Temporary work
    Work experience placement
    Flexible hours

    nou Systems

    Arlington, VA
    4 days ago
  • $73.49k

     ...including managed mobility, cloud, cybersecurity, network operations, and...  ...Opportunity DMI, LLCis seeking a NOC Analyst to join us. The NOC Analyst provides 24x7 monitoring support for the city-wide...  ...and field operations. Support continual service improvement along with... 
    Remote work
    Night shift
    Rotating shift

    Digital Management

    Falls Church, VA
    1 day ago
  • $100k - $150k

     ...Cybersecurity Risk Analyst Salary Range: $100,000 – $150,000 Clearance: TS/SCI + CI Poly Location...  .... Provide recommendations for continuous improvement of the processes and...  ...RMF, ATO, NIST SP 800-53, continuous monitoring, vulnerability management, or SOC/SIEM... 
    Full time
    Contract work

    Ops Tech Alliance

    McLean, VA
    -5
  • $120k - $135k

     ...Digital Integrity (TDI) is a cybersecurity firm built for high-...  ...a Senior Incident Response Analyst to join our team in support...  ...Operations Center, you will help monitor, detect, investigate, and respond...  ...effectiveness and support continuous improvement. QUALIFICATIONS... 
    Permanent employment
    Contract work
    Remote work
    2 days per week

    Tetrad Digital Integrity

    Arlington, VA
    4 days ago
  •  ...Senior Analyst, Cybersecurity GRC, Washington, DC The Senior Analyst, Cybersecurity GRC will administer the completion of compliance-related client requests to assess security policies and...  ...initial, reassessments and ongoing monitoring) and supporting broader GRC... 
    Work experience placement

    Next Step Systems LTD

    Washington DC
    4 days ago
  •  ...programmatic, acquisition, compliance, and financial services for...  ...is seeking a Senior Research Analyst (Intelligent and Autonomous...  ...deliverable tracking, performance monitoring, transition planning, data...  ...accordance with policy, and continuously enhancing program... 
    Full time
    Contract work
    Work experience placement
    Work at office
    Remote work
    3 days per week

    Valiant Harbor International, LLC

    Arlington, VA
    2 days ago
  • $104k - $166k

     ...seeking an experienced Data Analyst/Cyber Analytics professional...  ...you'll work with large-scale cybersecurity and operational datasets to...  ...analysis to support operational monitoring, situational awareness, and...  ...before start date. Continued certification required as a... 
    Contract work
    Shift work

    Peraton Corporation

    Arlington, VA
    23 hours ago
  •  ...Job Title Business Analyst Date Needed By 6/8/2026...  ...design, documentation, and continuous improvement of enterprise IT...  ...initiatives in a fast-paced, compliance-driven environment. This role...  ...federal standards and continuous monitoring expectations. The role also... 
    Full time
    For contractors
    Work at office
    Remote work
    Flexible hours

    CTAC

    Falls Church, VA
    3 days ago
  • $101.1k - $115.4k

     ...Sr. Business Analyst - Global Payment Network Summary:...  ...into actionable insights. From monitoring billions of transactions to...  ...new responsibility, promotes continuous learning, and rewards innovation...  ...committed to non-discrimination in compliance with applicable federal,... 
    Full time
    Temporary work
    Part time
    Local area

    Capital One Financial Corp

    McLean, VA
    23 hours ago
  • $111.2k - $126.9k

     ...AnalystAs a Senior Business Analyst at Capital One, you will apply...  ...responsibility, promotes continuous learning, and rewards innovation...  ...hypotheses using rigorous monitoring and analysisExecution:...  ...committed to non-discrimination in compliance with applicable federal,... 
    Full time
    Temporary work
    Part time
    Local area

    Capital One

    McLean, VA
    2 days ago
  • $115.5k - $180.53k

    ResponsibilitiesPosition OverviewWe are seeking a detail-oriented cybersecurity compliance professional to support system authorization and continuous monitoring activities within a Federal environment. This role is responsible for managing the security authorization lifecycle... 
    Permanent employment
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Noblis

    Washington DC
    4 days ago
  • Dovel Technologies, Inc is seeking a Monitoring & Evaluation Analyst to provide critical technical services for security programs. The role demands expertise in M&E frameworks, strong analytical skills, and the ability to produce detailed reports that inform leadership.... 
    Flexible hours

    Dovel Technologies, Inc

    Arlington, VA
    3 days ago
  •  ...SkyePoint Decisions is a leading Cybersecurity Architecture and Engineering...  ...is seeking a Cyber Data Analyst to support the Diplomatic...  ...analysis to support operational monitoring, situational awareness, and...  ...in gratitude, SkyePoint can continue to spread living in... 
    Contract work
    Remote work

    SkyePoint Decisions

    Arlington, VA
    4 days ago
  • $110.18k - $183.63k

     ...apply now.We are currently seeking a Cybersecurity and Risk Analyst to join our team in Arlington,...  ...threat intelligence, and supporting compliance efforts to ensure confidentiality, integrity...  ...response readiness, business continuity, and disaster recovery planning.Review... 
    Full time
    Temporary work
    Work at office
    Remote work
    Flexible hours

    NTT DATA

    Arlington, VA
    1 day ago
  • $111.2k - $126.9k

     ...Overview Senior Business Analyst, Credit Loss Forecasting...  ...new responsibility, promotes continuous learning, and rewards innovation...  ...testing hypotheses using rigorous monitoring and analysis Execution:...  ...to non-discrimination in compliance with applicable federal,... 
    Full time
    Temporary work
    Part time
    Local area

    Capital One

    McLean, VA
    a month ago
  • $120k - $130k

     ...Senior Information Assurance (IA) Analyst / Program Manager (PM) to...  ...provide Information Assurance/Cybersecurity leadership supporting systems...  ...and will oversee cybersecurity compliance, Risk Management Framework (RMF), continuous monitoring, Security Technical... 
    Permanent employment
    Full time
    Contract work
    For contractors
    Work at office
    Remote work
    Flexible hours

    Digital Consultants, LLC

    Arlington, VA
    2 days ago
  • $111.2k - $126.9k

     ...Overview Sr. Business Analyst - People Strategy & Analytics...  ...collaborative environment that promotes continuous learning, rewards innovation...  ...develop plans and tools for monitoring outcomes Partnership:...  ...to non-discrimination in compliance with applicable federal,... 
    Full time
    Part time
    Local area

    Capital One

    McLean, VA
    4 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Cybersecurity Compliance & Continuous Monitoring Analyst. Be the first to apply!