CyberSecurity Auditor

General Dynamics - IT

Chantilly (VA)

On-site

USD 110,000 - 140,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Growth opportunities
Internal mobility
Benefits and 401K
Military-friendly culture

Job summary

General Dynamics - IT (GDIT) is seeking a Cybersecurity Auditor to maintain audit-ready security postures for Cross Domain Solution systems and support RMF activities across DoW and IC requirements.

The role focuses on Linux system administration, log review (syslog, auditd), rule validation, and evidence collection for RMF assessments. TS/SCI eligibility and CDS training are highlighted as prerequisites; opportunity to grow within a defense-focused cyber security team.

Qualifications

  • Bachelor-level education with substantial cybersecurity experience or higher.
  • Experience applying RMF controls and NIST frameworks in DoD/IC contexts.
  • Direct experience auditing Linux systems and collecting evidence for assessments.
  • Familiarity with STIGs, SSPs and audit documentation.

Responsibilities

  • Assist ISSM with RMF/DoW guidance and continuous monitoring.
  • Perform Linux-based security audits of CDS systems including logs and guards.
  • Validate data-flow enforcement rules and cross-domain transfers.
  • Develop procedures for log collection, rotation, and secure storage.
  • Maintain documentation for monitoring controls and authorization packages.

Skills

Linux command-line
Log analysis
Security auditing
RMF compliance
NIST SP 800-53 AU/SI

Education

BA/BS + 12 yrs cybersecurity experience
MA/MS + 8 yrs cybersecurity experience
Ph.D. + 6 yrs cybersecurity experience
No Degree + 13 yrs cybersecurity experience

Tools

XACTA
DISA STIGs tooling
RSYSLOG

Job description

Advance your career while impacting our national security in cyber as a Cybersecurity Auditor at GDIT. Here, technologists have many paths to grow a meaningful career supporting cyber missions and operations across the federal government.

The Cybersecurity Auditor is responsible for maintaining the operational security posture of assigned Cross Domain Solution (CDS) systems at the enclave level (AFSCI, AOC SIPRNet, SIPRNet, ACBN and Private ISP), ensuring continuous compliance with Department of War (DoW), National Cross Domain Strategy & Management Office (NCDSMO) "Raise-the-Bar" (RTB) Standards, and Intelligence Community (IC) security requirements, with a strong emphasis on Linux-based security auditing and continuous monitoring. This role works closely with the Information System Security Manager (ISSM), system owners, enclave teams, and CDS engineering staff to execute day-to-day security operations focused on: Direct audit and review of CDS system logs and security-relevant events Continuous monitoring of guard behavior and data flows Validation of enforcement rules and configuration baselines Collection and organization of bodies of evidence for RMF and assessments

The Cybersecurity Auditor provides technical expertise in: Linux system administration and command-line analysis Native log review and correlation (e.g., syslog, auditd, application logs) Transfer decision validation and sanitization evidence review Development of procedures and checklists for recurring security audits

This work ensures compliance with NIST SP 800-53 Rev. 5, DoWI 8510.01, and NCDSMO-R-00008-005_01 Version 5.1, and helps maintain CDS systems in an audit-ready, fail-secure posture.

RESPONSIBILITIES

Assist the ISSM in meeting assigned duties and responsibilities in accordance with DoWI 8510.01 and NIST RMF guidance. Conduct continuous monitoring activities for assigned authorization boundaries, with specific focus on CDS guard behavior and data flows. Perform detailed security audits directly on Linux-based CDS systems, including review of operating system, application, and custom guard logs. Monitor guard behavior and validate data flow enforcement rules to ensure only authorized transfers occur across domains. Develop and maintain procedures for Linux log collection, rotation, retention, and secure storage to support audit requirements. Prepare, review, and update authorization documentation related to audit and monitoring controls (e.g., SSP sections, monitoring procedures, control implementation summaries). Conduct periodic reviews of information systems to ensure compliance with the security authorization package and applicable policies. Assess the security impact of system changes (e.g., configuration updates, patching, rule changes) and provide recommendations to the ISSM prior to implementation. Validate time synchronization, log integrity, and audit completeness across CDS components. Identify and troubleshoot logging gaps, misconfigurations, or failures directly on Linux systems (e.g., auditd, rsyslog, custom logging services). Provide log extracts, audit trails, and evidence packages to support internal and external audits and assessments. Ensure audit records are reviewed and documented, including identification, investigation, and resolution of anomalies. Ensure appropriate logging and monitoring of all internal components that make up the High Speed Guard (HSG) and Trusted Gateway System (TGS). Coordinate with system and network administrators to ensure logging and monitoring requirements are embedded in system deployments and configuration baselines. Support RMF lifecycle activities within XACTA, including maintenance of control implementations and bodies of evidence. Maintain SSP sections related to monitoring and audit architecture, and keep documentation current with system changes. Validate STIG implementation (particularly OS and application STIGs) and audit configuration settings, and coordinate remediation for non-compliant findings. Assist with development and maintenance of assessment and authorization documentation and other bodies of evidence.

REQUIRED QUALIFICATIONS

Strong Linux experience (e.g., RHEL/CentOS/Ubuntu), including command-line, log analysis, and basic system administration. Experience supporting DoW Risk Management Framework (RMF) and continuous monitoring activities. Experience reviewing DISA STIGs and correlating vulnerability findings with system logs and configuration settings. Working knowledge of NIST SP 800-53 Rev. 5 controls, particularly the AU (Audit) and SI (System and Information Integrity) control families. Experience conducting security audits, direct log/telemetry review on Linux systems, incident investigations, and preparing associated documentation or reports.

EDUCATION / EXPERIENCE

BA/BS + 12 yrs exp (8 yrs cybersecurity experience) OR MA/MS + 8 yrs exp (7 yrs cybersecurity experience) OR Ph.D. + 6 yrs exp (2 yrs cybersecurity experience) OR No Degree + 13 yrs exp (7 yrs cybersecurity experience)

CERTIFICATIONS

The CDS ISSO will complete vendor-provided CDS solution training, and will attain and maintain CDS vendor-provided certification. The CDS ISSO will maintain DoW 8570.01M IAT Level III Certification. Clearance: TS/SCIGDIT IS YOUR PLACE

At GDIT, the mission is our purpose, and our people are at the center of everything we do.

  • Growth: AI-powered career tool that identifies career steps and learning opportunities
  • Support: An internal mobility team focused on helping you achieve your career goals
  • Rewards: Comprehensive benefits and wellness packages, 401K with company match, and competitive pay and paid time off
  • Community: Award-winning culture of innovation and a military-friendly workplace

Explore a career in cyber at GDIT and you’ll find endless opportunities to grow alongside colleagues who share your focus on defending and protecting what matters. #GDITPriority #DefenseOCONUS

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Analyst (Risk Management Framework) – TS/SCI w/ Polygraph
Cybersecurity Analyst (Risk Management Framework) – TS/SCI w/ Polygraph

General Dynamics Information Technology • Maryland

On-site
USD 128,000 - 173,000
Cyber Security Analyst Senior
Cyber Security Analyst Senior

General Dynamics Information Technology • Hampton (VA)

On-site
USD 98,000 - 113,000
401K with company match
Comprehensive health and wellness
Paid educational opportunities
+1
Cybersecurity Analyst (Risk Management Framework) – TS/SCI w/ Polygraph
Cybersecurity Analyst (Risk Management Framework) – TS/SCI w/ Polygraph

General Dynamics - IT • Corridor North (MD)

On-site
USD 90,000 - 140,000
401K with company match
Competitive pay and paid time off
Internal mobility team
+1
Info. Security Analyst Principal
Info. Security Analyst Principal

General Dynamics Information Technology • McLean (VA)

On-site
USD 109,000 - 147,000
Cyber Security Analyst Senior
Cyber Security Analyst Senior

General Dynamics Information Technology • McLean (VA)

On-site
USD 98,000 - 113,000
401K match
Health & wellness
Career mobility
+3
Cybersecurity Engineer Principal
Cybersecurity Engineer Principal

General Dynamics Information Technology • Bossier City (LA)

Hybrid
USD 140,000 - 210,000
Growth opportunities
Internal mobility support
Competitive benefits and 401K matching
+1
SME Cyber Vulnerability Management
SME Cyber Vulnerability Management

General Dynamics - IT • Fort Bragg (NC)

On-site
USD 110,000 - 160,000
401K with company match
Comprehensive benefits
Paid time off
Cyber Analyst Principal - TS/SCI with Polygraph
Cyber Analyst Principal - TS/SCI with Polygraph

General Dynamics - IT • McLean (VA)

On-site
USD 130,000 - 190,000
NCIS Cyber Security Analyst | Active TS/SCI clearance
NCIS Cyber Security Analyst | Active TS/SCI clearance

General Dynamics - IT • Quantico (VA)

On-site
USD 100,000 - 150,000
Cybersecurity Engineer Principal
Cybersecurity Engineer Principal

General Dynamics Corporation • Bossier City (LA)

Hybrid
USD 146,000 - 198,000
Growth opportunities
Internal mobility team
Competitive benefits