IT and Cyber Risk Auditor Principal

General Dynamics IT

Las Cruces (NM)

On-site

USD 150,000 - 190,000

Full time

4 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

GENERAL DYNAMICS IT seeks an IT & Cyber Risk Auditor Principal to lead enterprise-level risk assessments and audits, ensuring systems and data security for national security missions.

You will evaluate IT controls, coordinate RMF/FISMA activities, and provide actionable insights to leadership while driving remediation with cross-functional teams.

The role requires TS/SCI with polygraph, extensive auditing experience, and strong communication skills within a federal contracting environment.

Qualifications

  • 5+ years of progressive IT audits, cybersecurity risk management, or information assurance experience.
  • Experience using XACTA database applications and the ICD 503, NIST 800-83 rev4 policy.
  • Experience with Splunk, Security Center, Telos XACTA, and McAfee ePO.
  • Expertise with cybersecurity and IT control frameworks and compliance requirements.
  • Experience conducting complex IT/cybersecurity audits in government or federal contracting environments.
  • Experience with cloud security risk assessments and modern technologies.
  • Clear and effective communication with technical and executive audiences.
  • Ability to multi-task and adapt in a fast-paced environment.
  • Ability to learn an application environment to update/create documentation.

Responsibilities

  • Lead and execute rigorous IT and cybersecurity risk audits and assessments.
  • Evaluate IT general controls, cybersecurity controls, and risk management processes.
  • Assess compliance with federal frameworks and guidance (NIST, RMF, FISMA, FedRAMP, ISO 27001).
  • Identify and document control gaps, risk exposures, and areas for improvement.
  • Provide risk-based recommendations and executive-style briefings.
  • Support audit report preparation and remediation tracking.
  • Manage Authority to Operate (ATO) packages and security documentation.
  • Collaborate with IT, cybersecurity, compliance, and program teams on remediation.

Skills

Cybersecurity risk
IT audits
NIST RMF
Security controls
Cloud security

Education

Bachelor's degree in Information Systems or related field

Tools

Splunk
Security Center
Telos XACTA
McAfee ePO

Job description

Type of Requisition: Regular
Clearance Level Must Currently Possess: Top Secret SCI + Polygraph
Clearance Level Must Be Able to Obtain: Top Secret SCI + Polygraph
Public Trust/Other Required: None
Job Family: Cyber and IT Risk Management
Job Qualifications:

Skills: Cyber Risks, Cybersecurity Controls, Cybersecurity Risk Management, Security Controls, Security Risk Certifications:

None Experience: 5+ years of related experience US Citizenship Required: Yes

Job Description:
Your Impact

Own your opportunity as an IT & Cyber Risk Auditor Principal at GDIT. You'll lead enterprise-level IT and cybersecurity risk and compliance assessments that help secure the systems and data vital to our national security missions. At GDIT, the mission is our purpose, and our people are at the center of everything we do.

What You'll Do
  • Lead and execute rigorous IT and cybersecurity risk audits and assessments
  • Evaluate IT general controls, cybersecurity controls, and risk management processes
  • Assess compliance with federal frameworks and guidance (e.g., NIST, RMF, FISMA, FedRAMP, ISO 27001)
  • Identify and document control gaps, risk exposures, and areas for process improvement
  • Provide risk-based recommendations and actionable insights to senior leadership and stakeholders
  • Support preparation of audit reports and executive briefings
  • Manage and execute system Certification and Accreditation processes, ensuring compliance with security controls and requirements outlined in agency policies.
  • Collaborate with cybersecurity, IT, compliance, and program teams to drive remediation and sustainable improvements
  • Participate in internal and external audit activities, including customer assessments
  • Experience using XACTA data base applications and the ICD 503, NIST 800-83 rev4 policy
  • Review monthly vulnerability scan reports and track and address weaknesses in plans as needed.
  • Perform security system event analysis, investigation, and validation
  • Provide incident response to classification spills, malware infection, misconfiguration exposure, internal inappropriate behavior and technical issue
  • Perform Security Technical Implementation Guide (STIG) and Federal Information Security Management Act (FISMA) assessments and annual reporting
  • Work and completing multiple Authority to Operate (ATO) security packages simultaneously
What You'll Need to Succeed
  • 5+ years of progressive experience to an intermediate level in IT audits, cybersecurity risk management, or information assurance
  • Experience using XACTA data base applications and the ICD 503, NIST 800-83 rev4 policy
  • Experience with Splunk, Security Center, Telos XACTA, and MacAfee EPO
  • Expertise with cybersecurity and IT control frameworks and compliance requirements
  • Experience conducting complex IT and cybersecurity audits in government or federal contracting environments
  • Experience with cloud security risk assessments and modern technologies
  • Clear and effective communication skills with the ability to influence technical and executive audiences
  • Ability to multi-task, prioritize, and re-prioritize work in a fast-paced environment
  • Ability to learn an application environment in order to update or create supported security documentation
Qualifications
  • Bachelor's degree or equivalent military training in Information Systems, Cybersecurity, Computer Science, Accounting, or related field
  • Maintain certification in accordance with DoD Directive 8140.01 Cyberspace Workforce Management requirements
  • Applicable certifications include: SecurityX / CASP+, CGRC/CAP, GSEC, GSNA, Security+, SSCP, CISSP, CISM
  • Currently hold certification in good standing to satisfy IAM Level II (Information Assurance Management Level 2) per DoD 8570/8140
  • Hold a current security clearance of Top Secret/Special Compartmented Information (TS/SCI) with an in-scope counter-intelligence (CI) or full-scope polygraph. Successfully completed Tier 5 investigation (T5), formerly known as a Single Scope Background Investigation (SSBI) by the federal government within the last 5 years, or requires candidate to have been enrolled in a Continuous Vetting program within the last 5 years
GDIT Is Your Place

At GDIT, you'll work alongside mission-first teams solving some of the nation's most complex cybersecurity challenges. Our people grow here - with opportunities for career development, continuous learning, professional certifications, and internal mobility. We offer a comprehensive total rewards package, including competitive pay, robust benefits, and a culture dedicated to your success.

Own your opportunity. Join a community where your work makes a real difference to mission success and national security.

The likely salary range for this posit

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

IT and Cyber Risk Auditor Principal
IT and Cyber Risk Auditor Principal

General Dynamics Information Technology, Inc. • Las Cruces (NM)

On-site
USD 111,000 - 150,000
Cyber Analyst Principal - TS/SCI with Polygraph
Cyber Analyst Principal - TS/SCI with Polygraph

General Dynamics Information Technology, Inc. • McLean (VA)

On-site
USD 170,000 - 230,000
Cyber Technical Analyst - TS/SCI w/Polygraph
Cyber Technical Analyst - TS/SCI w/Polygraph

General Dynamics Information Technology, Inc. • Herndon (VA)

On-site
USD 170,000 - 230,000
401K with company match
Comprehensive health and wellness
Paid education and certifications
+1
Information Systems Security Officer - TS/SCI w/Poly
Information Systems Security Officer - TS/SCI w/Poly

General Dynamics Information Technology, Inc. • Maryland

On-site
USD 108,000 - 138,000
Information Security Director
Information Security Director

General Dynamics Information Technology, Inc. • Bellevue Second IV Precinct (NE)

On-site
USD 170,000 - 205,000
Health benefits
401(k)
Education assistance
+2
IT Risk and Compliance Specialist Principal
IT Risk and Compliance Specialist Principal

General Dynamics Information Technology (GDIT) • Bossier City (LA)

Hybrid
USD 111,000 - 150,000
Cyber Security Analyst Senior Advisor
Cyber Security Analyst Senior Advisor

General Dynamics Information Technology, Inc. • Tampa (FL)

On-site
USD 110,000 - 150,000
401K with company match
Health and wellness packages
Internal mobility
+3
Cybersecurity Engineer Sr Principal
Cybersecurity Engineer Sr Principal

General Dynamics Information Technology, Inc. • McLean (VA)

On-site
USD 170,000 - 230,000
Growth opportunities
Internal mobility support
Competitive benefits and PTO
+2
Cybersecurity Engineer
Cybersecurity Engineer

General Dynamics Information Technology • Herndon (VA)

Hybrid
USD 170,000 - 230,000
Sr. Cybersecurity Architect - Active Top Secret
Sr. Cybersecurity Architect - Active Top Secret

General Dynamics Information Technology, Inc. • Washington

On-site
USD 179,000 - 242,000
401K with company match
Paid time off
Health benefits