IT Risk and Compliance Specialist Principal

General Dynamics Information Technology, Inc.

Bossier City (LA)

On-site

USD 140,000 - 200,000

Full time

13 days ago
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

General Dynamics Information Technology, Inc. seeks a Principal IT Risk and Compliance Security Analyst to lead RMF execution across AWS, Azure, and Google Cloud.

You translate federal requirements into technical baselines, issue and maintain artifacts, and drive continuous monitoring in a fast-paced federal program environment. You will collaborate with engineering teams to maintain secure, resilient systems and support ATO issuance and maintenance, audits, and security governance across

Qualifications

  • Bachelor's degree in Computer Science, IT, Cybersecurity or related field or 10+ years IT/security experience.
  • Minimum 8+ years federal cybersecurity compliance experience; 4+ years ISSO/technical role.
  • Delivered at least one federal information system through initial authorization or re-authorization.
  • Technical literacy across AWS, Azure and/or GCP; review architecture and controls.
  • Experience evaluating scan data from Qualys, Nessus, CrowdStrike, Splunk.
  • Active DoD 8570/8140 IAM Level III certification.

Responsibilities

  • Lead RMF steps and authorize artifacts; maintain SSPs, POA&Ms, SARs, ISCPs.
  • Interpret and enforce NIST controls across multi-cloud environments.
  • Coordinate with assessors, AOs, and engineers for continuous monitoring.
  • Review IAM, network protections, and crypto implementations for compliance.
  • Ensure automated auditing and logging within delivery pipelines.
  • Prepare for audits and support accreditation activities.

Skills

Federal cybersecurity compliance
ISSO experience
RMF knowledge
Cloud security (AWS/Azure/GCP)
NIST SP 800-53 & 800-171
NIST SP 800-37 RMF
Security governance

Education

Bachelor's degree in Computer Science / IT / Cybersecurity or related field
10+ years enterprise IT/security experience

Tools

Qualys
Tenable/Nessus
CrowdStrike
Splunk
SharePoint
Xacta
Archer
CSAM
ServiceNow IRM
DISA STIGs tooling

Job description

TSS is proactively seeking Principal-level IT Risk and Compliance Security Analysts to support upcoming and ongoing federal programs across civilian and defense agencies. In this senior individual contributor role, you will serve as a technical ISSO, leading governance, compliance, and continuous monitoring activities for complex information systems hosted in AWS, Azure, and Google Cloud.

You will translate federal requirements into actionable technical baselines, drive the full RMF lifecycle, and partner with engineering teams to maintain secure, resilient, mission-enabling technologies and support ATO issuance and maintenance.

Key Responsibilities
RMF Execution & Authorisation Lifecycle
  • Execute RMF steps (Categorization through Continuous Monitoring) per NIST SP 800-37.
  • Author and maintain SSPs, POA&Ms, SARs, ISCPs, and supporting authorization artifacts.
  • Establish evidentiary libraries and audit records within program repositories (e.g., SharePoint, agency GRC tools).
  • Coordinate with SCAs and AOs during assessments and finding adjudication.
  • Lead and sustain continuous monitoring through baseline reviews and periodic control assessments.
Security Governance & Compliance
  • Serve as the primary advisor on system security posture, threats, vulnerabilities, and compliance requirements.
  • Interpret, implement, and validate NIST SP 800-53 and 800-171 controls across multi-cloud environments.
  • Develop and update security documentation, test plans, and continuous monitoring artifacts.
  • Prepare for and respond to internal/external audits and compliance evaluations.
  • Drive security-driven configuration changes and accreditation updates in collaboration with system owners and engineers.
Engineering Interface & Technical Compliance
  • Analyze outputs from vulnerability scanners, container security tools, and static analysis utilities; prioritize remediation with engineering.
  • Assess IaC templates (Terraform/CloudFormation) and cloud configurations against DISA STIGs and CIS Benchmarks.
  • Review IAM, network ACLs, boundary protections, and FIPS-compliant cryptography implementations.
  • Ensure automated compliance auditing and logging are integrated into delivery pipelines.
Security Tools & Operations
  • Review vulnerability, EDR, and SIEM outputs; drive risk-based remediation.
  • Investigate potential incidents with SOC/engineering and document actions according to agency timelines.
  • Audit logs to detect compliance issues or abnormal activity; verify secure recovery and configuration restoration.
  • Oversee decommissioning activities and media sanitization aligned to NIST SP 800-88.
Authorization to Operate (ATO) Leadership
  • Lead teams through ATO preparation, readiness reviews, assessment support, and findings adjudication.
  • Collaborate with stakeholders, assessors, and program leadership to achieve and sustain ATOs.
Risk Management & Security Strategy

Evaluate architecture, processes, and controls to identify gaps; develop mitigation strategies and decision briefs.

  • Provide guidance to engineering, program management, and customer leadership on cybersecurity priorities.
Data Privacy
  • Perform Privacy Threshold Analyses and support PIAs to track CUI/PII and mission-sensitive data.
  • Enforce role-based access, regular access reviews, and MFA/password policy requirements.
  • Monitor retention and disposal aligned with security and privacy controls.
Minimum Qualifications
  • Bachelor’s degree in Computer Science, IT, Cybersecurity, or related field (or 10+ years of enterprise IT/security experience).
  • 8+ years of federal cybersecurity compliance experience, with 4+ years as an ISSO or equivalent technical compliance role.
  • Demonstrated delivery of at least one federal information system through initial authorization or re-authorization under NIST SP 800-37.
  • Technical literacy across AWS, Azure, and/or GCP; ability to review architecture diagrams, infrastructure settings, and control outputs.
  • Experience evaluating scan data from enterprise tools (Qualys, Tenable/Nessus, CrowdStrike, Splunk).
  • Direct experience applying DISA STIGs and SCAP content to system baselines.
  • Active DoD 8570/8140 IAM Level III certification (e.g., CISSP, CISM, or GSLC).
  • Ability to obtain and maintain a U.S. Government security clearance (Secret or Top Secret, per program).
Preferred Qualifications
  • Active Secret or Top Secret clearance.
  • Experience maintaining authorization packages and evidentiary files in SharePoint or agency GRC tools.
  • Hands-on with federal/commercial GRC platforms (Archer, CSAM, ServiceNow IRM, Xacta).
  • Cloud security/architecture certifications (AWS Security Specialty, AWS Solutions Architect, Azure Security Engineer, Google Associate Cloud Engineer).
  • Experience with Kubernetes/Docker, container security, or serverless baselines.
  • Familiarity with CMMC, NIST SP 800-171, and FedRAMP authorization structures.
  • Project management skills with demonstrated experience developing security solutions and security-related projects.
Tools & Platforms

Qualys VMDR, Tenable/Nessus, CrowdStrike Falcon, Splunk Enterprise/Cloud; cloud-native security tooling across AWS, Azure, GCP

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Sr. Information Assurance Specialist
Sr. Information Assurance Specialist

NR Labs LLC • Washington, Northern (KY)

Hybrid
USD 140,000 - 190,000
Cybersecurity - Lead ISSO
Cybersecurity - Lead ISSO

Securepro Inc • Arlington (VA)

On-site
USD 120,000 - 190,000
401(k)
401(k) matching
Dental insurance
+1
Information System Security Officer (ISSO)
Information System Security Officer (ISSO)

JFL Consulting LLC • Omaha (NE)

On-site
USD 120,000 - 140,000
Full medical coverage (incl. depend.)
FSAs
Life and disability insurance
+3
ME00672-Lead Information Security Officer (ISSO)
ME00672-Lead Information Security Officer (ISSO)

Momentum Engineering • Washington

On-site
USD 150,000 - 190,000
11 paid holidays
3 weeks PTO
Company-sponsored health plan
+2
Senior Information Security Analyst
Senior Information Security Analyst

Wood River Federal, LLC • San Antonio (TX)

On-site
USD 120,000 - 180,000
Information System Security Manager (ISSM)
Information System Security Manager (ISSM)

JFL Consulting LLC • Springfield (VA)

On-site
USD 155,000 - 175,000
Salary 155k-175k
Medical/dental/vision premiums
FSA accounts
+4
ME00672-Lead Information Security Officer (ISSO)
ME00672-Lead Information Security Officer (ISSO)

Momentum Engineering, Inc • Washington, Northern (KY)

On-site
USD 140,000 - 220,000
Paid holidays
PTO
Group medical plan
+4
Information Systems Security Officer (ISSO)
Information Systems Security Officer (ISSO)

Quantum Sky • Washington

On-site
USD 110,000 - 140,000
ME00672-Lead Information Security Officer (ISSO)
ME00672-Lead Information Security Officer (ISSO)

Momentum Engineering, Inc. • Washington

On-site
USD 150,000 - 210,000
11 paid holidays
3 weeks PTO (min)
Medical plan
+4
ISSO Senior Analyst
ISSO Senior Analyst

Cybersecurity Jobs • San Antonio (TX)

Hybrid
USD 110,000 - 140,000