IT Risk and Compliance Specialist Principal

General Dynamics Information Technology (GDIT)

Bossier City (LA)

Hybrid

USD 111.000 - 150.000

Vollzeit

Vor 11 Tagen
Bewerbungsgenerator

Bekomme eine Antwort von diesem Arbeitgeber — ein Lebenslauf und ein Anschreiben, die genau auf die Eigenschaften eingehen, die gesucht werden.

Schaffe es an den ATS-Filtern vorbei

Zusammenfassung

General Dynamics Information Technology (GDIT) in the United States seeks Principal IT Risk and Compliance Security Analysts to support federal programs. You will act as a technical ISSO, leading governance, compliance, and continuous monitoring for systems in AWS, Azure, and Google Cloud.

You will translate federal requirements into technical baselines, drive the RMF lifecycle, and partner with engineering to maintain secure, mission-enabled technologies and support ATO issuance and maintenance.

Qualifikationen

  • Bachelor’s degree (or 10+ years of enterprise IT/security experience).
  • 8+ years of federal cybersecurity compliance experience, with 4+ years as an ISSO.
  • Experience delivering at least one federal information system through initial authorization or re-authorization under NIST SP 800-37.
  • Technical literacy across AWS, Azure, and/or GCP; ability to review architecture diagrams and control outputs.
  • Experience evaluating scan data from enterprise tools (Qualys, Tenable/Nessus, CrowdStrike, Splunk).
  • Direct experience applying DISA STIGs and SCAP content to system baselines.
  • Active DoD 8570/8140 IAM Level III certification (e.g., CISSP, CISM, or GSLC).
  • Ability to obtain and maintain a U.S. Government security clearance (Secret or Top Secret).

Aufgaben

  • Execute RMF steps (Categorization through Continuous Monitoring) per NIST SP 800-37.
  • Author and maintain SSPs, POA&Ms, SARs, ISCPs, and supporting artifacts.
  • Establish evidentiary libraries and audit records within program repositories.
  • Coordinate with SCAs and AOs during assessments and finding adjudication.
  • Lead continuous monitoring through baseline reviews and control assessments.
  • Interpret and validate NIST SP 800-53 and 800-171 controls across multi-cloud environments.
  • Review IAM, network ACLs, and encryption implementations; ensure automated auditing.
  • Investigate incidents with SOC/engineering and document actions per agency timelines.

Kenntnisse

AWS Security
Cloud Security
FedRAMP

Ausbildung

Bachelor’s degree in Computer Science, IT, Cybersecurity, or related field

Tools

Qualys
Tenable/Nessus
CrowdStrike
Splunk

Jobbeschreibung

Type of Requisition:
Pipeline

Clearance Level Must Currently Possess:
None

Clearance Level Must Be Able to Obtain:
Secret

Public Trust/Other Required:
None

Job Family:
Cyber and IT Risk Management

Job Qualifications

Skills:
Amazon Web Services (AWS) Security, Cloud Security, Federal Risk and Authorization Management Program (FedRAMP)
Certifications:
None
Experience:
8 + years of related experience
US Citizenship Required:
Yes

Job Description

TSS is proactively seeking Principal-level IT Risk and Compliance Security Analysts to support upcoming and ongoing federal programs across civilian and defense agencies. In this senior individual contributor role, you will serve as a technical ISSO, leading governance, compliance, and continuous monitoring activities for complex information systems hosted in AWS, Azure, and Google Cloud.

You will translate federal requirements into actionable technical baselines, drive the full RMF lifecycle, and partner with engineering teams to maintain secure, resilient, mission-enabling technologies and support ATO issuance and maintenance.

Key Responsibilities
RMF Execution & Authorization Lifecycle
  • Execute RMF steps (Categorization through Continuous Monitoring) per NIST SP 800-37.
  • Author and maintain SSPs, POA&Ms, SARs, ISCPs, and supporting authorization artifacts.
  • Establish evidentiary libraries and audit records within program repositories (e.g., SharePoint, agency GRC tools).
  • Coordinate with SCAs and AOs during assessments and finding adjudication.
  • Lead and sustain continuous monitoring through baseline reviews and periodic control assessments.
Security Governance & Compliance
  • Serve as the primary advisor on system security posture, threats, vulnerabilities, and compliance requirements.
  • Interpret, implement, and validate NIST SP 800-53 and 800-171 controls across multi-cloud environments.
  • Develop and update security documentation, test plans, and continuous monitoring artifacts.
  • Prepare for and respond to internal/external audits and compliance evaluations.
  • Drive security-driven configuration changes and accreditation updates in collaboration with system owners and engineers.
Engineering Interface & Technical Compliance
  • Analyze outputs from vulnerability scanners, container security tools, and static analysis utilities; prioritize remediation with engineering.
  • Assess IaC templates (Terraform/CloudFormation) and cloud configurations against DISA STIGs and CIS Benchmarks.
  • Review IAM, network ACLs, boundary protections, and FIPS-compliant cryptography implementations.
  • Ensure automated compliance auditing and logging are integrated into delivery pipelines.
Security Tools & Operations
  • Review vulnerability, EDR, and SIEM outputs; drive risk-based remediation.
  • Investigate potential incidents with SOC/engineering and document actions according to agency timelines.
  • Audit logs to detect compliance issues or abnormal activity; verify secure recovery and configuration restoration.
  • Oversee decommissioning activities and media sanitization aligned to NIST SP 800-88.
Authorization to Operate (ATO) Leadership
  • Lead teams through ATO preparation, readiness reviews, assessment support, and findings adjudication.
  • Collaborate with stakeholders, assessors, and program leadership to achieve and sustain ATOs.
Risk Management & Security Strategy
  • Evaluate architecture, processes, and controls to identify gaps; develop mitigation strategies and decision briefs.
  • Provide guidance to engineering, program management, and customer leadership on cybersecurity priorities.
Data Privacy
  • Perform Privacy Threshold Analyses and support PIAs to track CUI/PII and mission-sensitive data.
  • Enforce role-based access, regular access reviews, and MFA/password policy requirements.
  • Monitor retention and disposal aligned with security and privacy controls.
Minimum Qualifications
  • Bachelor’s degree in Computer Science, IT, Cybersecurity, or related field (or 10+ years of enterprise IT/security experience).
  • 8+ years of federal cybersecurity compliance experience, with 4+ years as an ISSO or equivalent technical compliance role.
  • Demonstrated delivery of at least one federal information system through initial authorization or re-authorization under NIST SP 800-37.
  • Technical literacy across AWS, Azure, and/or GCP; ability to review architecture diagrams, infrastructure settings, and control outputs.
  • Experience evaluating scan data from enterprise tools (Qualys, Tenable/Nessus, CrowdStrike, Splunk).
  • Direct experience applying DISA STIGs and SCAP content to system baselines.
  • Active DoD 8570/8140 IAM Level III certification (e.g., CISSP, CISM, or GSLC).
  • Ability to obtain and maintain a U.S. Government security clearance (Secret or Top Secret, per program).
Preferred Qualifications

Active Secret or Top Secret clearance.

Experience maintaining authorization packages and evidentiary files in SharePoint or agency GRC tools.

Hands-on with federal/commercial GRC platforms (Archer, CSAM, ServiceNow IRM, Xacta).

Cloud security/architecture certifications (AWS Security Specialty, AWS Solutions Architect, Azure Security Engineer, Google Associate Cloud Engineer).

Experience with Kubernetes/Docker, container security, or serverless baselines.

Familiarity with CMMC, NIST SP 800-171, and FedRAMP authorization structures.

Project management skills with demonstrated experience developing security solutions and security-related projects.

Tools & Platforms

Qualys VMDR, Tenable/Nessus, CrowdStrike Falcon, Splunk Enterprise/Cloud; cloud-native security tooling across AWS, Azure, GCP

The likely salary range for this position is $111,155 - $150,385. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.

Scheduled Weekly Hours:
40

Travel Required:
None

T elecommuting Options:
Hybrid

Work Location:
USA LA Bossier City

Total Rewards at GDIT:
Our benefits package for all US-based employees includes a variety of medical plan options, some with Health Savings Accounts, dental plan options, a vision plan, and a 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match. To encourage work/life balance, GDIT offers employees full flex work weeks where possible and a variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave. To ensure our employees are able to protect their income, other offerings such as short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available. We regularly review our Total Rewards package to ensure our offerings are competitive and reflect what our employees have told us they value most.

Our Identity Verification Process:
As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during virtual interviews. We reserve the right to take your picture to verify your identity and prevent fraud. By proceeding, you authorize the collection, processing, and use of your biometric data for identity verification and security purposes.

About Our Work:
We are GDIT. A global technology and professional services company that delivers technology solutions and mission services to every major agency across the U.S. government, defense and intelligence community. Our 26,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. We operate across 50+ countries worldwide, offering leading mission-ready capabilities in AI, cloud, cyber and software development.

Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans

Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.

oder ziehe deine Datei hierhin.

Similar jobs

Ähnliche Jobs, die dir auch gefallen könnten

IT and Cyber Risk Auditor Principal
IT and Cyber Risk Auditor Principal

General Dynamics Information Technology, Inc. • Las Cruces (NM)

Vor Ort
USD 111.000 - 150.000
Information Security Director
Information Security Director

gdit • Bellevue Second IV Precinct (NE)

Vor Ort
USD 170.000 - 205.000
Health benefits
401(k) with company match
Educational assistance and eLearning
+3
Cyber Analyst Principal - TS/SCI with Polygraph
Cyber Analyst Principal - TS/SCI with Polygraph

General Dynamics Information Technology, Inc. • McLean (VA)

Vor Ort
USD 170.000 - 230.000
Information Security Analyst Advisor
Information Security Analyst Advisor

General Dynamics Information Technology, Inc. • Maryland

Vor Ort
USD 115.000 - 155.000
Full-flex work week
401K with company match
Health and wellness packages
+3
Information Systems Security Manager (ISSM) - TS/SCI w/Polygraph
Information Systems Security Manager (ISSM) - TS/SCI w/Polygraph

General Dynamics Information Technology, Inc. • McLean (VA)

Vor Ort
USD 123.000 - 167.000
401K with company match
Health and wellness packages
Internal mobility team
+3
Information Systems Security Officer (Active TS/SCI with Polygraph)
Information Systems Security Officer (Active TS/SCI with Polygraph)

General Dynamics Information Technology, Inc. • McLean (VA)

Vor Ort
USD 155.000 - 209.000
Information Systems Security Officer (Active TS/SCI with Polygraph)
Information Systems Security Officer (Active TS/SCI with Polygraph)

gdit • McLean (VA)

Vor Ort
USD 155.000 - 209.000
401K with company match
Health and wellness packages
Internal mobility team
+3
Information Systems Security Officer - TS/SCI with Polygraph
Information Systems Security Officer - TS/SCI with Polygraph

General Dynamics Information Technology, Inc. • McLean (VA)

Vor Ort
USD 159.000 - 215.000
401K with company match
Comprehensive health and wellness
Internal mobility support
+2
Information Security Director
Information Security Director

General Dynamics Information Technology, Inc. • Bellevue Second IV Precinct (NE)

Vor Ort
USD 170.000 - 205.000
Health benefits
401(k)
Education assistance
+2
Cyber Security Analyst (ISSO)
Cyber Security Analyst (ISSO)

General Dynamics Information Technology, Inc. • Missouri

Vor Ort
USD 84.000 - 114.000