Junior Cybersecurity GRC Analyst

Talanto

Northern (KY)

Hybrid

USD 5,500 - 12,000

Full time

2 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical: Health plan options with HSA
Dental: PPO coverage
Vision: Annual exam allowance
401(k) with employer match
Long-Term Disability: Employer-paid
Life Insurance & AD&D
PTO: 15–25 days annually
Paid federal holidays

Job summary

Dragonfli is seeking a Junior Cyber Governance and Compliance Analyst to support a multi-year RMF program for a large federal agency. This early-career role focuses on risk management framework activities, including categorization, control selection, implementation, and evidence collection.

Strong written and verbal communication skills are required, including comfort presenting to clients. U.S. Citizenship or Permanent Residency is required, with work performed within the continental U.S.

Qualifications

  • Bachelor’s degree in cybersecurity, information technology, or a related field.
  • Exposure to RMF work via coursework, internship, or professional experience.
  • Understanding of RMF and federal authorization processes.
  • Strong written and verbal communication skills, including presenting to clients.

Responsibilities

  • Support RMF execution to authorize IT systems.
  • Provide information on risk levels for information systems.
  • Assist with risk trade-off analyses for authorization decisions.
  • Contribute to risk mitigation strategy development.
  • Support technical analysis across categorization, control selection, implementation, and assessments.
  • Assist with security control assessments per NIST SP 800-37/53A.
  • Prepare presentations for clients and decision-makers.
  • Advise on designs and solutions to protect against cyber attacks.
  • Track POA&Ms and cybersecurity regulations and data calls.
  • Develop cybersecurity dashboards and automate risk reporting.

Skills

RMF fundamentals
NIST SP 800-37
NIST SP 800-53A
Security control familiarity
Risk trade-off analysis
Documentation & artifacts
Dashboard & reporting
Communication skills

Education

Bachelor's degree in cybersecurity or IT

Tools

Xacta
eMASS
CSAM
Archer
ServiceNow IRM

Job description

cybersecurity

Important: if an employer asks you to log into their system via iCloud or Google, send a code, an SMS or Telegram password, run some code, or install software — refuse. These are signs of fraud.

Description

••••••••••••••• is a cybersecurity and IT consulting firm providing services to federal agencies and Fortune 100 enterprises. Headquartered in Washington, DC, Dragonfli supports clients in securing mission-critical systems across on-site, hybrid, and fully remote environments.

••••••••••••••• is seeking a Junior Cyber Governance and Compliance Analyst to support a multi-year cybersecurity program for a large federal agency. This is an early-career governance role for someone who wants to learn the Risk Management Framework by working it. You will support and contribute to the execution of RMF to authorize IT systems, help the organization understand whether its systems are operating at an acceptable level of risk, and support authorization decisions by performing risk trade-off analyses and contributing to risk mitigation strategies. You will support technical analysis across categorization, control selection, control implementation, and comprehensive assessments of risk posture. You will also support presentations and, at times, present directly to clients and other decision makers. It suits a versatile early-career analyst with strong communication skills and some exposure to assessment and authorization work.

This is a multi-year contract position involving a large US federal agency. Candidates with previous federal contracting experience are preferred. U.S. Citizenship or Permanent Residency is required. If hired, all work related to this role must be performed within the continental U.S.

Responsibilities
  • Support and contribute to the execution of the Risk Management Framework to authorize IT systems
  • Provide information on whether information systems are operating at an acceptable level of risk to the organization
  • Support information system authorization decisions by performing risk trade-off analyses
  • Contribute to the development of risk mitigation strategies and solutions
  • Support technical analysis across cybersecurity risk management activities: categorizing a system, proposing security control selections, implementing security controls, and providing comprehensive assessments of risk posture
  • Support security control assessment activities in accordance with NIST SP 800-37 and NIST SP 800-53A
  • Support presentations and, at times, present to clients and other decision makers across technical and non-technical audiences
  • Support advice to clients on technical designs, implementations, and solutions that protect against cybersecurity attacks
  • Support POA&M tracking, cyber risk register upkeep, and tracking of cybersecurity regulations, guidance, and data calls
  • Support cybersecurity dashboard development and the automation of routine risk reporting and compliance tracking
Requirements
Must-Have
  • Bachelor’s degree in cybersecurity, information technology, or a related field
  • Exposure to Assessment and Authorization (RMF) work, including testing or assessing cybersecurity solutions, through coursework, internship, or professional experience
  • Working understanding of the Risk Management Framework and the federal authorization process
  • Strong written and verbal communication skills, including comfort supporting or delivering presentations
  • Ability to work independently and as a member of a team
  • U.S. Citizenship or Permanent Residency, with all work performed within the continental U.S.
  • Ability to pass a federal agency suitability or background investigation
Preferred / Nice-to-Have
  • Internship, co-op, or 1 to 2 years of professional experience in a GRC, audit, or compliance role
  • Familiarity with NIST SP 800-53 control families and evidence expectations
  • Exposure to a GRC platform such as Xacta, eMASS, CSAM, Archer, or ServiceNow IRM
  • Exposure to FISMA reporting, SCRM, or TPRM concepts
  • Interest in or exposure to automation and AI-assisted compliance tooling
  • Security+ or CGRC (formerly CAP) certification, or active pursuit of one
Skill(s)
Technical Skills
  • Risk Management Framework fundamentals under NIST SP 800-37
  • Security control familiarity under NIST SP 800-53 and assessment basics under 800-53A
  • Risk trade-off analysis and mitigation strategy support
  • POA&M tracking and evidence collection
  • Security documentation and authorization artifact support
  • Cyber risk register and regulatory tracking support
  • Dashboard, reporting, and spreadsheet analysis skills
  • Exposure to automation and AI-assisted compliance tooling
Soft Skills
  • Clear written and verbal communication with both technical and non-technical audiences
  • Ability to work independently and as a contributing member of a distributed team
  • Comfort operating in a fully remote setting with a camera-on meeting culture
  • Sound judgment about when to decide and when to elevate
  • Collaborative posture with system owners, business owners, developers, and assessors
  • Attention to documentation quality and follow-through on commitments
  • Medical: Multiple POS health plan options including an HSA-compatible plan
  • Dental: PPO coverage for preventive, basic, and major services
  • Vision: Annual exam, frames, lenses, and contact lens allowance
  • 401(k): Employer match up to 5% of eligible compensation
  • Long-Term Disability: 100% employer-paid coverage at 50% of pre-disability earnings
  • Life Insurance & AD&D: 100% employer-paid coverage valued at $10,000 each
  • PTO: 15–25 days annually based on tenure
  • Paid Federal Holidays: All 11 federal holidays observed

5500–11874$ /month

5500 $ 25%

8333 $ median

11874 $ 75%

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

GRC Analyst II
GRC Analyst II

Frontgrade Technologies • Colorado Springs (CO)

On-site
USD 70,000 - 90,000
Immediate Medical, Dental, and Vision
401K Match with 100% immediate vesting
Tuition Reimbursement/Student Loan Repayment
+2
GRC Analyst
GRC Analyst

The Emery Company, LLC • Houston (TX)

On-site
USD 85,000 - 110,000
Senior Cybersecurity Risk & Governance Analyst
Senior Cybersecurity Risk & Governance Analyst

Mortgage-Trade-Holding-Company,-LL • Oxford (MS)

On-site
USD 110,000 - 150,000
Senior Cybersecurity Risk & Governance Analyst
Senior Cybersecurity Risk & Governance Analyst

mTrade, LLC. • Oxford (MS)

On-site
USD 110,000 - 160,000
Senior Governance, Risk & Compliance (GRC) Analyst
Senior Governance, Risk & Compliance (GRC) Analyst

Cianbro • Pittsfield (ME)

On-site
Employee-owned
Equal opportunity employer
Information Technology Security Analyst
Information Technology Security Analyst

The Phoenix Group • Charlotte (NC)

Hybrid
USD 95,000 - 116,000
Hybrid work model
Relocation assistance
Certification sponsorship
Cybersecurity Audit Analyst
Cybersecurity Audit Analyst

Applied Aerospace • Huntsville (AL)

On-site
USD 70,000 - 90,000
Cyber GRC Specialist
Cyber GRC Specialist

Brown Advisory • Baltimore (MD)

On-site
USD 95,000 - 125,000
Medical
Dental
Vision
+11
Cyber GRC Specialist
Cyber GRC Specialist

Brown Advisory • Washington

On-site
USD 105,000 - 127,000
Medical
Dental
Vision
+1
Cybersecurity Analyst
Cybersecurity Analyst

SHR Consulting Group • Arlington (VA)

On-site
USD 120,000 - 160,000
Medical Insurance
Dental Insurance
Vision Insurance
+7