Junior Cybersecurity GRC Analyst

Dragonfli Group

United States

Hybrid

USD 65,000 - 90,000

Full time

37 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Medical plans and insurance options
Dental coverage
Vision coverage
401(k) with employer match
Long-Term Disability insurance
Life Insurance
Paid time off 15–25 days
Federal holidays

Job summary

Dragonfli Group is seeking a Junior Cyber Governance and Compliance Analyst to support RMF-based authorization for a large federal agency. The role emphasizes learning RMF by doing, with opportunities to present to clients and decision makers and to contribute to risk mitigation strategies.

Ideal candidates bring foundational RMF exposure, strong communication skills, and a willingness to work in a multi-year contract. U.S.

Qualifications

  • Must have a Bachelor's degree in cybersecurity, information technology, or a related field.
  • Exposure to Assessment and Authorization (RMF) work through coursework, internship, or professional experience.
  • Working understanding of the Risk Management Framework and the federal authorization process.
  • Strong written and verbal communication skills, including comfort supporting or delivering presentations.
  • Ability to work independently and as a member of a team.
  • U.S. Citizenship or Permanent Residency, with all work performed within the continental U.S.
  • Ability to pass a federal agency suitability or background investigation.

Responsibilities

  • Support and contribute to the execution of the Risk Management Framework to authorize IT systems.
  • Provide information on whether information systems are operating at an acceptable level of risk to the organization.
  • Support information system authorization decisions by performing risk trade-off analyses.
  • Contribute to the development of risk mitigation strategies and solutions.
  • Support technical analysis across cybersecurity risk management activities: categorizing a system, proposing security control selections, implementing security controls, and providing comprehensive assessments of risk posture.
  • Support security control assessment activities in accordance with NIST SP 800-37 and NIST SP 800-53A.
  • Support presentations and, at times, present to clients and other decision makers across technical and non-technical audiences.
  • Support advice to clients on technical designs, implementations, and solutions that protect against cybersecurity attacks.
  • Support POA&M tracking, cyber risk register upkeep, and tracking of cybersecurity regulations, guidance, and data calls.
  • Support cybersecurity dashboard development and the automation of routine risk reporting and compliance tracking.

Skills

RMF fundamentals
Security control familiarity
Risk trade-off analysis
POA&M tracking
Security documentation
Cyber risk register
Dashboard & reporting
Automation tooling exposure

Education

Bachelor's degree in cybersecurity or IT

Tools

Xacta
eMASS
CSAM
Archer
ServiceNow IRM

Job description

Dragonfli Group is a cybersecurity and IT consulting firm providing services to federal agencies and Fortune 100 enterprises. Headquartered in Washington, DC, Dragonfli supports clients in securing mission-critical systems across on-site, hybrid, and fully remote environments.

Dragonfli Group is seeking a Junior Cyber Governance and Compliance Analyst to support a multi-year cybersecurity program for a large federal agency. This is an early-career governance role for someone who wants to learn the Risk Management Framework by working it. You will support and contribute to the execution of RMF to authorize IT systems, help the organization understand whether its systems are operating at an acceptable level of risk, and support authorization decisions by performing risk trade-off analyses and contributing to risk mitigation strategies. You will support technical analysis across categorization, control selection, control implementation, and comprehensive assessments of risk posture. You will also support presentations and, at times, present directly to clients and other decision makers. It suits a versatile early-career analyst with strong communication skills and some exposure to assessment and authorization work.

This is a multi-year contract position involving a large US federal agency. Candidates with previous federal contracting experience are preferred. U.S. Citizenship or Permanent Residency is required. If hired, all work related to this role must be performed within the continental U.S.

Responsibilities

  • Support and contribute to the execution of the Risk Management Framework to authorize IT systems
  • Provide information on whether information systems are operating at an acceptable level of risk to the organization
  • Support information system authorization decisions by performing risk trade-off analyses
  • Contribute to the development of risk mitigation strategies and solutions
  • Support technical analysis across cybersecurity risk management activities: categorizing a system, proposing security control selections, implementing security controls, and providing comprehensive assessments of risk posture
  • Support security control assessment activities in accordance with NIST SP 800-37 and NIST SP 800-53A
  • Support presentations and, at times, present to clients and other decision makers across technical and non-technical audiences
  • Support advice to clients on technical designs, implementations, and solutions that protect against cybersecurity attacks
  • Support POA&M tracking, cyber risk register upkeep, and tracking of cybersecurity regulations, guidance, and data calls
  • Support cybersecurity dashboard development and the automation of routine risk reporting and compliance tracking

Dragonfli Group is a cybersecurity and IT consulting firm providing services to federal agencies and Fortune 100 enterprises. Headquartered in Washington, DC, Dragonfli supports clients in securing mission-critical systems across on-site, hybrid, and fully remote environments.

Dragonfli Group is seeking a Junior Cyber Governance and Compliance Analyst to support a multi-year cybersecurity program for a large federal agency. This is an early-career governance role for someone who wants to learn the Risk Management Framework by working it. You will support and contribute to the execution of RMF to authorize IT systems, help the organization understand whether its systems are operating at an acceptable level of risk, and support authorization decisions by performing risk trade-off analyses and contributing to risk mitigation strategies. You will support technical analysis across categorization, control selection, control implementation, and comprehensive assessments of risk posture. You will also support presentations and, at times, present directly to clients and other decision makers. It suits a versatile early-career analyst with strong communication skills and some exposure to assessment and authorization work.

This is a multi-year contract position involving a large US federal agency. Candidates with previous federal contracting experience are preferred. U.S. Citizenship or Permanent Residency is required. If hired, all work related to this role must be performed within the continental U.S.

Responsibilities

  • Support and contribute to the execution of the Risk Management Framework to authorize IT systems
  • Provide information on whether information systems are operating at an acceptable level of risk to the organization
  • Support information system authorization decisions by performing risk trade-off analyses
  • Contribute to the development of risk mitigation strategies and solutions
  • Support technical analysis across cybersecurity risk management activities: categorizing a system, proposing security control selections, implementing security controls, and providing comprehensive assessments of risk posture
  • Support security control assessment activities in accordance with NIST SP 800-37 and NIST SP 800-53A
  • Support presentations and, at times, present to clients and other decision makers across technical and non-technical audiences
  • Support advice to clients on technical designs, implementations, and solutions that protect against cybersecurity attacks
  • Support POA&M tracking, cyber risk register upkeep, and tracking of cybersecurity regulations, guidance, and data calls
  • Support cybersecurity dashboard development and the automation of routine risk reporting and compliance tracking
Requirements:

Must-Have

  • Bachelor's degree in cybersecurity, information technology, or a related field
  • Exposure to Assessment and Authorization (RMF) work, including testing or assessing cybersecurity solutions, through coursework, internship, or professional experience
  • Working understanding of the Risk Management Framework and the federal authorization process
  • Strong written and verbal communication skills, including comfort supporting or delivering presentations
  • Ability to work independently and as a member of a team
  • U.S. Citizenship or Permanent Residency, with all work performed within the continental U.S.
  • Ability to pass a federal agency suitability or background investigation

Preferred / Nice-to-Have

  • Internship, co-op, or 1 to 2 years of professional experience in a GRC, audit, or compliance role
  • Familiarity with NIST SP 800-53 control families and evidence expectations
  • Exposure to a GRC platform such as Xacta, eMASS, CSAM, Archer, or ServiceNow IRM
  • Exposure to FISMA reporting, SCRM, or TPRM concepts
  • Interest in or exposure to automation and AI-assisted compliance tooling
  • Security+ or CGRC (formerly CAP) certification, or active pursuit of one
Skill(s):

Technical Skills

  • Risk Management Framework fundamentals under NIST SP 800-37
  • Security control familiarity under NIST SP 800-53 and assessment basics under 800-53A
  • Risk trade-off analysis and mitigation strategy support
  • POA&M tracking and evidence collection
  • Security documentation and authorization artifact support
  • Cyber risk register and regulatory tracking support
  • Dashboard, reporting, and spreadsheet analysis skills
  • Exposure to automation and AI-assisted compliance tooling

Soft Skills

  • Clear written and verbal communication with both technical and non-technical audiences
  • Ability to work independently and as a contributing member of a distributed team
  • Comfort operating in a fully remote setting with a camera-on meeting culture
  • Sound judgment about when to decide and when to escalate
  • Collaborative posture with system owners, business owners, developers, and assessors
  • Attention to documentation quality and follow-through on commitments
Benefits:

Dragonfli Group offers a comprehensive benefits package that includes:

  • Medical: Multiple POS health plan options including an HSA-compatible plan
  • Dental: PPO coverage for preventive, basic, and major services
  • Vision: Annual exam, frames, lenses, and contact lens allowance
  • 401(k): Employer match up to 5% of eligible compensation
  • Long-Term Disability: 100% employer-paid coverage at 50% of pre-disability earnings
  • Life Insurance & AD&D: 100% employer-paid coverage valued at $10,000 each
  • PTO: 15–25 days annually based on tenure
  • Paid Federal Holidays: All 11 federal holidays observed
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Junior Cybersecurity GRC Analyst
Junior Cybersecurity GRC Analyst

Talanto • Northern (KY)

Hybrid
USD 5,500 - 12,000
Medical: Health plan options with HSA
Dental: PPO coverage
Vision: Annual exam allowance
+5
Cloud Security Engineer
Cloud Security Engineer

Dragonfli Group • United States

On-site
USD 110,000 - 160,000
Medical plans
Dental coverage
Vision coverage
+4
Remote Junior Cyber GRC Analyst (RMF & Risk)
Remote Junior Cyber GRC Analyst (RMF & Risk)

Talanto • Northern (KY)

Hybrid
USD 5,500 - 12,000
Medical: Health plan options with HSA
Dental: PPO coverage
Vision: Annual exam allowance
+5
IT Auditor
IT Auditor

Jobgether • United States

On-site
USD 107,000 - 120,000
Fully remote
Health insurance
Vision insurance
+8
Security Engineer (Insider Risk)
Security Engineer (Insider Risk)

Dragonfli Group • Washington

Hybrid
USD 120,000 - 160,000
Insurance - health, dental, and vision
Paid Time Off (PTO) and 11 Federal Holidays
401(k) employer match
Senior Security Compliance Engineer, Public Sector
Senior Security Compliance Engineer, Public Sector

Jobgether • United States

On-site
USD 139,000 - 196,000
Equity
Health benefits
Flexible PTO
+2
Risk and Compliance Analyst
Risk and Compliance Analyst

Jobgether • United States

On-site
USD 98,000 - 115,000
Medical, dental, and vision insurance
401(k) retirement plan
Paid time off
Cybersecurity Analyst
Cybersecurity Analyst

SHR Consulting Group • Arlington (VA)

On-site
USD 120,000 - 160,000
Medical Insurance
Dental Insurance
Vision Insurance
+7
Governance, Risk, & Compliance (GRC) Analyst
Governance, Risk, & Compliance (GRC) Analyst

Districttechgroup • Washington

Hybrid
USD 80,000 - 100,000
Fully remote work environment
Competitive salary and performance bonuses
Health, dental, and vision insurance
+2
Information Technology Security Analyst
Information Technology Security Analyst

The Phoenix Group • Charlotte (NC)

Hybrid
USD 95,000 - 116,000
Hybrid work model
Relocation assistance
Certification sponsorship