Seize your opportunity to make a personal impact supporting the Case Management Modernization (CMM) Program. The CMM program is an initiative to support the Administrative Office of the US Courts (AO) in developing a modern cloud-based solution to support all 204+ federal courts across the United States.
GDIT is your place to make meaningful contributions to challenging projects and grow a rewarding career. The Security & Compliance Analyst will work as part of the CMM Data Modernization and Governance team responsible for delivering an integrated data governance, engineering, data platform, reporting, analytics, and Artificial Intelligence (AI)/Machine Learning (ML) capabilities that support operational decision-making and fulfill AO's data and analytics objectives in support of the CMM program.
To protect the CMM program's operational environment, GDIT mandates 24/7 supplemental monitoring, rapid escalation within 30 minutes for critical, service-impacting issues, and monthly incident/problem reporting. Security analysts embedded here ensure operations remain compliant and responsive during and after releases.
The Security & Compliance Analyst defines data privacy, security, retention, and classification rules, and manages data classification, sensitive data governance, and data sharing agreements across the program.
The Security & Compliance Analyst will execute the following responsibilities:
- Support analysis of systems, programs, and/or planning activities across the CMM operational environment.
- Perform research in support of policies, procedures, and other technical documentation, and support analysis of IA/Cyber-related programs and initiatives.
- Research and analyze options to develop relationships and solutions that resolve problems within the specialty area.
- Analyze information assurance-related technical problems and provide engineering and technical support in solving them.
- Design, develop, engineer, and implement solutions that meet network security requirements.
- Perform vulnerability and risk analyses of computer systems and applications during all phases of the system development life cycle.
- Establish and satisfy complex system-wide information security requirements based on the analysis of user, policy, regulatory, and resource demands.
- Support customers in the development and implementation of security policies.
- Provide 24/7 supplemental monitoring of the operational environment and **escalate** critical, service-impacting issues within 30 minutes.
- Prepare monthly incident and problem management reports, ensuring operations remain compliant and responsive during and after releases.
- Define data privacy, security, retention, and classification rules; manage data classification, sensitive data governance, and data sharing agreements.
- Support Authority to Operate (ATO) documentation and gather supporting artifacts for ATO packages.
- Monitor performance scans and system logs, analyzing and reporting vulnerabilities.
- Investigate and analyze security issues and incidents, leveraging SIEM tools for monitoring and log analysis.
- Maintain awareness of emerging security threats and modern attack methods to inform monitoring and response activities.
QUALIFICATIONS
- BS/BA degree with 5+ years of experience of general experience in information systems providing enterprise cybersecurity through policy, architecture, and training processes.
- Experience developing plans to safeguard sensitive data against accidental or unauthorized modification, destruction, or disclosure.
- Experience working with Agile teams and SAFe, responding to security assessments, and providing oversight of vulnerability audits and assessments.
- Experience may be considered in lieu of degree.
- Experience using tools to detect cloud-based security issues (1-2+ years' experience).
- Exposure to SIEM tools such as Splunk for monitoring and log analysis (1-2+ years' experience).
- Prior experience performing incident response and forensics (1-2+ years' experience).
- Knowledge of modern security methods, vulnerabilities, and emerging threats.
- Experience with software and security testing, including containerized applications.
- Understanding of data privacy, retention, and classification requirements in a regulated environment.
- Familiarity with data governance, metadata management, and data quality practices.
- Experience with SQL for data querying and validation.
- Proficiency with BI/reporting tools such as Power BI, Tableau, or QuickSight.
- Familiarity with statistical analysis tools/techniques (e.g., Excel, R, Python) preferred.
- Experience with cloud data platforms (Snowflake, Databricks, AWS preferred).
- Understanding of data architecture concepts (data lake, lakehouse, warehouse).
- Strong analytical, problem‑solving, & statistical analysis skills with attention to detail and data accuracy.
- Preferred: Certified Information Systems Security Professional (CISSP).
COMMUNICATION & ORGANIZATIONAL
- Excellent presentation and communication (oral and written) skills.
- Consultant mindset with the ability to work with high level customer stakeholders and build excellent customer relationships.
- Experience identifying and applying industry tools, solutions, methods best practices, and emerging technologies.
- Strong analytical skills and problem-solving skills with the ability to formulate and communicate recommendations for improvement.
- Demonstrated ability to work effectively, independently, and as part of a team.
- Strong compliance mindset, with the ability to translate security and privacy requirements into clear governance guidance for stakeholders and leadership.