Senior Continuous Monitoring (ConMon) Analyst

Rividium

Washington (District of Columbia)

On-site

USD 120,000 - 170,000

Full time

2 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

RiVidium Inc. seeks a Senior Continuous Monitoring (ConMon) Analyst to support federal cybersecurity and RMF activities.

The role focuses on continuous monitoring, security assessments, risk analysis, and compliance documentation to keep systems aligned with federal requirements. The successful candidate will work with ISSOs/ISSMs/SCAs, manage POA&Ms, and coordinate with government stakeholders to ensure effective remediation and reporting.

Qualifications

  • Bachelor’s degree in Cybersecurity, Information Systems, Computer Science, Information Assurance, or related field.
  • Demonstrated experience supporting cybersecurity, continuous monitoring, RMF, security compliance, or information assurance programs.
  • Strong understanding of RMF and NIST cybersecurity standards.
  • Experience with security controls, assessments, vulnerability management, risk management, and POA&M tracking.
  • Experience analyzing security documentation and technical evidence to determine control compliance.
  • Experience working with ISSOs, ISSMs, SCAs, system owners, and engineers.
  • Strong written and verbal communication for technical and executive reports.
  • Ability to manage multiple systems and findings in a federal environment.

Responsibilities

  • Perform continuous monitoring to identify changes in security posture, vulnerabilities, risks, and compliance status.
  • Support implementation and execution of ConMon strategies per federal requirements and policies.
  • Monitor security controls and assess control effectiveness via reviews, evidence, and data.
  • Support RMF activities throughout the system lifecycle.
  • Review assessment results, changes, vulnerabilities, and artifacts to identify risks and gaps.
  • Track and report weaknesses, vulnerabilities, and POA&Ms.
  • Coordinate with ISSOs/ISSMs/SCAs and technical teams to remediate deficiencies.
  • Maintain and update cybersecurity documentation including evidence and POA&Ms.
  • Review vulnerability scan results to assess impact on security posture.
  • Assist with security impact analyses for changes and new technologies.
  • Prepare recurring security/compliance reports for leadership.
  • Analyze metrics to identify recurring weaknesses and mitigation strategies.
  • Support testing and validation of controls as required.
  • Ensure monitoring activities align with policies and regulations.
  • Use GRC and cybersecurity tools to maintain security information and compliance docs.
  • Participate in working groups and risk reviews with stakeholders.
  • Provide recommendations to improve processes and posture.
  • Stay current on federal policies, guidance, threats, and best practices.

Skills

RMF
ConMon
NIST 800-53
A&A
ATO
POAM management
Vulnerability management
Risk assessment
Security control assessment
GRC tools
Cybersecurity compliance
Security documentation
Security metrics & reporting
Federal cybersecurity policies & STDS

Education

Bachelor’s degree in Cybersecurity, Information Systems, Computer Science, Information Assurance, or related field

Tools

RSA Archer
ServiceNow GRC
eMASS

Job description

Full-Time/Part-Time Full-Time

Description

Summary

RiVidium Inc. seeking a Senior Continuous Monitoring (ConMon) Analyst to support federal cybersecurity and Risk Management Framework (RMF) activities. The Senior ConMon Analyst will provide cybersecurity continuous monitoring, security assessment, risk analysis, and compliance support to ensure information systems remain compliant with applicable federal security requirements.

The ideal candidate will have strong experience with RMF, security controls, continuous monitoring, vulnerability management, POA&M management, security documentation, and Governance, Risk, and Compliance (GRC) tools. This position requires the ability to work closely with Information System Security Officers (ISSOs), Information System Security Managers (ISSMs), Security Control Assessors (SCAs), system owners, engineers, and government stakeholders.

Key Responsibilities
  • Perform continuous monitoring of information systems to identify changes in security posture, vulnerabilities, risks, and compliance status.
  • Support implementation and execution of Continuous Monitoring (ConMon) strategies in accordance with federal cybersecurity requirements and organizational policies.
  • Monitor security controls and assess ongoing control effectiveness through documentation reviews, technical evidence, vulnerability data, and other assessment activities.
  • Support NIST Risk Management Framework (RMF) activities throughout the system lifecycle.
  • Review security controls, assessment results, system changes, vulnerabilities, and security-related artifacts to identify potential risks and compliance gaps.
  • Track, analyze, and report security weaknesses, vulnerabilities, and Plans of Action and Milestones (POA&Ms).
  • Coordinate with ISSOs, ISSMs, SCAs, system owners, and technical teams to ensure identified security deficiencies are properly documented and remediated.
  • Maintain and update cybersecurity documentation, including security assessment evidence, control implementation statements, POA&Ms, risk assessments, and continuous monitoring reports.
  • Review vulnerability scan results and other security assessment data to determine potential impact to system security posture.
  • Support security impact analyses for system changes, configuration changes, new technologies, and changes to the operational environment.
  • Assist with preparation of recurring security and compliance reports for government leadership and cybersecurity stakeholders.
  • Analyze security metrics and trends to identify recurring weaknesses and recommend risk mitigation strategies.
  • Support security control testing, assessment, and validation activities as required.
  • Ensure continuous monitoring activities are properly documented and aligned with applicable policies, standards, and federal regulations.
  • Use GRC and cybersecurity tools to maintain system security information, control status, assessment findings, POA&Ms, and compliance documentation.
  • Participate in cybersecurity working groups, risk reviews, security meetings, and technical discussions with government and contractor stakeholders.
  • Provide recommendations to improve cybersecurity processes, control effectiveness, risk management, and compliance posture.
  • Stay current on evolving federal cybersecurity policies, NIST guidance, threats, vulnerabilities, and security best practices.
Required Qualifications
  • Bachelor’s degree in Cybersecurity, Information Systems, Computer Science, Information Assurance, or a related field.
  • Demonstrated professional experience supporting cybersecurity, continuous monitoring, RMF, security compliance, or information assurance programs.
  • Strong understanding of the NIST Risk Management Framework (RMF) and NIST cybersecurity standards.
  • Experience with security controls, security assessments, vulnerability management, risk management, and POA&M tracking.
  • Experience analyzing security documentation and technical evidence to determine control compliance and system security posture.
  • Experience working with cybersecurity stakeholders, including ISSOs, ISSMs, SCAs, system owners, and system administrators/engineers.
  • Strong written and verbal communication skills with the ability to prepare clear technical and executive-level security reports.
  • Ability to manage multiple systems, security requirements, findings, and competing priorities in a federal environment.
Preferred Qualifications
  • CISM, CAP, or equivalent GRC/cybersecurity certification.
  • Experience with GRC platforms such as RSA Archer, ServiceNow GRC, eMASS, or equivalent tools.
  • Experience supporting federal civilian or Department of Defense cybersecurity programs.
  • Knowledge of NIST SP 800-37, NIST SP 800-53, NIST SP 800-30, NIST SP 800-137, FISMA, and related federal cybersecurity requirements.
  • Experience with vulnerability management and security scanning tools.
  • Experience developing dashboards, metrics, and cybersecurity status reports.
  • Experience supporting ATO, continuous authorization, security assessment, and ongoing authorization activities.
  • Familiarity with federal cybersecurity policies, standards, and compliance requirements.
Desired Skills
  • Risk Management Framework (RMF)
  • Continuous Monitoring (ConMon)
  • NIST 800-53 security controls
  • Security Assessment & Authorization (A&A)
  • Authority to Operate (ATO)
  • POA&M management
  • Vulnerability Management
  • Risk Assessment
  • Security Control Assessment
  • GRC tools
  • Cybersecurity compliance
  • Security documentation
  • Security metrics and reporting
  • Federal cybersecurity policies and standards
Education & Certification
Required:
  • Bachelor’s degree in Cybersecurity, Information Systems, Computer Science, Information Assurance, or related field.
Preferred:
  • Certified Information Security Manager (CISM)
  • Certified Authorization Professional (CAP)
  • Equivalent GRC, cybersecurity, or information assurance certification

RiVidium Inc is seeking a “Senior Continuous Monitoring (ConMon) Analyst” to support a federal client. This position is contingent upon contract award and funding approval. As such, this job posting is intended to identify qualified candidates for a potential future opportunity and does not represent a currently available position. Compensation has not yet been determined and will be established based on contract requirements, candidate qualifications, experience, and applicable market conditions.

About the Organization Established in 2008, RiVidium, Inc. (dba TripleCyber) is a VA-Verified SDVOSB and an SBA-Certified 8(a) company. To prepare our clients for the future, RiVidium has balanced all parts of our organization to attract the finest employees in order to 'Strive to be the missing element defining tomorrow's technology'. RiVidium keeps pace and surpasses its competitors by meeting challenges of advancements in Logistics, Human Capital, Cyber, Intelligence & Technology.

EOE Statement We are an equal employment opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veteran status or any other characteristic protected by law. If you need a reasonable accommodation for any part of the employment process, please contact Human Resources (HR) at hr@rividium.com.

This position is currently accepting applications.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IT Security Operations Specialist
IT Security Operations Specialist

Rividium • Washington

On-site
USD 100,000 - 150,000
Senior ConMon Analyst – RMF & Compliance Lead
Senior ConMon Analyst – RMF & Compliance Lead

Rividium • Washington

On-site
USD 120,000 - 170,000
Cybersecurity Program Manager — Level III
Cybersecurity Program Manager — Level III

Rividium Inc • Washington

On-site
USD 150,000 - 210,000
Information Systems Security Manager - Intermediate
Information Systems Security Manager - Intermediate

Rividium Inc • Springfield (VA)

On-site
USD 140,000 - 220,000
Cybersecurity Engineer, Jr - Continuous Monitoring
Cybersecurity Engineer, Jr - Continuous Monitoring

Agecareers • Trenton (PA)

Hybrid
USD 75,000 - 105,000
26 Days Paid Leave
Performance Bonuses
401(k) with Match
+6
Information Systems Security Officer (ISSO) ? Junior
Information Systems Security Officer (ISSO) ? Junior

Rividium • Washington

On-site
USD 65,000 - 95,000
Cybersecurity Engineer Jr - Continuous Monitoring (Current Contract)
Cybersecurity Engineer Jr - Continuous Monitoring (Current Contract)

AGE Solutions LLC • Fort Meade (MD)

On-site
USD 60,000 - 70,000
26 Days Paid Leave
Performance Bonuses
401(k) with Match
+5
Senior ISSO/ISSE ? National Vetting Center
Senior ISSO/ISSE ? National Vetting Center

Rividium • Washington

On-site
USD 140,000 - 190,000
Cybersecurity Engineer, Jr - Continuous Monitoring
Cybersecurity Engineer, Jr - Continuous Monitoring

Age Solutions • Salem (PA)

Hybrid
USD 68,000 - 83,000
26 Days Paid Leave
Performance Bonuses
401(k) with Match
+4
Vulnerability Assessment Analyst - Intermediate
Vulnerability Assessment Analyst - Intermediate

Rividium • Springfield (VA)

On-site
USD 80,000 - 110,000