Cybersecurity Compliance & Continuous Monitoring Analyst

General Dynamics Information TechnologyMcLean, VA
Onsite

About The Position

Advance your career while impacting our national security in cyber as a Cyber Technical Analyst Sr Principal at GDIT. Here, technologists have many paths to grow a meaningful career supporting cyber missions and operations across the federal government. MEANINGFUL WORK AND PERSONAL IMPACT As a Cyber Technical Analyst Sr Principal, the work you’ll do at GDIT will be impactful to the mission of our customer’s classified commercial cloud environment. You will play a crucial role in securing and continuously monitoring a classified workstation secure enclave, ensuring it meets stringent FedRAMP and CNSSI 1253 requirements while enabling mission-critical operations. Support the full RMF and Assessment & Authorization (A&A) lifecycle for the workstation secure enclave, including control implementation, assessment, authorization, and continuous monitoring. Maintain a comprehensive body of evidence for FedRAMP/DoW A&A packages and continuous monitoring requirements, including POA&M tracking, reporting, and remediation. Collaborate with security engineers, system administrators, ISSO/ISSM, vendors, and leadership to integrate and validate security controls and align operations with FedRAMP, DoD, and CNSSI 1253 requirements. Identify, assess, and remediate vulnerabilities using Tenable Nessus, Tenable.sc, SCC, STIG tooling, and related security tools; ensure host inventory and scan policies are accurate and complete. Review scan results, STIG findings, and patching activities to ensure accurate, actionable data and effective hardening of operating systems, network devices, and applications. Evaluate system designs, network architectures, firewall rules, and PPSM submissions to ensure security principles are integrated from the outset and architecture risks are addressed. Lead preparation and execution of security control audits and FedRAMP 3PAO assessments, reviewing artifacts, logs, and configurations to validate evidence of compliance and a strong security posture. Provide security control assessment and audit oversight, including reviewing and validating implementation work performed by engineers and system administrators. Manage a robust continuous monitoring and GRC program, aggregating and analyzing security data to identify trends, anomalies, and potential incidents and providing actionable risk insights to leadership. Support risk assessments and incident response, recommending mitigating controls and assisting the ISSM and incident response team with artifacts and deep system/security expertise.

Requirements

  • Bachelor of Arts/Bachelor of Science
  • 8+ years of related experience
  • Hands-on experience with Tenable.sc and Tenable Nessus
  • Progressive experience in information assurance and cybersecurity roles
  • Minimum of 5 years of direct, hands-on experience as an ISSO or ISSM with a proven track record of achieving and maintaining ATO for classified systems
  • Expert-level knowledge of the NIST SP 800 series (especially 800-37, 800-53, 800-30) and risk management principles
  • Experience with FedRAMP and CNSSI 1253 baselines, continuous monitoring, POA&M management, and A&A body-of-evidence documentation
  • Active Top Secret security clearance
  • On-site McLean, VA
  • Must be DoD 8140 / 8570.01-M compliant

Nice To Haves

  • CISSP strongly preferred

Responsibilities

  • Support the full RMF and Assessment & Authorization (A&A) lifecycle for the workstation secure enclave, including control implementation, assessment, authorization, and continuous monitoring.
  • Maintain a comprehensive body of evidence for FedRAMP/DoW A&A packages and continuous monitoring requirements, including POA&M tracking, reporting, and remediation.
  • Collaborate with security engineers, system administrators, ISSO/ISSM, vendors, and leadership to integrate and validate security controls and align operations with FedRAMP, DoD, and CNSSI 1253 requirements.
  • Identify, assess, and remediate vulnerabilities using Tenable Nessus, Tenable.sc, SCC, STIG tooling, and related security tools; ensure host inventory and scan policies are accurate and complete.
  • Review scan results, STIG findings, and patching activities to ensure accurate, actionable data and effective hardening of operating systems, network devices, and applications.
  • Evaluate system designs, network architectures, firewall rules, and PPSM submissions to ensure security principles are integrated from the outset and architecture risks are addressed.
  • Lead preparation and execution of security control audits and FedRAMP 3PAO assessments, reviewing artifacts, logs, and configurations to validate evidence of compliance and a strong security posture.
  • Provide security control assessment and audit oversight, including reviewing and validating implementation work performed by engineers and system administrators.
  • Manage a robust continuous monitoring and GRC program, aggregating and analyzing security data to identify trends, anomalies, and potential incidents and providing actionable risk insights to leadership.
  • Support risk assessments and incident response, recommending mitigating controls and assisting the ISSM and incident response team with artifacts and deep system/security expertise.

Benefits

  • Comprehensive benefits and wellness packages
  • 401K with company match
  • Competitive pay
  • Paid time off
  • Full flex work weeks where possible
  • Variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave
  • Short and long-term disability benefits
  • Life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service