GD
Posted 1w ago

Cybersecurity Analyst (Risk Management Framework) – TS/SCI w/ Polygraph

General Dynamics Information Technology
Annapolis Junction or Sterling
$128k-$173k/yrOnsiteFull Time
Responsibilities
  • acting ISSO
  • authoring documentation
  • conducting assessments
Requirements
  • Active TS/SCI with Polygraph
  • 6+ years related experience
  • 3+ years IC RMF A&A experience
  • Bachelor’s in technical field or equivalent
  • DoD 8570 IAT Level II cert (e.g
  • Security+ CE) and 1+ year Xacta experience
Technical tools mentioned
Xacta

Job description

Type of Requisition:

Regular

Clearance Level Must Currently Possess:

Top Secret/SCI

Clearance Level Must Be Able to Obtain:

Top Secret SCI + Polygraph

Public Trust/Other Required:

None

Job Family:

Cyber and IT Risk Management

Job Qualifications:

Skills:

Information Assurance, Information Systems, Information Technology (IT)

Certifications:

None

Experience:

6 + years of related experience

US Citizenship Required:

Yes

Job Description:

GDIT is your place.  Make it your own by discovering new ways to apply the latest technologies securely and expertly.  By owning your opportunity at GDIT, you’ll become a critical part in how we successfully solve our clients’ biggest challenges and deliver on promise.  Our work depends on a Cybersecurity Analyst joining our team to support Government activities in Sterling, V.A. or Annapolis Junction, M.D.

At GDIT, we foster a people-focused and customer-centric environment in delivering Engineering Support Services.  As a Cybersecurity Analyst supporting the Government, you will be trusted with ensuring our IT engineering solutions meet the highest security standards, that they adhere to all applicable standards, guidelines, and mandates; and that all appropriate documentation to make up a Body of Evidence (BoE) is provided to the Government.

In this role, a typical day may include:

  • Acting as an appointed Information System Security Officer (ISSO) for IC cyber systems being developed by the engineering team
  • Reporting, documenting, and briefing the status of systems under development, while assuring their successful and timely progression through the clients’ Risk Management Framework (RMF) to the satisfaction of the appointed Information System Security Manager (ISSM), and/or Senior Government leadership
  • Providing clear justification satisfying all applicable security control implementation as specified by the IC, AO, or NIST-800-53, rev 4 rev 5
  • Authoring System Security Plans (SSP) and System Security Test Plans (SSTP)
  • Conducting self-assessments of all systems under development
  • Analyzing security controls and the impacts the changes would have on the environment
  • Preparing for and assisting with formal risk assessments conducted by the AO’s designated Security Control Assessors (SCA) while acting as a member of the security assessment test team
  • Ensuring the remediation of any findings assigned to engineering as documented in the Security Assessment Report (SAR) and its Plan of Actions and Milestones (PO&AM)
  • Documenting and defending reasoning when waivers are sought, or non-standard remediation solutions are requested for specific security controls
  • Assisting with the transition of systems granted an ATO to the Operations branch and the assignment of an operations ISSO
  • Researching remediation options for vulnerabilities identified for systems under development or already in production under an ATO

What you’ll need:

  • Active TS/SCI with Polygraph
  • Must meet DoD 8570 IAT Level II requirements including one of the following: Security+ CE, CND, SSCP, GSEC, GICSP, CySA+, or CCNA Security
  • Bachelor’s Degree in a related technical discipline +6 years’ experience or the equivalent combination of education, technical certification or training, or work/military experience
  • Minimum of 3-years IC (SCI) RMF Assessment and Authorization (A&A) experience and the ability to describe the differences between collateral and SCI authorization requirements as they apply to DoW and IC instructions and guidelines
  • Ability to speak to the intent of all NIST 800-53 security controls
  • Minimum 1-year hands on experience with the Xacta application
  • Excellent oral and technical writing skills
  • Ability to work both independently and as a member of a team


GDIT IS YOUR PLACE
At GDIT, the mission is our purpose, and our people are at the center of everything we do.
● Growth: AI-powered career tool that identifies career steps and learning opportunities
● Support: An internal mobility team focused on helping you achieve your career goals
● Rewards: Comprehensive benefits and wellness packages, 401K with company match, and competitive pay and paid time off
● Community: Award-winning culture of innovation and a military-friendly workplace

OWN YOUR OPPORTUNITY
Explore a career in cyber at GDIT and you’ll find endless opportunities to grow alongside colleagues who share your focus on defending and protecting what matters.

#VA_2026Alumni

#MD_2026Alumni

#JET

#GDITCareers

#WeAreGDIT

The likely salary range for this position is $127,500 - $172,500. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.

Scheduled Weekly Hours:

40

Travel Required:

None

Telecommuting Options:

Onsite

Work Location:

USA MD Annapolis Junction

Additional Work Locations:

USA VA Sterling

Total Rewards at GDIT:

Our benefits package for all US-based employees includes a variety of medical plan options, some with Health Savings Accounts, dental plan options, a vision plan, and a 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match. To encourage work/life balance, GDIT offers employees full flex work weeks where possible and a variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave. To ensure our employees are able to protect their income, other offerings such as short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available. We regularly review our Total Rewards package to ensure our offerings are competitive and reflect what our employees have told us they value most.

 

 


Our Identity Verification Process:

As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during virtual interviews. We reserve the right to take your picture to verify your identity and prevent fraud. By proceeding, you authorize the collection, processing, and use of your biometric data for identity verification and security purposes.

 

 

About Our Work:

We are GDIT. A global technology and professional services company that delivers technology solutions and mission services to every major agency across the U.S. government, defense and intelligence community. Our 26,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. We operate across 50+ countries worldwide, offering leading mission-ready capabilities in AI, cloud, cyber and software development.

Join our Talent Community to stay up to date on our career opportunities and events at

gdit.com/tc.

Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans

About General Dynamics Information Technology

Provides mission-critical IT services to government and defense organizations.

Organization type
Public

Similar jobs

Cybersecurity Analyst roles near Annapolis Junction, Maryland
12h
Save
Mark Applied
Hide
Associate Cybersecurity Analyst I
Fulton, Maryland, United States
OnsiteFull Time
Tharros
Tharros: Provides specialized cybersecurity defense and vulnerability research services.
1.5+ YOERequires active TS/SCI clearance, IAT Level I, and either a bachelor's degree in a relevant technical field with 18 months' experience or a high school diploma with 4 years' experience.
ACAS, DISA STIGs, SRGs, Enterprise Mission Assurance Support Service (eMASS), POA&M, RMF
3d
Save
Mark Applied
Hide
Cybersecurity Analyst 1
Rockville, Maryland, United States
$45k-$55k/yr RemoteFull Time
Dataprise
Dataprise: Provides managed IT, cybersecurity, and cloud infrastructure services.
Cybersecurity monitoring and incident response experience with SIEM, cloud, endpoint, Windows Server, networking, documentation, customer communication, and troubleshooting skills. Security certifications are highly desired.
SIEM, Azure Sentinel, Splunk, Elastic, QRadar, CrowdStrike, Azure, Amazon Web Services (AWS), Microsoft 365, Windows Server, Active Directory Domain Services (ADDS), DNS, DHCP, DFS, PowerShell, Kaseya VSA, Auvik, ITIL, COBIT, MOF
5d
Save
Mark Applied
Hide
Sr Principal Classified Cybersecurity Analyst - TS/SCI
Dulles, Virginia, United States
$142k-$213k/yr OnsiteFull Time
Northrop Grumman
Northrop GrummanNYSE: NOC: Develops and manufactures advanced aerospace, defense, and space systems.
6+ YOE6–12 years of relevant technical experience based on education; IAM Level III certification, current U.S. Government Top Secret clearance with SCI eligibility, and ability to obtain SAP access required.
ACAS, Nessus, Splunk, Trellix, SCAP, NIST, JSIG, DAAG, System Security Plan (SSP), Plan of Action and Milestones (POA&M), Security Controls Traceability Matrix (SCTM), Risk Management Framework (RMF)
6d
Save
Mark Applied
Hide
Cybersecurity Analyst
Arlington, Virginia, United States
$130k-$155k/yr OnsiteFull Time
Venture Global LNG
Venture Global LNGNYSE: VG: Develops and operates liquefied natural gas export facilities.
10+ YOEBachelor's degree or equivalent experience; 10+ years in cybersecurity, information security engineering, or security architecture; cloud, multi-cloud, risk assessment, security frameworks, IAM, cryptography, and DevSecOps expertise.
Azure, AWS, NIST 800-53, FISMA, FedRAMP, ISO 27000, SAML, OAuth, OIDC, Multi-Factor Authentication, DevSecOps
1w
Save
Mark Applied
Hide
Cybersecurity Analyst (ISSO)
Silver Spring, Maryland, United States
$140k/yr HybridFull Time
ActioNet
ActioNet: Provides IT modernization and cybersecurity services for government agencies.
4+ YOEBachelor's or associate degree in Information Assurance or InfoSec plus 4 years' experience; IAT Level II or approved certification, Public Trust clearance, RMF, vulnerability analysis, STIG, networking, Windows, and Linux knowledge.
NIST Risk Management Framework (RMF), Tenable, BigFix, CSAM, eMASS, Defense Information Systems Agency (DISA), Security Technical Implementation Guide (STIG), Windows, Linux, Rapid7 InsightVM, ACAS, SCAP Compliance Checker
1w
Save
Mark Applied
Hide
Senior Cybersecurity Analyst
Fort Meade, Maryland, United States
$105k-$115k/yr OnsiteFull Time
Chickasaw Nation Industries
Chickasaw Nation Industries: Provides federal contracting, engineering, and technology services.
5+ YOEBachelor's degree in computer science or related field, 5+ years of relevant experience, DoD 8570 IAM/IA Technical IAT Level II certification, U.S. citizenship, and ability to obtain Top Secret/SCI access.
Risk Management Framework (RMF), eMASS, ACAS, IAVM, NIST SP 800-53, CNSSI 1253, Linux, Windows, DevSecOps
1w
Save
Mark Applied
Hide
Enterprise Cybersecurity Analyst
McLean, Virginia, United States
$99k-$225k/yr HybridFull Time
Booz Allen Hamilton
Booz Allen HamiltonNYSE: BAH: Consulting and technology services for government and commercial clients
Cybersecurity operations or security engineering experience, threat detection or incident response, vulnerability assessment support, a bachelor's degree, and U.S. citizenship; cloud and DoD security experience preferred.
CrowdStrike Falcon EDR/AV, Tenable Cloud Security Enterprise, BigID, Security Information and Event Management (SIEM), Security Orchestration, Automation, and Response (SOAR), Python, PowerShell, AWS, Azure, Google Cloud, Risk Management Framework (RMF), NIST 800-53, Defense Federal Acquisition Regulation Supplement (DFARS)
1w
Save
Mark Applied
Hide
Enterprise Cybersecurity Analyst
McLean, Virginia, United States
$99k-$225k/yr OnsiteFull Time
Booz Allen Hamilton
Booz Allen HamiltonNYSE: BAH: Provides technology and management consulting services to diverse organizations.
Cybersecurity operations or security engineering experience, threat detection or incident response, vulnerability assessment, cross-functional collaboration, and a bachelor's degree. U.S. citizenship required.
CrowdStrike Falcon EDR/AV, Tenable Cloud Security Enterprise, BigID, Security Information and Event Management (SIEM), Security Orchestration, Automation, and Response (SOAR), Python, PowerShell, AWS, Azure, Google Cloud, Risk Management Framework (RMF), NIST 800-53, Defense Federal Acquisition Regulation Supplement (DFARS)