Cyber Compliance Officer
General Dynamics - IT
Job Description
Cyber Compliance Officer - Secret Clearance Required We are GDIT. We stay at the forefront of innovation to solve complex technical challenges. GDIT is your place—make it your own by discovering new ways to apply the latest technologies securely and expertly.
Our work depends on a Cyber Compliance Officer joining our team to support the Guard Enterprise Cyber Operations Support (GECOS) program in Falls Church, VA. This is an IT Service Management (ITSM) contract supporting the operation, modernization, expansion, and evolution of the Army National Guard’s (ARNG) global IT services, including networking, compute, storage, infrastructure, applications, hosting, and program management. The GECOS program supports the ARNG enterprise IT infrastructure, its WAN, authentication and directory services, cybersecurity, application hosting, and associated services, leveraging ITIL best practices.
As a Cyber Compliance Officer, you will provide cybersecurity compliance support in accordance with applicable DoW and Army guidance and regulations. You will work closely with the client and senior staff, so clear, articulate communication is essential. You must be collaborative and able to work within a team, while also being a self-starter who can complete tasks independently and explain complex technical information in an easily understood manner.
Responsibilities The Cyber Compliance Officer will:Provide Risk Management Framework (RMF) support to the 54 supported organizations (50 states, three territories, and the District of Columbia) for Installation Campus Area Networks (ICANs) and HQ Enterprise investments, including eMASS record reviews.Serve as an RMF SME to the 54, delivering customer training and briefs, managing multiple states simultaneously, and briefing the Program Information System Security Manager (P-ISSM) on progress, hurdles, and roadblocks.Provide RMF support for Steps 0–3, 5, and 6:Step 0: Deliver RMF roles and responsibilities training.Step 1: Guide system/ICAN categorization.Step 2: Guide security control baseline selection.Step 3: Advise on security control implementation and delegation of technology areas in eMASS.Step 5: Support submission of ATO package artifacts to the Authorizing Official.Step 6: Support continuous monitoring (ConMon) strategies and execution.Identify and maintain cybersecurity compliance requirements for IT investments of the 54 and the DoWIN-A(NG) and DoWIN-A(NG)-S networks and computing services.Ensure adherence to DoW, DISA, and Department of the Army enterprise security requirements, including preparation for and successful completion of CCRIs, obtaining and maintaining Authority to Connect (ATC) and Authority to Operate (ATO), and compliance with STIGs and required IA controls.Help ensure compliance with Army directives and mandates aligned with the future Joint Information Environment (JIE) architecture.Measure ARNG compliance with cybersecurity requirements and recommend program execution activities, processes, and practices.Assist with secure configuration and preparation of IT below the system level (Software Assurance) across the 54 in coordination with RCC-NG, in accordance with applicable guidance prior to acceptance into or connection to Army IS and DoWIN-A(NG).Maintain an Accreditations and Expiration Dates Record for upcoming accreditation expirations using RMF Work Management SharePoint tracking tools.Ensure cybersecurity inspections, tests, assessments, and reviews are synchronized and coordinated with all stakeholders.Assist in the implementation, management, and administration of organizational structure and workflow within eMASS.Review cybersecurity information papers and plans with CYBERCOM, ARCYBER, Air National Guard Cyber, NSA, FBI, DOJ, and DHS.Support enforcement of the DoW Cyberspace Workforce Framework (DCWF) and cybersecurity certification program to ensure training and certification are enforced, managed, and reported.Help implement a streamlined process for reviewing, processing, and approving eMASS system access requests in support of RMF.Assist in examining security architectures and vulnerabilities through scans, configuration reviews, design documentation, and stakeholder interviews.Support identification, dissemination, and delivery of approved policy and process documentation for system authorization efforts using DoW, Army, and NIST guidance. Qualifications Education / TrainingBachelor’s degree in cybersecurity, information assurance, computer science, or related technical discipline; or equivalent combination of education, technical certifications/training, and work experience. Experience4–6 years of experience in cybersecurity, information assurance, or computer science.Hands-on RMF experience across Steps 0–6 is required.
Technical & Professional SkillsStrong problem-solving, analytical, and decision-making skills.Ability to understand user requirements, troubleshoot technical issues, and develop creative process improvements.Demonstrated dependability: punctual, follows instructions, responds to direction, and seeks feedback.Customer service experience and comfort engaging with senior military and government leadership.Ability to clearly present ideas through briefings, meetings, and interaction with leadership of varied technical backgrounds.Ability to deliver training sessions and engage stakeholders to ensure task progress and adherence to timelines.Excellent communication and documentation skills.Strong organizational, collaborative, and teamwork skills.Ability to rapidly assimilate new information and self-study emerging requirements.Current industry knowledge of relevant concepts, practices, and procedures.Ability to work under time constraints and adapt to changing requirements and new projects.Commitment to maintaining and upgrading certifications.Other duties as assigned. CertificationsMust meet DoW 8570 IAM-I (e.G., Security+ CE); certification must be current and included with resume.Must obtain an additional certification within one year (e.G., CGRC, CISM, CISSP or CISSP Associate). ClearanceActive Secret clearance required at time of interview and must be maintained.
Work Location & ScheduleLocation: Falls Church, VAHours and days TBD upon hire; occasional schedule adjustments may be required.On-site support required for the first 3 months. Pending performance, part-time telework may be considered (3 days onsite, up to 2 days remote per week). The government may require full-time onsite work.
TravelUp to 10% travel.May include up to two conferences annually and site visits to the 54 up to eight times annually. GDIT IS YOUR PLACEAt GDIT, the mission is our purpose, and our people are at the center of everything we do.● Growth: AI-powered career tool that identifies career steps and learning opportunities● Support: An internal mobility team focused on helping you achieve your career goals● Rewards: Comprehensive benefits and wellness packages, 401K with company match, and competitive pay and paid time off● Community: Award-winning culture of innovation and a military-friendly workplaceOWN YOUR OPPORTUNITYExplore an enterprise IT career at GDIT and you’ll find endless opportunities to grow alongside colleagues who share your desire to drive operations forward. #GDITPriority