Cybersecurity GRC Analyst

Posted 7 Days Ago
Be an Early Applicant
Hiring Remotely in GBR
Remote
Mid level
Artificial Intelligence • Machine Learning • Analytics
The Role
Support federal cybersecurity governance, risk, and compliance activities across the NIST RMF lifecycle. Conduct security control assessments, risk analyses, POA&M reviews, authorization support, and mitigation tracking. Maintain cyber risk registers, dashboards, and FISMA reporting while supporting IRM, SCRM, and TPRM programs. Present technical findings and recommendations to technical and non-technical stakeholders, using Power BI and automation tools to improve compliance reporting and risk visibility.
Summary Generated by Built In
Description

Dragonfli Group is a cybersecurity and IT consulting firm providing services to federal agencies and Fortune 100 enterprises. Headquartered in Washington, DC, Dragonfli supports clients in securing mission-critical systems across on-site, hybrid, and fully remote environments.

Dragonfli Group is seeking a Cyber Governance and Compliance Specialist to support a multi-year cybersecurity program for a large federal agency. You will tell the organization whether its information systems are operating at an acceptable level of risk, and you will back that judgment with evidence: risk trade-off analyses, risk mitigation strategies, POA&M review, and comprehensive assessments of risk posture. You will provide the technical analysis that supports authorization decisions across the full risk management lifecycle, from categorizing a system through selecting, implementing, and assessing its controls. This is a versatile, stakeholder-facing role. You will present findings and recommendations to both technical and non-technical decision makers and advise them on designs, implementations, and solutions that protect against cybersecurity attacks. It suits an assessment and authorization practitioner with at least 4+ years of cyber governance and compliance experience who is as comfortable in a briefing as in an assessment.

This is a multi-year contract position involving a large US federal agency. Candidates with previous federal contracting experience are preferred. U.S. Citizenship or Permanent Residency is required. If hired, all work related to this role must be performed within the continental U.S.

This position is fully remote.

Responsibilities

  • Provide information on whether information systems are operating at an acceptable level of risk to the organization
  • Support information system authorization decisions with technical analysis and supporting evidence
  • Perform risk trade-off analyses and develop risk mitigation strategies and solutions
  • Review information system Plans of Action and Milestones (POA&Ms) and track remediation
  • Support cybersecurity risk management activities including categorizing a system, selecting security controls, implementing security controls, and providing comprehensive assessments of the organization’s risk posture
  • Execute Security Control Assessments in accordance with NIST SP 800-37 and NIST SP 800-53A
  • Prepare and deliver briefings of assessment results and recommendations supporting an authorization decision
  • Support implementation and maintenance of Integrated Risk Management (IRM) processes
  • Support the agency’s Supply Chain Risk Management (SCRM) and Third-Party Risk Management (TPRM) programs
  • Maintain the Cyber Risk Register and track cybersecurity regulations, guidance, and data calls
  • Support FISMA score and maturity improvements, and normalize and translate cyber risks to support enterprise-wide risk visibility
  • Develop and maintain cybersecurity dashboards aligned with key performance metrics (hosted on Power BI)
  • Apply automation and AI tooling to streamline risk reporting, compliance tracking, performance analysis, and regulatory monitoring
Requirements

Must-Have

  • Bachelor’s degree in cybersecurity, information technology, or a related field
  • 4 or more years of cyber governance, risk, and compliance experience
  • Assessment and Authorization (RMF) subject matter expertise, including hands-on experience testing and assessing cybersecurity solutions
  • Demonstrated experience performing risk trade-off analyses and developing risk mitigation strategies
  • Experience reviewing POA&Ms and supporting authorization decisions
  • Experience presenting to clients or other decision makers, adapting the message to technical and non-technical audiences
  • Ability to work independently and as a member of a team
  • U.S. Citizenship or Permanent Residency, with all work performed within the continental U.S.
  • Ability to pass a federal agency suitability or background investigation

Preferred / Nice-to-Have

  • Prior federal contracting experience supporting a civilian agency governance or compliance program
  • Experience with Integrated Risk Management, Supply Chain Risk Management, or Third-Party Risk Management programs
  • Experience supporting FISMA reporting and maturity improvement
  • Experience building or maintaining cybersecurity dashboards and KPI reporting
  • Experience with JCAM, the agency’s GRC platform of record (formerly known as CSAM)
  • Familiarity with automation, low-code/no-code, or AI-assisted compliance tooling
  • Certifications such as CGRC (formerly CAP), CISA, CRISC, CISM, or CISSP
Skill(s)

Technical Skills

  • Assessment and Authorization (RMF) subject matter expertise under NIST SP 800-37
  • Security control assessment and testing under NIST SP 800-53A
  • Risk trade-off analysis and risk mitigation strategy development
  • POA&M review, tracking, and remediation oversight
  • Integrated Risk Management, SCRM, and TPRM program support
  • Cyber risk register maintenance and regulatory and data call tracking
  • FISMA reporting and maturity improvement
  • Cybersecurity dashboard and KPI development (Power BI)
  • Automation and AI-assisted compliance tracking and reporting

Soft Skills

  • Clear written and verbal communication with both technical and non-technical audiences
  • Ability to work independently and as a contributing member of a distributed team
  • Comfort operating in a fully remote setting with a camera-on meeting culture
  • Sound judgment about when to decide and when to escalate
  • Collaborative posture with system owners, business owners, developers, and assessors
  • Attention to documentation quality and follow-through on commitments
Benefits

Dragonfli Group offers a comprehensive benefits package that includes:

  • Medical: Multiple POS health plan options including an HSA-compatible plan
  • Dental: PPO coverage for preventive, basic, and major services
  • Vision: Annual exam, frames, lenses, and contact lens allowance
  • 401(k): Employer match up to 5% of eligible compensation
  • Long-Term Disability: 100% employer-paid coverage at 50% of pre-disability earnings
  • Life Insurance & AD&D: 100% employer-paid coverage valued at $10,000 each
  • PTO: 15-25 days annually based on tenure
  • Paid Federal Holidays: All 11 federal holidays observed

Skills Required

  • Bachelor's degree in cybersecurity, information technology, or a related field
  • 4 or more years of cyber governance, risk, and compliance experience
  • Assessment and Authorization subject matter expertise, including hands-on cybersecurity solution testing and assessment
  • Experience performing risk trade-off analyses and developing risk mitigation strategies
  • Experience reviewing POA&Ms and supporting authorization decisions
  • Experience presenting to clients or decision makers and adapting communication for technical and non-technical audiences
  • Ability to work independently and as a team member
  • U.S. Citizenship or Permanent Residency
  • Ability to perform all work within the continental United States
  • Ability to pass a federal agency suitability or background investigation
  • Prior federal contracting experience supporting a civilian agency governance or compliance program
  • Experience with Integrated Risk Management, Supply Chain Risk Management, or Third-Party Risk Management programs
  • Experience supporting FISMA reporting and maturity improvement
  • Experience building or maintaining cybersecurity dashboards and KPI reporting
  • Experience with JCAM, formerly known as CSAM
  • Familiarity with automation, low-code/no-code, or AI-assisted compliance tooling
  • CGRC, CISA, CRISC, CISM, or CISSP certification
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: London
35 Employees
Year Founded: 2018

What We Do

Dragonfly AI uses a biologically driven AI to predict attention on visual assets. Across all channels and environments, the platform can be integrated with workflows to validate decision-making with data for creative that has a higher impact and performs better. Particularly relevant for CPG and FMCG brands but can be integrated with any creative process for a new layer of data insights to support teams in optimizing creative specifically for attention

Similar Jobs

Dragonfly AI Logo Dragonfly AI

Junior Cybersecurity GRC Analyst

Artificial Intelligence • Machine Learning • Analytics
Remote
GBR
35 Employees

SailPoint Logo SailPoint

Forward Deployed Engineer

Artificial Intelligence • Cloud • Sales • Security • Software • Cybersecurity • Data Privacy
Remote or Hybrid
United Kingdom
2461 Employees
106K-179K Annually

Tapestry - Coach and Kate Spade Logo Tapestry - Coach and Kate Spade

Sales Associate

eCommerce • Fashion • Retail • Sales • Wearables • Design
Remote or Hybrid
Wirral, England, GBR
16000 Employees
26K-28K Annually

Skillsoft Logo Skillsoft

EMEA Market Solutions Director

Artificial Intelligence • Consumer Web • Edtech • HR Tech • Information Technology • Software • Conversational AI
Remote
United Kingdom
2900 Employees

Similar Companies Hiring

Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Blee Thumbnail
Artificial Intelligence • Marketing Tech • Software
New York, New York
30 Employees
Vega Thumbnail
Artificial Intelligence • Automotive • Insurance • Transportation
US
43 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account