Summary
Dragonfli Group is a cybersecurity and IT consulting firm serving federal agencies and Fortune 100 enterprises. The Cybersecurity GRC Analyst supports a federal cybersecurity program by conducting risk assessments, analyzing security controls, supporting authorization decisions, tracking remediation, and presenting findings to technical and non-technical stakeholders.
Responsibilities
- Provide information on whether information systems are operating at an acceptable level of risk to the organization
- Support information system authorization decisions with technical analysis and supporting evidence
- Perform risk trade-off analyses and develop risk mitigation strategies and solutions
- Review information system Plans of Action and Milestones (POA&Ms) and track remediation
- Support cybersecurity risk management activities including categorizing a system, selecting security controls, implementing security controls, and providing comprehensive assessments of the organization’s risk posture
- Execute Security Control Assessments in accordance with NIST SP 800-37 and NIST SP 800-53A
- Prepare and deliver briefings of assessment results and recommendations supporting an authorization decision
- Support implementation and maintenance of Integrated Risk Management (IRM) processes
- Support the agency’s Supply Chain Risk Management (SCRM) and Third-Party Risk Management (TPRM) programs
- Maintain the Cyber Risk Register and track cybersecurity regulations, guidance, and data calls
- Support FISMA score and maturity improvements, and normalize and translate cyber risks to support enterprise-wide risk visibility
- Develop and maintain cybersecurity dashboards aligned with key performance metrics (hosted on Power BI)
- Apply automation and AI tooling to streamline risk reporting, compliance tracking, performance analysis, and regulatory monitoring
Skills
- Bachelor's degree in cybersecurity, information technology, or a related field
- 4 or more years of cyber governance, risk, and compliance experience
- Assessment and Authorization (RMF) subject matter expertise, including hands-on experience testing and assessing cybersecurity solutions
- Demonstrated experience performing risk trade-off analyses and developing risk mitigation strategies
- Experience reviewing POA&Ms and supporting authorization decisions
- Experience presenting to clients or other decision makers, adapting the message to technical and non-technical audiences
- Ability to work independently and as a member of a team
- U.S. Citizenship or Permanent Residency, with all work performed within the continental U.S
- Ability to pass a federal agency suitability or background investigation
- Assessment and Authorization (RMF) subject matter expertise under NIST SP 800-37
- Security control assessment and testing under NIST SP 800-53A
- Risk trade-off analysis and risk mitigation strategy development
- POA&M review, tracking, and remediation oversight
- Integrated Risk Management, SCRM, and TPRM program support
- Cyber risk register maintenance and regulatory and data call tracking
- FISMA reporting and maturity improvement
- Cybersecurity dashboard and KPI development (Power BI)
- Automation and AI-assisted compliance tracking and reporting
- Clear written and verbal communication with both technical and non-technical audiences
- Ability to work independently and as a contributing member of a distributed team
- Comfort operating in a fully remote setting with a camera-on meeting culture
- Sound judgment about when to decide and when to escalate
- Collaborative posture with system owners, business owners, developers, and assessors
- Attention to documentation quality and follow-through on commitments
- Prior federal contracting experience supporting a civilian agency governance or compliance program
- Experience with Integrated Risk Management, Supply Chain Risk Management, or Third-Party Risk Management programs
- Experience supporting FISMA reporting and maturity improvement
- Experience building or maintaining cybersecurity dashboards and KPI reporting
- Experience with JCAM, the agency's GRC platform of record (formerly known as CSAM)
- Familiarity with automation, low-code/no-code, or AI-assisted compliance tooling
- Certifications such as CGRC (formerly CAP), CISA, CRISC, CISM, or CISSP
Qualifications
Must Haves
- Bachelor's degree in cybersecurity, information technology, or a related field
- 4 or more years of cyber governance, risk, and compliance experience
- Assessment and Authorization (RMF) subject matter expertise, including hands-on experience testing and assessing cybersecurity solutions
- Demonstrated experience performing risk trade-off analyses and developing risk mitigation strategies
- Experience reviewing POA&Ms and supporting authorization decisions
- Experience presenting to clients or other decision makers, adapting the message to technical and non-technical audiences
- Ability to work independently and as a member of a team
- U.S. Citizenship or Permanent Residency, with all work performed within the continental U.S
- Ability to pass a federal agency suitability or background investigation
- Assessment and Authorization (RMF) subject matter expertise under NIST SP 800-37
- Security control assessment and testing under NIST SP 800-53A
- Risk trade-off analysis and risk mitigation strategy development
- POA&M review, tracking, and remediation oversight
- Integrated Risk Management, SCRM, and TPRM program support
- Cyber risk register maintenance and regulatory and data call tracking
- FISMA reporting and maturity improvement
- Cybersecurity dashboard and KPI development (Power BI)
- Automation and AI-assisted compliance tracking and reporting
- Clear written and verbal communication with both technical and non-technical audiences
- Ability to work independently and as a contributing member of a distributed team
- Comfort operating in a fully remote setting with a camera-on meeting culture
- Sound judgment about when to decide and when to escalate
- Collaborative posture with system owners, business owners, developers, and assessors
- Attention to documentation quality and follow-through on commitments
Nice to Haves
- Prior federal contracting experience supporting a civilian agency governance or compliance program
- Experience with Integrated Risk Management, Supply Chain Risk Management, or Third-Party Risk Management programs
- Experience supporting FISMA reporting and maturity improvement
- Experience building or maintaining cybersecurity dashboards and KPI reporting
- Experience with JCAM, the agency's GRC platform of record (formerly known as CSAM)
- Familiarity with automation, low-code/no-code, or AI-assisted compliance tooling
- Certifications such as CGRC (formerly CAP), CISA, CRISC, CISM, or CISSP
Benefits
- Medical: Multiple POS health plan options including an HSA-compatible plan
- Dental: PPO coverage for preventive, basic, and major services
- Vision: Annual exam, frames, lenses, and contact lens allowance
- 401(k): Employer match up to 5% of eligible compensation
- Long-Term Disability: 100% employer-paid coverage at 50% of pre-disability earnings
- Life Insurance & AD&D: 100% employer-paid coverage valued at $10,000 each
- PTO: 15-25 days annually based on tenure
- Paid Federal Holidays: All 11 federal holidays observed
- This position is fully remote.