Dragonfli Group logo
Dragonfli Group
Posted 18 days agoVerified live 2d ago

Cybersecurity GRC Analyst

Brief overview

Remote
UndergradOr in progress
4+ yrsMinimum
Assessment and Authorization (RMF)NIST SP 800-37NIST SP 800-53ASecurity Control Assessment and TestingRisk Trade-off AnalysisRisk Mitigation StrategiesPOA&M Review and Remediation TrackingIntegrated Risk ManagementSupply Chain Risk ManagementThird-Party Risk ManagementFISMA ReportingPower BI

About the company

Dragonfli Group logo
Dragonfli Groupdragonfligroup.com

The Dragonfli Group is a Washington, DC based LLC specializing in management and technology consulting.

Job description

Summary

Dragonfli Group is a cybersecurity and IT consulting firm serving federal agencies and Fortune 100 enterprises. The Cybersecurity GRC Analyst supports a federal cybersecurity program by conducting risk assessments, analyzing security controls, supporting authorization decisions, tracking remediation, and presenting findings to technical and non-technical stakeholders.

Responsibilities

  • Provide information on whether information systems are operating at an acceptable level of risk to the organization
  • Support information system authorization decisions with technical analysis and supporting evidence
  • Perform risk trade-off analyses and develop risk mitigation strategies and solutions
  • Review information system Plans of Action and Milestones (POA&Ms) and track remediation
  • Support cybersecurity risk management activities including categorizing a system, selecting security controls, implementing security controls, and providing comprehensive assessments of the organization’s risk posture
  • Execute Security Control Assessments in accordance with NIST SP 800-37 and NIST SP 800-53A
  • Prepare and deliver briefings of assessment results and recommendations supporting an authorization decision
  • Support implementation and maintenance of Integrated Risk Management (IRM) processes
  • Support the agency’s Supply Chain Risk Management (SCRM) and Third-Party Risk Management (TPRM) programs
  • Maintain the Cyber Risk Register and track cybersecurity regulations, guidance, and data calls
  • Support FISMA score and maturity improvements, and normalize and translate cyber risks to support enterprise-wide risk visibility
  • Develop and maintain cybersecurity dashboards aligned with key performance metrics (hosted on Power BI)
  • Apply automation and AI tooling to streamline risk reporting, compliance tracking, performance analysis, and regulatory monitoring

Skills

  • Bachelor's degree in cybersecurity, information technology, or a related field
  • 4 or more years of cyber governance, risk, and compliance experience
  • Assessment and Authorization (RMF) subject matter expertise, including hands-on experience testing and assessing cybersecurity solutions
  • Demonstrated experience performing risk trade-off analyses and developing risk mitigation strategies
  • Experience reviewing POA&Ms and supporting authorization decisions
  • Experience presenting to clients or other decision makers, adapting the message to technical and non-technical audiences
  • Ability to work independently and as a member of a team
  • U.S. Citizenship or Permanent Residency, with all work performed within the continental U.S
  • Ability to pass a federal agency suitability or background investigation
  • Assessment and Authorization (RMF) subject matter expertise under NIST SP 800-37
  • Security control assessment and testing under NIST SP 800-53A
  • Risk trade-off analysis and risk mitigation strategy development
  • POA&M review, tracking, and remediation oversight
  • Integrated Risk Management, SCRM, and TPRM program support
  • Cyber risk register maintenance and regulatory and data call tracking
  • FISMA reporting and maturity improvement
  • Cybersecurity dashboard and KPI development (Power BI)
  • Automation and AI-assisted compliance tracking and reporting
  • Clear written and verbal communication with both technical and non-technical audiences
  • Ability to work independently and as a contributing member of a distributed team
  • Comfort operating in a fully remote setting with a camera-on meeting culture
  • Sound judgment about when to decide and when to escalate
  • Collaborative posture with system owners, business owners, developers, and assessors
  • Attention to documentation quality and follow-through on commitments
  • Prior federal contracting experience supporting a civilian agency governance or compliance program
  • Experience with Integrated Risk Management, Supply Chain Risk Management, or Third-Party Risk Management programs
  • Experience supporting FISMA reporting and maturity improvement
  • Experience building or maintaining cybersecurity dashboards and KPI reporting
  • Experience with JCAM, the agency's GRC platform of record (formerly known as CSAM)
  • Familiarity with automation, low-code/no-code, or AI-assisted compliance tooling
  • Certifications such as CGRC (formerly CAP), CISA, CRISC, CISM, or CISSP

Qualifications

Must Haves

  • Bachelor's degree in cybersecurity, information technology, or a related field
  • 4 or more years of cyber governance, risk, and compliance experience
  • Assessment and Authorization (RMF) subject matter expertise, including hands-on experience testing and assessing cybersecurity solutions
  • Demonstrated experience performing risk trade-off analyses and developing risk mitigation strategies
  • Experience reviewing POA&Ms and supporting authorization decisions
  • Experience presenting to clients or other decision makers, adapting the message to technical and non-technical audiences
  • Ability to work independently and as a member of a team
  • U.S. Citizenship or Permanent Residency, with all work performed within the continental U.S
  • Ability to pass a federal agency suitability or background investigation
  • Assessment and Authorization (RMF) subject matter expertise under NIST SP 800-37
  • Security control assessment and testing under NIST SP 800-53A
  • Risk trade-off analysis and risk mitigation strategy development
  • POA&M review, tracking, and remediation oversight
  • Integrated Risk Management, SCRM, and TPRM program support
  • Cyber risk register maintenance and regulatory and data call tracking
  • FISMA reporting and maturity improvement
  • Cybersecurity dashboard and KPI development (Power BI)
  • Automation and AI-assisted compliance tracking and reporting
  • Clear written and verbal communication with both technical and non-technical audiences
  • Ability to work independently and as a contributing member of a distributed team
  • Comfort operating in a fully remote setting with a camera-on meeting culture
  • Sound judgment about when to decide and when to escalate
  • Collaborative posture with system owners, business owners, developers, and assessors
  • Attention to documentation quality and follow-through on commitments

Nice to Haves

  • Prior federal contracting experience supporting a civilian agency governance or compliance program
  • Experience with Integrated Risk Management, Supply Chain Risk Management, or Third-Party Risk Management programs
  • Experience supporting FISMA reporting and maturity improvement
  • Experience building or maintaining cybersecurity dashboards and KPI reporting
  • Experience with JCAM, the agency's GRC platform of record (formerly known as CSAM)
  • Familiarity with automation, low-code/no-code, or AI-assisted compliance tooling
  • Certifications such as CGRC (formerly CAP), CISA, CRISC, CISM, or CISSP

Benefits

  • Medical: Multiple POS health plan options including an HSA-compatible plan
  • Dental: PPO coverage for preventive, basic, and major services
  • Vision: Annual exam, frames, lenses, and contact lens allowance
  • 401(k): Employer match up to 5% of eligible compensation
  • Long-Term Disability: 100% employer-paid coverage at 50% of pre-disability earnings
  • Life Insurance & AD&D: 100% employer-paid coverage valued at $10,000 each
  • PTO: 15-25 days annually based on tenure
  • Paid Federal Holidays: All 11 federal holidays observed
  • This position is fully remote.

More jobs like this