Dragonfli Group logo
Dragonfli Group
Posted 31 days agoVerified live 1d ago

Junior Cybersecurity GRC Analyst

Brief overview

Remote
Risk Management Framework (RMF)NIST SP 800-37NIST SP 800-53NIST SP 800-53AAssessment and Authorization (A&A)Risk Trade-off AnalysisRisk Mitigation StrategiesPOA&M TrackingEvidence CollectionGRC Platforms XactaGRC Platforms eMASSGRC Platforms CSAMGRC Platforms ArcherGRC PlatformsGRC Platforms ServiceNow IRMFISMA ReportingSecurity+ or CGRC Certification

About the company

Dragonfli Group logo
Dragonfli Groupdragonfligroup.com

The Dragonfli Group is a Washington, DC based LLC specializing in management and technology consulting.

Job description

Summary

Dragonfli Group is a cybersecurity and IT consulting firm serving federal agencies and Fortune 100 enterprises. The Junior Cybersecurity GRC Analyst will support a federal cybersecurity program by executing the Risk Management Framework, assessing risk posture, supporting authorization decisions, developing mitigation strategies, and maintaining compliance reporting and tracking.

Responsibilities

  • Support and contribute to the execution of the Risk Management Framework to authorize IT systems
  • Provide information on whether information systems are operating at an acceptable level of risk to the organization
  • Support information system authorization decisions by performing risk trade-off analyses
  • Contribute to the development of risk mitigation strategies and solutions
  • Support technical analysis across cybersecurity risk management activities: categorizing a system, proposing security control selections, implementing security controls, and providing comprehensive assessments of risk posture
  • Support security control assessment activities in accordance with NIST SP 800-37 and NIST SP 800-53A
  • Support presentations and, at times, present to clients and other decision makers across technical and non-technical audiences
  • Support advice to clients on technical designs, implementations, and solutions that protect against cybersecurity attacks
  • Support POA&M tracking, cyber risk register upkeep, and tracking of cybersecurity regulations, guidance, and data calls
  • Support cybersecurity dashboard development and the automation of routine risk reporting and compliance tracking

Skills

  • * Bachelor's degree in cybersecurity, information technology, or a related field
  • * Exposure to Assessment and Authorization (RMF) work, including testing or assessing cybersecurity solutions, through coursework, internship, or professional experience
  • * Working understanding of the Risk Management Framework and the federal authorization process
  • * Strong written and verbal communication skills, including comfort supporting or delivering presentations
  • * Ability to work independently and as a member of a team
  • * U.S. Citizenship or Permanent Residency, with all work performed within the continental U.S
  • * Internship, co-op, or 1 to 2 years of professional experience in a GRC, audit, or compliance role
  • * Familiarity with NIST SP 800-53 control families and evidence expectations
  • * Exposure to a GRC platform such as Xacta, eMASS, CSAM, Archer, or ServiceNow IRM
  • * Exposure to FISMA reporting, SCRM, or TPRM concepts
  • * Interest in or exposure to automation and AI-assisted compliance tooling
  • * Security+ or CGRC (formerly CAP) certification, or active pursuit of one
  • * Risk Management Framework fundamentals under NIST SP 800-37
  • * Security control familiarity under NIST SP 800-53 and assessment basics under 800-53A
  • * Risk trade-off analysis and mitigation strategy support
  • * POA&M tracking and evidence collection
  • * Security documentation and authorization artifact support
  • * Cyber risk register and regulatory tracking support
  • * Dashboard, reporting, and spreadsheet analysis skills
  • * Exposure to automation and AI-assisted compliance tooling
  • * Clear written and verbal communication with both technical and non-technical audiences
  • * Ability to work independently and as a contributing member of a distributed team
  • * Comfort operating in a fully remote setting with a camera-on meeting culture
  • * Sound judgment about when to decide and when to escalate
  • * Collaborative posture with system owners, business owners, developers, and assessors
  • * Attention to documentation quality and follow-through on commitments
  • Candidates with previous federal contracting experience are preferred

Qualifications

Must Haves

  • * Bachelor's degree in cybersecurity, information technology, or a related field
  • * Exposure to Assessment and Authorization (RMF) work, including testing or assessing cybersecurity solutions, through coursework, internship, or professional experience
  • * Working understanding of the Risk Management Framework and the federal authorization process
  • * Strong written and verbal communication skills, including comfort supporting or delivering presentations
  • * Ability to work independently and as a member of a team
  • * U.S. Citizenship or Permanent Residency, with all work performed within the continental U.S
  • * Internship, co-op, or 1 to 2 years of professional experience in a GRC, audit, or compliance role
  • * Familiarity with NIST SP 800-53 control families and evidence expectations
  • * Exposure to a GRC platform such as Xacta, eMASS, CSAM, Archer, or ServiceNow IRM
  • * Exposure to FISMA reporting, SCRM, or TPRM concepts
  • * Interest in or exposure to automation and AI-assisted compliance tooling
  • * Security+ or CGRC (formerly CAP) certification, or active pursuit of one
  • * Risk Management Framework fundamentals under NIST SP 800-37
  • * Security control familiarity under NIST SP 800-53 and assessment basics under 800-53A
  • * Risk trade-off analysis and mitigation strategy support
  • * POA&M tracking and evidence collection
  • * Security documentation and authorization artifact support
  • * Cyber risk register and regulatory tracking support
  • * Dashboard, reporting, and spreadsheet analysis skills
  • * Exposure to automation and AI-assisted compliance tooling
  • * Clear written and verbal communication with both technical and non-technical audiences
  • * Ability to work independently and as a contributing member of a distributed team
  • * Comfort operating in a fully remote setting with a camera-on meeting culture
  • * Sound judgment about when to decide and when to escalate
  • * Collaborative posture with system owners, business owners, developers, and assessors
  • * Attention to documentation quality and follow-through on commitments

Nice to Haves

  • Candidates with previous federal contracting experience are preferred

Benefits

  • Medical: Multiple POS health plan options including an HSA-compatible plan
  • Dental: PPO coverage for preventive, basic, and major services
  • Vision: Annual exam, frames, lenses, and contact lens allowance
  • 401(k): Employer match up to 5% of eligible compensation
  • Long-Term Disability: 100% employer-paid coverage at 50% of pre-disability earnings
  • Life Insurance & AD&D: 100% employer-paid coverage valued at $10,000 each
  • PTO: 15–25 days annually based on tenure
  • Paid Federal Holidays: All 11 federal holidays observed
  • Fully remote work arrangement

More jobs like this