> Markdown version of [/jobs/ext/1010795-continuous-monitoring-analyst](https://www.wearedevelopers.com/jobs/ext/1010795-continuous-monitoring-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Continuous Monitoring Analyst - **Company:** Booz Allen Hamilton Holding Corporation - **Location:** Rockville, MD, United States - **Experience:** Experienced - **Salary:** $62,000.0 - $141,000.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Amazon Web Services, Microsoft Azure, Cloud Computing Security, Cyber Security, Information Systems, Continuous Integration, DevOps, Identity and Access Management, Ansible, Zero Trust Network Access, Curam Configuration Tools, Okta, Git, Kubernetes, Terraform, Splunk, SentinelOne Expertise, Docker, Security Orchestration, Automation & Response, Servicenow - **Published:** June 5, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=c278e4c2cb911737 ## About the Role Do you have experience in Vuls?, Do you have a Bachelor's degree?, * 3+ years experience with Continuous Monitoring, ongoing authorization, or cybersecurity * Experience with monitoring and assessing NIST SP 800-53 controls, including collecting and evaluating control evidence generated from Splunk, Cribl, SentinelOne, or Elastic * Experience with supporting continuous ATO and ongoing authorization processes using data from Tenable, Prisma, Git, JFrog, AWS Security Hub, Azure Security Tower, or Google SCC vulnerability and configuration tools * Experience with reviewing POA&Ms, validating remediation evidence, and tracking corrective actions through ServiceNow or JCAM * Experience with analyzing system changes, configuration updates, or architectural modifications for security impact across cloud or hybrid environments * Experience with security automation or orchestration workflows using Kubernetes, Docker, Terraform, or Ansible, and identifying or interpreting AI-generated findings using Gemini, Copilot, Claude, or Bedrock * Knowledge of enterprise IAM and access control concepts supported by Entra ID, Okta, AWS IAM, or Microsoft Conditional Access tools * Ability to evaluate control effectiveness, synthesize evidence from multiple security tools, and communicate risk posture to technical and non-technical stakeholders * Public Trust * Bachelor's degree Nice If You Have: * Experience with cross-functional collaboration with ISSOs, system owners, or engineering teams to support RMF lifecycle activities * Experience with process improvement, workflow standardization, or automation of continuous monitoring or ATO processes * Experience with dashboards, reporting, or enterprise governance tools that aggregate security telemetry * Experience with stakeholder engagement, team coordination, or agile delivery support * Knowledge of Zero Trust principles, cloud security governance, or enterprise modernization initiatives * Knowledge of secure DevOps practices, CI/CD workflows, or automated compliance pipelines * Ability to clearly communicate complex compliance, risk, or control concepts in actionable terms * Ability to adapt quickly to evolving federal guidance, emerging technologies, or shifting program priorities * Master's degree in Cybersecurity, Information Systems, or related field * CISSP, Security+, or AWS, GCP, or Azure cloud certifications Vetting: Applicants selected will be subject to a government investigation and may need to meet eligibility requirements of the U.S. government client; Public Trust determination is required. ## Description Serve as a Continuous Monitoring Analyst responsible for supporting an enterprise-wide ongoing authorization program, ensuring systems maintain their Authority to Operate (ATO)/Continuous Authority to Operate (cATO) through continuous monitoring of security controls, evidence collection, risk tracking, and reporting. You will assess control effectiveness, validate system changes, support remediation activities, and help modernize continuous monitoring processes across hybrid and cloud environments. This position strengthens the organization's risk posture by enabling consistent, automated, and compliance-aligned security oversight. ## Related Videos - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [How a Small Team Shrank a Microsoft Monorepo by 94%](https://www.wearedevelopers.com/videos/1236-how-a-small-team-shrank-a-microsoft-monorepo-by-94) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Docker build without Docker](https://www.wearedevelopers.com/videos/100114-docker-build-without-docker) - [Git for Code Reviews](https://www.wearedevelopers.com/videos/429-git-for-code-reviews) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)