> Markdown version of [/jobs/ext/1251131-cyber-analyst-principal-ts-sci-with-polygraph](https://www.wearedevelopers.com/jobs/ext/1251131-cyber-analyst-principal-ts-sci-with-polygraph). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Analyst Principal - TS/SCI with Polygraph - **Company:** General Dynamics Information Technology - **Location:** McLean, VA, United States - **Experience:** Expert - **Salary:** $124,093.0 - $166,750.0 - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, Information Security Management, Information Systems Security Architecture Professional - **Published:** July 12, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=16cae0f5c13c23c4 ## About the Role Bring your cyber expertise and drive for innovation to GDIT. The Cyber Analyst Principal must have: * Security clearance level: Must possess a current and active TS/SCI with Polygraph. * Certifications: Must be DoW 8140 / 8570.01-M compliant * Education: BA/BS Degree or equivalent experience in lieu of degree * Experience: 5+ years of related experience * Technical skills: - Expert-level knowledge of the complete NIST SP 800 series (especially 800-37, 800-53, 800-30) and risk management principles. - Progressive experience in information assurance and cybersecurity roles. - Direct, hands-on experience as an ISSO or ISSM, with a proven track record of successfully supporting ATO for classified systems under ICD 503 policies. - Extensive, hands-on experience navigating the IC Risk Management Framework (RMF) requirements for classified commercial cloud services and cross domain solutions. * Location: Onsite in McLean, VA, 5 + years of related experience * may vary based on technical training, certification(s), or degree Certification Certified Information Systems Security Professional (CISSP) | International Information System Security Certification Consortium (ISC2) - International Information System Security Certification Consortium (ISC2) Travel Required Less than 10% Citizenship ## Description GDIT is seeking a highly skilled and multi-faceted Cyber Analyst Principal for a critical contract role supporting a commercial cloud service provider's mission-critical systems. This position requires the employee to report full time on site in McLean, VA. The ideal candidate is a proactive and seasoned professional with extensive, hands-on experience navigating the Intel Community (IC) Risk Management Framework (RMF) requirements for classified commercial cloud services and cross domain solutions. This role requires a unique blend of technical engineering prowess, security assessment and auditing skills, deep expertise in continuous monitoring, and the polish to communicate risk to executive leadership. You will be a key contributor to our Governance, Risk, and Compliance (GRC) program, supporting the Information System Security Manager (ISSM), and Cyber Lead in ensuring the unyielding security and integrity of mission-critical systems. The Cyber Analyst Principal will support the following key areas - * RMF & Assessment and Authorization (A&A) * Security Engineering & System Hardening * Security Control Assessor (SCA) & Auditing * Continuous Monitoring & GRC Additionally, the Cyber Analyst Principal will - * Support Assessment & Authorization (A&A) execution for classified commercial cloud service offerings, and Cross Domain Solutions (CDS) as needed, through the entire respective IC RMF lifecycles to obtain and maintain the applicable authorizations. * Assist in maintaining a comprehensive body of evidence for A&A packages. * Support the monthly and overall IC Continuous Monitoring requirements. * Work with security engineering to proactively identify and assess vulnerabilities related to scans, STIGs, security controls, etc. * Support assessment preparation for security control audits, traditional security reviews, and formal inspections, including preparing for and executing IC assessments. * Meticulously review artifacts, logs, and system configurations to ensure they provide sufficient evidence of compliance. * Coordinate and/or participate in security testing and penetration testing activities to provide an independent validation of the system's security posture. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Don't Be A Naive Developer: How To Avoid Basic Cybersecurity Mistakes](https://www.wearedevelopers.com/videos/498-don-t-be-a-naive-developer-how-to-avoid-basic-cybersecurity-mistakes) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Make it simple, using generative AI to accelerate learning](https://www.wearedevelopers.com/videos/969-make-it-simple-using-generative-ai-to-accelerate-learning) - [Hacking Kubernetes: Live Demo Marathon](https://www.wearedevelopers.com/videos/488-hacking-kubernetes-live-demo-marathon) - [Don’t shoot yourself in the foot.](https://www.wearedevelopers.com/videos/580-don-t-shoot-yourself-in-the-foot) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Dev Digest 216: CyberSec + Mythos, Stack Overflow for Agents & DOOM in TTF](https://www.wearedevelopers.com/magazine/728-dev-digest-216-cybersec-mythos-stack-overflow-for-agents-doom-in-ttf) - [Dev Digest 182: GPT5 Prompts, MCP Vulnerabilities, Code Traps](https://www.wearedevelopers.com/magazine/622-dev-digest-182-gpt5-prompts-mcp-vulnerabilities-code-traps) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)