> Markdown version of [/jobs/ext/1718916-technical-lead-cybersecurity-operations](https://www.wearedevelopers.com/jobs/ext/1718916-technical-lead-cybersecurity-operations). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Technical Lead Cybersecurity Operations - **Company:** General Dynamics Information Technology - **Location:** Rockville, MD, United States - **Experience:** Expert - **Salary:** $142,792.0 - $184,000.0 - **Contract:** Permanent contract - **Skills:** Configuration Management Databases, Cyber Security, Information Security Management, Information Systems Security Architecture Professional, Information Technology, Servicenow - **Published:** July 2, 2026 - **Apply:** https://dejobs.org/x/x/FE65D7DD661348B7BFC61C2B2D5D8FB8/job/ ## About the Role Assessment & Authorization (A&A),CISSP,Cyber Security Governance,Governance Risk Compliance (GRC),NIST 800-53 Certifications: Certified Information Systems Security Professional (CISSP) | International Information System Security Certification Consortium (ISC2) - International Information System Security Certification Consortium (ISC2), ITIL v3 Foundation | PeopleCert - PeopleCert Experience: 10 + years of related experience, * Education: Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field * Experience: 5+ years leading cybersecurity governance programs for federal agencies. * Certification: Possess at least one of the following CISSP, CISM, CRISC, CISA, GSLC * Security clearance level: the ability to obtain a Public Trust Skills * Experience applying NIST risk assessment methodologies. * Experience managing cybersecurity teams and prioritizing workloads and risks. * Experience with eGRC tools (JCAM, Archer, or equivalent). * ITIL Foundations certification (or ability to obtain within 3 months). * Demonstrated experience developing A&A and governance streamlining processes. * Experience with ServiceNow GRC, CMDB, or custom workflow development. * Experience supporting federal research or health-science organizations. * Familiarity with OSCAL, control inheritance models, and continuous monitoring frameworks. * Policy development and governance strategy * Risk analysis & risk communication * Process design and automation leadership * Strong written communication and documentation skills * Cross-team collaboration and change management ## Description As the Governance, Risk & Compliance (GRC) Lead, the work you'll do at GDIT will be impactful to the mission of the customer. The GRC Lead oversees all GRC-related functions supporting NCI's cybersecurity governance framework, ensuring consistent implementation of policies, processes, and enterprise-wide compliance efforts. This position leads teams that design, document, automate, and enhance governance workflows, system inventories, common controls, policy frameworks, and enterprise risk processes. The role mirrors senior GRC leadership positions at large federal contractors., * Lead NCI's enterprise cybersecurity governance program, ensuring alignment with NIH, HHS, FISMA, and NIST RMF requirements. * Develop and maintain cybersecurity policies, SOPs, standards, templates, and procedural documentation. * Oversee FISMA system inventory accuracy and integration with ServiceNow CMDB modules. * Lead the development and optimization of GRC automation tools, including ServiceNow modules (e.g., FAST, eGRC integrations). * Provide expert consulting to system owners, development teams, and stakeholders on governance practices, risk mitigation, and compliance requirements. * Support security audits, internal assessments, OIG/GAO readiness, and CAP tracking. * Lead common controls program activities including documentation, tailoring, assessment, and inheritance guidance. * Analyze enterprise risks, identify trends, and prepare reports and dashboards for leadership decision-making. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) - [Enabling intelligent logistics automation: home-grown Industrial IoT platform at Austrian Post](https://www.wearedevelopers.com/videos/2018-enabling-intelligent-logistics-automation-home-grown-industrial-iot-platform-at-austrian-post) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [AI in Production: applied AI & enterprise use cases](https://www.wearedevelopers.com/videos/100130-ai-in-production-applied-ai-enterprise-use-cases) - [It's not easy being green](https://www.wearedevelopers.com/videos/558-it-s-not-easy-being-green) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)