> Markdown version of [/jobs/ext/2303852-it-and-cyber-risk-auditor-principal](https://www.wearedevelopers.com/jobs/ext/2303852-it-and-cyber-risk-auditor-principal). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # IT and Cyber Risk Auditor Principal - **Company:** General Dynamics Information Technology - **Location:** La Plata, MD, United States - **Experience:** Expert - **Salary:** $119,000.0 - $161,000.0 - **Contract:** Permanent contract - **Skills:** Xacta, Microsoft Windows, Macintosh Application Environment, Unix, Cyber Security, Databases, Information Security Management, Splunk, Plan of Action and Milestones, Vulnerability Analysis - **Published:** August 30, 2026 - **Apply:** https://www.juju.com/job/00000000gpswtn ## About the Role Cyber Risks,Cybersecurity Controls,NIST 800-53, 8 + years of related experience, + Candidate must be able to favorably pass government background investigation + Candidate must have, at a minimum, a Top Secret clearance w/t polygraph. + Maintain Certification in accordance with DoW Directive 8140.01 Cyberspace Workforce Management requirements + U.S. Citizenship eligibility requirements. Team Responsibilities: + BA/BS or equivalent, 8+ years of experience + Minimum of 3-5 years specific experience with ICD 503 and NIST 800-53 policies. + Excellent communication skills with the ability to state messages in a clear and concise manner over any form of communication. + Ability to multi-task, prioritize, and re-prioritize work in a fast paced environment + Senior level of experience in engineering IT systems, as well as working knowledge of current technologies. + Ability to learn an application environment in order to update or create supported security documentation., Ideal Candidate: Candidates who are highly motivated, passionate in their IT security tradecraft, and looking to make a positive difference every day are best suited for this position. Candidates should possess a general level of understanding and basic level of experience across all team roles and responsibilities with a concentration of significant experience in at least 2-3 skill sets below. Preferred Skill Sets: + 2-3 years fulfilling Information System Security Engineer (ISSE) + 2-3 years fulfilling Windows and/or Unix administrator role or support + Experience using XACTA data base applications and the ICD 503, NIST 800-83 rev4 policy + Experience with Splunk, Security Center, Telos XACTA, and MacAfee EPO ## Description The candidate should be able to monitor and enforce security controls for technical, operational, and management support. The candidate will need to be vastly knowledgeable in developing and documenting system security plans, contingency plans, and other security related documents. This candidate will need to identify, create, track and remediate any system vulnerabilities. This candidate will be responsible for preparing system artifacts for annual system audits. This candidate should have an understanding of reviewing vulnerability scans. This candidate should have experience in completing multiple Authority to Operate (ATO) security packages. This candidate will need to be knowledgeable in plans of action and milestones (POA&M)s Management. This candidate must be able to establish system-level POA&Ms and implement corrective actions to develop, implement, manage, and track actions as required by the program ISSM/CISO., + The candidate will perform all tasks related to perform a system Certification and Accreditation and assuring the system is compliant with all required security controls as defined by agency policies. + The candidate will review system configurations to ensure they are in accordance with agency hardening guidelines. + The candidate will review all proposed change requests related to system design / configuration and perform security impact analysis. + The candidate will review monthly vulnerability scan reports and track and address weaknesses in POA&Ms as needed. + Perform security system event analysis, investigation, and validation + Provide incident response to classification spills, malware infection, misconfiguration exposure, internal inappropriate behavior and technical issue + Perform Security Technical Implementation Guide (STIG) and Federal Information Security Management Act (FISMA) assessments and annual reporting ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [WeAreDevelopers LIVE - Node and Package Security](https://www.wearedevelopers.com/videos/2138-wearedevelopers-live-node-and-package-security) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [The Time Paradox: Building Timezone-Safe Python/Django Applications](https://www.wearedevelopers.com/videos/1915-the-time-paradox-building-timezone-safe-python-django-applications) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Coffee with Developers - Robby Russell](https://www.wearedevelopers.com/videos/917-coffee-with-developers-robby-russell) ## Related Articles - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [System change: restart as developer?](https://www.wearedevelopers.com/magazine/39-system-change-restart-as-developer)