> Markdown version of [/jobs/ext/2707854-cyber-security-analyst](https://www.wearedevelopers.com/jobs/ext/2707854-cyber-security-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Security Analyst - **Company:** General Dynamics Information Technology - **Location:** Quantico, VA, United States - **Experience:** Expert - **Salary:** $96,569.0 - $130,651.0 - **Contract:** Permanent contract - **Skills:** Xacta, Artificial Intelligence, Public-Key Cryptography, Biometrics, CompTIA Security+, Cyber Security, Systems Development Life Cycle, Privacy Controls, Information Technology, Vulnerability Analysis - **Published:** September 4, 2026 - **Apply:** https://gdit.wd5.myworkdayjobs.com/External_Career_Site/job/USA-VA-Quantico/NCIS-Cyber-Security-Analyst---Active-TS-SCI-clearance_RQ224019-2/apply ## About the Role Bring your cybersecurity expertise along with a drive for innovation to GDIT. Our Cyber Security Analyst must have: * Security Clearance Level: Active TS/SCI required. A Top Secret clearance with SCI Eligibility is also acceptable. * Required Experience: * 5+ years of experience in the systems security discipline with specific emphasis on Navy Cybersecurity practices. * Experience in the development of RMF Assessment and Authorization (A&A) Security Plans (SP), System Level Continuous Monitoring (SLCM), Ports, Protocols and Services Management (PPSM), Host Based Security Systems (HBSS), Assured Compliance Assessment Solution (ACAS) vulnerability scanning and Security Technical Implementation Guides (STIGs). * Experience with Enterprise Mission Assurance Support Service (eMASS) tools. * Experience preparing, processing, assessing, validating, and maintaining RMF A&A packages using eMASS and XACTA tools. * Experience with using public key-based technologies for applications. * Required Certifications: CompTIA Security+ CE * Education: BS Degree or 4 years additional experience in lieu of degree., * Completed Navy RMF training * Formal ACAS training * Formal eMASS training, Years of Experience 5 + years of related experience * may vary based on technical training, certification(s), or degree Certification CompTIA Security+ CE | CompTIA - CompTIA Travel Required ## Description As a Cyber Security Analyst, the work you'll do at GDIT will be impactful to the mission of the NCIS ITD organization in Quantico, VA * Supports all authorization package ACAS related tasks assigned to Issues and NQVs. The goal is to provide the required artifacts IAW the Navy Testing Guidance and Risk Management Framework (RMF) Process Guide required for the submission of an RMF Authorization package. * Manages and validates system security compliance by reviewing Security Technical Implementation Guides (STIGs); utilizes scanning tools to assess and report on STIG compliance, ensuring all security configurations meet DoW requirements and support the RMF A&A process. * Executes and documents the testing of RMF security controls to validate their effectiveness and compliance with NCIS policies, providing evidence of control implementation for Assessment & Authorization (A&A) packages. * Applies a comprehensive understanding of NIST SP 800-53 Revision 5 to select, tailor, and document security and privacy controls, ensuring alignment with federal requirements and the specific operational needs of the authorization package * Performs 90 Day Baseline Scans for each Authorization package in accordance with Navy requirements; provide Detailed Vulnerability List (DVL) Reports for use in the eMASS record; provide ACAS Summary Reports in accordance with the Navy Testing Guidance. * Conducts weekly and "As Needed" ACAS scans in support of RMF STEP 3/STEP 4 processes, vulnerability assessments and queries specifically targeting authorization package assets; support continuous monitoring for authorized packages and report vulnerability status of all active Enterprise Security packages; create asset lists using provided hardware lists. * Performs risk analyses of computer systems and applications during all phases of the system development life cycle using the Assured Compliance Assessment Solution (ACAS) tool. * Initiates Enterprise Mission Assurance Support Service (eMASS) registrations, prepares, processes, updates and monitors RMF Assessment and Authorization (A&A) packages; ensures A&A packages are evaluated and maintained in a compliant status; implements and validates A&A packages to ensure security controls and vulnerabilities meet DON RMF authorization compliance requirements. ## Related Videos - [Biometric Phone Chargers, $40m Domain Names & AI Movies Winning Awards - Peter Kröner](https://www.wearedevelopers.com/videos/1810-biometric-phone-chargers-40m-domain-names-ai-movies-winning-awards-peter-kroner) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [WeAreDevelopers LIVE - What Development and Tattoos Have in Common and more](https://www.wearedevelopers.com/videos/1380-wearedevelopers-live-what-development-and-tattoos-have-in-common-and-more) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 216: CyberSec + Mythos, Stack Overflow for Agents & DOOM in TTF](https://www.wearedevelopers.com/magazine/728-dev-digest-216-cybersec-mythos-stack-overflow-for-agents-doom-in-ttf) - [Dev Digest 164: AI Agents, AI Blindspots and MCP security problems](https://www.wearedevelopers.com/magazine/578-dev-digest-164-ai-agents-ai-blindspots-and-mcp-security-problems) - [Dev Digest 182: GPT5 Prompts, MCP Vulnerabilities, Code Traps](https://www.wearedevelopers.com/magazine/622-dev-digest-182-gpt5-prompts-mcp-vulnerabilities-code-traps)