> Markdown version of [/jobs/ext/3282180-cyber-technical-analyst-sr-principal](https://www.wearedevelopers.com/jobs/ext/3282180-cyber-technical-analyst-sr-principal). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Technical Analyst Sr Principal - **Company:** General Dynamics Information Technology - **Location:** McLean, VA, United States - **Experience:** Expert - **Salary:** $158,950.0 - $215,050.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Biometrics, Networking Hardware, Network Architecture, Tenable Nessus, Firewall Services Module, Plan of Action and Milestones - **Published:** September 4, 2026 - **Apply:** https://gdit.wd5.myworkdayjobs.com/External_Career_Site/job/USA-VA-McLean/Cybersecurity-Compliance---Continuous-Monitoring-Analyst_RQ227716-1/apply ## About the Role Bring your cyber expertise and drive for innovation to GDIT. The Cyber Technical Analyst Sr Principal must have: * Education: Bachelor of Arts/Bachelor of Science * Experience: 8+ years of related experience * Technical skills: * Hands-on experience with Tenable.sc and Tenable Nessus * Progressive experience in information assurance and cybersecurity roles * Minimum of 5 years of direct, hands-on experience as an ISSO or ISSM with a proven track record of achieving and maintaining ATO for classified systems * Expert-level knowledge of the NIST SP 800 series (especially 800-37, 800-53, 800-30) and risk management principles * Experience with FedRAMP and CNSSI 1253 baselines, continuous monitoring, POA&M management, and A&A body-of-evidence documentation * Security clearance level: Active Top Secret * Role requirements: * On-site McLean, VA * Must be DoD 8140 / 8570.01-M compliant * CISSP strongly preferred, Years of Experience 8 + years of related experience * may vary based on technical training, certification(s), or degree Certification Certified Information Systems Security Professional (CISSP) | International Information System Security Certification Consortium (ISC2) - International Information System Security Certification Consortium (ISC2) Travel Required Less than 10% Citizenship ## Description Advance your career while impacting our national security in cyber as a Cyber Technical Analyst Sr Principal at GDIT. Here, technologists have many paths to grow a meaningful career supporting cyber missions and operations across the federal government. MEANINGFUL WORK AND PERSONAL IMPACT As a Cyber Technical Analyst Sr Principal, the work you'll do at GDIT will be impactful to the mission of our customer's classified commercial cloud environment. You will play a crucial role in securing and continuously monitoring a classified workstation secure enclave, ensuring it meets stringent FedRAMP and CNSSI 1253 requirements while enabling mission-critical operations. * Support the full RMF and Assessment & Authorization (A&A) lifecycle for the workstation secure enclave, including control implementation, assessment, authorization, and continuous monitoring. * Maintain a comprehensive body of evidence for FedRAMP/DoW A&A packages and continuous monitoring requirements, including POA&M tracking, reporting, and remediation. * Collaborate with security engineers, system administrators, ISSO/ISSM, vendors, and leadership to integrate and validate security controls and align operations with FedRAMP, DoD, and CNSSI 1253 requirements. * Identify, assess, and remediate vulnerabilities using Tenable Nessus, Tenable.sc, SCC, STIG tooling, and related security tools; ensure host inventory and scan policies are accurate and complete. * Review scan results, STIG findings, and patching activities to ensure accurate, actionable data and effective hardening of operating systems, network devices, and applications. * Evaluate system designs, network architectures, firewall rules, and PPSM submissions to ensure security principles are integrated from the outset and architecture risks are addressed. * Lead preparation and execution of security control audits and FedRAMP 3PAO assessments, reviewing artifacts, logs, and configurations to validate evidence of compliance and a strong security posture. * Provide security control assessment and audit oversight, including reviewing and validating implementation work performed by engineers and system administrators. * Manage a robust continuous monitoring and GRC program, aggregating and analyzing security data to identify trends, anomalies, and potential incidents and providing actionable risk insights to leadership. * Support risk assessments and incident response, recommending mitigating controls and assisting the ISSM and incident response team with artifacts and deep system/security expertise. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Building the Nervous System of AI - Michael Kagan (NVIDIA)](https://www.wearedevelopers.com/videos/2133-building-the-nervous-system-of-ai-michael-kagan-nvidia) - [Biometric Phone Chargers, $40m Domain Names & AI Movies Winning Awards - Peter Kröner](https://www.wearedevelopers.com/videos/1810-biometric-phone-chargers-40m-domain-names-ai-movies-winning-awards-peter-kroner) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Optimizing Your App for Success: Tips and Techniques for managing slow devices](https://www.wearedevelopers.com/videos/655-optimizing-your-app-for-success-tips-and-techniques-for-managing-slow-devices) - [WeAreDevelopers LIVE - What Development and Tattoos Have in Common and more](https://www.wearedevelopers.com/videos/1380-wearedevelopers-live-what-development-and-tattoos-have-in-common-and-more) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 216: CyberSec + Mythos, Stack Overflow for Agents & DOOM in TTF](https://www.wearedevelopers.com/magazine/728-dev-digest-216-cybersec-mythos-stack-overflow-for-agents-doom-in-ttf) - [Dev Digest 164: AI Agents, AI Blindspots and MCP security problems](https://www.wearedevelopers.com/magazine/578-dev-digest-164-ai-agents-ai-blindspots-and-mcp-security-problems) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer)