Junior Cybersecurity GRC Analyst
TypeContract
LocationUnited States
Posted1 hour ago
Description
Dragonfli Group is a cybersecurity and IT consulting firm providing services to federal agencies and Fortune 100 enterprises. Headquartered in Washington, DC, Dragonfli supports clients in securing mission-critical systems across on-site, hybrid, and fully remote environments.
Dragonfli Group is seeking a Junior Cyber Governance and Compliance Analyst to support a multi-year cybersecurity program for a large federal agency. This is an early-career governance role for someone who wants to learn the Risk Management Framework by working it. You will support and contribute to the execution of RMF to authorize IT systems, help the organization understand whether its systems are operating at an acceptable level of risk, and support authorization decisions by performing risk trade-off analyses and contributing to risk mitigation strategies. You will support technical analysis across categorization, control selection, control implementation, and comprehensive assessments of risk posture. You will also support presentations and, at times, present directly to clients and other decision makers. It suits a versatile early-career analyst with strong communication skills and some exposure to assessment and authorization work.
This is a multi-year contract position involving a large US federal agency. Candidates with previous federal contracting experience are preferred. U.S. Citizenship or Permanent Residency is required. If hired, all work related to this role must be performed within the continental U.S.
Responsibilities
Support and contribute to the execution of the Risk Management Framework to authorize IT systems
Provide information on whether information systems are operating at an acceptable level of risk to the organization
Support information system authorization decisions by performing risk trade-off analyses
Contribute to the development of risk mitigation strategies and solutions
Support technical analysis across cybersecurity risk management activities: categorizing a system, proposing security control selections, implementing security controls, and providing comprehensive assessments of risk posture
Support security control assessment activities in accordance with NIST SP 800-37 and NIST SP 800-53A
Support presentations and, at times, present to clients and other decision makers across technical and non-technical audiences
Support advice to clients on technical designs, implementations, and solutions that protect against cybersecurity attacks
Support POA&M tracking, cyber risk register upkeep, and tracking of cybersecurity regulations, guidance, and data calls
Support cybersecurity dashboard development and the automation of routine risk reporting and compliance tracking
Requirements
Must-Have
Bachelor's degree in cybersecurity, information technology, or a related field
Exposure to Assessment and Authorization (RMF) work, including testing or assessing cybersecurity solutions, through coursework, internship, or professional experience
Working understanding of the Risk Management Framework and the federal authorization process
Strong written and verbal communication skills, including comfort supporting or delivering presentations
Ability to work independently and as a member of a team
U.S. Citizenship or Permanent Residency, with all work performed within the continental U.S.
Ability to pass a federal agency suitability or background investigation
Preferred / Nice-to-Have
Internship, co-op, or 1 to 2 years of professional experience in a GRC, audit, or compliance role
Familiarity with NIST SP 800-53 control families and evidence expectations
Exposure to a GRC platform such as Xacta, eMASS, CSAM, Archer, or ServiceNow IRM
Exposure to FISMA reporting, SCRM, or TPRM concepts
Interest in or exposure to automation and AI-assisted compliance tooling
Security+ or CGRC (formerly CAP) certification, or active pursuit of one
Skill(s)
Technical Skills
Risk Management Framework fundamentals under NIST SP 800-37
Security control familiarity under NIST SP 800-53 and assessment basics under 800-53A
Risk trade-off analysis and mitigation strategy support
POA&M tracking and evidence collection
Security documentation and authorization artifact support
Cyber risk register and regulatory tracking support
Dashboard, reporting, and spreadsheet analysis skills
Exposure to automation and AI-assisted compliance tooling
Soft Skills
Clear written and verbal communication with both technical and non-technical audiences
Ability to work independently and as a contributing member of a distributed team
Comfort operating in a fully remote setting with a camera-on meeting culture
Sound judgment about when to decide and when to escalate
Collaborative posture with system owners, business owners, developers, and assessors
Attention to documentation quality and follow-through on commitments
Benefits
Dragonfli Group offers a comprehensive benefits package that includes:
Medical: Multiple POS health plan options including an HSA-compatible plan
Dental: PPO coverage for preventive, basic, and major services
Vision: Annual exam, frames, lenses, and contact lens allowance
401(k): Employer match up to 5% of eligible compensation
Long-Term Disability: 100% employer-paid coverage at 50% of pre-disability earnings
Life Insurance & AD&D: 100% employer-paid coverage valued at $10,000 each
PTO: 15–25 days annually based on tenure
Paid Federal Holidays: All 11 federal holidays observed
Originally posted on Himalayas
Dragonfli Group is a cybersecurity and IT consulting firm providing services to federal agencies and Fortune 100 enterprises. Headquartered in Washington, DC, Dragonfli supports clients in securing mission-critical systems across on-site, hybrid, and fully remote environments.
Dragonfli Group is seeking a Junior Cyber Governance and Compliance Analyst to support a multi-year cybersecurity program for a large federal agency. This is an early-career governance role for someone who wants to learn the Risk Management Framework by working it. You will support and contribute to the execution of RMF to authorize IT systems, help the organization understand whether its systems are operating at an acceptable level of risk, and support authorization decisions by performing risk trade-off analyses and contributing to risk mitigation strategies. You will support technical analysis across categorization, control selection, control implementation, and comprehensive assessments of risk posture. You will also support presentations and, at times, present directly to clients and other decision makers. It suits a versatile early-career analyst with strong communication skills and some exposure to assessment and authorization work.
This is a multi-year contract position involving a large US federal agency. Candidates with previous federal contracting experience are preferred. U.S. Citizenship or Permanent Residency is required. If hired, all work related to this role must be performed within the continental U.S.
Responsibilities
Support and contribute to the execution of the Risk Management Framework to authorize IT systems
Provide information on whether information systems are operating at an acceptable level of risk to the organization
Support information system authorization decisions by performing risk trade-off analyses
Contribute to the development of risk mitigation strategies and solutions
Support technical analysis across cybersecurity risk management activities: categorizing a system, proposing security control selections, implementing security controls, and providing comprehensive assessments of risk posture
Support security control assessment activities in accordance with NIST SP 800-37 and NIST SP 800-53A
Support presentations and, at times, present to clients and other decision makers across technical and non-technical audiences
Support advice to clients on technical designs, implementations, and solutions that protect against cybersecurity attacks
Support POA&M tracking, cyber risk register upkeep, and tracking of cybersecurity regulations, guidance, and data calls
Support cybersecurity dashboard development and the automation of routine risk reporting and compliance tracking
Requirements
Must-Have
Bachelor's degree in cybersecurity, information technology, or a related field
Exposure to Assessment and Authorization (RMF) work, including testing or assessing cybersecurity solutions, through coursework, internship, or professional experience
Working understanding of the Risk Management Framework and the federal authorization process
Strong written and verbal communication skills, including comfort supporting or delivering presentations
Ability to work independently and as a member of a team
U.S. Citizenship or Permanent Residency, with all work performed within the continental U.S.
Ability to pass a federal agency suitability or background investigation
Preferred / Nice-to-Have
Internship, co-op, or 1 to 2 years of professional experience in a GRC, audit, or compliance role
Familiarity with NIST SP 800-53 control families and evidence expectations
Exposure to a GRC platform such as Xacta, eMASS, CSAM, Archer, or ServiceNow IRM
Exposure to FISMA reporting, SCRM, or TPRM concepts
Interest in or exposure to automation and AI-assisted compliance tooling
Security+ or CGRC (formerly CAP) certification, or active pursuit of one
Skill(s)
Technical Skills
Risk Management Framework fundamentals under NIST SP 800-37
Security control familiarity under NIST SP 800-53 and assessment basics under 800-53A
Risk trade-off analysis and mitigation strategy support
POA&M tracking and evidence collection
Security documentation and authorization artifact support
Cyber risk register and regulatory tracking support
Dashboard, reporting, and spreadsheet analysis skills
Exposure to automation and AI-assisted compliance tooling
Soft Skills
Clear written and verbal communication with both technical and non-technical audiences
Ability to work independently and as a contributing member of a distributed team
Comfort operating in a fully remote setting with a camera-on meeting culture
Sound judgment about when to decide and when to escalate
Collaborative posture with system owners, business owners, developers, and assessors
Attention to documentation quality and follow-through on commitments
Benefits
Dragonfli Group offers a comprehensive benefits package that includes:
Medical: Multiple POS health plan options including an HSA-compatible plan
Dental: PPO coverage for preventive, basic, and major services
Vision: Annual exam, frames, lenses, and contact lens allowance
401(k): Employer match up to 5% of eligible compensation
Long-Term Disability: 100% employer-paid coverage at 50% of pre-disability earnings
Life Insurance & AD&D: 100% employer-paid coverage valued at $10,000 each
PTO: 15–25 days annually based on tenure
Paid Federal Holidays: All 11 federal holidays observed
Originally posted on Himalayas
Apply on Himalayas →
Job sourced from Himalayas. Applications happen directly on the original platform — we never collect your data.