Cyber Compliance Officer
Listed on 2026-08-13
-
IT/Tech
Cybersecurity
Cyber Compliance Officer - Secret Clearance Required
We are GDIT. We stay at the forefront of innovation to solve complex technical challenges. GDIT is your place—make it your own by discovering new ways to apply the latest technologies securely and expertly. Our work depends on aCyber Compliance Officerjoining our team to support the Guard Enterprise Cyber Operations Support (GECOS) program in Falls Church, VA.
This is anIT Service Management (ITSM) contract supporting the operation, modernization, expansion, and evolution of the Army National Guard’s (ARNG) global IT services, including networking, compute, storage, infrastructure, applications, hosting, and program management. The GECOS program supports the ARNG enterprise IT infrastructure, its WAN, authentication and directory services, cybersecurity, application hosting, and associated services, leveragingITIL best practices.
As a Cyber Compliance Officer, you will provide cybersecurity compliance support in accordance with applicable
DoW and Armyguidance and regulations. You will work closely with the client and senior staff, so clear, articulate communication is essential. You must be collaborative and able to work within a team, while also being a self-starter who can complete tasks independently and explain complex technical information in an easily understood manner.
The Cyber Compliance Officer will:
- Provide Risk Management Framework (RMF) support to the 54 supported organizations (50 states, three territories, and the District of Columbia) for Installation Campus Area Networks (ICANs) and HQ Enterprise investments, includingeMASSrecord reviews.
- Serve as an RMF SME to the 54, delivering customer training and briefs, managing multiple states simultaneously, and briefing the Program Information System Security Manager (P-ISSM) on progress, hurdles, and roadblocks.
- Provide RMF support for Steps 0–3, 5, and 6:
- Step 0:
Deliver RMF roles and responsibilities training. - Step 1:
Guide system/ICAN categorization. - Step 2:
Guide security control baseline selection. - Step 3:
Advise on security control implementation and delegation of technology areas in eMASS. - Step 5:
Support submission of ATO package artifacts to the Authorizing Official. - Step 6:
Support continuous monitoring (Con Mon) strategies and execution.
- Step 0:
- Identify and maintain cybersecurity compliance requirements for IT investments of the 54 and theDoWIN-A(NG) andDoWIN-A(NG)-Snetworks and computing services.
- Ensure adherence to DoW, DISA, and Department of the Army enterprise security requirements, including preparation for and successful completion ofCCRIs, obtaining and maintaining
Authority to Connect (ATC) and Authority to Operate (ATO), and compliance withSTIGsand required IA controls. - Help ensure compliance with Army directives and mandates aligned with the future
Joint Information Environment (JIE) architecture. - Measure ARNG compliance with cybersecurity requirements and recommend program execution activities, processes, and practices.
- Assist with secure configuration and preparation of IT below the system level (Software Assurance) across the 54 in coordination withRCC-NG, in accordance with applicable guidance prior to acceptance into or connection to Army IS and DoWIN-A(NG).
- Maintain an Accreditations and Expiration Dates Recordfor upcoming accreditation expirations using RMF Work Management SharePoint tracking tools.
- Ensure cybersecurity inspections, tests, assessments, and reviews are synchronized and coordinated with all stakeholders.
- Assist in the implementation, management, and administration of organizational structure and workflow withineMASS.
- Review cybersecurity information papers and plans withCYBERCOM, ARCYBER, Air National Guard Cyber, NSA, FBI, DOJ, and DHS.
- Support enforcement of theDoW Cyberspace Workforce Framework (DCWF) and cybersecurity certification program to ensure training and certification are enforced, managed, and reported.
- Help implement a streamlined process for reviewing, processing, and approving eMASS system access requests in support of RMF.
- Assist in examining security architectures and vulnerabilities through scans, configuration reviews, design…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).