×
Register Here to Apply for Jobs or Post Jobs. X

Senior Continuous Monitoring; ConMon) Analyst

Job in Washington, District of Columbia, 20022, USA
Listing for: Rividium
Full Time, Part Time position
Listed on 2026-09-14
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection, Security Management & Operations
Salary/Wage Range or Industry Benchmark: 120000 - 170000 USD Yearly USD 120000.00 170000.00 YEAR
Job Description & How to Apply Below
Position: Senior Continuous Monitoring (ConMon) Analyst

Full-Time/Part-Time Full-Time

Description

Summary

RiVidium Inc. seeking a Senior Continuous Monitoring (Con Mon) Analyst to support federal cybersecurity and Risk Management Framework (RMF) activities. The Senior Con Mon Analyst will provide cybersecurity continuous monitoring, security assessment, risk analysis, and compliance support to ensure information systems remain compliant with applicable federal security requirements.

The ideal candidate will have strong experience with RMF, security controls, continuous monitoring, vulnerability management, POA&M management, security documentation, and Governance, Risk, and Compliance (GRC) tools. This position requires the ability to work closely with Information System Security Officers (ISSOs), Information System Security Managers (ISSMs), Security Control Assessors (SCAs), system owners, engineers, and government stakeholders.

Key Responsibilities
  • Perform continuous monitoring of information systems to identify changes in security posture, vulnerabilities, risks, and compliance status.
  • Support implementation and execution of Continuous Monitoring (Con Mon) strategies in accordance with federal cybersecurity requirements and organizational policies.
  • Monitor security controls and assess ongoing control effectiveness through documentation reviews, technical evidence, vulnerability data, and other assessment activities.
  • Support NIST Risk Management Framework (RMF) activities throughout the system lifecycle.
  • Review security controls, assessment results, system changes, vulnerabilities, and security-related artifacts to identify potential risks and compliance gaps.
  • Track, analyze, and report security weaknesses, vulnerabilities, and Plans of Action and Milestones (POA&Ms).
  • Coordinate with ISSOs, ISSMs, SCAs, system owners, and technical teams to ensure identified security deficiencies are properly documented and remediated.
  • Maintain and update cybersecurity documentation, including security assessment evidence, control implementation statements, POA&Ms, risk assessments, and continuous monitoring reports.
  • Review vulnerability scan results and other security assessment data to determine potential impact to system security posture.
  • Support security impact analyses for system changes, configuration changes, new technologies, and changes to the operational environment.
  • Assist with preparation of recurring security and compliance reports for government leadership and cybersecurity stakeholders.
  • Analyze security metrics and trends to identify recurring weaknesses and recommend risk mitigation strategies.
  • Support security control testing, assessment, and validation activities as required.
  • Ensure continuous monitoring activities are properly documented and aligned with applicable policies, standards, and federal regulations.
  • Use GRC and cybersecurity tools to maintain system security information, control status, assessment findings, POA&Ms, and compliance documentation.
  • Participate in cybersecurity working groups, risk reviews, security meetings, and technical discussions with government and contractor stakeholders.
  • Provide recommendations to improve cybersecurity processes, control effectiveness, risk management, and compliance posture.
  • Stay current on evolving federal cybersecurity policies, NIST guidance, threats, vulnerabilities, and security best practices.
Required Qualifications
  • Bachelor’s degree in Cybersecurity, Information Systems, Computer Science, Information Assurance, or a related field.
  • Demonstrated professional experience supporting cybersecurity, continuous monitoring, RMF, security compliance, or information assurance programs.
  • Strong understanding of the NIST Risk Management Framework (RMF) and NIST cybersecurity standards.
  • Experience with security controls, security assessments, vulnerability management, risk management, and POA&M tracking.
  • Experience analyzing security documentation and technical evidence to determine control compliance and system security posture.
  • Experience working with cybersecurity stakeholders, including ISSOs, ISSMs, SCAs, system owners, and system administrators/engineers.
  • Strong written and verbal communication skills with the ability to prepare clear technical and executive-level security reports.
  • Ability to manage multiple systems, security requirements, findings, and competing priorities in a federal environment.
Preferred Qualifications
  • CISM, CAP, or equivalent GRC/cybersecurity certification.
  • Experience with GRC platforms such as RSA Archer, Service Now GRC,…
Position Requirements
10+ Years work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary