Cyber Compliance Officer

Clearance Level
Cyber Security
Falls Church, Virginia
Arlington, Virginia

REQ#: RQ135838

Travel Required: Less than 10%
Requisition Type: Regular


Cyber Compliance Officer

GDIT has an opening for a Cyber Compliance Officer position supporting the Army National Guard (ARNG) in Chantilly, VA. This is an IT Service Management contract in support of the operation, modernization, expansion, and further evolution of the ARNG’s global Information Technology (IT) services including networking, compute, storage, infrastructure, applications, hosting, and program management services.  The GECOS program supports the ARNG enterprise IT infrastructure, its Wide Area Network (WAN), authentication and directory services, cybersecurity, application hosting, and associated services. GECOS uses ITIL best practices framework as the basis for IT Service Management (ITSM) model. The work includes the following:

  • Operating the DoDIN-Army (National Guard) (DoDIN-A(NG) and DoDIN-A(NG)-Secret (S) networks and maintaining service delivery and cybersecurity of DoDIN-A(NG) and DoDIN-A(NG)-S networks and computing services.

  • Supporting the DoDIN-A(NG) and DoDIN-A(NG)-S networks and associated computing services from requirement identification to service retirement / replacement.

  • Ensuring continued security of the network and proactive enhancement of cybersecurity to meet evolving and emerging threats, to include compliance with DoD Risk Management Framework (RMF) and continuous monitoring requirements.

  • Providing support to the 54 supported organizations (i.e., 50 states, three territories, and the District of Columbia) to ensure flexible and responsive operation and defense of the network.  Some OCONUS travel might be required.

  • Adhering to all Department of Defense (DoD) enterprise security requirements to include those required by the Defense Information Systems Agency (DISA) and the Department of the Army (DA); prepping for and passing Command Cyber Readiness Inspections (CCRIs), obtaining and maintaining Authority to Connect (ATC) and Authority to Operate (ATO) from the Designated Approving Authority (DAA); ensuring compliance with all Secure Technical Implementation Guides (STIGS) and required information assurance (IA) controls.

  • Maintaining the lifecycle of all services, ensuring they meet business needs, comply with Army directives and mandates, and are in keeping with the future Joint Information Environment (JIE) architecture.

  • Maintain continuity of service when primary support systems operate in degraded mode per COOP.

The Cyber Compliance Officer will:

  • Measure ARNG compliance with cybersecurity requirements and recommends cybersecurity program operational execution activities, processes, and practices.

  • Identify, protect, detect, respond to, recover, and analyze threats to the ARNG enterprise network and its enabling technologies based on compliance-related gaps and risks, in close coordination with the RCC-NG.

  • Assist ARNG with identifying vulnerabilities in the ARNG enterprise network and its enabling technologies and assessing compliance with cybersecurity requirements and prescribed operational execution activities, processes, and practices.

  • Assist the Government with ensuring the secure configuration and preparation for approval of IT below the system level in coordination with the RCC-NG and in accordance with applicable guidance prior to acceptance into, or connection to, an Army IS.

  • Assist in the implementation, management, and administration of the organization’s structure and workflow within eMASS.

  • Assist in the enforcement of the DCWF and cybersecurity certification program to ensure training and certification requirements are enforced, managed, and reported.

  • Assist ARNG with the implementation of a documented and streamlined process for reviewing, processing, and approving systems access requests.

  • Leverage the ACAS and other compliance-related tools to scan network devices for compliance with current best practices and CCRI requirements to interrogate systems for configuration and status.

  • Create and submit appropriate security-related reports, such as those required by IAVA, intrusion, virus infection incidents, FISMA, and others as requested by the Government.

  • Track IAVA compliance at the enterprise level and reports on state efforts to achieve compliance.

  • Assist the states and territories in scan policy implementation, appropriate asset identification, plug-in related issues, and general scan-related troubleshooting.

  • Coordinate with the SOC and the RCC-NG to leverage the AESS tools suite to perform coordination with states on compliance findings and remediation efforts.

  • Process FPA requests and WCF requests to validate requirements and appropriately identify associated risks.

  • Assist in examining the security architecture and vulnerabilities of systems in cooperation with system owners and administrators through security scans, examinations of system configurations, reviews of system design documentation, and interviews.

Qualifications: Bachelors and/or 10+ years of IT management experience including network engineering and cybersecurity support.  Desired degree: Cybersecurity or Network Engineering. Will consider other combinations of years of experience, degree, and certifications.

Clearance: Secret

Shift/Work Schedule: 40% Telework (2 days a week) optional

Required Certification(s): DoD 8570 IAT II (Sec+ or equivalent) or above

Desired Certification(s): DoD 8570 IAT III (CISSP or equivalent); ITIL


#GECOS #GDITPriority

About Our Work

We are GDIT. The people supporting some of the most complex government, defense, and intelligence projects across the country. We deliver. Bringing the expertise needed to understand and advance critical missions. We transform. Shifting the ways clients invest in, integrate, and innovate technology solutions. We ensure today is safe and tomorrow is smarter. We are there. On the ground, beside our clients, in the lab, and everywhere in between. Offering the technology transformations, strategy, and mission services needed to get the job done.

COVID-19 Vaccination

GDIT does not have a vaccination mandate applicable to all employees. To protect the health and safety of its employees and to comply with customer requirements, however, GDIT may require employees in certain positions to be fully vaccinated against COVID-19. Vaccination requirements will depend on the status of the federal contractor mandate and customer site requirements.

GDIT is an Equal Opportunity/Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or veteran status, or any other protected class.