IT Risk and Compliance Specialist Senior Principal

General Dynamics Information Technology
Falls Church, VA
Public Trust: None
Requisition Type: Regular
Your Impact

Own your opportunity to manage the network that makes mission success possible. Make an impact by using your skills to deliver “One GDIT Network” for our clients.

Job Description

Transform technology into opportunity as an IT Risk and Compliance Specialist Senior Principal with GDIT. A career in enterprise IT means connecting and enhancing the systems that matter most. At GDIT you’ll be at the forefront of innovation and play a meaningful part in improving how agencies operate.

GDIT's Technology Shared Services (TSS), Governance, Risk, and Compliance (GRC) team is seeking an experienced IT Risk and Compliance Specialist Senior Principal. Our team provides services across GDIT programs to ensure the confidentiality, integrity, and availability of information systems while supporting compliance with relevant regulations and standards.

This role requires a highly knowledgeable self-starter to independently manage the full Risk Management Framework (RMF) lifecycle for multiple systems concurrently. The ideal candidate will operate in a dynamic, high-tempo environment, applying deep expertise in risk management and regulatory compliance to protect critical information assets.

HOW THE IT RISK AND COMPLIANCE SPECIALIST SENIOR PRINCIPAL WILL MAKE AN IMPACT:

  • Manage the security posture and authorization lifecycle for multiple cloud and on-premises information systems.
  • Conduct continuous monitoring activities, including vulnerability scan analysis, audit log reviews, and security control assessments.
  • Develop, maintain, and update security documentation, including System Security Plans (SSPs), Plan of Action & Milestones (POAMs), and Risk Assessment Reports (RARs).
  • Periodically assess the risk to organizational operations (mission, functions, image, reputation) and organizational assets in accordance with organizational risk management policies.
  • Proactively monitor emerging security threats and technology advancements to recommend and implement process and tools improvements. to contribute
  • Ensure system compliance with NIST special publications, FedRAMP requirements, DISA STIGs, and CIS Benchmarks.
  • Assess and mitigate system vulnerabilities; track remedial actions to closure.
  • Support incident response, contingency planning, and disaster recovery efforts.
  • Serve as the primary security advisor to system owners, developers, and administrators.
  • Interface with auditors and assessors during security control assessments and authorization events.
  • Provide security-focused input for new business proposals and solutions.

KEY RESPONSIBILITIES:

  • Act as a subject matter expert on information security topics and provide guidance to management and staff
  • Oversee the identification, assessment, and mitigation of IT risks across GDIT’s and our customer’s information technology systems environments
  • Facilitate and collaborate RMF steps with data owners, system owners, authorizing officials, and technical teams to prepare, categorize, select, implement, assess, authorize and monitor privacy and security controls in accordance with organizational risk policy.
  • Ensure compliance with applicable regulatory requirements and policies
  • Lead the development and execution of IT risk management and compliance strategies
  • Develop, implement, and maintain IT risk and compliance processes, procedures, and standards
  • Collaborate with IT and other departments to design and implement security controls for new and existing systems
  • Maintain and update security documentation, including System Security Plans (SSPs), Cyber Security Environment and Program Requirements “Security Controls Workbook”, Architecture Diagrams, Risk Assessments, Plan of Action and Milestones (POA&Ms), and other AO/AODR required documents, etc.
  • Monitor and analyze information systems for security incidents to identify vulnerabilities and propose solutions
  • Conduct regular security assessments and audits to evaluate the effectiveness of information system security controls,
  • Review vulnerability and compliance scan reports, and other relevant security reports and alerts for assigned systems
  • Support incident response activities, including investigation, containment, and recovery efforts and annual incident response testing
  • Lead incident response efforts for IT security and compliance breaches
  • Collaborate with IT, legal, and business teams to address and resolve IT risk and compliance issues
  • Provide guidance and recommendations to senior management on IT risk and compliance matters
  • Train and mentor staff on IT risk management and compliance best practices
  • Support business development recommending solutions, contributing to responding to Request for Proposals (RFPs), and providing input for costing/pricing
  • Stay current with industry trends, regulatory changes, and emerging risks in the IT landscape

WHAT YOU’LL NEED TO SUCCEED:

  • Education: Technical training, certificate, or degree in information/cyber security or a related field
  • Experience: Minimum of 8+ years of experience in IT risk management, IT compliance, or information security, with a significant portion in a leadership role (e.g., ISSO, ISSE, ISSM)
  • Certifications: At least one of the of the following: CISSP, CISM, and/or CISA
  • Experience managing security projects as well as delivering and supporting customer security requirements
  • Comprehension of change and configuration management and security impact analysis
  • Excellent problem-solving, analytical, and communication skills
  • Ability to effectively collaborate across multi-functional teams
  • Demonstrated experience performing complex technical tasks with minimal direction
  • Possesses experience with communicating and presenting technical solutions and status to executives, key stakeholders and decision makers
  • Experience with security tools and technologies (e.g., Firewalls, VPNs, SIEM, End Point Protection, Vulnerability & Compliance Scanning, Identity & Access Management)
  • Strong understanding of security boundary protection strategies to include Intrusion Detection/Prevention devices, compensating controls, and firewall rules
  • Experience supporting new business opportunities developing solutions, participating in oral presentations, and supporting costing / pricing

Knowledge of:

  • IT risk management frameworks and regulatory requirements (e.g., NIST, ISO 27001, COBIT, FISMA)
  • Security and privacy controls (e.g., CIS Level 2, DISA STIG)
  • GDIT Cyber Security Handbook (for internal candidates)
  • Security authorization process (e.g., FedRAMP, DoD)
  • Security audits and associated processes
  • Contingency planning and disaster recovery

PREFERRED QUALIFICATIONS:

  • Ability to obtain and maintain a Top Secret security clearance
  • Proven track record of successfully managing large-scale IT risk and compliance programs
  • Additional relevant certifications such as CISA, CISSP, CISM, CGRC, and/or CRISC
  • Familiarity with security management tools (e.g., Splunk, CrowdStrike, Qualys, Tenable, Enterprise Mission Assurance Support Service (eMASS). Archer, etc.)
  • Experience with Microsoft Office Products, Adobe Pro, Visio, JIRA, ServiceNow
  • Experience in a government or highly regulated environment (e.g., Department of Defense, Federal Civilian, Federal Health, Department of Homeland Security)
  • Knowledge of cloud security best practices and technologies
  • Experience with security automation and orchestration

Location: Hybrid at Bossier City, LA or Falls Church, VA. Candidates in Louisiana, District of Columbia, Maryland, or Virginia who are not within range of GDIT's offices in Bossier City or Falls Church may be considered for remote work.

GDIT IS YOUR PLACE
At GDIT, the mission is our purpose, and our people are at the center of everything we do.
  • Growth: AI-powered career tool that identifies career steps and learning opportunities
  • Support: An internal mobility team focused on helping you achieve your career goals
  • Rewards: Comprehensive benefits and wellness packages, 401K with company match, and competitive pay and paid time off
  • Flexibility: Full-flex work week to own your priorities at work and at home
  • Community: Award-winning culture of innovation and a military-friendly workplace


OWN YOUR OPPORTUNITY
Explore a career in cyber at GDIT and you’ll find endless opportunities to grow alongside colleagues who share your focus on defending and protecting what matters.

Work Requirements

Years of Experience

8 + years of related experience

* may vary based on technical training, certification(s), or degree

Certification

Certified Information Security Manager (CISM) | Information Systems Audit and Control Association (ISACA) - Information Systems Audit and Control Association (ISACA)

Certified Information Systems Auditor (CISA) | Information Systems Audit and Control Association (ISACA) - Information Systems Audit and Control Association (ISACA)

Certified Information Systems Security Professional (CISSP) | International Information System Security Certification Consortium (ISC2) - International Information System Security Certification Consortium (ISC2)

Travel Required

Less than 10%

Posted 2025-09-21

Recommended Jobs

Postdoctoral Associate - Systems Neuroscience: In Vivo Imaging & Electrophysiology

Virginia Tech
Roanoke, VA

Postdoctoral Associate – Systems Neuroscience: In Vivo Imaging & Electrophysiology Location: Virginia Tech, Fralin Biomedical Research Institute at VTC (Roanoke, Virginia, USA) Lab: Shin Lab | …

View Details
Posted 2025-07-30

Remote Inside Sales Representative

Right Path Law
Fairfax, VA

Inside Sales Representative – Remote Right Path Law Group, PLLC Our team is rapidly expanding, and we’re searching for a driven Inside Sales Representative! You’ll be responsible for converting…

View Details
Posted 2025-07-31

Cleaner Overnight

Grand Fitness Mgmt, LLC
Richmond, VA

Job Description Job Description Description: Planet Fitness is looking for reliable and motivated individuals to join our growing team! The Overnight Cleaner provides an essential role in ensuri…

View Details
Posted 2025-09-20

Service Lot Attendant/Porter

Casey Toyota
Williamsburg, VA

Casey Auto Group is actively seeking a Service Lot Attendant/Porter to join the team! The Service Lot Attendant is responsible for assisting with various duties related to maintaining the organizat…

View Details
Posted 2025-08-23

RN I - Palliative

Carilion Clinic
Roanoke, VA

How You’ll Help Transform Healthcare: The Palliative Care unit is an adult inpatient medical—surgical unit with 10 private patient rooms that have excellent views of the Roanoke Valley. Comprised …

View Details
Posted 2025-07-25

Property Management Specialist II

Semper Valens Solutions
Fort Belvoir, VA

Job Description Job Description Property Management Specialist II Full Time, Ft. Belvoir, VA Secret clearance required **This position is contingent upon contract award** Overview: S…

View Details
Posted 2025-08-09

Catering Production Cook - Univ. of Virginia-Catering

Aramark
Charlottesville, VA

The Virginia Catering Company, operated by UVA Dine, is seeking a skilled and dedicated Catering Production Cook to join our culinary team. This role is crucial for the efficient and high-quality pre…

View Details
Posted 2025-09-15

Mountain Views Await: Travel ER Nurse Opportunity in Harrisonburg!

NurseRecruiter
Harrisonburg, VA

Registered Nurse - Emergency Room - Travel - (ER RN) Embark on an enriching journey as a Travel ER Nurse in the charming city of Harrisonburg, surrounded by breathtaking mountain views and a vibrant …

View Details
Posted 2025-07-31

Marketing Assistant

Marine Corps Heritage Foundation (MCHF)
Triangle, VA

About Us: Are you seeking a fun, unique and interesting work environment? Consider working at the National Museum of the Marine Corps - a lasting tribute to U.S. Marine Corps history, traditions a…

View Details
Posted 2025-09-03

Deliver Care Amidst Mechanicsville’s Charm!

NurseRecruiter
Mechanicsville, VA

Registered Nurse - Labor & Delivery - Travel - (LD RN) Embrace an enchanting journey as a Labor and Delivery Registered Nurse in the picturesque Mechanicsville. Picture your first day surrounded by c…

View Details
Posted 2025-07-31