General Dynamics Information Technology logo

IT and Cyber Risk Auditor Principal

General Dynamics Information Technology
  • Las Cruces, New Mexico
    3 days ago

    Job Description

    Type of Requisition:

    Regular

    Clearance Level Must Currently Possess:

    Top Secret SCI + Polygraph

    Clearance Level Must Be Able to Obtain:

    Top Secret SCI + Polygraph

    Public Trust/Other Required:

    None

    Job Family:

    Cyber and IT Risk Management

    Job Qualifications:

    Skills:

    Cyber Risks, Cybersecurity Controls, Cybersecurity Risk Management, Security Controls, Security Risk

    Certifications:

    None

    Experience:

    5 + years of related experience

    US Citizenship Required:

    Yes

    Job Description:

    Your Impact

    Own your opportunity as an IT & Cyber Risk Auditor Principal at GDIT. You’ll lead enterprise-level IT and cybersecurity risk and compliance assessments that help secure the systems and data vital to our national security missions. At GDIT, the mission is our purpose, and our people are at the center of everything we do.

    As a trusted audit leader, you’ll evaluate cyber and IT controls, identify risk exposure, and influence remediation strategies while partnering with cross-functional teams to strengthen enterprise risk posture. Your work will have meaningful impact across federal government and defense programs.

    What You’ll Do

    • Lead and execute rigorous IT and cybersecurity risk audits and assessments
    • Evaluate IT general controls, cybersecurity controls, and risk management processes
    • Assess compliance with federal frameworks and guidance (e.g., NIST, RMF, FISMA, FedRAMP, ISO 27001)
    • Identify and document control gaps, risk exposures, and areas for process improvement
    • Provide risk-based recommendations and actionable insights to senior leadership and stakeholders
    • Support preparation of audit reports and executive briefings
    • Manage and execute system Certification and Accreditation processes, ensuring compliance with security controls and requirements outlined in agency policies.
    • Collaborate with cybersecurity, IT, compliance, and program teams to drive remediation and sustainable improvements
    • Participate in internal and external audit activities, including customer assessments
    • Experience using XACTA data base applications and the ICD 503, NIST 800-83 rev4 policy
    • Review monthly vulnerability scan reports and track and address weaknesses in plans as needed.
    • Perform security system event analysis, investigation, and validation
    • Provide incident response to classification spills, malware infection, misconfiguration exposure, internal inappropriate behavior and technical issue
    • Perform Security Technical Implementation Guide (STIG) and Federal Information Security Management Act (FISMA) assessments and annual reporting
    • Work and completing multiple Authority to Operate (ATO) security packages simultaneously

    What You’ll Need to Succeed

    • 5+ years of progressive experience to an intermediate level in IT audits, cybersecurity risk management, or information assurance
    • Experience using XACTA data base applications and the ICD 503, NIST 800-83 rev4 policy
    • Experience with Splunk, Security Center, Telos XACTA, and MacAfee EPO
    • Expertise with cybersecurity and IT control frameworks and compliance requirements
    • Experience conducting complex IT and cybersecurity audits in government or federal contracting environments
    • Experience with cloud security risk assessments and modern technologies
    • Clear and effective communication skills with the ability to influence technical and executive audiences
    • Ability to multi-task, prioritize, and re-prioritize work in a fast-paced environment
    • Ability to learn an application environment in order to update or create supported security documentation

    Qualifications

    • Bachelor’s degree or equivalent military training in Information Systems, Cybersecurity, Computer Science, Accounting, or related field
    • Maintain certification in accordance with DoW Directive 8140.01 Cyberspace Workforce Management requirements
    • Applicable certifications include: SecurityX / CASP+, CGRC/CAP, GSEC, GSNA, Security+, SSCP, CISSP, CISM
    • Currently hold certification in good standing to satisfy IAM Level II (Information Assurance Management Level 2) per DoW 8570/8140
    • Hold a current security clearance of Top Secret/Special Compartmented Information (TS/SCI) with an in-scope counter-intelligence (CI) or full-scope polygraph. Successfully completed Tier 5 investigation (T5), formerly known as a Single Scope Background Investigation (SSBI) by the federal government within the last 5 years, or requires candidate to have been enrolled in a Continuous Vetting program within the last 5 years

    GDIT Is Your Place

    At GDIT, you’ll work alongside mission-first teams solving some of the nation’s most complex cybersecurity challenges. Our people grow here — with opportunities for career development, continuous learning, professional certifications, and internal mobility. We offer a comprehensive total rewards package, including competitive pay, robust benefits, and a culture dedicated to your success.

    Own your opportunity. Join a community where your work makes a real difference to mission success and national security.

    The likely salary range for this position is $110,500 - $149,500. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.

    Scheduled Weekly Hours:

    40

    Travel Required:

    Less than 10%

    Telecommuting Options:

    Onsite

    Work Location:

    USA NM Las Cruces

    Additional Work Locations:

    Total Rewards at GDIT:

    Our benefits package for all US-based employees includes a variety of medical plan options, some with Health Savings Accounts, dental plan options, a vision plan, and a 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match. To encourage work/life balance, GDIT offers employees full flex work weeks where possible and a variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave. To ensure our employees are able to protect their income, other offerings such as short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available. We regularly review our Total Rewards package to ensure our offerings are competitive and reflect what our employees have told us they value most.

     

     


    Our Identity Verification Process:

    As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during virtual interviews. We reserve the right to take your picture to verify your identity and prevent fraud. By proceeding, you authorize the collection, processing, and use of your biometric data for identity verification and security purposes.

     

     

    About Our Work:

    We are GDIT. A global technology and professional services company that delivers technology solutions and mission services to every major agency across the U.S. government, defense and intelligence community. Our 26,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. We operate across 50+ countries worldwide, offering leading mission-ready capabilities in AI, cloud, cyber and software development.

    Join our Talent Community to stay up to date on our career opportunities and events at

    gdit.com/tc.

    Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans

    Numbers & Facts

    LocationLas Cruces, New Mexico
    IndustryAerospace and Defense
    Company Size10,000 employees or more
    Websitehttps://gdit.com/careers

    About Company

    General Dynamics Information Technology solves our customers’ challenges through future-focused technology and services, ingenuity and deep mission-knowledge. Partnering with government, defense, the intelligence community, industry leaders and cutting-edge technology companies, we deliver solutions that make a difference – helping our customers to advance mission performance, transform operations and discover opportunities to build a better future.

    Headquartered in Fairfax, Va., with major offices worldwide, General Dynamics IT and General Dynamics Mission Systems form the Information Systems and Technology (IS&T) business group of General Dynamics. IS&T and the Aerospace, Combat Systems and Marine Systems groups form General Dynamics Corp.

    Skills

    • Accidental Death and Dismemberment (AD&D)unmatched
    • Accountingunmatched
    • Artificial Intelligence (AI)unmatched
    • Auditingunmatched
    • Biometricsunmatched
    • CISM - Certified Information Security Managerunmatched
    • CISSP - Certified Information Systems Security Professionalunmatched
    • Certification & Accreditation Process (C&A)unmatched
    • Cloud Computingunmatched
    • Communication Skillsunmatched
    • CompTIA Security+unmatched
    • Computer Scienceunmatched
    • Contract Requirementsunmatched
    • Cross-Functionalunmatched
    • Cyberspaceunmatched
    • Defense Intelligenceunmatched
    • Document Controlunmatched
    • Establish Prioritiesunmatched
    • External Auditunmatched
    • FISMA - Federal Information Security Management Actunmatched
    • Federal Contractsunmatched
    • Federal Governmentunmatched
    • GSEC - GIAC Security Essentials Certificationunmatched
    • GSNA - GIAC System & Network Auditorunmatched
    • Governmentunmatched
    • Government Contractsunmatched
    • Health Planunmatched
    • IAM - Information Assurance Managementunmatched
    • ISO (International Organization for Standardization)unmatched
    • Incident Responseunmatched
    • Information Technology & Information Systemsunmatched
    • Information Technology/Systems Auditunmatched
    • Information/Data Security (InfoSec)unmatched
    • Insuranceunmatched
    • Intelligence Communityunmatched
    • Internal Auditunmatched
    • International Classification of Diseases (ICD)unmatched
    • Internet Securityunmatched
    • Leadershipunmatched
    • Maintain Complianceunmatched
    • Malwareunmatched
    • Militaryunmatched
    • Multitaskingunmatched
    • Process Improvementunmatched
    • Professional Servicesunmatched
    • Regulatory Complianceunmatched
    • Riskunmatched
    • Risk Analysisunmatched
    • Risk Managementunmatched
    • SSCP - Systems Security Certified Practitionerunmatched
    • Security Analysisunmatched
    • Security Complianceunmatched
    • Single Scope Background Investigation (SSBI)unmatched
    • Software Developmentunmatched
    • Splunkunmatched
    • Systems Administration/Managementunmatched
    • Systems Analysisunmatched
    • Technical Deliveryunmatched
    • U.S. National Institute of Standards and Technology (NIST)unmatched
    • United States Citizenunmatched
    • Vulnerability Scannersunmatched
    • Willing to Travelunmatched
    • Workforce Managementunmatched

    Be found by employers

    5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

    Level up your application

    Professional resume templates

    Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

    Free resume templates

    Free resume builder

    Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

    Free resume builder