Cyber Compliance Officer

USA VA Falls ChurchFull-time$102k–$138kPosted Jul 20, 2026

Type of Requisition:

Regular

Clearance Level Must Currently Possess:

Secret

Clearance Level Must Be Able to Obtain:

Secret

Public Trust/Other Required:

None

Job Family:

Cyber and IT Risk Management

Job Qualifications:

Skills:

Customer Service, Cybersecurity Compliance, Information Technology Security, IT Documentation, RMF

Certifications:

None

Experience:

4 + years of related experience

US Citizenship Required:

Yes

Job Description:

Cyber Compliance Officer

We are GDIT. We stay at the forefront of innovation to solve complex technical challenges. GDIT is your place—make it your own by discovering new ways to apply the latest technologies securely and expertly. Our work depends on a Cyber Compliance Officer joining our team to support the Guard Enterprise Cyber Operations Support (GECOS) program in Falls Church, VA.

This is an IT Service Management (ITSM) contract supporting the operation, modernization, expansion, and evolution of the Army National Guard’s (ARNG) global IT services, including networking, compute, storage, infrastructure, applications, hosting, and program management. The GECOS program supports the ARNG enterprise IT infrastructure, its WAN, authentication and directory services, cybersecurity, application hosting, and associated services, leveraging ITIL best practices.

As a Cyber Compliance Officer, you will provide cybersecurity compliance support in accordance with applicable DoD and Army guidance and regulations. You will work closely with the client and senior staff, so clear, articulate communication is essential. You must be collaborative and able to work within a team, while also being a self-starter who can complete tasks independently and explain complex technical information in an easily understood manner.

Responsibilities

The Cyber Compliance Officer will:

  • Provide Risk Management Framework (RMF) support to the 54 supported organizations (50 states, three territories, and the District of Columbia) for Installation Campus Area Networks (ICANs) and HQ Enterprise investments, including eMASS record reviews.
  • Serve as an RMF SME to the 54, delivering customer training and briefs, managing multiple states simultaneously, and briefing the Program Information System Security Manager (P-ISSM) on progress, hurdles, and roadblocks.
  • Provide RMF support for Steps 0–3, 5, and 6:
    • Step 0: Deliver RMF roles and responsibilities training.
    • Step 1: Guide system/ICAN categorization.
    • Step 2: Guide security control baseline selection.
    • Step 3: Advise on security control implementation and delegation of technology areas in eMASS.
    • Step 5: Support submission of ATO package artifacts to the Authorizing Official.
    • Step 6: Support continuous monitoring (ConMon) strategies and execution.
  • Identify and maintain cybersecurity compliance requirements for IT investments of the 54 and the DoDIN-A(NG) and DoDIN-A(NG)-S networks and computing services.
  • Ensure adherence to DoD, DISA, and Department of the Army enterprise security requirements, including preparation for and successful completion of CCRIs, obtaining and maintaining Authority to Connect (ATC) and Authority to Operate (ATO), and compliance with STIGs and required IA controls.
  • Help ensure compliance with Army directives and mandates aligned with the future Joint Information Environment (JIE) architecture.
  • Measure ARNG compliance with cybersecurity requirements and recommend program execution activities, processes, and practices.
  • Assist with secure configuration and preparation of IT below the system level (Software Assurance) across the 54 in coordination with RCC-NG, in accordance with applicable guidance prior to acceptance into or connection to Army IS and DoDIN-A(NG).
  • Maintain an Accreditations and Expiration Dates Record for upcoming accreditation expirations using RMF Work Management SharePoint tracking tools.
  • Ensure cybersecurity inspections, tests, assessments, and reviews are synchronized and coordinated with all stakeholders.
  • Assist in the implementation, management, and administration of organizational structure and workflow within eMASS.
  • Review cybersecurity information papers and plans with CYBERCOM, ARCYBER, Air National Guard Cyber, NSA, FBI, DOJ, and DHS.
  • Support enforcement of the DoD Cyberspace Workforce Framework (DCWF) and cybersecurity certification program to ensure training and certification are enforced, managed, and reported.
  • Help implement a streamlined process for reviewing, processing, and approving eMASS system access requests in support of RMF.
  • Assist in examining security architectures and vulnerabilities through scans, configuration reviews, design documentation, and stakeholder interviews.
  • Support identification, dissemination, and delivery of approved policy and process documentation for system authorization efforts using DoD, Army, and NIST guidance.

Qualifications

Education / Training

  • Bachelor’s degree in cybersecurity, information assurance, computer science, or related technical discipline; or equivalent combination of education, technical certifications/training, and work experience.

Experience

  • 4–6 years of experience in cybersecurity, information assurance, or computer science.
  • Hands-on RMF experience across Steps 0–6 is required.

Technical & Professional Skills

  • Strong problem-solving, analytical, and decision-making skills.
  • Ability to understand user requirements, troubleshoot technical issues, and develop creative process improvements.
  • Demonstrated dependability: punctual, follows instructions, responds to direction, and seeks feedback.
  • Customer service experience and comfort engaging with senior military and government leadership.
  • Ability to clearly present ideas through briefings, meetings, and interaction with leadership of varied technical backgrounds.
  • Ability to deliver training sessions and engage stakeholders to ensure task progress and adherence to timelines.
  • Excellent communication and documentation skills.
  • Strong organizational, collaborative, and teamwork skills.
  • Ability to rapidly assimilate new information and self-study emerging requirements.
  • Current industry knowledge of relevant concepts, practices, and procedures.
  • Ability to work under time constraints and adapt to changing requirements and new projects.
  • Commitment to maintaining and upgrading certifications.
  • Other duties as assigned.

Certifications

  • Must meet DoD 8570 IAM-I (e.g., Security+ CE); certification must be current and included with resume.
  • Must obtain an additional certification within one year (e.g., CGRC, CISM, CISSP or CISSP Associate).

Clearance

  • Active Secret clearance required at time of interview and must be maintained.

Work Location & Schedule

  • Location: Falls Church, VA
  • Hours and days TBD upon hire; occasional schedule adjustments may be required.
  • On-site support required for the first 3 months. Pending performance, part-time telework may be considered (3 days onsite, up to 2 days remote per week). The government may require full-time onsite work.

Travel

  • Up to 10% travel.
  • May include up to two conferences annually and site visits to the 54 up to eight times annually.

The likely salary range for this position is $102,000 - $138,000. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.

Scheduled Weekly Hours:

40

Travel Required:

10-25%

Telecommuting Options:

Hybrid

Work Location:

USA VA Falls Church

Additional Work Locations:

Total Rewards at GDIT:

Our benefits package for all US-based employees includes a variety of medical plan options, some with Health Savings Accounts, dental plan options, a vision plan, and a 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match. To encourage work/life balance, GDIT offers employees full flex work weeks where possible and a variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave. To ensure our employees are able to protect their income, other offerings such as short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available. We regularly review our Total Rewards package to ensure our offerings are competitive and reflect what our employees have told us they value most.

 

 


Our Identity Verification Process:

As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during virtual interviews. We reserve the right to take your picture to verify your identity and prevent fraud. By proceeding, you authorize the collection, processing, and use of your biometric data for identity verification and security purposes.

 

 

About Our Work:

We are GDIT. A global technology and professional services company that delivers technology solutions and mission services to every major agency across the U.S. government, defense and intelligence community. Our 26,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. We operate across 50+ countries worldwide, offering leading mission-ready capabilities in AI, cloud, cyber and software development.

Join our Talent Community to stay up to date on our career opportunities and events at

gdit.com/tc.

Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans

Want jobs like this matched to you?

Swoopd scores fresh postings against your résumé so you only see the matches that matter.

Get started free