Cybersecurity GRC Analyst

🏢 Dragonfli Group · all 11 jobs
📍 United States
📅 Posted Sep 20, 2026 · via Himalayas
🏷 Governance Risk And Compliance (grc), Cybersecurity Grc Analyst, Assessment And Authorization, Federal Cybersecurity, Risk Management, Cybersecurity Grc Specialist +7 more
Apply on original site ↗

Description

Dragonfli Group is a cybersecurity and IT consulting firm providing services to federal agencies and Fortune 100 enterprises. Headquartered in Washington, DC, Dragonfli supports clients in securing mission-critical systems across on-site, hybrid, and fully remote environments.

Dragonfli Group is seeking a Cyber Governance and Compliance Specialist to support a multi-year cybersecurity program for a large federal agency. You will tell the organization whether its information systems are operating at an acceptable level of risk, and you will back that judgment with evidence: risk trade-off analyses, risk mitigation strategies, POA&M review, and comprehensive assessments of risk posture. You will provide the technical analysis that supports authorization decisions across the full risk management lifecycle, from categorizing a system through selecting, implementing, and assessing its controls. This is a versatile, stakeholder-facing role. You will present findings and recommendations to both technical and non-technical decision makers and advise them on designs, implementations, and solutions that protect against cybersecurity attacks. It suits an assessment and authorization practitioner with at least 4+ years of cyber governance and compliance experience who is as comfortable in a briefing as in an assessment.

This is a multi-year contract position involving a large US federal agency. Candidates with previous federal contracting experience are preferred. U.S. Citizenship or Permanent Residency is required. If hired, all work related to this role must be performed within the continental U.S.
This position is fully remote.

Responsibilities

- Provide information on whether information systems are operating at an acceptable level of risk to the organization

- Support information system authorization decisions with technical analysis and supporting evidence

- Perform risk trade-off analyses and develop risk mitigation strategies and solutions

- Review information system Plans of Action and Milestones (POA&Ms) and track remediation

- Support cybersecurity risk management activities including categorizing a system, selecting security controls, implementing security controls, and providing comprehensive assessments of the organization’s risk posture

- Execute Security Control Assessments in accordance with NIST SP 800-37 and NIST SP 800-53A

- Prepare and deliver briefings of assessment results and recommendations supporting an authorization decision

- Support implementation and maintenance of Integrated Risk Management (IRM) processes

- Support the agency’s Supply Chain Risk Management (SCRM) and Third-Party Risk Management (TPRM) programs

- Maintain the Cyber Risk Register and track cybersecurity regulations, guidance, and data calls

- Support FISMA score and maturity improvements, and normalize and translate cyber risks to support enterprise-wide risk visibility

- Develop and maintain cybersecurity dashboards aligned with key performance metrics (hosted on Power BI)

- Apply automation and AI tooling to streamline risk reporting, compliance tracking, performance analysis, and regulatory monitoring

Requirements
Must-Have

- Bachelor’s degree in cybersecurity, information technology, or a related field

- 4 or more years of cyber governance, risk, and compliance experience

- Assessment and Authorization (RMF) subject matter expertise, including hands-on experience testing and assessing cybersecurity solutions

- Demonstrated experience performing risk trade-off analyses and developing risk mitigation strategies

- Experience reviewing POA&Ms and supporting authorization decisions

- Experience presenting to clients or other decision makers, adapting the message to technical and non-technical audiences

- Ability to work independently and as a member of a team

- U.S. Citizenship or Permanent Residency, with all work performed within the continental U.S.

- Ability to pass a federal agency suitability

Flights + hotels

This role requires you to be in the United States. If that means relocating or flying in, it is worth checking fares before you commit to a start date.

Compare flights and hotels →

← All remote jobs

Want more like this? Browse every live remote developer role.All remote developer jobs →
Get new developer jobs by email
Daily email, only when there's something new. One click to stop.

Get remote developer jobs like this by email

10 hand-picked jobs, one email a day. No spam, unsubscribe anytime.

Similar for you