Job Requirements
Washington, DC
Secret Polygraph Unspecified
Career Level not specified
Salary not specified
Join Premium to unlock estimated salaries
Job Description
Title Senior Continuous Monitoring (ConMon) Analyst Full-Time/Part-Time Full-Time Description
Summary
RiVidium Inc. seeking a Senior Continuous Monitoring (ConMon) Analyst to support federal cybersecurity and Risk Management Framework (RMF) activities. The Senior ConMon Analyst will provide cybersecurity continuous monitoring, security assessment, risk analysis, and compliance support to ensure information systems remain compliant with applicable federal security requirements.
The ideal candidate will have strong experience with RMF, security controls, continuous monitoring, vulnerability management, POA&M management, security documentation, and Governance, Risk, and Compliance (GRC) tools. This position requires the ability to work closely with Information System Security Officers (ISSOs), Information System Security Managers (ISSMs), Security Control Assessors (SCAs), system owners, engineers, and government stakeholders.
Key Responsibilities
Required:
About the Organization Established in 2008, RiVidium, Inc. (dba TripleCyber) is a VA-Verified SDVOSB and an SBA-Certified 8(a) company. To prepare our clients for the future, RiVidium has balanced all parts of our organization to attract the finest employees in order to 'Strive to be the missing element defining tomorrow's technology'. RiVidium keeps pace and surpasses its competitors by meeting challenges of advancements in Logistics, Human Capital, Cyber, Intelligence & Technology. EOE Statement We are an equal employment opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veteran status or any other characteristic protected by law. If you need a reasonable accommodation for any part of the employment process, please contact Human Resources (HR) at hr@rividium.com.
This position is currently accepting applications.
Summary
RiVidium Inc. seeking a Senior Continuous Monitoring (ConMon) Analyst to support federal cybersecurity and Risk Management Framework (RMF) activities. The Senior ConMon Analyst will provide cybersecurity continuous monitoring, security assessment, risk analysis, and compliance support to ensure information systems remain compliant with applicable federal security requirements.
The ideal candidate will have strong experience with RMF, security controls, continuous monitoring, vulnerability management, POA&M management, security documentation, and Governance, Risk, and Compliance (GRC) tools. This position requires the ability to work closely with Information System Security Officers (ISSOs), Information System Security Managers (ISSMs), Security Control Assessors (SCAs), system owners, engineers, and government stakeholders.
Key Responsibilities
- Perform continuous monitoring of information systems to identify changes in security posture, vulnerabilities, risks, and compliance status.
- Support implementation and execution of Continuous Monitoring (ConMon) strategies in accordance with federal cybersecurity requirements and organizational policies.
- Monitor security controls and assess ongoing control effectiveness through documentation reviews, technical evidence, vulnerability data, and other assessment activities.
- Support NIST Risk Management Framework (RMF) activities throughout the system lifecycle.
- Review security controls, assessment results, system changes, vulnerabilities, and security-related artifacts to identify potential risks and compliance gaps.
- Track, analyze, and report security weaknesses, vulnerabilities, and Plans of Action and Milestones (POA&Ms).
- Coordinate with ISSOs, ISSMs, SCAs, system owners, and technical teams to ensure identified security deficiencies are properly documented and remediated.
- Maintain and update cybersecurity documentation, including security assessment evidence, control implementation statements, POA&Ms, risk assessments, and continuous monitoring reports.
- Review vulnerability scan results and other security assessment data to determine potential impact to system security posture.
- Support security impact analyses for system changes, configuration changes, new technologies, and changes to the operational environment.
- Assist with preparation of recurring security and compliance reports for government leadership and cybersecurity stakeholders.
- Analyze security metrics and trends to identify recurring weaknesses and recommend risk mitigation strategies.
- Support security control testing, assessment, and validation activities as required.
- Ensure continuous monitoring activities are properly documented and aligned with applicable policies, standards, and federal regulations.
- Use GRC and cybersecurity tools to maintain system security information, control status, assessment findings, POA&Ms, and compliance documentation.
- Participate in cybersecurity working groups, risk reviews, security meetings, and technical discussions with government and contractor stakeholders.
- Provide recommendations to improve cybersecurity processes, control effectiveness, risk management, and compliance posture.
- Stay current on evolving federal cybersecurity policies, NIST guidance, threats, vulnerabilities, and security best practices.
- Bachelor's degree in Cybersecurity, Information Systems, Computer Science, Information Assurance, or a related field.
- Demonstrated professional experience supporting cybersecurity, continuous monitoring, RMF, security compliance, or information assurance programs.
- Strong understanding of the NIST Risk Management Framework (RMF) and NIST cybersecurity standards.
- Experience with security controls, security assessments, vulnerability management, risk management, and POA&M tracking.
- Experience analyzing security documentation and technical evidence to determine control compliance and system security posture.
- Experience working with cybersecurity stakeholders, including ISSOs, ISSMs, SCAs, system owners, and system administrators/engineers.
- Strong written and verbal communication skills with the ability to prepare clear technical and executive-level security reports.
- Ability to manage multiple systems, security requirements, findings, and competing priorities in a federal environment.
- CISM, CAP, or equivalent GRC/cybersecurity certification.
- Experience with GRC platforms such as RSA Archer, ServiceNow GRC, eMASS, or equivalent tools.
- Experience supporting federal civilian or Department of Defense cybersecurity programs.
- Knowledge of NIST SP 800-37, NIST SP 800-53, NIST SP 800-30, NIST SP 800-137, FISMA, and related federal cybersecurity requirements.
- Experience with vulnerability management and security scanning tools.
- Experience developing dashboards, metrics, and cybersecurity status reports.
- Experience supporting ATO, continuous authorization, security assessment, and ongoing authorization activities.
- Familiarity with federal cybersecurity policies, standards, and compliance requirements.
- Risk Management Framework (RMF)
- Continuous Monitoring (ConMon)
- NIST 800-53 security controls
- Security Assessment & Authorization (A&A)
- Authority to Operate (ATO)
- POA&M management
- Vulnerability Management
- Risk Assessment
- Security Control Assessment
- GRC tools
- Cybersecurity compliance
- Security documentation
- Security metrics and reporting
- Federal cybersecurity policies and standards
Required:
- Bachelor's degree in Cybersecurity, Information Systems, Computer Science, Information Assurance, or related field.
- Certified Information Security Manager (CISM)
- Certified Authorization Professional (CAP)
- Equivalent GRC, cybersecurity, or information assurance certification
About the Organization Established in 2008, RiVidium, Inc. (dba TripleCyber) is a VA-Verified SDVOSB and an SBA-Certified 8(a) company. To prepare our clients for the future, RiVidium has balanced all parts of our organization to attract the finest employees in order to 'Strive to be the missing element defining tomorrow's technology'. RiVidium keeps pace and surpasses its competitors by meeting challenges of advancements in Logistics, Human Capital, Cyber, Intelligence & Technology. EOE Statement We are an equal employment opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veteran status or any other characteristic protected by law. If you need a reasonable accommodation for any part of the employment process, please contact Human Resources (HR) at hr@rividium.com.
This position is currently accepting applications.
group id: RTX15cf25