Job description
Description
Dragonfli Group is a cybersecurity and IT consulting firm providing services to federal agencies and Fortune 100 enterprises. Headquartered in Washington, DC, Dragonfli supports clients in securing mission-critical systems across on-site, hybrid, and fully remote environments.
Dragonfli Group is seeking a Cyber Governance and Compliance Specialist to support a multi-year cybersecurity program for a large federal agency. You will tell the organization whether its information systems are operating at an acceptable level of risk, and you will back that judgment with evidence: risk trade-off analyses, risk mitigation strategies, POA&M review, and comprehensive assessments of risk posture. You will provide the technical analysis that supports authorization decisions across the full risk management lifecycle, from categorizing a system through selecting, implementing, and assessing its controls. This is a versatile, stakeholder-facing role. You will present findings and recommendations to both technical and non-technical decision makers and advise them on designs, implementations, and solutions that protect against cybersecurity attacks. It suits an assessment and authorization practitioner with at least 4+ years of cyber governance and compliance experience who is as comfortable in a briefing as in an assessment.
This is a multi-year contract position involving a large US federal agency. Candidates with previous federal contracting experience are preferred. U.S. Citizenship or Permanent Residency is required. If hired, all work related to this role must be performed within the continental U.S.
This position is fully remote.
Responsibilities
Provide information on whether information systems are operating at an acceptable level of risk to the organization
Support information system authorization decisions with technical analysis and supporting evidence
Perform risk trade-off analyses and develop risk mitigation strategies and solutions
Review information system Plans of Action and Milestones (POA&Ms) and track remediation
Support cybersecurity risk management activities including categorizing a system, selecting security controls, implementing security controls, and providing comprehensive assessments of the organization’s risk posture
Execute Security Control Assessments in accordance with NIST SP 800-37 and NIST SP 800-53A
Prepare and deliver briefings of assessment results and recommendations supporting an authorization decision
Support implementation and maintenance of Integrated Risk Management (IRM) processes
Support the agency’s Supply Chain Risk Management (SCRM) and Third-Party Risk Management (TPRM) programs
Maintain the Cyber Risk Register and track cybersecurity regulations, guidance, and data calls
Support FISMA score and maturity improvements, and normalize and translate cyber risks to support enterprise-wide risk visibility
Develop and maintain cybersecurity dashboards aligned with key performance metrics (hosted on Power BI)
Apply automation and AI tooling to streamline risk reporting, compliance tracking, performance analysis, and regulatory monitoring
Requirements
Must-Have
Bachelor’s degree in cybersecurity, information technology, or a related field
4 or more years of cyber governance, risk, and compliance experience
Assessment and Authorization (RMF) subject matter expertise, including hands-on experience testing and assessing cybersecurity solutions
Demonstrated experience performing risk trade-off analyses and developing risk mitigation strategies
Experience reviewing POA&Ms and supporting authorization decisions
Experience presenting to clients or other decision makers, adapting the message to technical and non-technical audiences
Ability to work independently and as a member of a team
U.S. Citizenship or Permanent Residency, with all work performed within the continental U.S.
Ability to pass a federal agency suitability or background investigation
Preferred / Nice-to-Have
Prior federal contracting experience supporting a civilian agency governance or compliance program
Experience with Integrated Risk Management, Supply Chain Risk Management, or Third-Party Risk Management programs
Experience supporting FISMA reporting and maturity improvement
Experience building or maintaining cybersecurity dashboards and KPI reporting
Experience with JCAM, the agency’s GRC platform of record (formerly known as CSAM)
Familiarity with automation, low-code/no-code, or AI-assisted compliance tooling
Certifications such as CGRC (formerly CAP), CISA, CRISC, CISM, or CISSP
Skill(s)
Technical Skills
Assessment and Authorization (RMF) subject matter expertise under NIST SP 800-37
Security control assessment and testing under NIST SP 800-53A
Risk trade-off analysis and risk mitigation strategy development
POA&M review, tracking, and remediation oversight
Integrated Risk Management, SCRM, and TPRM program support
Cyber risk register maintenance and regulatory and data call tracking
FISMA reporting and maturity improvement
Cybersecurity dashboard and KPI development (Power BI)
Automation and AI-assisted compliance tracking and reporting
Soft Skills
Clear written and verbal communication with both technical and non-technical audiences
Ability to work independently and as a contributing member of a distributed team
Comfort operating in a fully remote setting with a camera-on meeting culture
Sound judgment about when to decide and when to escalate
Collaborative posture with system owners, business owners, developers, and assessors
Attention to documentation quality and follow-through on commitments
Benefits
Dragonfli Group offers a comprehensive benefits package that includes:
Medical: Multiple POS health plan options including an HSA-compatible plan
Dental: PPO coverage for preventive, basic, and major services
Vision: Annual exam, frames, lenses, and contact lens allowance
401(k): Employer match up to 5% of eligible compensation
Long-Term Disability: 100% employer-paid coverage at 50% of pre-disability earnings
Life Insurance & AD&D: 100% employer-paid coverage valued at $10,000 each
PTO: 15-25 days annually based on tenure
Paid Federal Holidays: All 11 federal holidays observed
Originally posted on Himalayas
Who can apply
Eligible countries: United States. Accepted UTC offsets: UTC-10, UTC-9, UTC-8, UTC-7, UTC-6, UTC-5, UTC+14. Review the full description for employer-specific work authorization, residency and schedule requirements.