IT and Cyber Risk Auditor Principal

General Dynamics

Confirmed live yesterday High trust

Quick summary

Work type
On-site
Location
La Plata, MD
Salary
$119,000–$161,000 / yr
Posted
13 days ago
Freshness
Confirmed live yesterday

Market check

Salary context

Below market

How this pay compares to similar roles

Similar $167k
This role $140k
$109k most similar roles pay here $213k

This role pays less than 72% of similar roles. Most pay $139,000–$195,500 — the shaded band above. At the midpoint, this role pays about $140k versus about $167k for comparable roles.

Based on 239 similar postings.

Employer

About General Dynamics

General Dynamics is a global aerospace and defense company offering a broad portfolio of products and services in business aviation, ship construction, land combat vehicles, and information technology. It serves customers in the U.S. government, allied governments, and a diverse array of commercial markets.

General Dynamics currently has 1123 open roles on FindRole.

Listed pay typically runs $124,093–$150,385 across 984 roles with salary data.

Most-posted roles

View all roles at General Dynamics

At a glance

TL;DR · IT and Cyber Risk Auditor Principal

The IT and Cyber Risk Auditor Principal joins the cyber and IT risk management team to monitor and enforce security controls for technical, operational, and management support. This role involves developing system security plans, managing contingency plans, and identifying, tracking, and remediating system vulnerabilities. The individual will prepare artifacts for annual audits, review vulnerability scans, manage Plans of Action and Milestones (POA&Ms), and perform Security Technical Implementation Guide (STIG) and FISMA assessments. Key responsibilities include performing security impact analyses on change requests and providing incident response for malware or misconfigurations. Required expertise includes NIST 800-53, ICD 503, and cyber risk management. The role utilizes tools such as Splunk, Security Center, Telos XACTA, and McAfee EPO to ensure systems remain compliant with agency hardening guidelines and security policies within a government defense environment.

What you'll do

  • Develop and document system security plans, contingency plans, and other required security documentation.
  • Identify, track, and remediate system vulnerabilities to ensure compliance with security controls.
  • Prepare system artifacts for annual audits and complete Authority to Operate (ATO) security packages.
  • Manage Plans of Action and Milestones (POA&Ms) by implementing corrective actions as required.
  • Review system configurations against agency hardening guidelines and perform security impact analyses on change requests.
  • Analyze monthly vulnerability scan reports and address identified weaknesses in the POA&M tracking system.
  • Perform security system event analysis, investigation, and validation to identify potential threats.
  • Provide incident response for classification spills, malware infections, and other technical security issues.

What we're looking for

  • Must be a U.S. citizen.
  • Must possess an active Top Secret clearance with a polygraph.
  • Must maintain certification in accordance with DoD Directive 8140.01 Cyberspace Workforce Management requirements.
  • Must have a BA/BS degree or equivalent.
  • Must have at least 8 years of related experience.
  • Must have 3 to 5 years of specific experience with ICD 503 and NIST 800-53 policies.
  • Must possess senior-level experience in engineering IT systems and knowledge of current technologies.
  • Must be proficient in cyber risks, cybersecurity controls, and NIST 800-53 standards.

More like this

Similar roles

Information Security Analyst Principal

General Dynamics

Remote 6 days ago $97,968$132,250
NIST 800-53 FIPS 199 FIPS 200 Zero Trust SBOM SDLC Agile fire-wall Source Code Control VistA RPMS Information Security Data Security
10+ yrs exp Remote

Cybersecurity Engineer Principal

General Dynamics

Bossier City, LA 46 days ago $146,200$197,800
Splunk CrowdStrike Falcon Microsoft Sentinel IBM QRadar Palo Alto XSOAR Python PowerShell Bash Active Directory IAM PKI EDR SIEM SOAR Qualys Tenable Rapid7 AWS Azure GCP MITRE ATT&CK NIST 800-53 FISMA DISA STIGs CIS Benchmarks
8+ yrs exp Hybrid

Senior Principal Information Security Analyst, Cloud

General Dynamics

Fort Meade, MD 12 days ago $142,792$184,000
RMF eMASS NIST 800-53 STIGs ACAS Nessus Microsoft Defender McAfee FedRAMP Azure ICAM Cybersecurity Information Security Incident Response Vulnerability Management Firewalls API Gateways Agile
8+ yrs exp Hybrid

Principal Auditor, Cyber, Risk and Analysis Technology Audit

Capital One Financial

McLean, VA +4 73 days ago $119,400$136,200
Cybersecurity Cloud Computing AWS GCP Azure Data Analytics Information Systems Audit Risk Management Application Security Network Security Microservices Agile IT Control Frameworks CISA CISSP CISM
4+ yrs exp Hybrid

Principal Associate, Cyber Risk & Analysis

Capital One Financial

McLean, VA 2 days ago $131,300$149,800
AI Prompt Engineering Multi-agent Systems Databricks Spark AWS GCP Azure CI/CD APIs Containers NIST CSF PCI DSS SOX ITGC FFIEC SIEM SOAR
3+ yrs exp

Cyber Security Principal

FedEx

Memphis, TN +2 10 days ago
Threat Modeling Security Automation Secure Architecture Python Java Go C# AWS Azure GCP OSCP OSWE GWAPT CISSP Multi-cloud Information Security Risk Frameworks
5+ yrs exp Hybrid