Jobs · Information Technology · Virginia

Continuous Monitoring Specialist (SCA)— Level III

Rividium Inc · Quantico, VA · Yesterday
Information TechnologyFull-time

About the Role

RiVidium Inc. is seeking an experienced Continuous Monitoring Specialist — Level III to serve the team for all Cybersecurity and Intelligence Enterprise Information Technology Services (CIEITS) program activities. The Continuous Monitoring Specialist — Level III provides senior-level cybersecurity continuous monitoring support across the Department of Homeland Security (DHS) Intelligence Enterprise (DHS IE). This position is responsible for ensuring assigned information systems remain compliant with the DHS I&A Chief Information Security Officer (CISO) Continuous Monitoring (ConMon) Program by performing ongoing security assessments, vulnerability management, audit log reviews, POA&M oversight, and security metrics reporting. The Continuous Monitoring Specialist works closely with Information System Security Officers (ISSOs), Information System Security Managers (ISSMs), system owners, engineers, and cybersecurity teams to maintain the security posture of enterprise systems throughout the Authorization to Operate (ATO) lifecycle. The ideal candidate possesses extensive experience with NIST Risk Management Framework (RMF), continuous diagnostics and mitigation, vulnerability management, security compliance, and cybersecurity reporting within classified Federal or Intelligence Community (IC) environments.

Key Responsibilities

  • Ensure all assigned DHS Intelligence Enterprise systems are enrolled in and remain compliant with the DHS I&A CISO Continuous Monitoring (ConMon) Program.
  • Perform and oversee scheduled vulnerability scans (bi-weekly, monthly, or as required) for assigned ATO packages using approved scanning tools.
  • Analyze vulnerability assessment results and coordinate remediation activities with ISSOs, system owners, engineers, and development teams.
  • Manage and track Plans of Action and Milestones (POA&Ms) in accordance with established review intervals (30, 60, 90, 120, and 180 days).
  • Monitor remediation progress and ensure timely updates are documented within the Governance, Risk, and Compliance (GRC) platform.
  • Conduct and review weekly audit log analyses to identify anomalous or suspicious activities and coordinate appropriate follow-up actions.
  • Respond to Network Operations and Security Center (NOSC) alerts and security events associated with assigned information systems.
  • Prepare and maintain Continuous Monitoring Executive Reports, including quarterly (or monthly when automated) ConMon reports and CPEM Data Collection Matrix (Scorecard) submissions.
  • Develop security metrics, dashboards, and trend analyses to support executive reporting and cybersecurity decision-making.
  • Identify opportunities to automate continuous monitoring processes, reporting, and compliance activities to improve operational efficiency.
  • Develop, maintain, and update Continuous Monitoring Standard Operating Procedures (SOPs) to ensure compliance with DHS, Intelligence Community, and Federal cybersecurity policies.
  • Participate in Intelligence Community continuous monitoring working groups and communicate policy updates, best practices, and implementation guidance to program stakeholders.
  • Support security authorization activities, ongoing assessments, and annual control reviews throughout the system lifecycle.
  • Collaborate with cybersecurity engineering, operations, and compliance teams to ensure enterprise security requirements are consistently implemented and maintained.

Minimum Qualifications

  • Active Top Secret/Sensitive Compartmented Information (TS/SCI) clearance.
  • Minimum 7–10 years of experience supporting cybersecurity, continuous monitoring, information assurance, or ISSO/ISSM functions within the Federal Government or Intelligence Community.
  • Demonstrated expertise implementing Continuous Monitoring requirements in accordance with NIST SP 800-137, NIST SP 800-53, NIST Risk Management Framework (RMF), CNSSI 1253, and Intelligence Community Continuous Monitoring (IC ConMon) requirements.
  • Experience performing vulnerability management using tools such as Nessus, ACAS, and Tenable Security Center.
  • Experience using Governance, Risk, and Compliance (GRC) platforms, including RSA Archer or equivalent.
  • Experience conducting audit log analysis using Security Information and Event Management (SIEM) solutions.
  • Experience developing cybersecurity dashboards, compliance metrics, executive reports, and POA&M tracking.
  • Strong understanding of system authorization, security controls, vulnerability remediation, and continuous assessment processes.
  • Bachelor's degree in Cybersecurity, Information Systems, Computer Science, Information Assurance, or a related technical discipline.

Preferred Qualifications

  • Experience supporting DHS Intelligence & Analysis (I&A) or other Intelligence Community cybersecurity programs.
  • AWS Certified Security – Specialty, Microsoft Azure Security Engineer Associate, or comparable cloud security certification.
  • Experience automating Continuous Monitoring workflows using scripting, APIs, PowerShell, or Python.
  • Familiarity with Continuous Protection and Evaluation Metrics (CPEM) reporting requirements.
  • Experience integrating vulnerability management, SIEM, and GRC platforms to improve cybersecurity reporting and operational efficiency.
  • Knowledge of Continuous Diagnostics and Mitigation (CDM) tools and enterprise cybersecurity monitoring solutions.

Required Certifications

One or more of the following current certifications: Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), or Certified Authorization Professional (CAP).

Similar jobs