Enter a job title or keyword

Senior Continuous Monitoring (ConMon) Analyst

Rividium


Job Location:

Washington, AR - USA

Monthly Salary: Not provided by the employer
Posted: 12 September 2026 (8 hours ago)
Application Deadline: 10 December 2026
Vacancies: 1 Vacancy

Job Summary

Summary

RiVidium Inc. seeking a Senior Continuous Monitoring (ConMon) Analyst to support federal cybersecurity and Risk Management Framework (RMF) activities. The Senior ConMon Analyst will provide cybersecurity continuous monitoring security assessment risk analysis and compliance support to ensure information systems remain compliant with applicable federal security requirements.

The ideal candidate will have strong experience with RMF security controls continuous monitoring vulnerability management POA&M management security documentation and Governance Risk and Compliance (GRC) tools. This position requires the ability to work closely with Information System Security Officers (ISSOs) Information System Security Managers (ISSMs) Security Control Assessors (SCAs) system owners engineers and government stakeholders.

Key Responsibilities

  • Perform continuous monitoring of information systems to identify changes in security posture vulnerabilities risks and compliance status.
  • Support implementation and execution of Continuous Monitoring (ConMon) strategies in accordance with federal cybersecurity requirements and organizational policies.
  • Monitor security controls and assess ongoing control effectiveness through documentation reviews technical evidence vulnerability data and other assessment activities.
  • Support NIST Risk Management Framework (RMF) activities throughout the system lifecycle.
  • Review security controls assessment results system changes vulnerabilities and security-related artifacts to identify potential risks and compliance gaps.
  • Track analyze and report security weaknesses vulnerabilities and Plans of Action and Milestones (POA&Ms).
  • Coordinate with ISSOs ISSMs SCAs system owners and technical teams to ensure identified security deficiencies are properly documented and remediated.
  • Maintain and update cybersecurity documentation including security assessment evidence control implementation statements POA&Ms risk assessments and continuous monitoring reports.
  • Review vulnerability scan results and other security assessment data to determine potential impact to system security posture.
  • Support security impact analyses for system changes configuration changes new technologies and changes to the operational environment.
  • Assist with preparation of recurring security and compliance reports for government leadership and cybersecurity stakeholders.
  • Analyze security metrics and trends to identify recurring weaknesses and recommend risk mitigation strategies.
  • Support security control testing assessment and validation activities as required.
  • Ensure continuous monitoring activities are properly documented and aligned with applicable policies standards and federal regulations.
  • Use GRC and cybersecurity tools to maintain system security information control status assessment findings POA&Ms and compliance documentation.
  • Participate in cybersecurity working groups risk reviews security meetings and technical discussions with government and contractor stakeholders.
  • Provide recommendations to improve cybersecurity processes control effectiveness risk management and compliance posture.
  • Stay current on evolving federal cybersecurity policies NIST guidance threats vulnerabilities and security best practices.

Required Qualifications

  • Bachelors degree in Cybersecurity Information Systems Computer Science Information Assurance or a related field.
  • Demonstrated professional experience supporting cybersecurity continuous monitoring RMF security compliance or information assurance programs.
  • Strong understanding of the NIST Risk Management Framework (RMF) and NIST cybersecurity standards.
  • Experience with security controls security assessments vulnerability management risk management and POA&M tracking.
  • Experience analyzing security documentation and technical evidence to determine control compliance and system security posture.
  • Experience working with cybersecurity stakeholders including ISSOs ISSMs SCAs system owners and system administrators/engineers.
  • Strong written and verbal communication skills with the ability to prepare clear technical and executive-level security reports.
  • Ability to manage multiple systems security requirements findings and competing priorities in a federal environment.

Preferred Qualifications

  • CISM CAP or equivalent GRC/cybersecurity certification.
  • Experience with GRC platforms such as RSA Archer ServiceNow GRC eMASS or equivalent tools.
  • Experience supporting federal civilian or Department of Defense cybersecurity programs.
  • Knowledge of NIST SP 800-37 NIST SP 800-53 NIST SP 800-30 NIST SP 800-137 FISMA and related federal cybersecurity requirements.
  • Experience with vulnerability management and security scanning tools.
  • Experience developing dashboards metrics and cybersecurity status reports.
  • Experience supporting ATO continuous authorization security assessment and ongoing authorization activities.
  • Familiarity with federal cybersecurity policies standards and compliance requirements.

Desired Skills

  • Risk Management Framework (RMF)
  • Continuous Monitoring (ConMon)
  • NIST 800-53 security controls
  • Security Assessment & Authorization (A&A)
  • Authority to Operate (ATO)
  • POA&M management
  • Vulnerability Management
  • Risk Assessment
  • Security Control Assessment
  • GRC tools
  • Cybersecurity compliance
  • Security documentation
  • Security metrics and reporting
  • Federal cybersecurity policies and standards

Education & Certification

Required:

  • Bachelors degree in Cybersecurity Information Systems Computer Science Information Assurance or related field.

Preferred:

  • Certified Information Security Manager (CISM)
  • Certified Authorization Professional (CAP)
  • Equivalent GRC cybersecurity or information assurance certification

RiVidium Inc is seeking a Senior Continuous Monitoring (ConMon) Analyst to support a federal client. This position is contingent upon contract award and funding approval. As such this job posting is intended to identify qualified candidates for a potential future opportunity and does not represent a currently available position. Compensation has not yet been determined and will be established based on contract requirements candidate qualifications experience and applicable market conditions.


Required Experience:

Senior IC


About Company

Established in 2008, RiVidium, Inc. (dba TripleCyber) is a VA-Verified SDVOSB and an SBA-Certified 8(a) company. To prepare our clients for the future, RiVidium has balanced all parts of our organization to attract the finest employees in order to 'Strive to be the missing element def ... View more

View Profile View Profile