|
Tharros supports the Department of Homeland Security (DHS) with cybersecurity services across its Intelligence Enterprise. In support of this mission, we have an immediate opportunity for a Security Governance and Policy Analyst. In this role you will help develop and maintain the cybersecurity policies that govern the DHS Intelligence Enterprise, translating Federal and Intelligence Community (IC) requirements into policy the enterprise can implement. You will work alongside the senior policy advisor to the Chief Information Security Officer (CISO), support cybersecurity audits, and prepare briefings for leadership. This position is on-site in a Government SCIF in Washington, DC. Duties include but not limited to:
- Develop and update enterprise cybersecurity policies and standards covering RMF, CNSSI, supply chain risk management, and AI/ML security.
- Research new Executive Orders, IC policies, and national security memos and recommend implementation actions.
- Identify required updates to the SCI Systems Instruction Manual (4300C), SCRM policy, and Security Common Controls Catalog.
- Coordinate with GRC personnel to validate control requirements in the GRC tool.
- Prepare responses in support of OIG FISMA and JWICS Cybersecurity Inspection Program audits.
- Draft stakeholder notifications and policy addendum or rescission language for CISO approval.
- Prepare reports, executive summaries, talking points, and briefing slides for the CISO and stakeholder forums.
- Maintain CISO SharePoint policy sites, the governance meeting calendar, and the data-call and tasker tracker.
- BS degree in Information Technology, Cybersecurity, Information Systems, or Computer Science OR minimum of 6 years' experience in cybersecurity or IT compliance.
- Minimum of 3 years' experience in cybersecurity policy, governance, or compliance.
- Active TS/SCI clearance and U.S. citizenship; willingness to undergo a DHS counterintelligence-scope polygraph.
- Knowledge of NIST SP 800-53, CNSSI 1253, and IC overlays.
- Knowledge of the Risk Management Framework (RMF), ICD 503, and FISMA.
- Knowledge of Federal and IC cybersecurity policy development and review processes.
- Knowledge of Federal cybersecurity audit processes.
- Skill in writing policy, standards, and executive-level communications.
- Ability to track and coordinate taskers across multiple stakeholders.
- Proficient in Microsoft Office Suite to include Teams or similar workplace chat and videoconferencing tools.
- Excellent written and oral communications skills.
Desired
- CISSP, CISM, CGRC, or CompTIA Security+ certification.
- Experience with DHS 4300C or IC supply chain risk management policy.
|