As a Cybersecurity Policy Specialist, this critical position focuses on developing and maintaining comprehensive security policies aligned with NIST and CIS standards. The role involves collaborating with various teams to ensure policies meet organizational needs, conducting regular reviews for compliance, and providing guidance on policy implementation. The ideal candidate will have a strong background in information security, excellent writing skills, and a deep understanding of cybersecurity principles. This position offers opportunities for professional growth within a collaborative work environment, allowing you to make a significant impact on the company's security posture.
Key Responsibilities Include:
- Develop and maintain security policies, procedures, and guidelines.
- Ensure alignment with NIST and CIS standards.
- Collaborate with teams to gather requirements and ensure policies meet organizational needs.
- Review and update policies regularly to ensure compliance with industry standards and regulatory requirements.
- Provide guidance on policy implementation and adherence.
- Conduct training sessions and workshops to educate employees on security policies and best practices.
- Monitor policy effectiveness and recommend improvements.
- Stay updated on cybersecurity standards and best practices.
- Develop policies for Cloud Technical Security Standards, ensuring secure cloud environments.
- Create guidelines for cryptographic algorithms to protect data.
- Implement Zero Trust security principles, including least privilege access and continuous verification.
- Establish network security policies, including firewalls, VPNs, and intrusion detection systems.
- Develop Identity and Access Management (IAM) policies, including SSO, MFA, and role-based access control.
- Formulate data security measures, including encryption, data masking, and data loss prevention.
- Maintain a risk register to document, prioritize, and manage risks effectively.
Skills and Qualifications:
- Proven experience as a Security Policy Writer on Cloud Technical Security Standards.
- Excellent writing and communication skills.
- Ability to translate technical concepts into clear policies.
- Strong understanding of cybersecurity principles.
- Expertise in Zero Trust security principles.
- Proficiency in network security.
- Experience with Identity and Access Management (IAM).
- Good understanding of NIST and CIS standards.
- Familiarity with regulatory requirements (e.g., GDPR, PCI-DSS, ISO 27001).
- Understanding of cryptographic algorithms.
- Knowledge of data security measures.
- Experience in maintaining a risk register.
- Ability to work independently and collaboratively.
- Analytical and problem-solving skills.
- Experience with risk assessment and management.
- Proficiency in policy management tools.
- Strong attention to detail and organizational skills.
- Ability to handle multiple projects and meet deadlines.
- Bachelor's degree in information security, Computer Science, or related field.
Other Desirable Skills:
- The Open Group Architecture Framework certification.