Cyber Security Service Provider (CSSP) Cybersecurity Policy Analyst

S2i2, Inc

Columbus, Northern (OH, KY)

Hybrid

USD 110,000 - 150,000

Full time

35 hours ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

S2I2 is seeking an experienced Cybersecurity Policy Analyst to support CSSP. The role requires an active DoD Top Secret clearance with SCI eligibility and on-site work in Columbus, OH.

You will develop, review, and streamline DoD/DLA cybersecurity policies, SOPs, and TTPs; lead CSSP inspections; prepare metrics and artifacts; coordinate incident response training; and brief senior leadership on program progress and readiness.

Qualifications

  • Minimum of seven (7) years of proven experience in cybersecurity policy development and implementation.
  • Active DoD Top Secret security clearance with current SCI eligibility.
  • DoD 8570.01-M / 8140 baseline certification at IAT Level II or higher.
  • DoD 8570.01-M / 8140 CSSP certification as CSSP Auditor or CSSP Incident Responder.

Responsibilities

  • Develop, review, and streamline DoD/DLA cybersecurity policies, SOPs, and TTPs.
  • Lead CSSP evaluation and inspection preparations; track metrics and artifacts.
  • Brief senior government leadership on policy updates and program progress.
  • Prepare, plan, and execute cybersecurity exercises; generate detailed reports.

Skills

Policy development
Incident response
Leadership
Briefing leadership
RMF knowledge
DoD policy knowledge

Job description

Cyber Security Service Provider (CSSP) Cybersecurity Policy Analyst
  • Posted 16-Sep-2026 (EST)
  • 3990 E Broad St, Columbus, OH 43213, USA

S2I2 is currently seeking an experienced Cybersecurity Policy Analyst in support of Cyber Security Service Provider (CSSP).

Clearance: Active Top Secret (TS) with SCI eligibility

Work Schedule: On-site, 5 days/week. Occasional after-hours support for incidents, exercises, and inspection preparation

Position Overview:

Develop, review, and streamline DLA CERT cybersecurity policies, SOPs, and TTPs to ensure compliance with DoD and DLA standards, emphasizing incident response across the DLA enterprise.

Lead and coordinate CSSP evaluation and inspection preparations, including the collection and compilation of relevant metrics and artifacts. Track progress against Evaluator Scoring Metrics and brief DLA CERT and Cybersecurity leadership on organizational readiness.

Receive, acknowledge, and rapidly disseminate Cyber Defense directives (orders, taskings, and alerts) within 30 minutes of receipt. Track and validate DLA's compliance with ongoing and recurring requirements.

Support the planning and execution of cybersecurity exercises, including tabletop scenarios for DLA programs and applications. Generate detailed exercise reports and capture lessons learned for continuous improvement.

Assist DLA program teams in developing RMF packages and associated compliance documentation to facilitate successful authorizations.

Create and deliver comprehensive incident response and cybersecurity training to ISSMs, system administrators, and incident response teams, both in-person and remotely.

Support After Action Reports and Joint Lessons Learned Information System (JLLIS) entries so that process gaps identified during incidents flow back into SOP and TTP updates.

Prepare monthly CSSP inspection metrics evaluations, annual SOP and TTP updates, and compile annual CSSP artifact deliverables.

Brief senior government leadership on cybersecurity policy changes, updates, and overall program progress.

Qualifications:

Required Qualifications:

Minimum of seven (7) years of proven experience in cybersecurity policy development and implementation.

Active DoD Top Secret security clearance with current SCI eligibility and IT-I (Tier 5) access required at time of application.

DoD 8570.01-M / 8140 baseline certification at IAT Level II or higher (for example, Security+ CE, CySA+, CCNA Security, GICSP, GSEC, or SSCP).

DoD 8570.01-M / 8140 CSSP certification as CSSP Auditor (CSSP-AU) or CSSP Incident Responder (CSSP-IR) (for example, CISA, CEH, GCIH, GCFA, CySA+, or CFR).

Strong working knowledge of DoD cybersecurity policy and the CSSP program, including CJCSM 6510.01B, DoDI 8530.01, Evaluator Scoring Metrics, and JFHQ-DODIN reporting requirements.

Demonstrated ability to develop clear, defensible policy and procedure documents and effectively brief senior leadership.

Desired Qualifications:

Experience preparing an organization for a CSSP evaluation or inspection, ideally with a role in metrics and artifact compilation.

Prior experience with DLA, DISA, DoD CSSP, or CERT.

Experience with the RMF process and direct support of system owners throughout authorization package development.

Experience planning and facilitating cybersecurity tabletop exercises.

Familiarity with SOC operations and incident handling sufficient to develop actionable procedures for analysts.

CISSP, CISM, or CISA certification preferred

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

DLA Cyber Emergency Response Team (CERT) Cyber Security Service Provider (CSSP) Cybersecurity Policy Analyst
DLA Cyber Emergency Response Team (CERT) Cyber Security Service Provider (CSSP) Cybersecurity Policy Analyst

S2i2, Inc • Columbus (OH)

On-site
USD 80,000 - 98,000
Cybersecurity Policy Lead – DoD CSSP & Incident Response
Cybersecurity Policy Lead – DoD CSSP & Incident Response

S2i2, Inc • Columbus (OH), Northern (KY)

Hybrid
USD 110,000 - 150,000
TS/SCI Cybersecurity Policy & Compliance Lead
TS/SCI Cybersecurity Policy & Compliance Lead

S2i2, Inc • Columbus (OH)

On-site
USD 80,000 - 98,000
Cybersecurity Policy Analyst
Cybersecurity Policy Analyst

Career Listings • Columbus (OH)

On-site
USD 90,000 - 130,000
401(k)
401(k) matching
Dental insurance
+6
Cybersecurity Policy Analyst
Cybersecurity Policy Analyst

Sarela Technology Solutions • Columbus (OH)

On-site
USD 100,000 - 150,000
401(k)
401(k) matching
Dental insurance
+6
Communications Technical Support Services (CTSS) Cybersecurity Engineer
Communications Technical Support Services (CTSS) Cybersecurity Engineer

S2i2, Inc • Columbus (OH), Northern (KY)

Hybrid
USD 110,000 - 140,000
Cyber Security Operations Jr Analyst
Cyber Security Operations Jr Analyst

Spahrsolutionsgroup • Fort Belvoir (VA)

On-site
USD 90,000 - 120,000
Communications Technical Support Services (CTSS) Cybersecurity Engineer
Communications Technical Support Services (CTSS) Cybersecurity Engineer

S2i2, Inc • Richmond (VA)

On-site
USD 120,000 - 160,000
Cyber Security Engineer
Cyber Security Engineer

Career Listings • Columbus (OH)

On-site
USD 130,000 - 170,000
Computer Network Defense Analyst
Computer Network Defense Analyst

Career Listings • Columbus (OH)

On-site
USD 90,000 - 120,000
401(k)
401(k) matching
Dental insurance
+6