Cybersecurity Policy Analyst

Gunnison

Chevy Chase (MD)

Hybrid

USD 95,000 - 107,000

Full time

11 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Personal Leave (3 weeks) toll
Paid Holidays (11 days)
Flexible Time Off (5 days)
401(k) company match
Medical, Dental and Vision Insurance
Life and Disability Insurance
Public Transportation Subsidies
Certifications and Training Allowance

Job summary

Gunnison Consulting Group in Bethesda, MD, is seeking a Policy Analyst to lead Security Policy and Standards Support for ZTA operations under NIH OCIO guidance. This hybrid role blends federal policy work with governance, risk management, and enterprise policy development.

You will translate mandates into an NIH policy framework, draft policy anchors and briefs, and ensure alignment with AI governance and data-management requirements, while maintaining Section 508 compliance.

Qualifications

  • US Citizenship required.
  • 8+ years in federal cybersecurity policy, governance, or compliance.
  • Working knowledge of HHS IS2P, FISMA, NIST frameworks, and OMB M-22-09.
  • Excellent technical writing and policy-drafting skills.
  • Bachelor's degree.
  • Security+ or CAP/CGRC certification.

Responsibilities

  • Lead Security Policy and Standards Support for ZTA Operationalization under NIH OCIO guidance.
  • Develop policy anchors, risk-based frameworks, and adoption paths.
  • Write ZTA Policy Briefs and enterprise communications conforming to Section 508.
  • Align policy with AI governance and data-management requirements.

Skills

Excellent technical writing
Policy-drafting skills
Strategic thinking

Education

Bachelor's degree

Tools

Microsoft 365/SharePoint
Confluence
OCIO ZTA Wiki
Jira

Job description

Salary: $95,000 - $107,000/year


Description

Salary: $95,000 - $107,000/year


Work location

Hybrid, 1-2 days per week on-site in Bethesda, MD.


The Policy Analyst will lead Security Policy and Standards Support for ZTA Operationalization, under the NIH Governance, Risk & Compliance (GRC) Zero Trust Architecture (ZTA) Support Services task order for the NIH Office of the Chief Information Officer (OCIO). Working in the Risk & Policy Pod, candidate will turn federal and HHS Zero Trust mandates into a single, enforceable NIH policy framework. Candidate will also support communications and governance.



  • Build the Single Policy Framework: NIH ZTA policy, then standards by pillar, then implementation guides by workload family, then procedures, with an enterprise risk management (ERM) risk-appetite statement at the top.

  • Trace every policy statement up to its federal or HHS source (EO 14028, OMB M-22-09, HHS IS2P, HHS ZTA Strategy) and down to the Overlay control, architecture pattern, and governance checkpoint that enforce it.

  • Inventory NIH security policies, IS2P-derived standards, and procedures. Benchmark them against NIST SP 800-53 Rev 5, 800-207, 800-63-4, the CISA ZTMM, and current threats (MITRE ATT&CK). Produce a gap register with draft language and an adoption path.

  • Develop policy anchors, each made up of the policy statement, the technical setting that enforces it, the evidence that proves it, and the owner. Start with identity (conditional access), devices, networks, and data (classification labels driving DLP).

  • Write ZTA Policy Briefs and role-based monthly enterprise communications with the NIH ISAO Communications Team. All content must conform to Section 508.

  • Align policy with AI governance (NIST AI RMF, OMB AI memoranda, HHS AI strategy) and with data-management requirements (NIH Data Management and Sharing Policy, Privacy Act, HIPAA where applicable).


Tools & Technology Environment

Microsoft 365/SharePoint, Confluence and the OCIO ZTA Wiki, Jira; Microsoft Accessibility Checker and Adobe Acrobat for Section 508 checks.


Requirements


  • US Citizenship required

  • 8+ years in federal cybersecurity policy, governance, or compliance.

  • Working knowledge of HHS IS2P, FISMA, NIST frameworks, and OMB M-22-09.

  • Experience applying ERM principles to security policy.

  • Excellent technical writing and policy-drafting skills.

  • Bachelor's degree

  • Security+ or CAP/CGRC certification.


Clearance Requirement

Ability to obtain and maintain a Public Trust.


Desired Qualifications


  • HHS or NIH policy development and approval experience.

  • CISSP, CISM, or CGRC certification.

  • Zero Trust policy experience; privacy knowledge (Privacy Act, HIPAA, research data).


The salary range for this position depends upon multiple factors including location, the individual's knowledge, skills, competencies, and experience, and contract-specific budget constraints and organizational requirements.


Benefits

Gunnison Consulting Group's total compensation package also includes bonus and profit-sharing opportunities, depending on company and employee performance. Available employee benefits include:



  • 3 weeks of Personal Leave your first year

  • 11 paid Holidays each year

  • 5 days of Flexible Time Off each year for approved training or certifications (self-study is ineligible)

  • 401(k) company match at 50% up to 10% of your salary

  • Medical, Dental and Vision Insurance

  • Life and Disability Insurance

  • Public Transportation Subsidies

  • Certifications and Training Allowance - Up to $5,000/year!


Why Join Gunnison?


  • Gunnison takes on ambitious projects. We target fun, challenging work that requires creative thinking and innovation.

  • Quality is our top priority.

  • Gunnison employee benefits meet or exceed what other companies in the Washington, D.C. metropolitan area offer.

  • There is a great sense of camaraderie at Gunnison. This is an atmosphere we will maintain as we continue to grow.

  • We are growing rapidly and the opportunity for individual professional growth with Gunnison is outstanding.

  • We hire for careers at Gunnison, not to fill a position.


Equal Opportunity/Affirmative Action Employer. Must be eligible for employment in the United States. We are unable to sponsor candidates at this time.


In 1994 Gunnison began serving the greater Washington, D.C. metro area, focused on tackling our customers' most ambitious technology projects.


By creating a culture dedicated to enabling our customers and employees to achieve more than they ever thought they could, the company has thrived for over 25 years.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Assessment & Authorization (A&A) Analyst
Assessment & Authorization (A&A) Analyst

Gunnison • Chevy Chase (MD)

Hybrid
USD 60,000 - 71,000
3 weeks personal leave
11 paid holidays
Flexible time off for training
+5
Cybersecurity Engineer
Cybersecurity Engineer

Gunnison Consulting Group • Northern (KY)

Hybrid
USD 115,000 - 121,000
Personal Leave 3 weeks
11 Paid Holidays
Flexible Time Off
+5
Cybersecurity Engineer
Cybersecurity Engineer

Gunnison Consulting Group • Washington

Hybrid
USD 115,000 - 121,000
3 weeks of Personal Leave
11 paid Holidays
5 days of Flexible Time Off
+5
Assessment & Authorization (A&A) Analyst
Assessment & Authorization (A&A) Analyst

Gunnison Consulting Group • Bethesda (MD), Northern (KY)

Hybrid
USD 60,000 - 71,000
3 weeks Personal Leave
11 paid Holidays
5 days Flexible Time Off
+5
Cybersecurity Engineer
Cybersecurity Engineer

Gunnison • Washington

Hybrid
USD 115,000 - 121,000
Personal Leave
Holidays (11)
Flexible Time Off
+5
Junior Artificial Intelligence (AI) Solutions Engineer
Junior Artificial Intelligence (AI) Solutions Engineer

Worky • Washington

On-site
USD 80,000 - 90,000
Personal Leave
Paid Holidays
Flexible Time Off
+5
Digital Forensics Analyst
Digital Forensics Analyst

Gunnison • Alexandria (VA)

On-site
USD 125,000 - 145,000
401(k) employer match
Medical, Dental & Vision
Professional development funds
+2
Artificial Intelligence (AI) Solutions Engineer (part-time)
Artificial Intelligence (AI) Solutions Engineer (part-time)

Worky • Washington

On-site
USD 99,000 - 112,000
Personal Leave
Holidays
Flexible Time Off
+5
Senior Cybersecurity Policy Analyst
Senior Cybersecurity Policy Analyst

eTelligent Group LLC • Bethesda (MD)

On-site
USD 110,000 - 120,000
Senior Zero Trust / Enterprise Security Architect
Senior Zero Trust / Enterprise Security Architect

eTelligent Group • Bethesda (MD)

Hybrid
USD 165,000 - 175,000