DLA Cyber Emergency Response Team (CERT) Cyber Security Service Provider (CSSP) Cybersecurity Policy Analyst

S2i2, Inc

Columbus (OH)

On-site

USD 80,000 - 98,000

Full time

17 hours ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

S2I2, Inc is seeking an experienced Cybersecurity Policy Analyst to support the DoD CSSP program. The role emphasizes DoD policy development, incident response readiness, and artifact management across the DLA enterprise.

The candidate will lead evaluations, coordinate metrics, disseminate directives promptly, and contribute to RMF packages and training; a TS clearance and SCI eligibility are required, with on-site work schedule.

Qualifications

  • Minimum of seven years in cybersecurity policy development and implementation.
  • Active DoD Top Secret clearance with SCI eligibility and IT-I access.
  • DoD 8570.01-M / 8140 baseline certification at IAT Level II or higher.
  • CSSP certification such as CSSP-AU or CSSP-IR.
  • Strong working knowledge of DoD cybersecurity policy and CSSP programs.
  • Ability to develop clear, defensible policy documents and brief senior leadership.

Responsibilities

  • Develop, review, and streamline DLA CERT cybersecurity policies, SOPs, and TTPs for incident response.
  • Coordinate CSSP evaluation and inspection preparations with metrics and artifacts.
  • Disseminate Cyber Defense directives within 30 minutes of receipt and track compliance.
  • Plan and execute cybersecurity exercises and generate detailed after-action reports.
  • Assist in RMF package development and related compliance documentation.
  • Create and deliver incident response training for ISSMs and system admins.
  • Support JLLIS entries and ensure lessons learned feed back to SOP/TTP updates.
  • Prepare monthly CSSP inspection metrics and annual artifact deliverables.
  • Brief senior government leadership on cybersecurity policy changes and program progress.

Skills

Cybersecurity policy development
DoD policy knowledge
Leadership briefings
Analytical thinking

Education

DoD 8570.01-M IAT Level II certification
CSSP Auditor (CSSP-AU) or CSSP Incident Responder (CSSP-IR)

Job description

S2I2 is currently seeking an experienced Cybersecurity Policy Analyst in support of Cyber Security Service Provider (CSSP).

Clearance: Active Top Secret (TS) with SCI eligibility Work Schedule: On-site, 5 days/week. Occasional after-hours support for incidents, exercises, and inspection preparation

Position Overview
  • Develop, review, and streamline DLA CERT cybersecurity policies, SOPs, and TTPs to ensure compliance with DoD and DLA standards, emphasizing incident response across the DLA enterprise.
  • Lead and coordinate CSSP evaluation and inspection preparations, including the collection and compilation of relevant metrics and artifacts. Track progress against Evaluator Scoring Metrics and brief DLA CERT and Cybersecurity leadership on organizational readiness.
  • Receive, acknowledge, and rapidly disseminate Cyber Defense directives (orders, taskings, and alerts) within 30 minutes of receipt. Track and validate DLA's compliance with ongoing and recurring requirements.
  • Support the planning and execution of cybersecurity exercises, including tabletop scenarios for DLA programs and applications. Generate detailed exercise reports and capture lessons learned for continuous improvement.
  • Assist DLA program teams in developing RMF packages and associated compliance documentation to facilitate successful authorizations.
  • Create and deliver comprehensive incident response and cybersecurity training to ISSMs, system administrators, and incident responseteams, both in-person and remotely.
  • Support After Action Reports and Joint Lessons Learned Information System (JLLIS) entries so that process gaps identified during incidents flow back into SOP and TTP updates.
  • Prepare monthly CSSP inspection metrics evaluations, annual SOP and TTP updates, and compile annual CSSP artifact deliverables.
  • Brief senior government leadership on cybersecurity policy changes, updates, and overall program progress.
Qualifications

Required Qualifications: Minimum of seven (7) years of proven experience in cybersecurity policy development and implementation.

Active DoD Top Secret security clearance with current SCI eligibility and IT-I (Tier 5) access required at time of application.

DoD 8570.01-M / 8140 baseline certification at IAT Level II or higher (for example, Security+ CE, CySA+, CCNA Security, GICSP, GSEC, or SSCP).

DoD 8570.01-M / 8140 CSSP certification as CSSP Auditor (CSSP-AU) or CSSP Incident Responder (CSSP-IR) (for example, CISA, CEH, GCIH, GCFA, CySA+, or CFR).

Strong working knowledge of DoD cybersecurity policy and the CSSP program, including CJCSM 6510.01B, DoDI 8530.01, Evaluator Scoring Metrics, and JFHQ-DODIN reporting requirements.

Demonstrated ability to develop clear, defensible policy and procedure documents and effectively brief senior leadership.

Desired Qualifications

Experience preparing an organization for a CSSP evaluation or inspection, ideally with a role in metrics and artifact compilation.

Prior experience with DLA, DISA, DoD CSSP, or CERT.

Experience with the RMF process and direct support of system owners throughout authorization package development.

Experience planning and facilitating cybersecurity tabletop exercises.

Familiarity with SOC operations and incident handling sufficient to develop actionable procedures for analysts.

CISSP, CISM, or CISA certification preferred

Salary: $80000 - $98000 per year

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Policy Analyst
Cybersecurity Policy Analyst

Career Listings • Columbus (OH)

On-site
USD 90,000 - 130,000
401(k)
401(k) matching
Dental insurance
+6
Cybersecurity Policy Analyst
Cybersecurity Policy Analyst

Sarela Technology Solutions • Columbus (OH)

On-site
USD 100,000 - 150,000
401(k)
401(k) matching
Dental insurance
+6
Cyber Security Operations Jr Analyst
Cyber Security Operations Jr Analyst

Spahrsolutionsgroup • Fort Belvoir (VA)

On-site
USD 90,000 - 120,000
Communications Technical Support Services (CTSS) Cybersecurity Engineer
Communications Technical Support Services (CTSS) Cybersecurity Engineer

S2i2, Inc • Richmond (VA)

On-site
USD 150,000 - 173,000
Cyber Security Engineer
Cyber Security Engineer

Sarela Technology Solutions • Columbus (OH)

On-site
USD 110,000 - 150,000
Cyber Security Engineer
Cyber Security Engineer

Career Listings • Columbus (OH)

On-site
USD 130,000 - 170,000
Computer Network Defense Analyst
Computer Network Defense Analyst

Career Listings • Columbus (OH)

On-site
USD 90,000 - 120,000
401(k)
401(k) matching
Dental insurance
+6
Cybersecurity Policy Analyst
Cybersecurity Policy Analyst

Unity Technologies Corporation • Columbus (OH)

On-site
USD 95,000 - 140,000
CSSP DCO Analyst
CSSP DCO Analyst

General Dynamics Information Technology • Fort Wayne (IN)

On-site
USD 110,000 - 150,000
Health benefits
401K with company match
Educational Assistance
+3
Communications Technical Support Services (CTSS) Cybersecurity Engineer
Communications Technical Support Services (CTSS) Cybersecurity Engineer

S2i2, Inc • Columbus (OH), Northern (KY)

Hybrid
USD 110,000 - 140,000