Security Governance and Policy Analyst

ANALYGENCE

Washington (District of Columbia)

On-site

USD 110,000 - 170,000

Full time

3 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Tharros in Washington, DC, supports the DHS with cybersecurity services and is actively seeking a Security Governance and Policy Analyst for on-site work in a Government SCIF. You will develop and maintain cybersecurity policies, translate federal/IC requirements into actionable policy, and support audits alongside the senior policy advisor to the CISO.

You will research orders and IC policies, draft policy language, and coordinate with GRC personnel to validate controls.

Qualifications

  • BS degree in IT, cybersecurity, information systems or computer science, or 6+ years in cybersecurity/IT compliance.
  • Minimum 3 years in cybersecurity policy, governance or compliance.
  • Active TS/SCI clearance and U.S. citizenship; willing to undergo a DHS polygraph.
  • Knowledge of NIST SP 800-53, CNSSI 1253, and IC overlays.
  • Knowledge of RMF, ICD 503, and FISMA.
  • Knowledge of Federal and IC policy development and review processes.
  • Knowledge of federal cybersecurity audit processes.
  • Excellent policy-writing and executive communication skills.

Responsibilities

  • Develop and update enterprise cybersecurity policies and standards.
  • Research Executive Orders, IC policies, and memos; recommend actions.
  • Identify updates to 4300C, SCRM policy, and Security Catalog.
  • Coordinate with GRC to validate control requirements.
  • Prepare responses for FISMA and JWICS audits.
  • Draft stakeholder communications and policy addenda.
  • Prepare reports and briefing slides for the CISO and forums.
  • Maintain CISO SharePoint policy sites and governance calendar.

Skills

Policy development
Governance
Compliance
Cybersecurity
Policy writing
Written communication
Stakeholder coordination
Audits
GRC awareness

Education

BS in IT/Cybersecurity/InfoSystems/CS

Tools

GRC tool
Microsoft Office
SharePoint

Job description

Tharros supports the Department of Homeland Security (DHS) with cybersecurity services across its Intelligence Enterprise. In support of this mission, we have an immediate opportunity for a Security Governance and Policy Analyst.

In this role you will help develop and maintain the cybersecurity policies that govern the DHS Intelligence Enterprise, translating Federal and Intelligence Community (IC) requirements into policy the enterprise can implement. You will work alongside the senior policy advisor to the Chief Information Security Officer (CISO), support cybersecurity audits, and prepare briefings for leadership. This position is on-site in a Government SCIF in Washington, DC.

  • Develop and update enterprise cybersecurity policies and standards covering RMF, CNSSI, supply chain risk management, and AI/ML security.
  • Research new Executive Orders, IC policies, and national security memos and recommend implementation actions.
  • Identify required updates to the SCI Systems Instruction Manual (4300C), SCRM policy, and Security Common Controls Catalog.
  • Coordinate with GRC personnel to validate control requirements in the GRC tool.
  • Prepare responses in support of OIG FISMA and JWICS Cybersecurity Inspection Program audits.
  • Draft stakeholder notifications and policy addendum or rescission language for CISO approval.
  • Prepare reports, executive summaries, talking points, and briefing slides for the CISO and stakeholder forums.
  • Maintain CISO SharePoint policy sites, the governance meeting calendar, and the data-call and tasker tracker.
  • BS degree in Information Technology, Cybersecurity, Information Systems, or Computer Science OR minimum of 6 years' experience in cybersecurity or IT compliance.
  • Minimum of 3 years' experience in cybersecurity policy, governance, or compliance.
  • Active TS/SCI clearance and U.S. citizenship; willingness to undergo a DHS counterintelligence-scope polygraph.
  • Knowledge of NIST SP 800-53, CNSSI 1253, and IC overlays.
  • Knowledge of the Risk Management Framework (RMF), ICD 503, and FISMA.
  • Knowledge of Federal and IC cybersecurity policy development and review processes.
  • Knowledge of Federal cybersecurity audit processes.
  • Skill in writing policy, standards, and executive-level communications.
  • Ability to track and coordinate taskers across multiple stakeholders.
  • Proficient in Microsoft Office Suite to include Teams or similar workplace chat and videoconferencing tools.
  • Excellent written and oral communications skills.

Desired

  • CISSP, CISM, CGRC, or CompTIA Security+ certification.
  • Experience with DHS 4300C or IC supply chain risk management policy.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Governance and Policy Analyst
Security Governance and Policy Analyst

Jimmy Jazz • Washington

On-site
USD 120,000 - 170,000
TS/SCI Security Policy & Governance Analyst
TS/SCI Security Policy & Governance Analyst

Jimmy Jazz • Washington

On-site
USD 120,000 - 170,000
Cyber Policy & Governance Analyst
Cyber Policy & Governance Analyst

ANALYGENCE • Washington

On-site
USD 110,000 - 170,000
IT Security Operations Specialist
IT Security Operations Specialist

ANALYGENCE • Washington

On-site
USD 110,000 - 160,000
Security Control Assessor
Security Control Assessor

ANALYGENCE • Washington

On-site
USD 120,000 - 180,000
Senior Security Control Assessor
Senior Security Control Assessor

ANALYGENCE • Washington

On-site
USD 140,000 - 170,000
Junior Security Control Assessor
Junior Security Control Assessor

ANALYGENCE • Washington

On-site
USD 65,000 - 90,000
Junior Information System Security Officer
Junior Information System Security Officer

ANALYGENCE • Washington

On-site
USD 70,000 - 100,000
Information System Security Officer
Information System Security Officer

ANALYGENCE • Washington

On-site
USD 140,000 - 190,000
IT Security Operations Specialist
IT Security Operations Specialist

Jimmy Jazz • Washington

On-site
USD 90,000 - 130,000