Security Governance and Policy Analyst

Jimmy Jazz

Washington (District of Columbia)

On-site

USD 120,000 - 170,000

Full time

28 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Tharros is seeking a Security Governance and Policy Analyst to develop and maintain cybersecurity policies for the DHS Intelligence Enterprise. You will translate federal requirements into actionable policy, support audits, and prepare leadership briefings.

This on-site role sits in a Government SCIF in Washington, DC. You will coordinate RMF/CNSSI/SCRM policy efforts, review Executive Orders and IC policies, and collaborate with GRC personnel to ensure compliance across programs.

Qualifications

  • BS degree in Information Technology, Cybersecurity, Information Systems, or Computer Science OR minimum of 6 years' experience in cybersecurity or IT compliance.
  • Minimum of 3 years' experience in cybersecurity policy, governance, or compliance.
  • Active TS/SCI clearance and U.S. citizenship; willingness to undergo a DHS counterintelligence-scope polygraph.
  • Knowledge of NIST SP 800-53, CNSSI 1253, and IC overlays.
  • Knowledge of RMF, ICD 503, and FISMA.
  • Knowledge of Federal and IC cybersecurity policy development and review processes.
  • Knowledge of Federal cybersecurity audit processes.
  • Excellent written and oral communications skills.

Responsibilities

  • Develop and update enterprise cybersecurity policies and standards covering RMF, CNSSI, supply chain risk management, and AI/ML security.
  • Research new Executive Orders, IC policies, and national security memos and recommend implementation actions.
  • Identify required updates to the SCI Systems Instruction Manual (4300C), SCRM policy, and Security Common Controls Catalog.
  • Coordinate with GRC personnel to validate control requirements in the GRC tool.
  • Prepare responses in support of OIG FISMA and JWICS Cybersecurity Inspection Program audits.
  • Draft stakeholder notifications and policy addendum or rescission language for CISO approval.
  • Prepare reports, executive summaries, talking points, and briefing slides for the CISO and stakeholder forums.
  • Maintain CISO SharePoint policy sites, the governance meeting calendar, and the data-call and tasker tracker.

Skills

Policy writing
Executive communications
Policy governance
Written & oral communication

Education

BS degree in IT / cybersecurity / information systems / computer science

Tools

MS Office Suite
GRC tools

Job description

  • Location 1790 Ash Street Southeast,Washington, DC, 20032,United States
  • Employee Type Regular Full-Time
  • Required Degree 4 Year Degree
Contact information
  • Name Talent Acquistion
  • Email recruiting@tharros.com
Description

Tharros supports the Department of Homeland Security (DHS) with cybersecurity services across its Intelligence Enterprise. In support of this mission, we have an immediate opportunity for a Security Governance and Policy Analyst.

In this role you will help develop and maintain the cybersecurity policies that govern the DHS Intelligence Enterprise, translating Federal and Intelligence Community (IC) requirements into policy the enterprise can implement. You will work alongside the senior policy advisor to the Chief Information Security Officer (CISO), support cybersecurity audits, and prepare briefings for leadership. This position is on-site in a Government SCIF in Washington, DC.

  • Develop and update enterprise cybersecurity policies and standards covering RMF, CNSSI, supply chain risk management, and AI/ML security.
  • Research new Executive Orders, IC policies, and national security memos and recommend implementation actions.
  • Identify required updates to the SCI Systems Instruction Manual (4300C), SCRM policy, and Security Common Controls Catalog.
  • Coordinate with GRC personnel to validate control requirements in the GRC tool.
  • Prepare responses in support of OIG FISMA and JWICS Cybersecurity Inspection Program audits.
  • Draft stakeholder notifications and policy addendum or rescission language for CISO approval.
  • Prepare reports, executive summaries, talking points, and briefing slides for the CISO and stakeholder forums.
  • Maintain CISO SharePoint policy sites, the governance meeting calendar, and the data-call and tasker tracker.
Requirements
  • BS degree in Information Technology, Cybersecurity, Information Systems, or Computer Science OR minimum of 6 years' experience in cybersecurity or IT compliance.
  • Minimum of 3 years' experience in cybersecurity policy, governance, or compliance.
  • Active TS/SCI clearance and U.S. citizenship; willingness to undergo a DHS counterintelligence-scope polygraph.
  • Knowledge of NIST SP 800-53, CNSSI 1253, and IC overlays.
  • Knowledge of the Risk Management Framework (RMF), ICD 503, and FISMA.
  • Knowledge of Federal and IC cybersecurity policy development and review processes.
  • Knowledge of Federal cybersecurity audit processes.
  • Skill in writing policy, standards, and executive-level communications.
  • Ability to track and coordinate taskers across multiple stakeholders.
  • Proficient in Microsoft Office Suite to include Teams or similar workplace chat and videoconferencing tools.
  • Excellent written and oral communications skills.
  • CISSP, CISM, CGRC, or CompTIA Security+ certification.
  • Experience with DHS 4300C or IC supply chain risk management policy.
Summary

Tharros combines extensive cyber defense knowledge with the world’s preeminent vulnerability expertise to identify and defend against attacks before they become problems. Working at mission speed, we harden mission systems faster and secure them for longer, so agencies never lose the mission edge. Tharros lifts the veil of enterprise cybersecurity to detect zero days before they affect you, enabling mission maneuverability and the confidence to move missions forward.

In the ever-evolving realm of cyberspace, we are dedicated to becoming the paramount defender in the 5th warfighting domain. By pioneering innovative security solutions and fostering an environment of continuous learning and vigilance, we aim to protect the interests of our nation’s security. Our commitment to excellence in cybersecurity will establish new benchmarks, transforming the digital landscape into a secure and thriving frontier for future generations.

Tharros. See Everything. Secure Anything.

Tharros is committed to hiring and retaining a diverse workforce. We are proud to be an Equal Opportunity/Affirmative Action Employer and make employment decisions without regard to race, color, religion, creed, sex, sexual orientation, gender identity, marital status, national origin, age, veteran status, disability, or any other protected status.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

IT Security Operations Specialist
IT Security Operations Specialist

Jimmy Jazz • Washington

On-site
USD 90,000 - 130,000
Security Governance and Policy Analyst
Security Governance and Policy Analyst

ANALYGENCE • Washington

On-site
USD 110,000 - 170,000
Senior Security Control Assessor
Senior Security Control Assessor

Jimmy Jazz • Washington

On-site
USD 120,000 - 150,000
Junior Security Engineer
Junior Security Engineer

Jimmy Jazz • Washington

On-site
USD 90,000 - 130,000
Senior Software Assurance and Vulnerability Assessment Engineer
Senior Software Assurance and Vulnerability Assessment Engineer

Jimmy Jazz • Washington

On-site
USD 140,000 - 200,000
Junior Security Control Assessor
Junior Security Control Assessor

Jimmy Jazz • Washington

On-site
USD 70,000 - 100,000
Junior Information System Security Officer, National Vetting Center
Junior Information System Security Officer, National Vetting Center

Jimmy Jazz • Washington

On-site
USD 90,000 - 120,000
Junior Information System Security Officer
Junior Information System Security Officer

Jimmy Jazz • Washington

On-site
USD 80,000 - 110,000
Information System Security Officer
Information System Security Officer

Jimmy Jazz • Washington

On-site
USD 120,000 - 170,000
Information Security Analyst
Information Security Analyst

Jimmy Jazz • Maryland

On-site
USD 90,000 - 120,000