Senior Cybersecurity Policy Analyst

Etelligent-Group-LLC

Bethesda (MD)

Hybrid

USD 110,000 - 120,000

Full time

6 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

eTel in Bethesda is seeking a policy-focused senior professional to lead the NIH ZTA policy and standards effort under OCIO guidance. You will translate federal and HHS mandates into a single NIH policy framework and support governance activities across Task 6 and Task 7.

The role emphasizes policy anchor development, evidence trails, and enterprise risk management, with collaboration across IS2P, NIST, and privacy requirements while ensuring Section 508 compliance.

Qualifications

  • Bachelor's degree plus 8+ years in federal cybersecurity policy, governance, or compliance.
  • Working knowledge of HHS IS2P, FISMA, NIST frameworks, and OMB M-22-09.
  • Experience applying ERM principles to security policy.
  • Excellent technical writing and policy-drafting skills.
  • Ability to obtain NIH suitability determination and PIV credential; fluent in English.

Responsibilities

  • Lead Task 5: Security Policy and Standards Support for ZTA.
  • Trace policy statements to sources and enforcement points.
  • Inventory NIH security policies and benchmark against NIST standards.
  • Develop policy anchors for identity, devices, networks, data.
  • Write ZTA Policy Briefs and monthly enterprise communications.
  • Align policy with AI governance and NIH data policies.

Skills

Federal cybersecurity policy
Policy governance
Policy writing
English fluency

Education

Bachelor's degree

Tools

HHS IS2P
NIST frameworks
FISMA
OMB M-22-09

Job description

Over the past 15 years, eTel has delivered essential solutions for the federal government by securing and managing data, providing scalable identity access, modernizing legacy systems, and building high-performance platforms. By integrating new technologies and ensuring reliable operations we help agencies stay prepared for future challenges As a premier technology solutions and services company to the US federal government, eTel possesses longstanding relationships across the federal civilian marketplace. Other customers include the broader Treasury Department, Commerce Department, and State Department.

eTel offers integrated CMMI Level 3 processes, tools, and techniques with innovative, cost-efficient, and secure solutions to address complex challenges. eTel also holds ISO 9001:2015, ISO/IEC 27001:2013, and ISO/IEC 20000-1:2018 certifications, and offers dedicated subject matter experts (SMEs) and thought leaders that possess a deep understanding of customers’ environments and challenges.

Work Location and On-Site/Telework Requirements: Hybrid - NIH, Bethesda, MD. On site for stakeholder workshops (typically 1-2 days/week during the first 120 days, then as scheduled).

Clearance: All staff must obtain NIH suitability and a PIV credential and be fluent in English. Anyone doing risk or vulnerability testing needs a current T2 (BI) or higher investigation.

Salary Range: $110,000-$120,000 yearly salary

Overview:

You will lead Task 5, Security Policy and Standards Support for ZTA Operationalization, under the NIH Governance, Risk & Compliance (GRC) Zero Trust Architecture (ZTA) Support Services task order for the NIH Office of the Chief Information Officer (OCIO). Working in the Risk & Policy Pod, you will turn federal and HHS Zero Trust mandates into a single, enforceable NIH policy framework. You will also support Task 6 communications and Task 7 governance.

Responsibilities:

  • Build the Single Policy Framework (Subtask 5.1): NIH ZTA policy, then standards by pillar, then implementation guides by workload family, then procedures, with an enterprise risk management (ERM) risk-appetite statement at the top.
  • Trace every policy statement up to its federal or HHS source (EO 14028, OMB M-22-09, HHS IS2P, HHS ZTA Strategy) and down to the Overlay control, architecture pattern, and governance checkpoint that enforce it.
  • Inventory NIH security policies, IS2P-derived standards, and procedures. Benchmark them against NIST SP 800-53 Rev 5, 800-207, 800-63-4, the CISA ZTMM, and current threats (MITRE ATT&CK). Produce a gap register with draft language and an adoption path (Subtask 5.2).
  • Develop policy anchors (Subtask 5.3), each made up of the policy statement, the technical setting that enforces it, the evidence that proves it, and the owner. Start with identity (conditional access), devices, networks, and data (classification labels driving DLP).
  • Write ZTA Policy Briefs and role-based monthly enterprise communications with the NIH ISAO Communications Team. All content must conform to Section 508.
  • Align policy with AI governance (NIST AI RMF, OMB AI memoranda, HHS AI strategy) and with data-management requirements (NIH Data Management and Sharing Policy, Privacy Act, HIPAA where applicable).

Tools & Technology Environment: Microsoft 365/SharePoint, Confluence and the OCIO ZTA Wiki, Jira; Microsoft Accessibility Checker and Adobe Acrobat for Section 508 checks.

Required Qualifications:

  • Bachelor's degree plus 8+ years in federal cybersecurity policy, governance, or compliance.
  • Working knowledge of HHS IS2P, FISMA, NIST frameworks, and OMB M-22-09.
  • Experience applying ERM principles to security policy.
  • Excellent technical writing and policy-drafting skills.
  • Ability to obtain an NIH suitability determination and PIV credential; fluent in English.

Preferred Qualifications:

  • HHS or NIH policy development and approval experience.
  • CISSP, CISM, or CGRC.
  • Zero Trust policy experience; privacy knowledge (Privacy Act, HIPAA, research data).
  • Current National Institutes of Health (NIH) or U.S. Department of Health and Human Services (HHS) experience is highly preferred.

Commitment to Diversity -
eTelligent Group provides equal employment opportunities (EEO) to all applicants without regard to race, color, religion, gender, sexual orientation, gender identity, nations origin, age, disability, genetic information, marital status, amnesty, status as a covered veteran, and any other characteristic provided in accordance with applicable, federal, state and local laws.

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey.Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiringprocess or thereafter. Any information that you do provide will be recorded and maintained in aconfidential file.

As set forth in eTelligent Group LLC's Equal Employment Opportunity policy,we do not discriminate on the basis of any protected group status under any applicable law.

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection.As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measurethe effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categoriesis as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Cybersecurity Policy Analyst
Senior Cybersecurity Policy Analyst

eTelligent Group LLC • Bethesda (MD)

Hybrid
USD 110,000 - 120,000
Cloud / Network Security Engineer
Cloud / Network Security Engineer

Etelligent-Group-LLC • Bethesda (MD)

Hybrid
USD 130,000 - 140,000
Cloud / Network Security Engineer
Cloud / Network Security Engineer

eTelligent Group LLC • Bethesda (MD)

Hybrid
USD 130,000 - 140,000
Program / Business Analyst
Program / Business Analyst

eTelligent Group LLC • Bethesda (MD)

Hybrid
USD 75,000 - 85,000
Remote eligible
RMF / A&A Analyst
RMF / A&A Analyst

Etelligent-Group-LLC • Bethesda (MD)

Hybrid
USD 90,000 - 100,000
Enterprise Architect – Governance
Enterprise Architect – Governance

eTelligent Group LLC • Bethesda (MD)

Hybrid
USD 145,000 - 155,000
Enterprise Architect – Governance
Enterprise Architect – Governance

Etelligent-Group-LLC • Bethesda (MD)

Hybrid
USD 145,000 - 155,000
Cloud / Network Security Engineer
Cloud / Network Security Engineer

etelligentgroup • Bethesda (MD)

Hybrid
USD 130,000 - 140,000
Senior Zero Trust / Enterprise Security Architect
Senior Zero Trust / Enterprise Security Architect

eTelligent Group LLC • Bethesda (MD)

Hybrid
USD 165,000 - 175,000
AI/ML Solutions Architect
AI/ML Solutions Architect

eTelligent Group LLC • Bethesda (MD)

Hybrid
USD 150,000 - 160,000