Cyber Governance Analyst

ITR
Oak Ridge, TN, US
Full-time

Job Description

Job Description

East Tennessee company seeks to hire a Cyber Governance Analyst to ensure compliance with cyber security policy and help manage governance and risk, while enabling mission / business objectives and compliance program initiatives.

The successful candidate should have a basic understanding of all aspects of cybersecurity. The candidate will collaborate with other teams across the lab, to include Information Technology, Physical Security, Classification Office, Cybersecurity, Lab Enterprise Risk, Lab Internal Audit, and others as appropriate.

The Cyber Governance Analyst develops policy documents, security control strategies, and risk mitigation strategies to ensure compliance with requirements. Can be remote.

Primary Responsibilities :

  • Identify, review, and provide analysis and recommendations to meet requirements of applicable laws, regulations, orders, and the contract, translate into policies, procedures, suggested control structures, analysis / white papers, aligning with business objectives
  • Provide guidance on policies and controls to support appropriate levels of risk, facilitate risk tolerance discussions and decisions, and recommend controls based on industry standards and practices
  • Assist risk management efforts including risk assessment process, identification of risk mitigation strategies, standardized assessment processes, and risk management training
  • Participate in internal / external compliance audits, reviews, self-assessments, assessments, and data calls
  • Identify, promote, and implement process improvements
  • Perform Security Control assessments per NIST SP 80053A Rev.5 guidance

Qualifications Required :

  • Bachelor’s degree in IT, Cyber, or related field and at least 5 years of experience in cyber policy, risk management, governance and compliance, though a combination of education and experience may be considered for exceptional candidates
  • Experience in security control assessments, Master Plans, and Cybersecurity program plans
  • Strong analytical and organizational skills as well as problem solving capabilities to understand Cyber risk and exposure (legal, regulatory violations, etc.)
  • Demonstrated experience implementing compliance frameworks (NIST, A123, Privacy)
  • Facilitation and project management knowledge, skills, and abilities; lead program implementations
  • Demonstrated excellent interpersonal, verbal, written and presentation communication skills and demonstrated ability to interact with all levels of internal and external stakeholders
  • Strong customer service, networking, and teamwork skills with all levels of internal and external personnel, demonstrated ability to work with all levels of an organization
  • Thorough understanding of industry standards and regulations including PCI, HIPAA, Privacy Act, NIST 800-53, NIST Risk Management Framework, FAIR
  • Working knowledge of privacy regulations and impacts
  • Experience integrating risk, compliance, and governance groups within an organization; support competing priorities, and provide guidance on how to meet requirements
  • Ability to work independently and meet deadlines
  • Exceptional communication, problem-solving and negotiation skills
  • High ethical standards and operates with integrity and professionalism
  • Must be able to obtain and maintain a DOE Q security clearance

Preferred Qualifications :

  • Master’s Degree in Information Assurance or related field
  • Minimum seven years’ experience working in an information security, information technology or information risk management related field
  • Cyber Security certifications (CISA, CISM, CRISC, CISSP)
  • Project Management certification (PgMP, PMP, PMI-ACP)
  • Privacy management, cyber security, evaluating security controls, identifying control gaps, and mitigating measures along with a strong understanding of business practices and technology concepts
  • Highly motivated individual with an enthusiasm for governance, risk and compliance who can communicate benefits and drive success
  • Experience gaining an Authority to Operate (ATO) for a government system
  • Proven track record of prioritizing tasking and meeting established deadlines
  • Active DOE Q or TS clearance
  • 22 hours ago
Related jobs
Promoted
Oak Ridge Associated Universities
Oak Ridge, Tennessee

Responsible for security controls, secure configurations and baselines for IT software, services, and equipment, support assessments of cyber, information, data, and information security. Computer & Information Security Analyst 2. Bachelor's degree in Computer Engineering, Information Security, Data...

Promoted
ITR
Oak Ridge, Tennessee

An East Tennessee Department of Energy Facility is looking for an AI Security Analyst. Ensure compliance with relevant regulatory requirements, standards, and best practices for AI security and ethics. Conduct risk assessments of AI systems and datasets to identify potential security vulnerabilities...

Promoted
United States Army
TN, United States

Similar Jobs: Telecommunications Equipment Installers & Repairers, Information Security Analysts, Computer Network Support REQUIREMENTS: 10 weeks of Basic Training 19 weeks of Advanced Individual Training 102 ASVAB Score: Electronics (EL) 105 ASVAB Score: Skilled Technical (ST) U. ...

Promoted
gpac
Oak Ridge, Tennessee

SEEKING COMMERCIAL DRYWALL PROJECT MANAGERS & ESTIMATORS. I am working with multiple well-respected, firmly established Commercial Drywall Contractors seeking experienced Project Managers and Estimators. Commercial Drywall Project Manager OR Estimator Experience Required. If you have the following, ...

Promoted
Y-12 National Security Complex
Oak Ridge, Tennessee

Project Controls Senior Analyst. Meaningful work and unique opportunities to support missions vital to national and global security. As an employee, you may be required to receive and maintain a security clearance from the United States Department of Energy in order to meet eligibility requirements ...

Highmark Health
TN, Working at Home, Tennessee

Ensures data integrity and compliance by performing data cleansing, data audit and/or data validation. Ensure data integrity and compliance by performing data cleansing, data audit and/or data validation. Provides business process, system support and data quality governance through data coordination...

N. Harris Computer Corporation - CAD
Tennessee, United States
Remote

We're on the hunt for a talented Project Manager to join our dynamic implementation team. Program management, involvement with multiple projects and project management office duties. These are billable projects, so project KPI tracking is critically important. Mentoring and coaching junior project m...

Jacobs
Oak Ridge, Tennessee

As the Engineering Design Project Manager you will plan, direct, coordinate engineering for assigned design projects to ensure client goals or objectives are accomplished within prescribed time frame and funding parameters within nuclear operations and engineering. Engineering Project Manager-(PFO00...

Deloitte
TN, United States

This role supports audits and assessment programs of the Technology Cyber Security Risk & Compliance team which includes risk management, audits, and assessments for on premises as well as cloud hosted IT applications and infrastructure. ...

Broadridge
Tennessee,
Remote

Business Analyst plays a critical role in supporting the business team by handling the configuration and home Office onboarding actions for our digital products. You will be a part of the Broadridge Advisor Solutions team using your business analysis skills to listen to clients and translate busines...