Tyto Athene is hiring a dynamic Lead Policy Analyst to support our customer in Arlington, VA.
Responsibilities:
Serve as a trusted advisor to the CISO and Deputy CISO as an expert in the field of information assurance and cybersecurity.
Provide advisory support to the customer agency's needs and challenges such as maturing the Governance, Risk, and Compliance (GRC) program, improving the ATO process, responding to government-wide mandates, and developing or updating policies to close agency gaps and improve metrics.
Continuously monitor for new federal guidance (e.g. BODs, mandates, etc.), perform research and assess impact, disseminate relevant information, and provide guidance to the customer and MPG team on relevant actions such as changes to agency policies and procedures.
Review the agency's existing GRC processes and templates for quality and completeness and recommend changes as needed.
Participate in the quality assurance process by reviewing the quality of team deliverable content and leading or participating in retrospectives to identify lessons learned and improvement opportunities.
Lead executive briefings.
Provide direction to and subject matter expertise in security control reviews, security audits, evaluations, and risk assessments of sensitive and complex operational systems and facilities and provides recommendations for remediating detected vulnerabilities.
Provide direction to and subject matter expertise in application or system security assessments, authorizations, and evaluations.
Represent the Department in working groups and cybersecurity committees that are tackling the government's current and emerging challenges such as maturing the CDM program, automating the ATO process, and developing and implementing enterprise security services.
Lead the development of the Department's program for identifying, protecting, and monitoring its High-Value Assets (HVAs).
Oversee and manage the day-to-day operation of information systems, including advanced technical assistance.
Perform control reviews, security audits, evaluations, and risk assessments of sensitive and complex operational systems and facilities and provides recommendations for remediating detected vulnerabilities.
Conduct application, system, and network security assessments, analyses, authorizations, and evaluations in classified and sensitive environments.
Develop requirements and specifications for reviewing and approving procurement requests, major systems development activities, telecommunications hardware and software, and hardware and software encryption techniques on the basis of security concerns.
Broadly assess technology to ensure security vulnerabilities are identified and remediated.
Analyze and optimize system operation and resource utilization and perform system capacity planning/analysis while maintaining the security posture.
Provide Automated Indicator Sharing (AIS) and client network guidance, training, research and recommendations.
Support specific technical reviews to support non-standard operational requirements and systems, including design, development, and maintenance of unique security assessment security tools and conducting assessments.
Required:
Bachelor's degree in Computer Science, Information Technology, or related field
12 years of relevant experience
Experience with NIST, FISMA, and Security Assessment & Authorization
Well-versed in risk management and must have experience working with SDLC and performing security tasks throughout
Experience with and working understanding of FISMA compliance, experience conducting all phases of Certification and Accreditation, and creating documentation in accordance with NIST guidance
Well-versed with NIST publications, including NIST 800 series, OMB circulars such as OMB A-123 circular and OMB A-130 circular and memoranda, and CNSS publications and their requirements and impact on system security such as CNSS 1253 and risk management methodologies
Strong analytical and organizational skills
Concise writing skills
Desired:
CISSP highly desired
Understanding of and experience with eMASS or XACTA are a plus
Clearance: Active TS/SCI clearance required
Required Certification: DoD 8570 IAM/IAT Level III certification. This will change to a DoD 8140 equivalent once a DISA 8140 policy is released.
Location: This is an on-site role with expectations of being on the client site in Arlington, VA five days a week.