Washington, DC, 20080, USA
1 day ago
Policy Analyst
Policy Analyst **Department:** GRC **Location:** Washington, DC **We are looking for a dynamic** **Policy Analyst** **.** **Responsibilities:** + Serve as a trusted advisor to the CISO and Deputy CISO as an expert in the field of information assurance and cybersecurity. + Represent the Department in working groups and cybersecurity committees that are tackling the government-s current and emerging challenges such as maturing the CDM program, automating the ATO process, and developing and implementing enterprise security services. + Lead the development of the Department-s program for identifying, protecting, and monitoring its High-Value Assets (HVAs). + Oversee and manage the day-to-day operation of information systems, including advanced technical assistance. + Perform control reviews, security audits, evaluations, and risk assessments of sensitive and complex operational systems and facilities and provides recommendations for remediating detected vulnerabilities. + Conduct application, system, and network security assessments, analyses, authorizations, and evaluations in classified and sensitive environments. + Develop requirements and specifications for reviewing and approving procurement requests, major systems development activities, telecommunications hardware and software, and hardware and software encryption techniques on the basis of security concerns. + Broadly assess technology to ensure security vulnerabilities are identified and remediated. + Analyze and optimize system operation and resource utilization and perform system capacity planning/analysis while maintaining the security posture. + Provide Automated Indicator Sharing (AIS) and client network guidance, training, research and recommendations. + Support specific technical reviews to support non-standard operational requirements and systems, including design, development, and maintenance of unique security assessment security tools and conducting assessments. **Requirements:** + Bachelor-s Degree or an equivalent combination of formal education and experience. Bachelor's Degree may be substituted for 8 additional years of relevant experience. + Minimum 8 years of general experience and 6 years of relevant experience in functional responsibility. + Well-versed in risk management and must have experience working with SDLC and performing security tasks throughout. + Experience with and working understanding of FISMA compliance, experience conducting all phases of Certification and Accreditation, and creating documentation in accordance with NIST guidance. + Well-versed with NIST publications, including NIST 800 series, OMB circulars such as OMB A-123 circular and OMB A-130 circular and memoranda, and CNSS publications and their requirements and impact on system security such as CNSS 1253 and risk management methodologies. + Strong analytical and organizational skills. + Concise writing skills. **Desired:** + CISSP highly desired + Understanding of and experience with CSAM is a plus **Clearance:** Secret Clearance Required **Location:** + There is a teleworking option with this role until a time when the client requires the team onsite in Washington, DC. **Compensation:** - Compensation is unique to each candidate and relative to the skills and experience they bring to the position. The salary range for this position is typically $110-$125K. This does not guarantee a specific salary as compensation is based upon multiple factors such as education, experience, certifications, and other requirements, and may fall outside of the above-stated range. **Benefits:** - Highlights of our benefits include Health/Dental/Vision, 401(k) match, Flexible Time Off, STD/LTD/Life Insurance, Referral Bonuses, professional development reimbursement, and maternity/paternity leave **Additional Information:** Tyto Athene is a trusted leader in IT services and solutions, delivering mission-focused digital transformation that drives measurable success. Our expertise spans four core technology domains-Network Modernization, Hybrid Cloud, Cybersecurity, and Enterprise IT-empowering our clients with cutting-edge solutions tailored to their evolving needs. With over 50 years of experience, Tyto Athene proudly support Defense, Intelligence, Space, National Security, Civilian, Health, and Public Safety clients across the United States and worldwide. At Tyto Athene, we believe that success starts with our people. We foster a collaborative, innovative, and mission-driven environment where every team member plays a critical role in shaping the future of technology. Are you ready to join #TeamTyto. Tyto Athene is an Equal Opportunity Employer and fully complies with all EEOC regulations. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, gender identity, age, national origin, disability, status as a protected veteran, or any other protected characteristic.
Confirm your E-mail: Send Email