Jobs and Careers
TR

Senior Cybersecurity Policy Analyst

Tria Federal (Tria)
United States - Remote, United StatesRemotefull_timeVerifiedPosted 30 May 2024

About the role

Remote

Full Time

Ability to obtain and maintain a Public Trust*

* US Citizenship and the ability to obtain and maintain the clearance level stated above are required for this specific opportunity. Tria Federal (Tria) is unable to sponsor at this time.


 

Who We Are:

Tria Federal (Tria) is the premier middle-market IT and Advisory services provider delivering digital transformation solutions to Civilian, Defense, and Intelligence agencies across the federal sector. With a future-forward vision and a mission rooted in service, we bridge capability gaps to help government agencies work faster, grow smarter, and stay nimble in the face of change. Wherever our customers are in their modernization journey, we are the trusted navigator in the path to possible.

 

Follow us on LinkedIn

#PoweringPossible

 

Who You Are:

You are a talented Senior Cybersecurity Policy Analyst with at least 3 years of experience and a passion for thinking big, taking action, and delivering exceptional results. You are outcome-driven, quality-obsessed, and relentlessly focused on innovation as a value-driver for world-class delivery, client satisfaction, and performance. You’re looking to grow as a professional in a team-oriented environment where you can put your fingerprint on mission-critical projects impacting the citizens we serve.

Military Veterans and individuals with disabilities are encouraged to apply! 

 

About This Role:

Favor TechConsulting, LLC (FTC) a wholly-owned subsidiary of Tria Federal (Tria) is seeking a talented Senior Cybersecurity Policy Analyst. Lead the analysis, design, implementation, and support of cyber security policy—specifically as it pertains to Risk Management Framework (RMF) Step 6: Monitor—by collaborating with business customers, end-users, and project managers to capture and document business and technical requirements. Support the full lifecycle of requirements management and implementation by participating in requirements elaboration and design, and then ensuring developed written policies and other associated deliverables match requirements. Specifically, support the development of the Department of Veterans Affairs (VA) Information Security Continuous Monitoring (ISCM) Program through stakeholder engagement, policy development, metric development, and tool/data source cataloging. Apply a deep understanding of RMF, and NIST Special Publications such as 800-137, 800-37, 800-53, and 800-55 to the development of contract deliverables and all recommendations to the customer.

Responsibilities:

  • Develop and update cybersecurity policies, standards, and procedures based on best practices and regulatory requirements. Ensure policies are aligned with organizational goals and objectives
  • Collaborate with stakeholders to elicit, gather, analyze, and implement business requirements for cyber security policies. Participate in requirements gathering, elaboration, and refinement sessions with VA stakeholders
  • Achieve complete technical understanding of the existing VA ISCM and Continuous Diagnostics and Mitigation (CDM) programs, including but not limited to:
    • Systems architecture, physical and logical network architectures, metrics, data sources and flows, dashboards, other tools, applications, and hardware in use
    • Associated objectives, strategies, plans, and other existing documentation
    • Governing and applicable policies, directives, guidance, etc.
  • Develop, update, and oversee the implementation of organizational-level and system-level metrics for the ISCM Program, leveraging a deep understanding of NIST SP 800-53 and the existing tools/capabilities at the agency
  • Continuously review the existing ISCM tools and data sources at the agency for changes, additions, and disposals. Document findings in a Tools Catalog with relevant information on tool interconnections, reporting frequencies, and capabilities. Provide recommendations for catalog improvements and updates
  • Propose and/or coordinate reviews, development, and/or updates of security policies, processes, workflows, controls, metrics, and procedures
  • Design and support the development and implementation of security policies aligned with FISMA and applicable VA documents
  • Intake, upload, track, and manage business requirements, task management with project management planner and tracking tools designated by customer
  • Perform problem analysis and analyze, validate, specify, and verify requirements defined by project leads, customers, and end users
  • Analyze existing business processes, business requirements, and workflows to document “as is” processes and proposed “to be” solutions to guide requirements development efforts
  • Facilitate executive-level

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Tria Federal (Tria)

View company profile →