Cyber Security Program Analyst
Delaware Nation IndustriesAbout the role
Overview
The Cyber Security Program Analyst provides cyber security support for the Enterprise Information Services for the Department of Energy (DOE) Savannah River Operations Office (DOE-SR), at the Savannah River Site (SRS) in Aiken, SC. This position leads the Cyber Security Assessment Team (CSAT) and is responsible for assisting in the planning, development, and review of Computer Security Program Management planning activities in support of DOE oversight role, and support to the Authorizing Official Designated Representative (AODR) in the development and coordination of Boundary Security Risk Assessments, Accreditation approvals, certifications of systems and program corrective action. This role is critical in ensuring that Governance, Risk and Compliance (GRC) functions are incorporated into key security services and Risk Assessment programs, while validating risk mitigation functions through analysis and Security Assessments across the DOE Enterprise.
Responsibilities
• This role will include leveraging knowledge of security policies, standards, controls, and industry best practices to consult with partners across the DOE complex• Will be involved in playing a critical role in ensuring that Governance, Risk and Compliance (GRC) functions are incorporated into key security services and program while validating risk mitigation functions are functioning correctly.• Document and assist others in documenting security domain specific policies, standards, controls, control operating procedures.• Liaise with GRC and stakeholders to ensure alignment between all groups.• Must take ambiguous high-level language and translate it into real world operations.• Diplomatically influence teams to implement a Governance Framework showing the value it will bring and tactfully help adjust existing operations to align with the framework.• Stay current on information security technologies, trends, standards and best practices.• Develop and understand Information Technology (IT)/cybersecurity strategies, policies, and guidelines for secure implementations• Assess policy needs and collaborate with stakeholders to develop policies to govern IT/cyber activities• Review, conduct, or participate in audits of cyber programs and projects• Support management in the formulation of IT/cyber-related policies and provide expertise to course of action development• Develop, implement, and recommend changes to appropriate planning procedures and policies• Facilitate the sharing of “best practices” and “lessons learned” throughout the IT/ cyber operations community• Provide subject matter expertise to planning teams, coordination groups, exercise, and task forces as necessary• Provide input for the development and refinement of the IT/cyber operations objectives, priorities, strategies, plans, and programs• Document lessons learned that convey the results of events and/or exercises• Initiate, develop, and work data audits by collecting and reviewing all requirements and ensuring the correct information and data are prepared for team lead. Supporting and improving internal controls and data projects.• Assist in developing data briefings for high-level executives.• Assist with development of internal organization policies and procedures, which affect cross-functional activities and best practices.• Create SOPs, including process maps, for developed dashboards and reporting procedures.• Research of emerging technologies that have potential for exploitation and the impact on systems• Provide and leverage industry best practices and lessons learned of external organizations and academic institutions dealing with cyber issues• Analyze and assess internal and external partner (i.e., EM-HQ, DOE OCIO) cyber operations capabilities and tools.• Assist DOE-SR Cyber Security with developing and maintenance of Cyber Lab.• Develop and perform Cyber Security Awareness training• Develop outcome-based measures (metrics) to determine the effectiveness and efficiency of the cyber security program and security controls
Knowledge, Skills and Abilities:
• Attention-to-detail is critical, proven ability to look closely at your work to identify and correct errors, spot and improve weaknesses and produce a near-perfect end-result.• Ability to identify problems, brainstorm and analyze answers, and implement the best solutions.• Ability to function in a collaborative environment, seeking continuous consultation with other analysts and experts—both internal and external to the organization—to leverage analytical and technical expertise. Participate as a member of planning teams, coordination groups, and task forces as necessary• Ability to socialize and influence others to buy into a process-oriented approach to their work.• Ability to gain a deep level of technical and process knowledge across multiple security domains in a short amount of time.• Ability to think both strategically and tactically t
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s