- Oversee, manage, and lead cybersecurity risk management, risk governance, risk assessments, and high-value asset oversight and assessments
- Maintain and improve the enterprise-level risk register
- Coordinate and plan enterprise and organizational unit risk assessments
- Oversee specified technology risk assessments and HVA oversight program functions
- Provide strategic direction and guidance to workstream team leads and support cross-training
- Review and advise on deliverables and perform QA/QC for all workstreams
- Advise on and incorporate federal cybersecurity frameworks into evaluations and assessments
- Develop, maintain, and provide input on agency-wide cybersecurity policies, procedures, and documentation
- Prepare and update risk management and HVA-related plans, SOPs, and project schedules
- Provide expert guidance to system owners, analysts, and leadership on cybersecurity best practices
- Lead discussions with agency stakeholders and provide standardized technical assistance
- Present complex risk assessment and HVA assessment findings and recommendations to technical and executive audiences
- Prepare briefing materials for weekly reports and specific audiences
- Advise on assessment severity and recommend courses of action to government stakeholders
- Collaborate with internal teams and external stakeholders, including CISA and the Department of State
Requirements
- Active and current Secret federal security clearance
- Bachelor’s Degree from an accredited university, or a Master’s Degree and five years of relevant experience
- Seven years of relevant cybersecurity experience, or five years with a Master’s Degree
- US Citizenship is required
- Excellent verbal and written communication skills, specifically in report writing
- Certification in CISSP, CRISC, CAP/CGRC, CISA, or another relevant certification
- Experience with cybersecurity risk assessments, risk governance, and high-value asset oversight
- Familiarity with federal cybersecurity mandates, including CISA and OMB Directives
- Knowledge of NIST guidance and principles related to risk management and risk assessment
- Familiarity with NIST IR 8286, SP 800-171, SP 800-60, SP A, FIPS 140-3, and FIPS 199
- Familiarity with project management techniques and methodologies
- Ability to present complex findings to technical and executive audiences
- Experience consulting at large federal agencies and on cybersecurity audits and/or IT controls is nice to have
- Demonstrated external client-facing management and/or consulting experience for large firms is nice to have
Core Competencies
Demonstrates expertise in cybersecurity risk management, including risk assessments and governance, while providing strategic guidance and oversight for high-value asset programs. Proficient in developing and maintaining cybersecurity policies and procedures aligned with federal frameworks and mandates.
Highest-signal resume keywords
- Cybersecurity Risk Management
- Risk Assessments
- CISSP Certification
- NIST Guidance Familiarity
- Excellent Communication Skills
ATS Optimization Keywords
Hard Skills
- Risk Governance
- High-Value Asset Oversight
- Cybersecurity Audits
- Project Management Techniques
- Federal Cybersecurity Frameworks
Soft Skills
- Verbal Communication
- Written Communication
- Client-Facing Management
Certifications & Qualifications
- CISSP
- CRISC
- CAP
- CGRC
- CISA
Industry Keywords
- Federal Cybersecurity Mandates
- CISA
- OMB Directives
- Risk Management
- Risk Assessment
Tools & Technologies
- NIST IR 8286
- NIST SP 800-171
- NIST SP 800-60
- NIST SP A
- FIPS 140-3
- FIPS 199