- Lead a cybersecurity risk management and risk governance workstream within an agency
- Oversee, manage, and lead development and execution of cybersecurity risk governance
- Maintain and improve the enterprise-level risk register
- Oversee technology risk assessments, including Tier 1 assessments supporting Technology Review Board decisions
- Prepare risk acceptance memoranda for CISO and CIO approval
- Conduct limited FOCI-style assessments to support agency decision‐making
- Interpret and adapt guidance for Tier 1 enterprise risk assessments
- Scope technology risk assessments, confirm outputs and required elements, and prepare decision‑support deliverables
- Prepare plans and goals to improve the cyber risk register and support agency cyber risk profiles
- Prepare and implement corrective action plans addressing open GAO or OIG recommendations
- Incorporate federal cybersecurity frameworks into evaluations and assessments
- Prepare and update risk management plans, standard operating procedures, and project schedules
- Present technology risk assessment findings and recommendations to technical and executive audiences
- Prepare briefing materials for weekly reports and specific audiences
- Advise on assessment severity and recommend courses of action to government stakeholders
- Adapt guidance and technical assistance to resource constraints, knowledge variability, and government leadership direction
Requirements
- Active and current Secret federal security clearance
- Bachelor’s Degree from an accredited university
- Minimum of five years of relevant cybersecurity experience
- US Citizenship contractually required
- Excellent verbal and written communication skills, specifically in report writing
- Certified in CISSP, CRISC, CAP/CGRC, CISA, or another relevant field
- Experience interpreting and applying federal cybersecurity requirements and frameworks
- Ability to conduct and scope technology risk assessments
- Ability to prepare risk acceptance memoranda, risk management plans, SOPs, schedules, briefings, and corrective action plans
- Nice to have: consulting experience with large federal agencies such as the Department of State, Department of Justice, or Department of Homeland Security on cybersecurity audits and/or IT controls
- Nice to have: external client‑facing management and/or consulting experience for large firms
Core Competencies
Demonstrates expertise in cybersecurity risk management, including the ability to conduct technology risk assessments, prepare risk management plans, and adapt federal cybersecurity frameworks. Strong communication skills are essential for presenting findings and recommendations to both technical and executive audiences.
Highest-signal resume keywords
- Cybersecurity Risk Management
- Technology Risk Assessments
- Risk Governance Development
- CISSP Certification
- Federal Cybersecurity Frameworks
ATS Optimization Keywords
Hard Skills
- Risk Management Plans
- Risk Acceptance Memoranda
- Standard Operating Procedures
- Corrective Action Plans
- Technology Review Board Assessments
- FOCI-Style Assessments
- Decision-Support Deliverables
- Cyber Risk Register Improvement
- Report Writing
- Project Schedules
Soft Skills
- Excellent Verbal Communication
- Excellent Written Communication
- Advisory Skills
Certifications & Qualifications
- CISSP
- CRISC
- CAP
- CGRC
- CISA
Industry Keywords
- Federal Security Clearance
- Cybersecurity Audits
- IT Controls
- Department of State
- Department of Justice
- Department of Homeland Security