Cybersecurity Policy Analyst

Gunnison Consulting Group•Bethesda, MD
•$95,000 - $107,000•Hybrid

About The Position

The Policy Analyst will lead Security Policy and Standards Support for ZTA Operationalization, under the NIH Governance, Risk & Compliance (GRC) Zero Trust Architecture (ZTA) Support Services task order for the NIH Office of the Chief Information Officer (OCIO). Working in the Risk & Policy Pod, the candidate will turn federal and HHS Zero Trust mandates into a single, enforceable NIH policy framework. The candidate will also support communications and governance. This role involves building a single policy framework, tracing policy statements to their sources and enforcement mechanisms, inventorying and benchmarking NIH security policies against various NIST frameworks and current threats, developing policy anchors, writing ZTA Policy Briefs and enterprise communications, and aligning policy with AI governance and data management requirements.

Requirements

  • US Citizenship required
  • 8+ years in federal cybersecurity policy, governance, or compliance.
  • Working knowledge of HHS IS2P, FISMA, NIST frameworks, and OMB M-22-09.
  • Experience applying ERM principles to security policy.
  • Excellent technical writing and policy-drafting skills.
  • Bachelor's degree
  • Security+ or CAP/CGRC certification.
  • Ability to obtain and maintain a Public Trust clearance.

Nice To Haves

  • HHS or NIH policy development and approval experience.
  • CISSP, CISM, or CGRC certification.
  • Zero Trust policy experience; privacy knowledge (Privacy Act, HIPAA, research data).

Responsibilities

  • Build the Single Policy Framework: NIH ZTA policy, then standards by pillar, then implementation guides by workload family, then procedures, with an enterprise risk management (ERM) risk-appetite statement at the top.
  • Trace every policy statement up to its federal or HHS source (EO 14028, OMB M-22-09, HHS IS2P, HHS ZTA Strategy) and down to the Overlay control, architecture pattern, and governance checkpoint that enforce it.
  • Inventory NIH security policies, IS2P-derived standards, and procedures. Benchmark them against NIST SP 800-53 Rev 5, 800-207, 800-63-4, the CISA ZTMM, and current threats (MITRE ATT&CK). Produce a gap register with draft language and an adoption path.
  • Develop policy anchors, each made up of the policy statement, the technical setting that enforces it, the evidence that proves it, and the owner. Start with identity (conditional access), devices, networks, and data (classification labels driving DLP).
  • Write ZTA Policy Briefs and role-based monthly enterprise communications with the NIH ISAO Communications Team. All content must conform to Section 508.
  • Align policy with AI governance (NIST AI RMF, OMB AI memoranda, HHS AI strategy) and with data-management requirements (NIH Data Management and Sharing Policy, Privacy Act, HIPAA where applicable).

Benefits

  • 3 weeks of Personal Leave your first year
  • 11 paid Holidays each year
  • 5 days of Flexible Time Off each year for approved training or certifications
  • 401(k) company match at 50% up to 10% of your salary
  • Medical, Dental and Vision Insurance
  • Life and Disability Insurance
  • Public Transportation Subsidies
  • Certifications and Training Allowance - Up to $5,000/year!
  • bonus and profit-sharing opportunities
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service