Cybersecurity Risk & Compliance Specialist

Idaho National LaboratoryIdaho Falls, ID
Onsite

About The Position

As a Cybersecurity Risk and Compliance Specialist in the Computer Engineering department at Idaho National Laboratory, you’ll shape the future of national energy supply by performing mechanical design and analysis of advanced nuclear reactors and associated systems. You’ll collaborate with world-class scientists and engineers to develop designs that enable advanced nuclear reactor projects through multiple INL program sponsors. This position is located at our Materials and Fuels Complex, which hosts the core of the U.S. nuclear research and development capabilities with a diverse array of nuclear facilities and reactor experiment test beds. In this role you will collaborate with multiple organizations within INL and external reactor developer partners. Our team works a 4x10 schedule every Friday off. You will develop and evaluate compliance with programs and processes to mitigate cybersecurity risk and ensure protection of company and allied assets and information. Research and interpret current and pending governmental laws and regulations, industry standards and customer and vendor contracts to communicate compliance requirements. Conduct information security risk assessments, security compliance audits and cybersecurity audits. Document, investigate, and report cybersecurity compliance issues and incidents. Work with business leaders to ensure information security risk findings are reviewed and solutions are implemented.

Requirements

  • Bachelor's and 5 years of experience OR Master's and 2 years of experience OR PhD and 2 years of experience (for Level 3).
  • Bachelor's and 9 years of experience OR Master's and 6 years of experience OR PhD and 4 years of experience (for Level 4).
  • Must have the following Professional Certifications: ISC2 CISSP, COMPTIA Security+, Cloud+, Network+, Project+.
  • Ability to obtain and maintain a Department of Energy "Q" clearance, which requires US Citizenship.

Responsibilities

  • Establish and maintain an appropriate IT/OT Cyber risk management methodology and work with management to document those items and risk.
  • Develop indicators and metrics for material technology risks, obligations, and controls.
  • Collaborate with stakeholders across the organization to reduce the likelihood and potential impacts to risks that could be realized.
  • Utilize the integrated risk management platform to monitor and report on the effectiveness of risk management controls and processes and make recommendations for improvement as needed.
  • Coordinate the cybersecurity audit program.
  • Act as the audit liaison to facilitate successful coordination with external auditors and the Lab.
  • Coordinate audit meetings, assessments activities, and requests.
  • Represent the Cybersecurity risk management program to INL senior leadership, DOE-ID, DOE-NE oversight, and internal and external auditors.
  • Coordinate with accountable Subject Matter Experts to ensure development and appropriate management approval of corrective action plans to address audit findings.
  • Submit corrective actions to the CISO and unclassified ISSM.
  • Track and communicate audit finding remediation milestones and due dates.
  • Provide status and milestone updates to DOE.
  • Ensure accountable Subject Matter Experts and management are aware of commitments to remediate findings and the status of ongoing remediations.
  • Maintain external audit findings in DOE’s Enterprise Cybersecurity Enterprise Governance (ECGS) system.
  • Serve as an advisor on all matters, technical and otherwise, involving security of assigned information systems.
  • Develop policy, programs, and guidelines for implementation.
  • Maintain communication channels with stakeholders.
  • Promote awareness of cyber policy and strategy as appropriate among management and ensure sound principles are reflected in the organization's mission, vision, and goals.
  • Assess policy needs and collaborate with stakeholders to develop policies to govern cyber activities.
  • Review, conduct, or participate in assessments and audits of cyber programs and projects.
  • Other duties as assigned.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service